Vulners’ cover photo
Vulners

Vulners

Computer and Network Security

Wilmington, DE 2,912 followers

Vulnerability database with an API - send your assets, get every vulnerability back enriched, ranked, ready to act

About us

Vulners is a vulnerability database with an API. Send us your assets in whatever shape you have them - inventories, SBOM, host data - and get back every vulnerability that affects them, already enriched with exploits, KEV, CVSS and EPSS, and ranked by real-world risk. Prioritize like an attacker, not a spreadsheet. No scanner to deploy, no agents to install, no feeds to stitch. Behind it: 230+ sources - CVEs, advisories, exploits, patches, KEV, scoring - normalized into one connected, machine-readable graph where every record is linked, so each vulnerability carries its full context from discovery to exploit to fix. Our AI scoring weighs CVSS, EPSS, and real-world exploitation, so the things that actually matter rise to the top. Enterprise security teams use Vulners to sharpen triage and automate remediation. Cybersecurity product builders, cloud platforms, and MSSPs use it as the data layer behind their own security features - and a new revenue stream. Built in 2015 by information security professionals. 230+ sources · 7M+ records · 270k+ exploits · 99.9% API SLA.

Website
http://vulners.com
Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
Wilmington, DE
Type
Privately Held
Founded
2015
Specialties
Vulnerability Management, Vulnerability Assessment, Vulnerability Research, Cyber Threats Intelligence, Common Vulnerabilities and Exposures (CVE), Common Vulnerability Scoring System (CVSS), Risk Based Security, Security Information and Event Management (SIEM), Security Operations Center (SOC), Security Orchestration, Automation, and Response (SOAR), Vulnerability Scanner, Vulnerability Feeds, Security Patch Management, Penetration Testing, Indicator of compromise (IoC), Threat Monitoring, Continuous Security Monitoring (CSM), Attack Vector Detection, External Security Testing, and Exploit Prediction Scoring System (EPSS)

Locations

Employees at Vulners

Updates

  • Vulners reposted this

    We’re pleased to announce the speakers for the CSS 2026 session “Securing Critical Assets: Expert Perspectives from Leading Companies.” Leading cyber security companies will share their expertise, technologies and practical approaches to protecting industrial control systems, supply chains and cloud infrastructure. The session will also explore real-world challenges, effective remediation strategies and ways to strengthen the resilience of critical environments. Meet the presenters: - Tang Zhijun, Cybersecurity & Privacy Officer, Huawei Session Host: - Corey Deng, Chief Security Officer, Huawei - Anosh Thakkar, President & CEO, Soteryan - Olzhas Satiyev, Founder & CEO, Tsarka - Sardor Ramazon, Chief Product Officer, TETRA Security - Andrey Lukashenkov, Head of Revenue, Product & Marketing, Vulners - Greg Mendeleev, Principal Major Account Executive, Akamai - Aleksey Neboga, Director, Softprom Uzbekistan The session will take place on 6 October. Only registered attendees may attend. Register to attend at https://lnkd.in/dCCMvnN5. Join us for valuable insights from cyber security experts. Find out more about CSS 2026 at https://lnkd.in/dXn3uHh2. #cybersecurity #centraleurasia #centralasia #digitalization #digitalisation #infosec #uzbekistan #css2026 Anosh Thakkar Sardor Ramazon Andrey Lukashenkov Greg Mendeleev Aleksey Neboga Huawei Soteryan TSARKA TETRA Security Vulners Akamai Technologies Softprom Asia & Caucasus

    • No alternative text description for this image
  • Vulners reposted this

    Nineteen #LinuxKernel #CVE flagged as exploited in the wild, ever. The top three rows all landed on Thursday, and two of them are a year old. The Cybersecurity and Infrastructure Security Agency put CVE-2026-53266, CVE-2025-39964 and CVE-2025-39682 into #KEV on 18 September, in two separate notices a few hours apart. One of the three is a 9.8 that was published on 5 September 2025. The #exploitation flag arrived a year and thirteen days later. In July the same query returned eleven. Since then the kernel #CNA has had its biggest month ever, 1644 #CVE in August, and September is at 1507 with eleven days to go. Year to date: 6547. The exploited list grew by eight in the same window, and part of the growth is coming from the back of the record, not the front. Two of Thursday three are 2025 IDs that sat there for a year before anyone was seen using them. So the question about this year's 6547 is not how many there are. It is how many of them are next year #KEV additions and which ones. Nobody has that number. The nineteen: https://lnkd.in/e5RXYi_M Kernel CNA by month: https://lnkd.in/einwvik6 #informationsecurity #vulnerabilityassessment #vulnerabilitymanagement

