On this page
CVE · CVSS · EPSS · CISA KEV · CWE · ATT&CK tactic · ATT&CK technique · MITRE ATLAS · Threat actor · Campaign · Incident · Cross-walk · Composite risk score · Today’s signal & the daily brief · AI-related vulnerability
A plain-language map of the words this site uses — what a CVE, an EPSS score, an ATT&CK technique, or a threat actor actually is. One short definition each, a link to the authority that owns it, and a link to see it live in our data. New here? Follow the guided path on Start here.
CVE · CVSS · EPSS · CISA KEV · CWE · ATT&CK tactic · ATT&CK technique · MITRE ATLAS · Threat actor · Campaign · Incident · Cross-walk · Composite risk score · Today’s signal & the daily brief · AI-related vulnerability
A CVE (Common Vulnerabilities and Exposures) is a unique public ID for one specific security flaw in a piece of software or hardware — for example CVE-2021-44228 (Log4Shell). Each CVE record carries a description, the affected products, and reference links. The ID by itself does not tell you how dangerous the flaw is; that is what the severity, likelihood and exploitation signals below add.
The CVE Program ↗ · See it live: the Daily CVE Tracker
CVSS (Common Vulnerability Scoring System) rates a flaw’s intrinsic severity from 0 to 10, derived from its technical characteristics — how it is reached, how hard it is to exploit, and the damage a successful attack would do. Roughly: 9.0–10.0 is Critical, 7.0–8.9 High, 4.0–6.9 Medium. CVSS measures how bad exploitation would be, not how likely it is.
FIRST — CVSS ↗ · See it live: how we use CVSS in the risk score
EPSS (Exploit Prediction Scoring System) is a daily-updated probability, from 0 to 1, that a CVE will be exploited in the wild within the next 30 days. It is the likelihood companion to CVSS’s severity: a Critical flaw nobody is attacking can have a low EPSS, and a medium-severity flaw under active weaponization can have a high one. Because it is re-scored every day, an EPSS number moves.
FIRST — EPSS ↗ · See it live: today’s biggest EPSS movers
The Known Exploited Vulnerabilities catalog is CISA’s authoritative list of CVEs confirmed to be exploited in the wild. A KEV listing is the strongest single signal on this site: it means attackers are actively using the flaw today, so it deserves urgent attention regardless of its CVSS or EPSS number.
CISA KEV catalog ↗ · See it live: recent KEV additions
A CWE (Common Weakness Enumeration) names the kind of mistake behind a CVE — for example CWE-79 (cross-site scripting) or CWE-89 (SQL injection). Many different CVEs share one CWE, so grouping by weakness reveals the recurring patterns that individual CVE IDs hide.
MITRE CWE ↗ · See it live: our CWE coverage
In MITRE ATT&CK, a tactic is the why of an attacker’s step — the objective, such as Initial Access, Persistence, or Exfiltration. Tactics are the columns of the ATT&CK matrix: the phases an intrusion moves through.
MITRE ATT&CK tactics ↗ · See it live: our threat mapping
A technique is the how — the specific method an attacker uses to achieve a tactic, such as T1566 (Phishing). Techniques carry T#### IDs. We map CVEs and threat actors to the techniques they enable or use, so you can pivot from a flaw to the behaviour it unlocks.
MITRE ATT&CK techniques ↗ · See it live: techniques on our threat map
ATLAS is ATT&CK’s counterpart for AI and machine-learning systems: techniques like data poisoning, model evasion, and prompt injection that target models rather than ordinary software. We map AI-related CVEs to ATLAS where they apply.
MITRE ATLAS ↗ · See it live: vulnerabilities in AI software
A threat actor is a tracked adversary — a group such as a nation-state crew or a ransomware gang — with observed tooling, targets, and motivations. The same actor is often known by different names across security vendors, so we reconcile those aliases. An actor is the author; a campaign and an incident are what they do.
MITRE ATT&CK groups ↗ · See it live: the threat-actor directory
A campaign is a time-bounded set of intrusions that share a common objective and infrastructure, usually (but not always) attributed to an actor. If the actor is the author, the campaign is a chapter — a specific push against a specific set of targets over a specific window.
MITRE ATT&CK campaigns ↗ · See it live: tracked campaigns
An incident is one concrete breach or attack that actually happened to a specific victim at a specific time. Keep the three apart: the actor is who, the campaign is the operation, and the incident is the individual event on the ground.
CISA advisories ↗ · See it live: landmark incidents
A cross-walk links an item in one framework to related items in another — a CWE to the ATT&CK techniques it enables, or a NIST control to the weaknesses it mitigates. Cross-walks let you pivot from a weakness to the defenses that address it. A caution: “mapped to” is not “equivalent to” — the cross-walk illusion essay explains why.
NIST OLIR — national crosswalks ↗ · See it live: our framework cross-walks
Our Risk Priority is a single 0–100 number that blends severity (CVSS), likelihood (peak EPSS), and active exploitation (KEV), then applies a floor so a genuinely dangerous CVE can never crater just because one component is quiet. It is a triage aid to rank what to look at first — not a verdict, and not a substitute for your own environment’s context.
FIRST — EPSS (a key input) ↗ · See it live: the full scoring method
The signal is what changed today that matters: new KEV additions, the biggest EPSS movers, and freshly published critical CVEs, ranked on every refresh. The daily brief packages that same picture as a short read. New to the vocabulary? Every term in the brief is defined on this page.
CISA KEV (a source) ↗ · See it live: today’s signal