How this is built
Methodology
Every claim on this site traces to a named public source. Here is exactly how each judgement is made, including where it is weak.
The vulnerability half
The corpus is the CISA Known Exploited Vulnerabilities catalogue — vulnerabilities with evidence of exploitation in the wild. That is a deliberate scope choice. A site that answers “is it exploited?” by listing every CVE ever issued is answering a different question, and answering it badly.
Each record is enriched with:
- NVD — CVSS base score, vector, weakness classification, publication date.
- FIRST EPSS — the modelled probability that a vulnerability will be exploited in the next 30 days.
- Exploit-DB — whether working public exploit code has been published, and how much.
The verdict bands
The verdict is the one thing here that is a judgement rather than a feed. It is deterministic, and it is this:
- Used in ransomware — CISA has linked this vulnerability to known ransomware campaigns. Treat any exposed instance as an active incident, not a patching ticket.
- Weaponised — Reliable public exploit code exists, or mass exploitation attempts are probable. Patch inside days, not weeks.
- Confirmed exploited — CISA has evidence of active exploitation. This is not theoretical risk — someone has already used it against someone.
Precisely: ransomware association wins over everything. Otherwise an EPSS score at or above 0.5, or three or more published exploits, means weaponised. Otherwise a passed CISA remediation deadline means overdue. Everything else is confirmed exploited, which is still the top 0.5% of all CVEs by real-world risk.
Where this is weak: absence of public exploit code is not evidence of safety, EPSS is a model and not a measurement, and KEV lags reality — a vulnerability can be exploited for weeks before it is catalogued. We show the dates so you can judge the lag yourself.
The enforcement half
Records come from the ICO's own published enforcement listing. The ICO publishes everything here; what it does not publish is structure. There is no cause field, no machine-readable penalty amount, and no way to total anything. We derive:
- Penalty — the largest monetary figure appearing next to fine, penalty, ordered-to-pay or confiscation language, and only for action types that imply a payment. Notices mention several figures; this heuristic prefers the one in penalty context.
- Root cause — pattern matching against the notice narrative, using the taxonomy on the causes page. First match wins, specific before general.
- Sector — taken directly from the ICO's own tagging, not inferred.
Where this is weak: automated classification will occasionally misread a notice, and a penalty figure extracted from prose is not the same as one read off a structured filing. Every record links to the original ICO notice, which is always the authoritative version. Tell us when we get one wrong and it gets fixed in the next build.
Updating
The whole site rebuilds daily from source. Nothing is hand-edited between builds, so what you see is what the sources said at 29 July 2026.
Corrections
If a record here is wrong, say so. Corrections are made against the primary source, and the fix ships in the next daily build.