Most risk signals react after an attack has already spread. VEDAS reads exploit data across the internet the moment it is published, works out what is genuinely exploitable, and writes the signatures that detect it. Every finding in Kenzer runs on it.
A vulnerability goes through the same few moments every time. What matters is which of them your tools can see.
A CVE or advisory is published. Severity is known, exploitability isn’t.
A proof of concept lands on an exploit database, a code host or a national feed. VEDAS flags it here.
Exploitation shows up in attack telemetry, and probability scores start to climb.
The vulnerability is added to a known-exploited catalog, once exploitation is proven.
Global vulnerability and exploit sources, plus national databases that never reach NVD.
Every exploit, proof of concept and advisory is parsed the moment it is published.
Records about the same weakness, under different IDs in different countries, become one cluster.
Each cluster gets a VEDAS score for how exploitable it really is today.
Scores, AI-written advisories and detection signatures flow straight into Kenzer.
The same vulnerability can carry a CVE, a GitHub advisory, a European ID and three national IDs, with exploits scattered across a dozen sites. VEDAS joins them into one cluster, so nothing is counted twice and nothing is missed.
| EPSS | CISA KEV | VEDAS | |
|---|---|---|---|
| What it tells you | The probability a CVE will be exploited soon | That exploitation in the wild has been confirmed | Whether a working exploit exists, and how usable it is |
| When it moves | As attack activity grows | After exploitation is proven | When the exploit is published |
| Coverage | CVEs only | A curated catalog | CVEs plus global and national identifiers, clustered |
| In Kenzer | Shown on every finding | Shown on every finding | Drives the ranking, the advisories and the signatures |
For each exploitable vulnerability, VEDAS uses AI to write a Suricata rule for network detection and a Nuclei template for an active check. They are published openly, syntax-checked in CI and open to community review, and Kenzer runs them against your targets.
alert http any any -> $HOME_NET any ( msg:"VEDAS CVE-YYYY-NNNNN exploit attempt"; flow:established,to_server; http.uri; content:"/vulnerable/path"; reference:cve,YYYY-NNNNN; sid:…; rev:1;)
id: CVE-YYYY-NNNNN info: author: vedas-arpsyndicate severity: high http: - method: GET path: ["{{BaseURL}}/vulnerable/path"] matchers: # proves the flaw, safely
The shape of a signature pair. Real rules are in the repository.
The scores and the signatures are published openly, so your scanners, SIEM and dashboards can use them today.
Both scores for every CVE in one CSV or JSON file, refreshed every 6 to 8 hours, with the day's biggest movers. Sister feeds cover EUVD, CNNVD and BDU identifiers.
Detection rules and active checks for 13,672 CVEs, generated by VEDAS and open to fixes and improvements from the community.
The public search over VEDAS: look up any CVE or national identifier and see its exploits, cluster and score.
Every finding shows its VEDAS score next to EPSS and KEV, so the list is ranked by what attackers can actually use.
Search any CVE, GHSA, EUVD or national identifier, and see the cluster, the exploits and the score.
Open source intelligence and AI combine into an advisory: how to reproduce the issue safely, how to detect it, and how to fix it.
The same VEDAS signatures run in Kenzer’s scans, often before the exploit has spread.
The Vulnerability and Exploit Data Aggregation System. It collects vulnerability and exploit data from public and national sources, groups records that describe the same weakness, and scores how exploitable each one really is.
EPSS estimates the probability of exploitation, largely from observed attack activity, so it tends to rise once attacks are already widespread. VEDAS looks for the exploits themselves as they are published, so it moves earlier.
No, it sits alongside it. KEV confirms exploitation in the wild, which is valuable but arrives after the fact. Kenzer shows the VEDAS score, the EPSS score and KEV status on every finding.
Some vulnerabilities and exploits are catalogued in national databases such as China's CNVD and CNNVD, Russia's BDU or Japan's JVN long before, or instead of, NVD. Leaving them out leaves gaps.
Yes. cve-scores publishes VEDAS and EPSS scores for every CVE as CSV and JSON, refreshed every 6 to 8 hours, and Exploit Observer lets you search the same data in a browser. Kenzer adds the scoring on your own findings, the advisories and the signatures run against your targets.
Yes. They are published at github.com/ARPSyndicate/vedas-signatures under the MIT license, and fixes and improvements are welcome through pull requests.
See VEDAS on your own findings, alongside everything else Kenzer grades.