Who runs this site
CVEs Live (cves.live) is operated by Anderson Gomes Ferreira.
How it works
We combine three public datasets and sort by exploitation evidence rather than by severity alone. Data is collected automatically on a schedule and every table shows when it was collected.
Where the data and rules come from
- CISA Known Exploited Vulnerabilities catalog
- FIRST EPSS — probability of exploitation
- CVE Program
- NIST National Vulnerability Database
How we keep the content up to date
Data is collected automatically on a schedule and every table shows when it was collected.
What this site is not
Scores and flags come from the sources above and can be late, incomplete or revised. This is not a substitute for your own risk assessment or your vendor's advisory. We are not affiliated with CISA, FIRST, MITRE or NIST.
Transparency about automation
The pages are generated automatically from the public datasets listed; we do not write the vulnerability descriptions.
This page was last reviewed: