Data sources and methods
Every number on the live pages comes from a public source. This page describes the data we use, what each source is used for and how the explanations are written.
The data we use
Used for: Exploited now
CISA Known Exploited Vulnerabilities catalog
The list of vulnerabilities that CISA has confirmed are being exploited, with the product each one affects and the date it was added.
Terms. US government work, public domain. CISA does not endorse this site.
Used for: Exploited now
NIST National Vulnerability Database: exploited CVEs
Severity scores and technical descriptions of the exploited vulnerabilities.
Terms. Public data. This product uses the NVD API but is not endorsed or certified by the NVD.
Used for: Exploited now
NIST National Vulnerability Database: new CVEs
Newly published vulnerabilities, shown as the count of new and critical CVEs.
Terms. Public data, as above.
Used for: Exploited now
FIRST Exploit Prediction Scoring System (EPSS)
The estimated probability that a vulnerability will be exploited.
Terms. Free to use. FIRST asks to be credited as the source.
Used for: Data breaches
Have I Been Pwned breach catalogue
The public list of data breaches: the name, the date, the number of accounts and the kinds of data that were exposed. We never look up email addresses.
Terms. Creative Commons Attribution 4.0.
Used for: Is it safe? and malware counts
abuse.ch URLhaus
Web addresses reported as distributing malware, with their threat tags and whether they are online. It also gives the malware URL counts.
Terms. Public download of abuse.ch, used under its fair-use terms.
Used for: Browser updates
Google Chrome release notes and version history
The current Chrome versions and the security fixes in each release.
Terms. Public release information of the vendor.
Used for: Browser updates
Microsoft Edge update data
The current Edge versions and the security fixes in each release.
Terms. Public release information of the vendor.
Used for: Browser updates
Mozilla product details and security advisories
The current Firefox versions and the security advisories for each release.
Terms. Public release information of the vendor.
Used for: Is it safe?
Domain registration data (RDAP)
The registration date, registrar and expiry of a domain, shown as the age of the site.
Terms. Public registry data, read through rdap.org.
How the plain-language text is written
The explanations on the vulnerability and breach pages are produced by fixed rules, not by a language model. A vulnerability's type is read from the name CISA gives it and mapped to a standard description of what that type allows an attacker to do. Whether it concerns home users, home network devices or businesses is decided from the vendor and product name. Breach advice is chosen from the kinds of data that leaked. Text quoted from a source is shown as a quotation with the source's name.
Because the rules are simple, they can be wrong for an unusual product. The facts in the table on each page always come unchanged from the source.
What the data cannot tell you
- The exploited list is not complete. It contains what CISA has confirmed. Other flaws are attacked without being listed.
- The site check is narrow. URLhaus tracks sites that distribute malware. It does not list phishing pages or fraudulent shops, so "no reports" never means "safe". We do not use a multi-engine scanner.
- Breach figures count accounts, not people, and only breaches that reached Have I Been Pwned.
Sources we do not use
We do not show ransomware victim listings: the available tracker forbids commercial use without written permission. We do not use VirusTotal, whose free interface is not licensed for commercial sites.
Articles
Removal guides, file descriptions, reviews and news are written by the editors named on each page. Links marked as advertisements are affiliate links. See the removal guides.