Exploitation Intelligence
Evidence-based exploit & vulnerability intelligence for vulnerability operations. Every number on this page comes from the live Harpia feed - the same data served by the API.
60.7% of exploited vulnerabilities are already under attack 24 hours after disclosure. 37.7% were under attack before the advisory was published at all. Time to exploit measures the gap between disclosure and the first confirmed exploitation in the wild, and across the last five years 64.5% were under attack by the end of the following day. A weekly patch cycle arrives after the fact in most of these cases.
Harpia tracks 62,032 CVEs published in 2026 across its merged vulnerability sources. Separately, Harpia tracks 237,692 malicious-package records across open-source ecosystems to date, covering all publication years. Tens of thousands of vulnerability records are labeled High or Critical, yet severity scores alone cannot tell you which handful will actually be used against you.
Harpia continuously merges, de-duplicates, and scores data from NVD, OSV.dev distribution feeds (Ubuntu, Debian, Red Hat, SUSE, Alma, Rocky), CISA KEV, EPSS, exploit databases, and public repository telemetry into one active view of the state of exploitation.
It answers one question about any CVE, advisory, or software component - is it being exploited right now? - and turns the answer into a decision you can act on.
One API call replaces dozens of upstream sources.
Harpia enriches every CVE with:
- Exploitation maturity - disclosed → PoC public → weaponized → exploited in the wild - with an exploit-evidence count and public exploit repositories.
- CVSS, EPSS probability, trending activity, CISA KEV status, and ransomware campaign use.
- Two live decision frameworks: SSVC returns Immediate, Out of cycle, Scheduled, or Defer with a matching deadline; BOD 26-04 returns the CISA KEV-based remediation timeline and forensic-triage requirement.
- CWE → CAPEC → MITRE ATT&CK mappings for every weakness.
- Affected software with version ranges and fixed versions, plus vendor advisory aliases (GHSA, RHSA, USN, DSA, SUSE-SU, ALSA, …) as first-class citizens.
- Machine-readable delivery: JSON API, bulk lookups (500 CVEs per request), delta sync, and a STIX 2.1 / TAXII 2.1 feed.
Vulnerability Prioritization
Move beyond severity scores to evidence of exploitation. The SSVC engine folds exploitation maturity and automatability together with your exposure and mission consequence, so teams fix the handful that matter instead of drowning in unexploited Criticals.
Threat Intelligence & Research
Track the exploit landscape as it moves: time-to-exploit trends, zero-day rates, survival curves, trending CVEs before they peak, and CWE → CAPEC → ATT&CK chains that explain how weaknesses are actually abused.
Security Product Enrichment
Enrich your platform with exploitation context per CVE: maturity, EPSS, KEV, ransomware use, and fixed versions. Bulk endpoints resolve 500 CVEs in one request; delta sync keeps your copy current without re-pulling the feed.
Application & OS Security
Distribution-aware intelligence from OSV.dev for Ubuntu, Debian, Red Hat, SUSE, Alma,
and Rocky. Vendor advisories resolve directly: search USN-7001-1 and land on
the CVE it patches, with affected and fixed version ranges.
SOC & Incident Triage
When a CVE surfaces in an alert, one lookup answers the triage question: exploited in the wild? weaponized? ransomware-linked? References and public exploit repositories give analysts the source material for deeper analysis.
SIEM & TIP Integration
A standards-compliant STIX 2.1 / TAXII 2.1 feed with collections, manifests, and search - ingest exploitation intelligence into your TIP, SIEM, or data lake with the tooling you already run. Explore it first in the embedded STIX explorer.
When a CVE is exploited it is usually exploited at once - of the 1,303 CVEs exploited within 90 days after disclosure or at any point in the six months before it, 60.7% were already under attack 24 hours after disclosure and 64.5% by the end of the following day. Each figure is cumulative: it counts every CVE exploited at or before that point, including those exploited before the advisory existed.
The KEV comparison covers 832 additions since 2023 that we hold independent evidence for, of which 639 carried a signal here first. It starts at 2023 deliberately: CISA launched KEV in November 2021 and spent its first year cataloguing older CVEs, which would hand us a head start we did not earn.
NVD has not finished analyzing 4,682 CVEs published more than 30 days ago; 3,976 of them already carry a CVSS score here. NVD has deferred a further 46,912 outright, of which 45,895 are scored here.
Every figure on this page is computed on the live feed and rendered with the page.
Every CVE in the feed sits on a four-rung maturity ladder. Each rung changes the decision the SSVC engine returns - and Harpia tells you the moment a CVE climbs.
1.Disclosed
Published, no public exploit observed. Advisory intelligence is aggregated and de-duplicated across NVD, OSV distribution feeds, and vendor advisories - aliases resolve to one record.
