Exploit & Vulnerability Intelligence by VulnCheck is a threat intelligence solution that provides data to assist organizations with vulnerability prioritization and remediation. The service delivers vulnerability information on average 14 days ahead of publication in the NIST National Vulnerability Database (NVD). It offers exploitation timelines that track initial disclosure, exploit publication, and evidence of exploitation by threat actors, ransomware, and botnets. Data is categorized using fields for exploit maturity, availability, and weaponization status, and is delivered through a JSON-based API.
A central component is the VulnCheck Known Exploited Vulnerabilities (KEV) catalog, which tracks CVEs that are exploited in the wild and contains a larger set of vulnerabilities than some public lists. The product enriches vulnerability intelligence by supplying exploit proof-of-concept (PoC) code, EPSS scores, and KEV status. This is supplemented with external links to exploit content and citations explaining a CVE's inclusion, regardless of whether a vendor patch is available.