Methodology

How Vexday calculates a CVE's risk score, what each incident seal means and where the data comes from. Everything here can be checked: the sources are public and the formula is written out below.

Vexday Risk Score

A score from 0 to 100 that answers one question: how likely is this flaw to be used in a real attack? CVSS measures theoretical severity; the score adds evidence of exploitation on top. Each signal is worth fixed points:

  • CVSS 9.0 or higher25 points
  • CVSS 7.0 to 8.918 points
  • CVSS 4.0 to 6.910 points
  • CVSS below 4.05 points
  • EPSS of 70% or more25 points
  • EPSS of 30% to 69%15 points
  • EPSS of 10% to 29%8 points
  • EPSS below 10%3 points
  • Public proof of concept20 points
  • … and the most popular repository has 20, 100 or 500 stars+2, +5 or +8
  • Nuclei template or Metasploit module15 points
  • … and the Metasploit module is ranked great or excellent+4 or +7
  • Listed in CISA's KEV catalog (confirmed exploitation)30 points
  • Not in CISA's KEV, but in VulnCheck's KEV (observed exploitation)22 points

The sum is capped at 100. A CVE with no CVSS score or no EPSS scores nothing for that signal.

Bands

  • 0 to 30low
  • 31 to 60attention
  • 61 to 80high
  • 81 to 100critical

SSVC reading

Next to the score comes a recommendation in CISA's SSVC vocabulary, derived from the same signals:

  • Act: there is active exploitation (CISA or VulnCheck KEV) and the flaw is automatable (EPSS of 50% or more, PoC, Nuclei or Metasploit) or high impact (CVSS 7.0 or higher).
  • Attend: there is active exploitation without the conditions above, or a proof of concept or ready-made exploit exists.
  • Track: no known sign of exploitation.

Incident confidence seals

Every published incident carries a seal stating how much independent confirmation exists:

  • Claimed by the actor: Only the claim exists. Nothing has been corroborated yet.
  • Corroborated: An independent, legitimate source confirmed elements of the claim.
  • Confirmed: The affected organization or a regulator acknowledged the incident.

Verdicts

Besides the seal, each case receives a verdict on the original claim:

  • Real: the incident held up under investigation.
  • Inflated volume: there was an incident, but smaller than announced.
  • Recycled data: the data announced as new was already circulating from an earlier case.
  • Bluff: the claim did not hold up.
  • To verify: the investigation is still under way.

Source grading

Admiralty rating (NATO standard, used by CERT-EU and OpenCTI): the letter rates SOURCE reliability (A completely reliable to F not rated); the number rates INFORMATION credibility (1 confirmed to 6 cannot be judged). Both dimensions are assessed independently — a good source does not make weak information reliable.

Data sources

The database is built only from open sources: CVE List (CVE Program), NVD, FIRST EPSS, CISA KEV, VulnCheck KEV, Exploit-DB, PoC-in-GitHub, Nuclei, Metasploit, MITRE ATT&CK, MISP Galaxy, ransomware.live, abuse.ch, HTTP Archive.

Use of AI

The summaries and analyses on CVE pages and the daily briefing are written with language models from the cited sources, and say so on the page itself. The risk score does not use AI: it is the sum described above.

See also