CVE / vulnerability · OSINT
How dangerous is this CVE?
Not every vulnerability is urgent. The ones with public exploits and active attacks are what you patch first.
DARKSHARE pulls severity, exploit availability, EPSS probability and known-exploited status into a single priority score.
What we check
- ✓Severity — CVSS score and affected products from the NVD.
- ✓Exploit availability — public proof-of-concept and exploit-kit presence.
- ✓EPSS — probability the flaw will be exploited in the wild.
- ✓Active exploitation — presence in CISA's Known Exploited Vulnerabilities catalog.
Data sources we cross-reference
We cross-reference 27+ specialised sources (of 176+ total).
How the 0–100 risk score works
A CVE that's actively exploited or has a working public exploit ranks far above a high-CVSS bug with no exploit. We weight real-world risk, not just the base score.
Frequently asked questions
What's the difference between CVSS and EPSS?
CVSS rates how bad a flaw could be; EPSS estimates how likely it is to actually be exploited. Use both to prioritise patching.
Why does CISA KEV matter?
It lists vulnerabilities confirmed exploited in real attacks — those should be patched immediately.
Can I look up any CVE?
Yes, enter the CVE-YYYY-NNNN identifier.