Harpia continuously correlates exploit maturity, active exploitation, threat activity, and vulnerability context so security teams can prioritize remediation with evidence, not severity alone.
Sign in to search · No credit card · Machine-readable intelligence
HARPIA / LIVE LOOKUP
Is it exploited in the wild?
try
Advanced search syntax
Search syntax
CVE & advisory IDs
Full text
Scores & evidence
Threat flags
has: shorthands
Software
Weakness & combinations
Who & why Pro
Origin and target accept ISO-2, a country name, or a partial word.
ATT&CK, CAPEC & tactics Pro
Worked examples Pro
AND is implicit · OR / NOT / - / parentheses supported · quote a phrase to match it literally · click any example to run it
37.7%of exploited CVEs attacked before disclosure
60.7%under attack within 24 hours
93%of what CVSS calls Critical has no weaponized exploit
15 daysahead of CISA KEV
Threat pulse
Trending in the vulnerability ecosystem.
Movement matters. Harpia tracks rising exploit activity, public repositories, exploitation evidence and observed probing to surface what deserves attention next.
Trending now
Loading live feed signals…
Harpia platform
From vulnerability signal to remediation decision.
A focused intelligence layer for vulnerability management, SOC workflows, threat intelligence, and security products.
01 / Exploit intelligence
Know when vulnerability becomes attack.
Track PoCs, weaponization, exploitation in the wild, ransomware associations, repository activity, and evidence provenance.
Harpia separates theoretical impact from operational urgency, helping teams concentrate remediation capacity where attacker behavior changes the decision.