Skip to main content

About

What cvebuzz is

CVE history
1999–present
Public records from the NVD
Evidence classes
4
Coverage, KEV, OTX, and PoC

cvebuzz is a free, public reference for tracking which Common Vulnerabilities and Exposures (CVEs) are actively being discussed, exploited, or written about right now — and for searching the full historical CVE archive back to 1999. We built it because the official CVE record tells you what a vulnerability is, but not whether anyone is talking about it — and that second question is often what actually matters for triage.

How the trending score works

Each CVE's score blends how often it's mentioned across our tracked sources, how many distinct sources and categories are covering it (a single noisy source counts for less than broad, independent coverage), whether it appears on CISA's Known Exploited Vulnerabilities (KEV) catalog, whether AlienVault OTX has observed related pulse activity, and whether a public proof-of-concept (PoC) repository exists on GitHub or GitLab. These are treated as genuinely different strengths of evidence — a raw mention is not the same as confirmed real-world exploitation.

Where the data comes from

CVE records, publication dates, and CVSS scores come directly from the National Vulnerability Database (NVD). Exploit and mention signals are pulled from official APIs and public RSS/Atom feeds — vendor security advisories and research blogs, independent security news outlets, government advisories, and dedicated exploit-tracking feeds — plus Hacker News, Reddit, GitHub (code search and repository topics), GitLab, CISA KEV, and AlienVault OTX, all through their official APIs. We never scrape GitHub, GitLab, or Bitbucket HTML pages for exploit discovery.

Vendor/product tags are beta

Vendor and product tags shown on CVE pages are extracted from NVD's CPE data with a lightweight, best-effort matcher — they do not yet account for version ranges or the full AND/OR structure NVD sometimes encodes. Pages showing these tags are explicitly labeled beta; treat them as a helpful starting point for discovery, not an authoritative product-affected list.

Advertising

cvebuzz plans to use Google AdSense to help cover its operating costs. If advertising is enabled, ads will be clearly separated from CVE content and will never influence which CVEs are ranked or how they're scored. See our Privacy Policy for details on advertising cookies.

Questions, corrections, or feedback? Visit our Contact page.