Every list on the site, unless you choose “Newest”, is sorted by the same comparison, applied in this order:
- In CISA KEV before not in KEV.
- Higher EPSS probability first. A CVE with no EPSS score goes after those that have one.
- Higher published CVSS score first, taking the highest among the published assessments.
- More recent first: date added to KEV, or publication date.
The rule is one function in the site’s code and is covered by tests, including the case that motivated it: a CVE rated 10.0 that nobody is exploiting must not come before one rated 4.3 that is in KEV.
How collection works
A scheduled job on the site’s edge worker runs every four hours and does one part of the work per run. Every other run it downloads the KEV catalog and rebuilds the list. The runs in between take turns: one asks FIRST for the EPSS of every listed CVE in batches of 100, one asks the NVD for the CVSS and dates of KEV entries, and one asks the NVD for CVEs published in the last 7 days with a CRITICAL rating. The result is stored as one file, /data/kev.json, which the pages read.
So a new KEV entry appears within eight hours, and EPSS scores and recent critical CVEs are refreshed once a day. The NVD limits anonymous clients to 5 requests per 30 seconds, so the job refreshes NVD data for KEV entries one slice per run, asks first for entries it has no NVD data for, and keeps the rest from earlier runs. The window of recent critical CVEs is read one or two days at a time, and the catalog states the days it covers.
Snapshot or scheduled collection
Each page carries a label. Scheduled collection means the catalog came from that job. Build snapshot means the data was collected once when the site was built: the copy bundled with this build was collected on 3 Oct 2026, with KEV catalog version 2026.10.02 and the EPSS model of 2 Oct 2026. Pages of individual CVEs and of weeks are generated at build time and keep the date of that build.
Known limits
- The watchlist only sees new CVEs that already have a CRITICAL rating on the NVD. A serious CVE that nobody has scored yet does not appear until it is scored or enters KEV.
- Vendor and product of CVEs outside KEV come from the first CPE in the NVD record, which is missing for many recent CVEs.
- Affected versions are shown only where the CVE record has structured version data.
- Lookups in the CVE lookup and the EPSS lookup depend on the CVE Program and FIRST APIs answering your browser at that moment.