CVE Priority Checker: Which Vulnerabilities Should You Patch First?
Paste your CVE IDs and this free tool tells you which to patch first, using CVSS severity, EPSS exploit probability, and CISA's Known Exploited Vulnerabilities (KEV) list. It runs in your browser, needs no account, and checks up to 25 CVEs at a time.
- Free
- No signup
- Runs in your browser
- Up to 25 CVEs at once
- CSV export
Adjust the rules
How it works
- 1PastePaste CVE IDs, or a whole scanner export. Anything shaped like CVE-YYYY-NNNN is picked up.
- 2We look it upCVSS comes from the CVE record, EPSS from FIRST, and known-exploited status from CISA.
- 3Fix in orderEach CVE gets Fix now, Fix soon or Fix later, with the reason and a CSV to share.
How the CVE priority verdict works
The tool gives each CVE one of three verdicts, and a CVE listed in CISA KEV is always "fix now". The thresholds below are the defaults, and you can change them under "Adjust the rules" above the results.
| Verdict | Default rule | What it means |
|---|---|---|
| Fix now | Listed in CISA KEV, or EPSS of 10% or more | Attackers are exploiting it or are likely to. Patch or mitigate first. |
| Fix soon | CVSS 7.0 or more, or EPSS of 1% or more | Serious, but no sign of exploitation yet. Schedule it in your next patch window. |
| Fix later | Everything else | Low risk right now. Patch in the normal cycle and recheck when scores change. |
What CVSS, EPSS and KEV each tell you
CVSS measures how severe a flaw is, EPSS estimates how likely it is to be exploited, and KEV confirms that someone already is. You need all three, because each one alone misleads.
- CVSS (Common Vulnerability Scoring System) scores the technical severity from 0 to 10. It says nothing about whether anyone is attacking the flaw, so a 9.8 can still be a low priority for you.
- EPSS (Exploit Prediction Scoring System) is published by FIRST. It estimates the probability that a CVE will see exploitation activity in the next 30 days, and the percentile shows how it ranks against other CVEs.
- KEV is the CISA Known Exploited Vulnerabilities catalog, a list of CVEs with evidence of active exploitation. US federal agencies must fix listed items by a due date, and for everyone else it is a strong signal to act.
How to use the results with your scanner report
Export the CVE column from your vulnerability scanner, paste it into the box, and work through the "fix now" list first.
- Paste the CVE IDs, or the whole report. The tool picks out anything shaped like CVE-YYYY-NNNN, so you do not need to clean the text first.
- Fix the "fix now" items first, starting with any marked as used in ransomware campaigns.
- Check exposure for the rest: a CVE on an internal-only host is less urgent than the same CVE on an internet-facing one.
- Download the CSV to attach to a ticket or a remediation plan.
- Retest from outside your network after patching, for example with our network vulnerability scanner. Our guide to prioritizing vulnerability remediation explains the full process.
What this tool cannot tell you
It cannot see your systems, so it cannot say whether a CVE affects software you actually run or whether it is reachable from the internet. Treat the verdict as a sorting aid, not a risk decision.
- Brand-new CVEs may have no EPSS score or CVSS score yet. The tool shows "n/a" instead of guessing.
- Scores change as new exploitation data arrives, so recheck important CVEs after a few weeks.
- CVSS source: the tool reads the score published in the CVE record by the vendor or by CISA's enrichment, and falls back to NVD when it is missing. NVD's own score can differ for the same CVE.
Frequently asked questions
What does "fix now" mean in this tool?
"Fix now" means the CVE is listed in the CISA Known Exploited Vulnerabilities catalog, or its EPSS probability is at or above your threshold (10% by default). In both cases there is evidence or a strong prediction that attackers are using it, so it belongs at the top of your patch queue.Why is a CVSS 9.8 not always "fix now"?
CVSS measures how bad a flaw could be, not how likely it is to be exploited. A 9.8 with a very low EPSS score and no KEV listing may be less urgent than a 7.5 that attackers are using today. Most CVEs are never exploited, which is why exploitation data helps you sort.Is KEV the same as critical?
No. KEV is about evidence of exploitation, not severity. A CVE can be listed in KEV with a medium CVSS score, and many critical CVEs are not in KEV. This tool treats KEV as the strongest signal because a confirmed attack matters more than a theoretical score.How many CVEs can I check at once?
Up to 25 per run. If you paste more, the tool checks the first 25 and tells you. Run it again with the next batch for longer lists.Is my data stored or sent to ScanTitan?
No. The tool runs in your browser. The CVE IDs you enter are sent only to the public sources that provide the data: the CVE List on GitHub, CISA's KEV list on GitHub, FIRST's EPSS service, and NVD for any missing score. ScanTitan does not receive or store them.Does this tool scan my systems?
No. It only looks up public information about the CVEs you paste. To find out which vulnerabilities your systems actually expose, run a scan with the IP vulnerability scanner or the network vulnerability scanner.Data sources
CVSS data comes from the CVE List V5 (CVE Program) including CISA's enrichment, with NVD as a fallback. KEV status comes from the CISA Known Exploited Vulnerabilities catalog as published in the cisagov/kev-data repository. EPSS scores are published by FIRST. This product uses data from the NVD API but is not endorsed or certified by the NVD. The date of the EPSS data and the KEV catalog version appear under the results each time you run a check.
Scores tell you what is dangerous in general. Find out which of these your systems actually expose.
Run a free network scanSee pricing