Blog

Security engineering,
written for developers.

CVE breakdowns, vulnerability management research, and practical security guides. No marketing copy.

RSS feed

CVSS vs EPSS vs CISA KEV: A Practical Comparison

Three vulnerability signals, three different questions. A practical guide to what CVSS, EPSS, and CISA KEV each measure, how they disagree, and how to combine them into a real prioritization workflow.

What Is CISA KEV and Why Does It Matter?

CISA's Known Exploited Vulnerabilities catalog tracks CVEs with confirmed active exploitation. Here's what it is, why it's the strongest remediation signal available, and how to use it alongside CVSS.

What Is an EPSS Score? A Plain-English Explanation

EPSS predicts the probability a CVE will be exploited in the next 30 days. Here's what the score actually represents, how it differs from CVSS, its limitations, and how to use it in prioritization.

Security Checks Every AI-Built App Needs Before Launch

LLMs write functional code fast. They also reproduce the same security gaps consistently. Here's what to check before you ship an app built with Cursor, Claude, or Copilot.

Why CVSS Alone Is Not Enough to Prioritize Vulnerabilities

CVSS scores severity if exploited — not whether anyone is. Here's how CISA KEV and EPSS close that gap, with a practical composite scoring model.