Make triage calls you can defend โ plus a sharper CVSS tool

Hey there ๐ This was a big one. Over the past few days your Stack turned into a real triage console, the CVSS page became a full toolkit, the homepage got a ground-up rewrite, and we added a second self-check scanner. Grab a coffee โ here's everything you can try right now.
โจ Your Stack is now a triage console
This is the headline. Your Stack no longer just lists the CVEs that match your products โ it helps you decide, record, and defend what you do about each one.

- Make an ACT or DEFER call on any finding and it sticks. Each decision freezes the risk that was known at that moment, so your history reads as real audit evidence โ "here's what we knew when we called it" โ not just today's shifting numbers. Set your own cut-line for what counts as ACT; every change to it is logged.
- Patched something? Mark it Resolved and it leaves your active queue into its own tab. If a fresh KEV listing or public exploit later lands on that CVE, we nudge you to reopen it โ we'll never silently reopen it behind your back.
- Tell us how each product is exposed โ internet-facing, internal, isolated or air-gapped โ and triage adapts. The CVE page now shows an environmental score tuned to your exposure, right next to the base score. It's your own estimate, clearly marked as unverified, and it never hides a KEV.
- Spot your blind spots: findings you've marked ACT that no scanner can even detect are flagged, so you know where automation won't help. And you can export your full in-scope set to CSV whenever an auditor asks.
- Open Decisions from your Stack to see all of it.
๐งฎ The CVSS calculator grew into a toolkit
It's the third most-visited page on the site, and people come to /cvss to change, build, and defend a vector โ not just read a number. So we rebuilt it.

- Look up any CVE right in the calculator to pull its live EPSS likelihood and CISA KEV status.
- Save environment profiles and re-score a vector for your own setup in one click.
- Get an SSVC recommendation โ Track / Attend / Act โ prefilled straight from the vector.
- Diff two vectors, or translate between CVSS v3.1 and v4.0, with clear warnings wherever the mapping is fuzzy.
- Hover any metric for a plain-language explanation, then export a PSIRT-ready advisory blurb and justification when you're done.
Everything runs in your browser โ your vector never leaves the device โ and it's open to everyone, no login required. Open the calculator.
๐ More coverage, sharper detail

- OpenVAS joins Nuclei as a second self-check scanner, so more of your CVEs now carry real detection coverage. Filter the CVE list by "Has OpenVAS Check" to see what's covered.
- Every CVE's timeline is richer: instead of a handful of milestones, you get the full lifecycle โ PoC and Metasploit modules, OpenVAS coverage, EPSS shifts, ATT&CK mappings, remediation and more โ in one honest sequence. Open any CVE and scroll.
- The CVE list filters got a real overhaul: new facets (including "Has OpenVAS Check"), regrouped into intent-based sections โ Threat Intel, CVSS Vector, Affected products, Weakness & Technique, Industry โ and reordered so the ones you actually reach for during triage sit up top. The noisy "Refine" suggestions are gone.
- Your Stack now collapses vendor spelling variants โ "jenkins" and "Jenkins Project" โ into a single row with unified CVE, KEV and exploit counts, instead of splitting one product across several.
๐งฐ For the API & CLI crowd
- A new buzz lens on the public threat API (
?lens=buzz) ranks CVEs purely by how much attention they're drawing right now โ and every result now carries a media-lag signal: how far ahead of (or behind) publication the press actually ran.
We'd love your take
Spotted something off, or have an idea? Open a bug or drop an idea โ we read every one.