Skip to content

Data collected

CVEs Live

About CVEs Live

Vulnerabilities sorted by evidence of exploitation: the CISA Known Exploited Vulnerabilities catalog first, then FIRST EPSS probability, with CVSS shown as each source published it.

Who runs this site

CVEs Live (cves.live) is operated by Anderson Gomes Ferreira.

How it works

We combine three public datasets and sort by exploitation evidence rather than by severity alone. Data is collected automatically on a schedule and every table shows when it was collected.

Where the data and rules come from

How we keep the content up to date

Data is collected automatically on a schedule and every table shows when it was collected.

What this site is not

Scores and flags come from the sources above and can be late, incomplete or revised. This is not a substitute for your own risk assessment or your vendor's advisory. We are not affiliated with CISA, FIRST, MITRE or NIST.

Transparency about automation

The pages are generated automatically from the public datasets listed; we do not write the vulnerability descriptions.

This page was last reviewed: