Sources & attributions

RealExploit is a KeyStone Labs brand. Our analysis combines public intelligence with the context supplied by each team.

Each verdict links to the evidence used in its calculation. This page identifies the original sources and their attribution information.

CISA KEV

The Known Exploited Vulnerabilities catalog records vulnerabilities with confirmed exploitation.

CISA KEV catalog

NIST NVD

Vulnerability records, references and severity data from the National Vulnerability Database API.

National Vulnerability Database

FIRST EPSS

EPSS data by FIRST.org. EPSS estimates the probability of exploitation over the next 30 days.

FIRST EPSS · CC BY 4.0

Metasploit

Metasploit modules by Rapid7. We reference the original module information.

Metasploit Framework

Nuclei

Detection templates by ProjectDiscovery. Template evidence contributes to the verdict under the published scoring rules.

Nuclei templates

ExploitDB & GitHub PoCs

ExploitDB and curated GitHub proof-of-concept references link to their original sources. RealExploit does not redistribute their exploit code.

ExploitDB · PoC-in-GitHub · Trickest CVE

How to read the evidence

Source evidence, asset context and patch verification are distinct. A vulnerability verdict is calculated from the available signals; a patch is verified through the evidence recorded by your team.

Read the verdict guide