VULNSOCIAL

Fix what matters

Start by selecting your industry, vendor, or product below

105CVEs in scope · 30 days

Built for security engineers, SOC analysts, and DevSecOps teams who need signal over noise, not another unread severity queue.

Live dashboardVendors, trends, and indicators below use the same live pipeline. Filter by vendor or product to match your stack.

Vendors by Exposure

Select to apply CPE scope

Products by Exposure

Select vendor or product to apply CPE scope

Attention over time (30D)

Mention volume for the top 30 CVEs in this view. Toggle series to compare momentum.

10/30 CVEs visible
023456890113CVE-2026-88771 (516 mentions / 30D)CVE-2026-87902 (404 mentions / 30D)CVE-2026-88772 (362 mentions / 30D)CVE-2026-85706 (312 mentions / 30D)CVE-2026-104286 (271 mentions / 30D)CVE-2026-86950 (264 mentions / 30D)CVE-2026-76461 (239 mentions / 30D)CVE-2026-76460 (237 mentions / 30D)CVE-2026-88779 (230 mentions / 30D)CVE-2026-76504 (202 mentions / 30D)09-0909-1209-1509-1809-2109-2409-2709-3010-0310-0610-08

Threat signal metrics

43,633

CVEs in scope

136,259

Signal volume

205

24h volume

23,182

Active exploitation

37,435

Patches / workarounds

Aggregate signal volume (30D)

Total mentions across in-scope CVEs. Spikes usually track advisories, PoC chatter, or exploitation reporting, not random drift.

01713425136842026-09-09: 676 mentions, 389 CVEs2026-09-10: 512 mentions, 304 CVEs2026-09-11: 518 mentions, 332 CVEs2026-09-12: 411 mentions, 245 CVEs2026-09-13: 285 mentions, 223 CVEs2026-09-14: 471 mentions, 313 CVEs2026-09-15: 495 mentions, 315 CVEs2026-09-16: 562 mentions, 351 CVEs2026-09-17: 551 mentions, 281 CVEs2026-09-18: 535 mentions, 326 CVEs2026-09-19: 354 mentions, 229 CVEs2026-09-20: 274 mentions, 195 CVEs2026-09-21: 356 mentions, 250 CVEs2026-09-22: 629 mentions, 325 CVEs2026-09-23: 635 mentions, 279 CVEs2026-09-24: 620 mentions, 323 CVEs2026-09-25: 551 mentions, 297 CVEs2026-09-26: 385 mentions, 211 CVEs2026-09-27: 379 mentions, 200 CVEs2026-09-28: 623 mentions, 277 CVEs2026-09-29: 561 mentions, 317 CVEs2026-09-30: 674 mentions, 335 CVEs2026-10-01: 684 mentions, 362 CVEs2026-10-02: 564 mentions, 318 CVEs2026-10-03: 369 mentions, 210 CVEs2026-10-04: 305 mentions, 202 CVEs2026-10-05: 539 mentions, 282 CVEs2026-10-06: 552 mentions, 355 CVEs2026-10-07: 642 mentions, 394 CVEs2026-10-08: 283 mentions, 204 CVEs09-0909-1209-1509-1809-2109-2409-2709-3010-0310-0610-08

Signal classification

Where discussion is coming from. Useful context when a CVE suddenly dominates a category.

  • Disclosure60,484(46.5%)
  • Patch23,425(18.0%)
  • Active Exploitation21,470(16.5%)
  • General19,669(15.1%)
  • PoC4,983(3.8%)

Threat indicators

PoC references, exploit code, active exploitation, patches, and technical detail, aggregated for the current scope.

  • Technical Details97,607(56.2%)
  • Patch Available37,435(21.5%)
  • Active Exploitation23,182(13.3%)
  • PoC Mentioned10,855(6.2%)
  • Exploit Code4,718(2.7%)

Why VulnSocial

The problem

Traditional tools optimize for severity. Your adversaries optimize for opportunity.

