About & methodology

PatchRadar helps you answer one question: of all the CVEs out there, which should you fix first?

How we prioritise

Raw CVSS severity over-counts: most "critical" CVEs are never exploited. We combine three signals:

Data sources

Data refreshes daily. EPSS and KEV cover the full CVE universe; NVD enrichment (CVSS, products, references) currently prioritises recently-modified and exploited CVEs and broadens over time.

Disclaimer

PatchRadar is an independent tool and is not affiliated with NIST, CISA or FIRST. Data is provided as-is for information only — always verify against the official sources before making patching decisions.