Platform · Discover

Vulnerability intelligence

Every year brings far more known weaknesses than any team can fix. The work that matters is spotting the ones an attacker is likely to use, and showing the evidence for it.

The concept

Vulnerability intelligence is the work of deciding which weaknesses deserve attention now, out of the long list a scan produces. A single piece of software may carry dozens of known flaws, each filed as a CVE, the public catalog entry that names a specific vulnerability. On its own, a CVE says only that a flaw exists, and stops short of telling you whether it matters to you.

Several scoring systems try to make sense of those flaws. The oldest, the Common Vulnerability Scoring System, or CVSS, rates how much damage a flaw could do if someone exploited it. A newer one, the Exploit Prediction Scoring System, or EPSS, published by FIRST, estimates the chance that a given flaw will be exploited within the coming month. Alongside them, CISA keeps its Known Exploited Vulnerabilities catalog, a running record of the flaws attackers are using in the wild right now. Read together, they give a clearer picture of real risk.

Where the industry falls short

The first problem is volume, and it keeps getting worse. The CVE program published roughly 40,000 vulnerabilities in 2024, and more than 48,000 in 2025, each year setting a record. No team can fix that many, so the whole exercise comes down to choosing what to fix first.

Most programs sort by CVSS. CVSS was only ever designed to describe how severe a flaw is, and it was never meant to predict how likely anyone is to exploit it. Because a large share of vulnerabilities are rated high or critical, sorting by that score leaves a team facing thousands of items all marked urgent. In practice only a thin slice of everything published is ever used by an attacker. So a program that chases every critical spends most of its effort on flaws no attacker will touch, and the ones being used in real attacks stay buried in the pile.

The Verskop difference

Ranked by what is being exploited.

Verskop puts prioritization first, and it draws on more than one reputable source so a single feed cannot skew the result.

48,000+ CVES A YEAR THE FEW TO FIX FIRST EXPLOITED NOWon CISA KEV LIKELY SOONEPSS 0.96 EXPLOITED NOWon CISA KEV

Most published flaws are never exploited. Verskop pulls out the ones being exploited now, on the CISA catalog, or likely to be soon by EPSS, and ranks those to the top.

Corroborate

More than one source, cross-checked

Every flaw Verskop detects is matched against several authorities at once: the National Vulnerability Database for the underlying record, CISA's catalog to see whether the flaw is being exploited in the real world right now, and FIRST's EPSS for the odds it will be exploited soon. Verskop corroborates across them, so a source that is briefly offline or plainly wrong cannot quietly distort the result. Coverage holds even when one feed drops out.

  • NVD, CISA KEV, and EPSS consulted together on every flaw
  • Cross-checking that raises confidence when the sources agree
  • Coverage that holds when one source is unavailable
Match

Version-aware, so patched hosts are spared

A flaw only counts against a host that is genuinely affected. Verskop matches vulnerabilities to the specific version it observed, so a server that has already been patched is not charged for a CVE it no longer carries. This keeps the report clear of old flaws that were closed long ago.

  • Vulnerabilities matched to the exact version observed on the host
  • Patched hosts kept clear of flaws they have already fixed
Rank

The top of the list earns its place

What reaches the top of a Verskop report is ordered by what is genuinely being exploited or likely to be, with severity as one input among several. Every entry carries the citation that backs it, so the ranking can be checked against the source. The point is a list short enough to act on, aimed at the flaws that put you at risk.

  • Ordered by real-world exploitation and probability, with severity as one input
  • Every ranked entry cited, so the order can be verified

The standards this rests on

National Vulnerability Database (NIST) CISA Known Exploited Vulnerabilities EPSS (FIRST) CVSS (FIRST) CVE Program

Every figure above is sourced. The only claim that is ours is what Rampart Cybersecurity LLC and Verskop do.

See it on your domain

See the flaws that put you at risk.

We will run it against a target you authorize and show you the findings ranked by what is being exploited, each one cited.