About
What Hazard is
What attackers actually exploit — and what it costs when it works.
Two public datasets that belong together and have never been joined.
The first answers a question security teams ask constantly and no official source will answer plainly: is this vulnerability actually being exploited, right now? The NVD will tell you a CVE exists and give it a score. It will not tell you whether anyone has ever used it. We do, for all 1,655 vulnerabilities with evidence of real-world exploitation.
The second answers the question that follows: what happens when the answer is ignored? The ICO publishes every enforcement action it takes against UK organisations, in prose, across 217 pages that cannot be searched, filtered or totalled. We structured them — by cause, by sector, by amount. £53.48m in penalties, finally addable.
Put together, they tell one story from both ends. The failure modes regulators punish are the failure modes attackers rely on.
What it costs
Nothing, to anyone. No signup, no wall, no rate limit on the API. The site is static files built from free public feeds, so serving it costs nothing either — which is why it can stay free rather than starting free and turning into a sales funnel later.
Who runs it
Hazard — a UK information security practice. If your organisation appears anywhere on the enforcement register, or on the wrong end of the vulnerability half, that is the day job. Get in touch.
Not affiliated
Independent of CISA, NIST, FIRST, Exploit-DB and the Information Commissioner's Office. All four are credited and linked on every record that uses their data.