Score 95–98
Confirmed exploitation in the wild. Drop everything.
Example: CVE-2021-44228 — Log4Shell
Deterministic · Versioned · Public methodology
One verdict per CVE, built from seven public threat-intel sources. No proprietary scoring, no enterprise gatekeeping, no ML hallucinations.
319,455
CVEs analyzed
7
Intelligence sources
6
Exploitability verdicts
Six verdict tiers
Every CVE collapses into a single label and a 0–100 score. No tabs, no toggles, no “contact sales for the real one.”
Score 95–98
Confirmed exploitation in the wild. Drop everything.
Example: CVE-2021-44228 — Log4Shell
Score 70–95
Production-grade exploit available. Patch this week.
Example: CVE-2017-0144 — EternalBlue
Score 25–69
Public PoC exists. Patch in next sprint.
Example: CVE-2023-23397 — Outlook NTLM leak
Score 10–24
No known exploitation. Patch in regular cycle.
Example: most low-severity library CVEs
Score 0
Rejected, reserved, or duplicate CVE. No action needed.
Example: any **REJECT** entry in NVD
Reserved fallback
Insufficient signals to score. Returning conservative estimate.
Example: brand-new CVEs awaiting enrichment
How the verdict is built
No magic, no opaque ML, no proprietary feed lock-in. The exact formula lives in our public scoring engine.
Verdict response
GET /v1/cve/CVE-2021-44228
{
"cve_id": "CVE-2021-44228",
"verdict": "ACTIVELY_EXPLOITED",
"score": 98,
"score_version": 1,
"sources": [
"cisa_kev",
"epss",
"metasploit",
"exploitdb",
"github_pocs"
]
}
Same shape on every tier. See what scales →
Why RealExploit
Same inputs always produce the same verdict. No ML hallucinations, no scoring drift between runs.
Every verdict cites its source records. Versioned scoring formula in public docs — nothing behind a sales call.
REST + webhooks. Single-CVE lookups, bulk batch, CSV upload, verdict-change notifications. JSON only.
Pricing
Web console for everyone. API on Pro and up. Full comparison →
Try it without a card
$0
For one engineer
$99/mo
3 shared seats
$499/mo
10 seats, per-seat quota
$1,499/mo
The Free tier covers most teams’ first month of triage. No credit card.