NVD and CVSS tell you what could be bad. They do not tell you what people are weaponizing, discussing, or patching this week. The result is the same backlog, reshuffled: alert fatigue with no clear order of operations.

Most teams do not lack CVE data. They lack a live read on where attention and exploitation momentum actually are.

The approach

Attention-driven risk, not score-driven noise.

VulnSocial aggregates real-time signals from researchers, exploits, advisories, and community discussion. We rank CVEs by what the landscape is amplifying: proof-of-concept mentions, active exploitation indicators, patch availability, and trending volume over the last 24 hours and 30 days. You filter by vendor and product so the feed matches your stack.

> pipeline.stream (live)

How it works

One post becomes signal: watch it move through ingest → classify → enrich → route.

Pipeline stage 1 of 4: Ingest signals
Ingestcapture
Classifytag + score
Enrichcontext
Emitroute

Simo @SimoKohonen

Example post · pipeline demo

Webshells be flowing into Cisco SD-WAN honeypots now.. Exploitation of CVE-2026-20127 is looking pretty heavy, new actors popping up by the hour

ingest: raw post · CVE-2026-20127

15.7K views65 likes19 RTs2 replies20 bookmarks

  1. [ 01 ]

    Ingest signals

    We collect and classify mentions across channels that move before tickets do: advisories, researcher posts, exploit references, and technical discussion.

  2. [ 02 ]

    Score attention

    CVEs surface by signal volume and trajectory, not a static severity label, so spikes in discussion map to spikes in urgency.

  3. [ 03 ]

    Surface threat context

    Exploit momentum, PoC noise, active exploitation flags, and patch availability appear alongside each CVE so triage is factual, not guesswork.

  4. [ 04 ]

    Scope to your stack

    Filter by vendor and product (Microsoft, Apple, Cisco, and more) so the feed reflects exposure you actually run, not the entire internet’s backlog.

> loop: raw social post → classify → enrich with threat context → emit to your scoped feed

What you get

High-signal capabilities, not generic scanning slides.

  • Exploit momentum tracking

    See when exploitation and exploit-code references accelerate, not just that a CVE exists.

  • Real-time signal aggregation

    Mentions and classifications update continuously so your picture matches the current discussion.

  • Trending windows (24h / 30d)

    Compare short-horizon spikes against sustained attention to separate flash from lasting risk.

  • Stack-specific threat view

    CPE-aware filters narrow the universe to the vendors and products you deploy.

  • PoC and patch visibility

    Proof-of-concept chatter and remediation signals sit next to severity so prioritization is grounded.

  • Attention-ranked CVE lists

    Rankings reflect what the ecosystem is focused on, aligned with how incidents actually unfold.

Who it's for

One feed, three common workflows.

SOC analyst

Triage inbound noise against a live ranked list. When something spikes in the feed, you already have exploitation and PoC context before the ticket lands.

Security lead

Brief leadership with what the landscape is amplifying, not a spreadsheet sorted by CVSS. Align patch windows with real attention and exposure.

DevSecOps

Scope to your shipped stack, watch trending CVEs for those vendors, and coordinate fixes with evidence that a vulnerability is actively discussed or exploited.

The backlog is static. The threat landscape is not.

Open the live feed, scope to your vendors, and align the next patch cycle with what is actually gaining traction, not what scored highest on a spreadsheet last quarter.

About VulnSocial

VulnSocial is not a generic scanner. We aggregate and classify vulnerability signals from the channels that move first: researchers, advisories, exploit references, and community discussion. CVEs are ordered by attention and momentum, not CVSS alone. Active exploitation indicators, PoC noise, and patch availability sit next to each CVE so triage is grounded in what is happening now.

Scope the dashboard with vendor and product filters to match your stack. Security teams use VulnSocial to cut through alert fatigue: SOC analysts for ranked triage, leads for credible briefings, DevSecOps for stack-specific trending and remediation timing. Share snapshots with your team from the feed when you need to align on what matters today.