About & methodology
PatchRadar helps you answer one question: of all the CVEs out there, which should you fix first?
How we prioritise
Raw CVSS severity over-counts: most "critical" CVEs are never exploited. We combine three signals:
- Act now — the CVE is on the CISA KEV list (confirmed actively exploited).
- High — EPSS ≥ 50% (likely to be exploited soon), or CVSS ≥ 9.0 with a known exploit.
- Medium — CVSS ≥ 7.0, or EPSS ≥ 10%.
- Low — no strong exploitation signal.
Data sources
- NVD (NIST) — CVE descriptions, CVSS scores, affected products, references.
- CISA KEV — the catalog of known-exploited vulnerabilities, with patch-by dates.
- EPSS (FIRST.org) — daily probability that a CVE will be exploited in the next 30 days.
Data refreshes daily. EPSS and KEV cover the full CVE universe; NVD enrichment (CVSS, products, references) currently prioritises recently-modified and exploited CVEs and broadens over time.
Disclaimer
PatchRadar is an independent tool and is not affiliated with NIST, CISA or FIRST. Data is provided as-is for information only — always verify against the official sources before making patching decisions.