Harpia - harpy eagle emblemHARPIAExploitation Intelligence

How it works

Harpia answers one question about any CVE, advisory, or software component: is it being exploited right now? - and turns the answer into a decision your team can defend: Immediate, Out of cycle, Scheduled, or Defer.

The exploitation feed

The feed tracks 613,585 distinct vulnerabilities (371,133 CVEs, 237,692 malicious packages and 4,760 advisories carrying no CVE), merged and de-duplicated from NVD, OSV.dev distribution feeds, CISA KEV, EPSS, exploit databases, and public repository telemetry - then scores every record continuously against real-world exploitation signals: public exploit code, weaponized tooling, KEV listings, ransomware campaign use, EPSS probability, and trending activity across the ecosystem.

The proportions are the whole story: of the CVEs tracked, roughly one record in 16 carries exploit evidence, about 1% ever gets weaponized, and under 1% are confirmed exploited in the wild. Severity scores cannot find that sliver. Evidence can - so every record sits on a maturity ladder:

Every CVE page opens with a verdict banner that states the current rung plainly - with the exploit-evidence count, KEV status, ransomware use, and trending state beside it. That count is not a count of exploits: it adds up exploit repositories, PoC and weaponized-tool references, and in-the-wild sightings, so the page breaks it down rather than leaving one number to be read as "N working exploits". When a CVE climbs a rung, the verdict changes the moment the feed does.

One search box resolves everything: CVE IDs, vendor advisories (GHSA, RHSA, USN, DSA, SUSE-SU, ALSA, …), free text, and a structured query language built for triage:

product:openssl version:<3.0
kev:true ransomware:true
epss:>0.9 has:exploit
cwe:rce vendor:microsoft

Advisory aliases are first-class citizens: searching USN-7001-1 lands on the CVE it patches, and every record lists its aliases grouped by vendor - the same vulnerability never hides behind a different name.

Exploit landscape

The landscape view turns the feed into the numbers an operations team actually uses: what is exploited today, what got weaponized this week, which vendors and weakness classes are taking hits, and what is trending before it peaks. It is the same data the search and CVE pages serve - aggregated, never sampled - and it is where the collapse of time-to-exploit is measured, year by year.

The decision framework - tuned to your environment

A severity score is not a decision. Harpia runs every finding through a Stakeholder-Specific Vulnerability Categorization (SSVC) policy engine, live, on every request:

Select SSVC for Immediate, Out of cycle, Scheduled, or Defer, each with its matching 3-day, 14-day, 60-day, or system-upgrade timeline. Select BOD 26-04 for the CISA remediation table using KEV membership exactly, including forensic triage when required. Change the exposure knob and the selected framework recomputes instantly. Decisions are always computed live; nothing is cached, nothing is pre-baked, and a CVE weaponized overnight changes its answer the moment the feed updates.

Get started

The homepage search is free and needs no account - the verdicts you see there are the same ones the API serves, minus the proprietary scoring.

Create a free account to mint an API key, raise your limits, and unlock trending and risk scores plus the live SSVC decision per CVE. References, exploit repositories, threat attribution, bulk lookup and delta sync are Pro and up. Or read the API documentation Search syntax to wire the feed into your own pipeline, including the STIX 2.1 / TAXII 2.1 feed.