    • No alternative text description for this image
  • Vulners reposted this

    Yesterday I wrote that a #patch is a #disclosure - whoever diffs it has the bug by the afternoon. #CVE-2026-43831 is the counterpart. Nothing was revealed at all, so there is nothing to read. Vendor: tbc. Product: tbc. Version: tbc. Title: tbc. Credits: tbc. The description says only that "full details and mitigation steps are currently restricted and will be published at a later date." The single reference is an unfilled template placeholder - the alert ID in that URL is still literally al-2026-xxx, and the page it points at does not exist. So downstream everyone mostly retells the #CWE and the #CVSS out loud. Both of those came from the Cybersecurity and Infrastructure Security Agency #Vulnrichment rather than from the #CNA - a stack-based buffer overflow, 7.5 HIGH, for software nobody has named. #NVD lists it as NOT SCHEDULED. Published 31 July. Forty-two days, no revision. One record is not a verdict on CVE quality in general. But the CVE Program should have rejected this one right away - it likely breaks every CNA rule. It is still in the books. NVD: https://lnkd.in/eEQq2pne Vulners: https://lnkd.in/e_UiEAjH #informationsecurity #vulnerabilityassessment #vulnerabilitymanagement

    • No alternative text description for this image
  • Vulners reposted this

    Red Hat rejected #CVE-2026-19582 on 4 September as "false due to upstream security policy." Two days earlier the #binutils maintainer had committed a fix for it. I pulled the record in Vulners. 15 downstream sources carry this CVE. Thirty hours on, one has propagated the rejection - #SUSE. Nine still carry the full vulnerability text as live. That includes Red Hat own downstream CVE page, which still lists the description and a mitigation: do not open unknown files using binutils. Same org, two records, opposite states. The vuln data ecosystem is interconnected enough that the ripple goes much further than the #CVE perturbation itself. One #CNA changes one field, and the copies keep their own state. On the #CVEList the record is now 124 characters of rejected note. The #AI description on the Vulners page is 628 and still up - richer than the original description ever was, because it carries the rejection reasoning the #CVERecord itself never held. https://lnkd.in/exGKE2au #informationsecurity #vulnerabilityassessment #vulnerabilitymanagement

    • No alternative text description for this image
  • View organization page for Vulners

    2,912 followers

    "Adobe Acrobat PDF Extension (Chrome) 26.5.2.2" Send that string as-is. It comes back resolved, with a confidence score, a fixed version, and a #KEV flag. Same for "Google Chrome 149.0.7827.102" and "7-Zip 24.09" - both exploited in the wild, both with fixes waiting. That's audit/smart, and it ships in the rebuilt Vulners #Python #SDK. The bigger change is duller and matters more: every endpoint signature and every response shape is now written down. There's a generated index of the whole public surface - every method, what it returns, and the route it calls. The data model reference is built from live data, every bulletin family and collection, field by field. Every method carries a real docstring. We put our own tools on it first. getsploit 3.0 and nmap-vulners 2.0 had both been quiet for years, and both were rebuilt in days - not because we finally found the time, but because you can point a coding agent at the SDK now and it doesn't have to guess. Turns out "write good docs" and "make it agent-ready" are the same job. Typed sync and async clients, streaming archive downloads, and an #MCP server in the box. Upgrading from 3.x is a drop-in. https://lnkd.in/e2RDcd96 #cybersecurity #vulnerabilitymanagement #informationsecurity

    • No alternative text description for this image
  • Vulners reposted this

    2,436 vulnerabilities found. 53 of them have a #CVE. Z.ai put up a public disclosure ledger for #GLM 5.3 - 269 #opensource projects, 1097 rated critical or high, and 2383 still under #embargo. Anthropic published the same shape in the spring. #Glasswing reported 23,000+ potential vulnerabilities across H1 and 126 of those became published CVE records, per the Cloud Security Alliance write-up. Two labs, two continents, same bottleneck. #AI made finding cheap. #CVD is still not, and four months of a second lab working the same problem has not made it cheaper. An embargo queue is not a failure state, it is what coordinated #disclosure looks like in the middle - but 53 out of 2,436 is a queue and nobody has built the thing that drains it. The oldest flaw was introduced in 1981. The average one sat there for 26.6 years before anyone found it. Somebody is still running code written before most of the developers reading this were born. And the distribution slopes down toward 2026, which is not code getting safer. However it is probably a statement about which codebase got scanned. Last thing, from the same screenshot: every CVE on that page opens on hover - published date, #EPSS, exploit count, references - no click. That is the free Vulners #Chrome extension. https://cvd.z.ai/ #informationsecurity #vulnerabilityassessment #vulnerabilitymanagement

    • No alternative text description for this image
  • Alexander Leonov as always thanks for the shout-out!