Exploitation feed2.PoC Public
Proof-of-concept code exists in the open. Exploit databases and public repository telemetry are tracked continuously - 39,143 CVEs currently carry exploit evidence - a public repository, a PoC or weaponized-tool reference, or an in-the-wild sighting - each linked to its sources.
Exploit tracking3.Weaponized
Reliable, packaged exploit tooling is available. 5,184 CVEs are flagged weaponized, and automatability is assessed - a non-overridable input that escalates the SSVC decision.
SSVC engine4.Exploited in the Wild
Active exploitation confirmed via CISA KEV, ransomware campaign use, and trending signals - 3,969 CVEs today. Decisions flip to Immediate or Out of cycle with BOD 26-04-aligned windows.
Live decisionsNo new dashboard, no new workflow. Harpia is delivered as data: a JSON API, bulk and delta endpoints, and a STIX 2.1 / TAXII 2.1 feed that drop into your SIEM, SOAR, vulnerability management tool, TIP, or security data lake. Decisions are computed live on every request - nothing is cached or pre-baked.
Exploitation Feed
- Maturity ladder
- Exploit counts & repos
- CISA KEV & ransomware
- EPSS & CVSS
- Trending signals
SSVC Decision Engine
- Immediate / Out of cycle / Scheduled / Defer
- Exposure & impact context
- BOD 26-04 windows
- Computed live, never cached
Search & Bulk API
- Query language & facets
- Advisory alias resolution
- Bulk: 500 CVEs / request
- Delta sync through the vulnerability change feed
STIX / TAXII Feed
- STIX 2.1 objects
- TAXII 2.1 collections
- CWE → CAPEC → ATT&CK
- Embedded STIX explorer
Every account carries two separate budgets. One for browsing this site, one shared by all of your API keys. They never draw from each other - reading CVEs here all day cannot use up the allowance your integration runs on.
The browsing budget is sized so you will not notice it: opening one CVE costs about five requests, so a Free account is roughly a thousand CVE reports a day. The API budget is the one sized to your plan. Both reset at midnight UTC, and your live figures are on the usage page.
| Signed out | Free | Pro | Enterprise | |
|---|---|---|---|---|
| Limits & access | ||||
| Browsing cap this site, per day | 150 shared per IP | 1,000 | 5,000 | unmetered |
| Browsing rate | 30 / min | 60 / min | 150 / min | unmetered |
| API request cap all your keys, per day | – | 500 | 10,000 | unmetered |
| API rate limit | – | 30 / min | 120 / min | unmetered |
| API keys | – | 2 | 5 | 25 |
| Search depth results you can page through | unlimited | unlimited | unlimited | unlimited |
| Exploitation intelligence | ||||
| Exploitation maturity ladder & CISA KEV | ✓ | ✓ | ✓ | ✓ |
| CVSS, severity & CWE | ✓ | ✓ | ✓ | ✓ |
| EPSS score & percentile | ✓ | ✓ | ✓ | ✓ |
| Exploit counts & malicious-package flags | ✓ | ✓ | ✓ | ✓ |
| Trending & risk scores | – | ✓ | ✓ | ✓ |
| References & public repositories | – | – | ✓ | ✓ |
| Threat attribution - ransomware, ATT&CK TTPs (the CVE's own and the actors' playbook), actors, origin, motivation, targeted sectors, victim geography - plus the actor:/ttp:/sector: search filters | – | – | ✓ | ✓ |
| SSVC automatability inputs | – | – | ✓ | ✓ |
| Live decisions | ||||
| Live SSVC decision per CVE | – | ✓ | ✓ | ✓ |
| Decision search & bulk (500 IDs / request) | – | – | ✓ | ✓ |
| Delivery & integration | ||||
| Affected software & fixed versions | – | ✓ | ✓ | ✓ |
| CLI inventory matching | - | - | ✓ | ✓ |
| Bulk lookup (500 CVEs / request) & delta sync | – | – | ✓ | ✓ |
| STIX explorer | – | – | ✓ | ✓ |
| Raw STIX 2.1 / TAXII 2.1 feed | – | – | – | ✓ |
| Air-gapped / on-prem delivery | – | – | – | ✓ |
Hitting a limit is never a dead end. You get a clear message naming which budget ran out - browsing or API keys - the limit itself, and when it resets. Nothing is deleted or throttled silently, and a refused request does not count against you.
Limits are enforced live from the service configuration.
Direct API calls require a key - the Free plan is self-serve. The exploitation maturity ladder is visible on every plan. All plans read the same feed with the same freshness - plans differ in volume, batch tooling, and the reference/exploit-repository detail, never in data quality. Pro and Enterprise are invite-reviewed - request access with your use case and we'll get back to you at your account email.
Running air-gapped or on-premises? The entire platform - feed, API, decision engine - can be deployed on your infrastructure with scheduled feed updates. Tell us about your environment at contact@harpia.ae.
Is it being exploited right now? Find out.
