Which CVEs to patch first: one call ranks them by real exploitation
A scanner report with 300 'critical' CVEs does not tell you what to fix today. Kevscope ranks each CVE by what attackers actually do: is it in CISA's Known Exploited Vulnerabilities catalog, is it used in ransomware, what is its EPSS chance of exploitation in the next 30 days, and what do CVSS and CISA's SSVC say. You get a verdict per CVE and the reasons, so the order is easy to defend.
Try it free on your own input
8 well-known CVEs, ranked live (1 Oct 2026)
| CVE | Verdict | Score | Why |
|---|---|---|---|
| CVE-2024-3400 (PAN-OS GlobalProtect) | act now | 100 | KEV, ransomware, EPSS 100%, CVSS 10.0 |
| CVE-2021-44228 (Log4Shell) | act now | 100 | KEV, ransomware, EPSS 100%, CVSS 10.0 |
| CVE-2019-0708 (BlueKeep) | act now | 99 | KEV, ransomware, EPSS 100%, CVSS 9.8 |
| CVE-2023-4966 (Citrix Bleed) | act now | 98 | KEV, ransomware, EPSS 100%, CVSS 9.4 |
| CVE-2022-22965 (Spring4Shell) | act now | 94 | KEV, EPSS 99.6%, CVSS 9.8 |
| CVE-2023-44487 (HTTP/2 Rapid Reset) | act now | 86 | KEV, EPSS 100%, CVSS 7.5 |
| CVE-2023-38545 (curl SOCKS5) | high | 71 | public PoC, EPSS 78.5%, CVSS 8.8, not in KEV |
| CVE-2024-6387 (OpenSSH regreSSHion) | high | 68 | public PoC, EPSS 99.5%, CVSS 8.1, not in KEV |
Source: Kevscope API GET /api/priority on the free tier, 1 Oct 2026 12:17 UTC (CISA KEV, FIRST EPSS, CVSS from NVD/CNA, CISA SSVC).
Kevscope vs the alternatives
Published prices, each checked on the date shown; prices change, so confirm on each site.
| Product | Price | Free | Checked |
|---|---|---|---|
| Kevscope API | $5 once for 2,000 calls of up to 20 CVEs; $19/month for 10,000 | 200 calls every day, no key | live |
| OpenCVE | Starter EUR 19/month; Pro EUR 49/month; Enterprise EUR 299/month | 1 project, 100 API calls/hour | 2026-09-27 |
| Vulners | Basic $600/month (600 API credits); Pro $1,300/month | 100 API credits/month | 2026-09-27 |
| CISA KEV + FIRST EPSS (do it yourself) | free data; you join the feeds and keep them fresh | public feeds | 2026-09-27 |
Why teams pick Kevscope
- CVSS alone misleads: in the live check below, CVE-2023-44487 (HTTP/2 Rapid Reset, CVSS 7.5) is act-now because it is in KEV, while CVE-2024-6387 (regreSSHion, CVSS 8.1) is high: public exploit code, but not in KEV.
- Of the 1,730 CVEs in CISA KEV (catalog 2026.09.30), 361 are known to be used in ransomware and 859 have an EPSS of 50% or more (FIRST EPSS, 30 Sep 2026).
- Every verdict lists its reasons, so a ticket or an auditor can see why.
- $5 covers up to 40,000 CVE checks; OpenCVE starts at EUR 19/month and Vulners at $600/month.
Try it in one call
curl 'https://kevscope-api.cybermax-tools.workers.dev/api/priority?cve=CVE-2024-3400,CVE-2024-6387,CVE-2023-44487'FAQ
Which CVEs should I patch first?
Start with CVEs in CISA's Known Exploited Vulnerabilities catalog (attackers already use them), then those with a high EPSS score, then by CVSS. Kevscope applies that order for you and shows the evidence for each CVE.
What is EPSS?
FIRST's Exploit Prediction Scoring System: the estimated chance that a CVE is exploited in the next 30 days, updated daily.
Why not just sort by CVSS?
CVSS measures how bad a flaw could be, not whether anyone is exploiting it. Many CVSS 9+ CVEs are never exploited, and some CVSS 7 CVEs are in KEV.
Can I use it in CI or a SOAR playbook?
Yes: one GET with up to 20 CVEs returns JSON; the MCP server at /mcp serves AI agents with the same key.
Is there a weekly summary instead of an API?
Yes: Kevscope Weekly is a Monday brief of what attackers exploited that week (see the store).