Vulnerability intelligence

    Look up a CVE, check whether attackers are exploiting it, and find the CISA advisories for industrial products, from data feeds Ansvar keeps in sync.

    Plan Every plan, Free included.

    Try it

    Using Ansvar, look up CVE-2024-3400: give me the CVSS score, whether it is in CISA KEV and its due date, the EPSS score, and any public exploits. Tell me when each feed last synced.

    More examples:

    Using Ansvar, list critical CVEs for OpenSSL 3.0.7 and mark which ones are in CISA KEV.
    Using Ansvar, find CISA ICS advisories for Siemens published since 2026-01-01 with CVSS 9 or higher, then open the most recent one and list the affected product versions.
    Using Ansvar, check this list of CVE ids in one batch and sort them by EPSS score: CVE-2023-4966, CVE-2023-34362, CVE-2024-21762.

    What comes back

    Your assistant gets structured records, not prose: the CVE, its severity score, whether it is on CISA's list of known exploited vulnerabilities, how likely exploitation is, and links to the source. It also learns when each data feed last updated, so it can tell you how current the answer is.

    For developers, the fields to read:

    • CVE id, CVSS vector and score, CPE mappings and references
    • KEV membership with the required action and due date
    • EPSS probability of exploitation in the next 30 days and its percentile
    • Exploit references (Metasploit, ExploitDB, GitHub proofs of concept)
    • ICS advisory id, affected vendors and product version ranges, referenced CVEs and the CSAF source URL
    • Per-feed last sync time, data age, record count and health state (current, stale, critical)

    Which plan

    Every plan, Free included. Premium also adds the CAPEC, CWE and D3FEND catalogues as searchable sources, for attack-pattern and weakness context. Rescoring a CVE for your own asset is effective risk: Team and Company can use effective risk directly. On Premium you cannot call it yourself: the vulnerability assessment, deferral dossier and ICS advisory-to-risk workflows use parts of it for you during a run.

    Tools

    Limits

    • The data is as fresh as the last sync. Before a decision that depends on today's KEV or EPSS state, have your assistant check feed freshness; a stale or critical feed is reported as such.
    • An empty search means no record matched your terms. It does not prove a product has no vulnerabilities.
    • CVSS, KEV and EPSS describe a vulnerability in general, not its risk in your environment.