AKalenkrga.com Vulnerability Intelligence

DECISION SUPPORT / PUBLIC DATA

From CVE to a priority
you can explain.

Technical severity, exploitation probability, confirmed active exploitation and your asset context — without a black box.

Up to 10 CVEs, separated by commas, spaces or new lines.0 / 10
Asset context

Describe the vulnerable component, not only the host or application as a whole.

METHODOLOGY v2.0

Rule-based remediation priority

The result orders remediation work. It is not a probability of exploitation, compromise or loss.

PRIORITY = EVIDENCETECHNICAL SEVERITYCONTEXT
  1. Exploitation evidenceCISA KEV first; EPSS probability is a likelihood input. Percentile is informational only.
  2. Technical severityCVSS Base severity; missing CVSS is treated as a data gap, not a low score.
  3. Asset contextComponent reachability and business criticality can escalate; verified relevant controls can reduce one level.

Base from CVSS: ≥9.0 → P2; 7.0–8.9 → P3; below 7.0 → P4. Missing CVSS → DATA.

Modifiers: EPSS ≥10% raises one level; internet reachability or critical asset raises one; verified relevant controls on a segmented/isolated component reduce one.

P1: applicable KEV with an internet-reachable component or critical asset and no verified mitigation; non-KEV reaches P1 through the documented modifiers.

P2 floor for KEV: other applicable KEV records cannot be reduced below P2 by controls.

Unknown applicability: remediation priority is provisional and a separate V1/V2 verification priority is shown.

Rounding: none. The model uses decision rules; EPSS is displayed without rounding to 100%.

P1 ImmediateP2 AcceleratedP3 ScheduledP4 Monitor