    The Vulners team has released nmap-vulners 2.0. This plugin (an NSE script) turns the popular Nmap port scanner into a black-box vulnerability scanner. Simply run $ nmap -sV --script vulners <target> to get a prioritized report on vulnerabilities and exploits. And all of this is available for free with no limitations. 🆓😉 How exactly does this plugin work? To find vulnerabilities, the software is identified first: 🔹 The service's CPE identifier may be provided by Nmap itself (using the -sV option). 🔹 If Nmap fails to identify the service, the plugin attempts to determine the CPE identifier from the raw banner using rules for FTP, SMTP, SSH, MySQL, DNS, NTP, LDAP, and other services. Starting with version 2.0, the fingerprint catalog is updated weekly based on Recog, Wappalyzer, WhatWeb, FingerprintHub, and nuclei-templates. The latest catalog is automatically fetched when the plugin runs. 🔹 If an HTTP service is detected, nmap-vulners also attempts to identify the web stack, including the framework, CMS, or PHP version behind a reverse proxy. It analyzes Server and X-Powered-By headers, cookies, the page title, meta tags, filenames in script src, and page content. The plugin includes more than 700 rules. In version 2.0, the number of HTTP path fingerprints increased from 125 to 939, while parallelization kept the processing time at around 6 seconds per port. 🔹 If a product is identified but its version is unknown, the plugin makes a single request to a known file that contains version information, such as /CHANGELOG.txt for Drupal or /administrator/manifests/files/joomla.xml for Joomla. This works with Concrete5, Drupal, Jira, Joomla, Apache Tomcat, and WordPress. 🔹 Finally, if a service cannot be identified, Smart Audit can be used. The raw banner is sent to the Vulners server, which identifies the software and its version and then looks for related vulnerabilities. This is the only paid feature! Each unique request costs 1 credit, and results are cached. The number of requests is limited by the vulners.max_items parameter, which defaults to 32. Smart Audit can be disabled entirely with --script-args vulners.max_items=0. The service data is then sent to the Vulners server, which returns a prioritized vulnerability report. For each vulnerability or exploit, the report includes its ID, SEVERITY level, CVSS and EPSS scores, Vulners AI score, KEV and EXP flags, and a link to its page on the Vulners website. [ Read the full post on avleonov[.]com ] Subscribe to my Telegram channel "Vulnerability Management and more" and follow the RSS feed on my blog avleonov[.]com! All links are in the first comment. #Nmap #Vulners #CPE #CVSS #EPSS #KEV #exploit #API #Fingerprinting #HTTP #CMS #PHP #ReverseProxy #ApacheTomcat #WordPress #Drupal #Joomla #Jira #Nuclei #AIScore #Prioritization

    • No alternative text description for this image
  • Vulners reposted this

    A little Friday story for security fellows 🙂 I’ve been programming pretty much my whole life. Not only for Vulners. I still write a lot of things for myself, simply because I genuinely enjoy building things that actually work and are useful. Some technologies came naturally to me: C, Python, parsers. Others made my brain hurt. NumPy, PyTorch and most of the ML ecosystem, for example. But one particularly stupid obstacle was... Lua. Back in 2017 we had an idea: take the software Nmap already detects and immediately show known vulnerabilities from Vulners. You’ve probably used the result: vulners.nse has been shipping with Nmap for years. And when you type nmap, you probably don’t think about how insanely polished, optimized and complicated the machinery underneath is. Huge respect to Gordon Lyon and the entire Nmap team. 🙌 I spent a day meditating over NSE and Lua, then made a very sensible engineering decision: I gave the task to Ilya Govorkov (gmedian). 😅 Ilya wrote the first prototype, Ivan Elkin helped get the first public version out, and in 2019 Daniel Miller (bonsaiviking) from the Nmap team picked it up for upstream. He didn’t just merge it. He properly Nmap-ified the thing: cleaned up NSE conventions, reworked output handling, added structured output, and made it work properly. And suddenly our little Lua script became part of Nmap itself. Which is when we learned another technology: CDN caching for an API being hammered by Nmap scans from all over the planet. 🔥 We seriously underestimated the traffic and had to rework the backend so everyone could keep scanning without setting Vulners on fire. That was more than seven years ago. Ever since, I wanted to make the plugin faster, smarter, better at identifying software and better at prioritizing what actually matters. But, as usual, there was always something more urgent to do. But now we finally did it. 🚀 nmap-vulners 2.0 is out. What changed: • One vulners.nse script instead of three. • Raw service banner detection, even when -sV can’t identify the software. • 700+ product/version fingerprint rules. • Fingerprints are updated weekly and fetched at scan time, so detection can improve without waiting for a new plugin release. • Parallel HTTP probing that follows Nmap’s own timing settings. • Better output and structured XML. • Prioritization by CISA KEV → SSVC active exploitation → published exploit → EPSS → CVSS. And just like before, it’s all still free. No mandatory API key, no registration required to install it and start scanning. Same boring interface: nmap -sV --script vulners <target> Just eight years of things I wanted to put into it finally caught up 🙂 https://lnkd.in/d8cD5wUK

Similar pages

Browse jobs