Back to workflows

CVE workflow

Check a CVE or exploit claim safely.

A workflow for reading vulnerability claims without testing unauthorized systems.

Passive and safe research workflow

When to use it

You have CVE ID and want to check it through safe, legal, source-based research.

What you get

CVE context note, affected scope, confidence, and defensive recommendation.

Safety boundary

This workflow is not for exploitation, probing, or unauthorized scanning. It reads public records, records dates and uncertainty, and avoids turning signals into final claims.

Simple order

Work through the steps in order.

  1. Confirm the identifier

    Check CVE, NVD, vendor bulletin, and publication date.

    Check: The CVE exists and matches the product.

  2. Read vendor context

    Compare affected versions, fixes, mitigations, and advisories.

    Check: A headline is not treated as full impact.

  3. Check exploitation context

    Use KEV, EPSS, advisories, and reputable reporting.

    Check: No exploit steps are reproduced.

  4. Write priority, not panic

    State exposure, uncertainty, and safe remediation path.

    Check: The note stays defensive.

Report language

The CVE is assessed through official records and defensive sources; exploitability in a specific environment requires separate authorized validation.

Move to evidence notes

Sources

Start with these sources.

Open resource archive
  • AlienVault OTX logo

    AlienVault OTX

    Threat intelligence

    Use for IOC context, reputation checks, and defensive security notes.

    Open source
  • CISA Known Exploited Vulnerabilities Catalog logo

    CISA Known Exploited Vulnerabilities Catalog

    CVE and vulnerability tracking

    Use for vendor advisories, CVE status, exploitation context, and defensive reporting.

    Open source
  • CVE.org logo

    CVE.org

    CVE and vulnerability tracking

    Use for vendor advisories, CVE status, exploitation context, and defensive reporting.

    Open source
  • data.europa.eu logo

    data.europa.eu

    Government and official datasets

    Use for primary records, public data, and official statements.

    Open source
  • Data.gov logo

    Data.gov

    Government and official datasets

    Use for primary records, public data, and official statements.

    Open source
  • FIRST EPSS logo

    FIRST EPSS

    CVE and vulnerability tracking

    Use for vendor advisories, CVE status, exploitation context, and defensive reporting.

    Open source