ARPSyndicate ARPSyndicate
Talk to sales Login
Vulnerability & Exploit Data Aggregation System

Know what’s exploitable before everyone else.

Most risk signals react after an attack has already spread. VEDAS reads exploit data across the internet the moment it is published, works out what is genuinely exploitable, and writes the signatures that detect it. Every finding in Kenzer runs on it.

See it in KenzerSearch Exploit Observer
4,894,403vulnerabilities tracked
983,857exploits indexed
251,340VEDAS clusters
13,672CVEs with open detection signatures
The timing problem

Most signals arrive after the damage

A vulnerability goes through the same few moments every time. What matters is which of them your tools can see.

Moment 1

Disclosed

A CVE or advisory is published. Severity is known, exploitability isn’t.

Moment 2 · VEDAS

A working exploit appears

A proof of concept lands on an exploit database, a code host or a national feed. VEDAS flags it here.

Moment 3 · EPSS

Attacks spread

Exploitation shows up in attack telemetry, and probability scores start to climb.

Moment 4 · KEV

Confirmed in the wild

The vulnerability is added to a known-exploited catalog, once exploitation is proven.

✓ Ahead of EPSS and KEV, every day of 2025The earlier you know, the shorter your window of exposure.
How it works

From the open internet to your findings

01

Collect

Global vulnerability and exploit sources, plus national databases that never reach NVD.

02

Read

Every exploit, proof of concept and advisory is parsed the moment it is published.

03

Cluster

Records about the same weakness, under different IDs in different countries, become one cluster.

04

Score

Each cluster gets a VEDAS score for how exploitable it really is today.

05

Act

Scores, AI-written advisories and detection signatures flow straight into Kenzer.

Clustering

One weakness, many names

The same vulnerability can carry a CVE, a GitHub advisory, a European ID and three national IDs, with exploits scattered across a dozen sites. VEDAS joins them into one cluster, so nothing is counted twice and nothing is missed.

CVEGHSAOSVEUVDCNVDCNNVDBDUJVNDBExploit-DBGitHub PoCsZDI advisoriesVendor advisoriesSnyk / WPScanDetection rulesOne clusterVEDAS SCOREIDENTIFIERSEXPLOIT EVIDENCE
Global identifiersNational databasesExploit evidence
CVEGHSAOSVEDBZDISNYKWPSCANCNVDCNNVDBDUJVNDBEUVD
Compared

Three signals, three different questions

EPSSCISA KEVVEDAS
What it tells youThe probability a CVE will be exploited soonThat exploitation in the wild has been confirmedWhether a working exploit exists, and how usable it is
When it movesAs attack activity growsAfter exploitation is provenWhen the exploit is published
CoverageCVEs onlyA curated catalogCVEs plus global and national identifiers, clustered
In KenzerShown on every findingShown on every findingDrives the ranking, the advisories and the signatures
From intelligence to defence

VEDAS also writes the signatures

For each exploitable vulnerability, VEDAS uses AI to write a Suricata rule for network detection and a Nuclei template for an active check. They are published openly, syntax-checked in CI and open to community review, and Kenzer runs them against your targets.

13,672CVEs covered
Suricatanetwork detection rules
Nucleiactive check templates
MITopen source, open to review
suricata / CVE-YYYY-NNNNN.rulesnetwork detection
alert http any any -> $HOME_NET any (
  msg:"VEDAS CVE-YYYY-NNNNN exploit attempt";
  flow:established,to_server;
  http.uri; content:"/vulnerable/path";
  reference:cve,YYYY-NNNNN;
  sid:…; rev:1;)
nuclei / CVE-YYYY-NNNNN.yamlactive check
id: CVE-YYYY-NNNNN
info:
  author: vedas-arpsyndicate
  severity: high
http:
  - method: GET
    path: ["{{BaseURL}}/vulnerable/path"]
    matchers: # proves the flaw, safely

The shape of a signature pair. Real rules are in the repository.

Open data

Use VEDAS in your own tools, free

The scores and the signatures are published openly, so your scanners, SIEM and dashboards can use them today.

Inside Kenzer

VEDAS on every finding

Scored findings

Every finding shows its VEDAS score next to EPSS and KEV, so the list is ranked by what attackers can actually use.

Look up anything

Search any CVE, GHSA, EUVD or national identifier, and see the cluster, the exploits and the score.

Advisories in one click

Open source intelligence and AI combine into an advisory: how to reproduce the issue safely, how to detect it, and how to fix it.

Signatures on your targets

The same VEDAS signatures run in Kenzer’s scans, often before the exploit has spread.

Questions

Common questions

What is VEDAS?

The Vulnerability and Exploit Data Aggregation System. It collects vulnerability and exploit data from public and national sources, groups records that describe the same weakness, and scores how exploitable each one really is.

How is the VEDAS score different from EPSS?

EPSS estimates the probability of exploitation, largely from observed attack activity, so it tends to rise once attacks are already widespread. VEDAS looks for the exploits themselves as they are published, so it moves earlier.

Does VEDAS replace CISA KEV?

No, it sits alongside it. KEV confirms exploitation in the wild, which is valuable but arrives after the fact. Kenzer shows the VEDAS score, the EPSS score and KEV status on every finding.

Why include national databases?

Some vulnerabilities and exploits are catalogued in national databases such as China's CNVD and CNNVD, Russia's BDU or Japan's JVN long before, or instead of, NVD. Leaving them out leaves gaps.

Can I get VEDAS scores for my own tools?

Yes. cve-scores publishes VEDAS and EPSS scores for every CVE as CSV and JSON, refreshed every 6 to 8 hours, and Exploit Observer lets you search the same data in a browser. Kenzer adds the scoring on your own findings, the advisories and the signatures run against your targets.

Can I use the signatures?

Yes. They are published at github.com/ARPSyndicate/vedas-signatures under the MIT license, and fixes and improvements are welcome through pull requests.

Fix what attackers will use next

See VEDAS on your own findings, alongside everything else Kenzer grades.