
CVESSE - CVE Severity Search Engine
Real-time CVE tracking with unified severity scoring
What this is
Merges CVSS, EPSS, KEV, and CVE.org data into one unified per-vulnerability severity record, for anyone deciding what to patch first instead of checking four separate sources.
Our one-line summary — not the founder’s tagline.
- How it works
- Ingests NVD, CISA KEV, FIRST EPSS, and CVE.org into one pipeline covering hundreds of thousands of CVEs, running them through a priority-based severity engine to serve a unified record — CVSS, EPSS percentile, KEV status, affected vendors/products, and weaknesses — per CVE.
- What's different
- Built on Cloudflare's edge with a continuously running collection pipeline and visible source-freshness status.
What we measured
Nobody else publishes this — it comes from knocking on the door every day.
- Watched by us
- 7 days
- Last checked
- 1d ago
Where it shows up
Every group here is a page of its own — each one checked daily.
The numbersIs it still shipping, is it overpriced, where did it land — and what the price is built from.
League price & chart
No money. No seat. It goes on your record — and in 28 days reality settles it.
Calls are closed while we rebuild accounts. You can still read every one of them.
Analytics. Launched 7d ago on PeerPush, where it placed #530. Today, the site itself changed 1d ago — evidence it's still shipping, not just announcing.
Moving right now. The clock only starts when a launch goes quiet.
We check this site every day, ourselves. A founder can post “still working on it” — a claim like that doesn't price. What we price is what we can verify from the outside: evidence, not announcements. The real question isn't “will this be huge?” — it's “will they still be moving in four weeks?”
Shipping record
1 separate day we saw this ship · source: page changed
Beyan değil kanıt: founder “çalışıyoruz” diye post atabilir, ama sevk ettiyse izi kalır. ⚠️ Kaydı olmayan ürün “sevk etmedi” demek değildir — o üründe izleyecek bir kaynağımız yok demektir.
The market viewHow this launch is priced and ranked in our league — the investor side of the page.
ranked by the reality anchor, not the market price
It placed #530 on PeerPush with 4 votes.
No matter how much money goes in. There is no pump here — you can't make yourself right by buying more. The line only moves on things that actually happened: an award, revenue that grew, a new platform, code that shipped — or silence.
3 quiet days in between are left out — nothing happened on them. A launch that goes quiet eases down a little at a time — never a cliff you could have run from the night before.
No names, on purpose — a call is worth what it turns out to be worth, not who made it.
How the launch is moving on its own board, day by day — the crowd's attention.
A flat line is normal: votes stop within a day or two of launch, on every board. What's unusual — and what actually counts — is a launch that keeps pulling votes long after its day is over.
About
The problem: answering "what should I patch first?" today means checking NIST NVD for CVSS scores, CISA KEV for active exploitation, FIRST EPSS for exploit probability, and CVE.org for the authoritative record. Four tabs, four data formats, and no single ranking. What CVESSE does: it ingests all four sources into one pipeline covering hundreds of thousands of CVEs, runs them through a priority-based severity engine, and serves a unified record per CVE — CVSS, EPSS percentile, KEV status, affected vendors/products (CPE), and weaknesses (CWE) — so the most dangerous vulnerabilities surface immediately. Built on Cloudflare's edge, pages load fast globally and data stays fresh via a continuously running collection pipeline with visible source-freshness status. Feature list Unified CVE records — NVD, CISA KEV, EPSS, and CVE.org merged into one page per CVE; no more cross-referencing. Priority-based severity engine — every CVE ranked so critical, actively-exploited vulnerabilities float to the top. Live intel feed & severity dashboard — see the current threat landscape at a glance, filterable by severity. Vendor & product pages — browse every CVE affecting Microsoft, Cisco, your stack — one URL per vendor/product. CVE watches with email alerts — watch a CVE or a vendor, set alert rules, get emailed when severity, EPSS, or KEV status changes. Embeddable severity badges — shields.io-style SVG badge for any CVE (cvesse.com/badge/CVE-2024-3094.svg) for READMEs, advisories, and docs. API access with keys — programmatic access to CVE data for your own tooling and pipelines. Transparent data freshness — a sources page and per-page "Last Data Collection" card show exactly when each upstream was last synced. Fast everywhere — edge-deployed (Cloudflare Workers), aggressively cached, no login required to search. Who it's for SOC analysts triaging alerts, security researchers, DevOps/IT admins doing patch management, and anyone tired of tab-hopping between NVD, KEV, and EPSS.
Where it launched
1 platform| Platform | Votes | Counts toward price | Link |
|---|---|---|---|
| PeerPush | 4 | sets the price | ↗ |
The board it did best on sets the price. Every other board only adds to it if the launch also placed high on that board too — because just showing up somewhere isn't an achievement. Listing on twelve directories is free; placing well on them isn't.
Discussion (0)
No thesis posted yet. Be the first.