Measured, not restated. These are our own analyses of public vulnerability data: every number comes from code we run against the named source, every page states its method and its limits, and each study is recomputed every month, so the findings below are the current ones.
The question behind the series
Security teams rank patches with a handful of free, public signals: CISA’s list of exploited vulnerabilities, the EPSS exploit-probability score, public exploit code, and scanner templates. Vendors and guides recommend them constantly. We measure how well each one actually predicts what CISA later confirms as exploited — and what it misses.
Studies
EPSS, a GitHub PoC or a Nuclei Template: Which Warns First?
Three public early-warning signals on one scoreboard, measured a year ahead.
Current finding (recomputed 2026-09-28): Together, EPSS, GitHub PoCs and Nuclei templates flagged 3% of CVEs and caught 50% of the next year's KEV additions; the other 50% had no public warning.
Does a Public Exploit on GitHub Predict What CISA Confirms?
Whether public proof-of-concept code comes before confirmed exploitation, and how often it is followed by it.
Current finding (recomputed 2026-09-28): 40% of the vulnerabilities CISA confirmed in the last two years never had a public GitHub PoC; a year ahead, a PoC flagged 38% of what went on to reach KEV.
Does EPSS Predict What CISA Confirms?
The standard triage advice — patch KEV, rank the rest by EPSS — checked against a year of data.
Current finding (recomputed 2026-09-26): 61% of the vulnerabilities CISA confirmed as exploited scored under 0.10 on EPSS a month before they were listed; of the CVEs scored above 0.9 a year earlier, 1.4% reached KEV.
How we work
- Public data only: CISA KEV, FIRST EPSS, NVD and open-source repositories.
- Every figure is computed by code, never typed in by hand, and studies that measure the same thing are checked against each other before a page is published.
- Correlation is reported as correlation. Small samples are flagged as such.
- We never link to individual exploit or proof-of-concept repositories.
- Spotted an error? Tell us and we will correct it.
Live data behind the studies
- Known Exploited Vulnerabilities tracker — refreshed daily
- Exploit likelihood watchlist — refreshed daily
- AI attack tracker — refreshed daily

