CVE Triage · for engineers who own security
Fix the 3 that matter, ignore the 200 that don't.
Your scanner flags 200 critical CVEs. CVSS says they're all 9.8. But EPSS says 3 have a real chance of exploitation this month, and CISA is only tracking 1. CVE Triage will rank your scan results by actual exploitability and give you a plain-English fix-this-week list.
In development, not available yet. Reserve a founding spot free, no card needed.
What CVSS scores won't tell you
200 critical CVEs, 3 are exploitable
Your container scan says 200 critical vulnerabilities. CVSS calls them all 9.8. But only 3 have known exploits in the wild. Which 3?
The CVE in a test dependency
Half your critical findings are in devDependencies or build tools that never touch production. Scanners can’t tell the difference.
NVD is months behind
NIST’s National Vulnerability Database stopped enriching CVEs in February 2024. Your scanner’s severity data is stale. EPSS and KEV are current, but your tools don’t use them.
How it will work
Upload scanner output
Paste or upload JSON from Trivy, Grype, Snyk, or Dependabot. Any format.
Declare your stack
Tell it your runtime (Node 20, Python 3.12, Go 1.22) and deployment target. CVEs that can’t affect your stack get filtered.
See what actually matters
Each CVE gets an EPSS probability (chance of exploitation in 30 days), KEV status (is CISA tracking it?), and a plain-English verdict.
Get your fix-this-week list
A ranked shortlist: fix these 3, monitor these 5, dismiss these 192. With one-line explanations your team lead can read.
Founding pricing
Reserve now at no cost. Founding members get CVE Triage first, at these prices.
Solo
$29/month
For individual engineers and small teams.
- 1 project
- Weekly scans
- EPSS + CISA KEV ranking
- Plain-English verdicts
- Fix-this-week shortlist
Free, no card. We'll email you when checkout opens.
Team
$79/month
For platform teams and DevSecOps.
- Unlimited projects
- Everything in Solo
- CI integration
- Slack alerts
- Team-wide triage dashboard
Free, no card. We'll email you when checkout opens.
Questions
Is this available today?
No. Reserve a founding spot free, no card needed.
How is this different from Snyk?
Snyk is a full platform at $105/dev/month. This is a triage layer you put on top of any scanner output — it ranks what you already have, without replacing your toolchain.
Where does the exploitability data come from?
FIRST’s EPSS API (public, updated daily) and CISA’s Known Exploited Vulnerabilities catalog (public). Both are more current than NVD CVSS scores.
Does it work with container scans?
Yes. Trivy and Grype container scan output is supported alongside filesystem and repository scans.
Is my vulnerability data safe?
Processing happens in your browser. Scanner output stays on your machine.