Vulnder

Why I built Vulnder

2025 set a record with 48,185 CVEs, a fifth more than the year before.1 Then 2026 doubled the monthly rate: Google's threat intelligence team counted 5,045 new vulnerabilities in January and 10,740 in August.2 Nobody reads that many. You shouldn't have to. Most of them don't touch what you run, and of the ones that do, only a few are being used by attackers.

Vulnder answers two questions about your stack: which new CVEs affect it, and which of those is anyone exploiting. Describe what you run in a sentence or drop in a lockfile, and you get the answer in seconds, in the order to fix things.

The usual way to triage is running out

For years, the answer to "which ones matter?" was the CVSS score that NIST added to each CVE in the National Vulnerability Database. In April 2026 NIST said it can't keep up. It now enriches CVEs on CISA's Known Exploited Vulnerabilities list, software the US government uses and critical software first. Everything else is listed without being scored straight away.3 The supply chain behind CVEs is fragile too: in April 2025 the CVE programme came within a day of losing its funding.4

A severity score was never a full answer anyway. It says how bad a bug would be, not whether anyone can reach it or is trying to. A missing score shouldn't read as "safe" either, so Vulnder says what it doesn't know.

AI cuts both ways

AI is now finding real bugs, and serious ones. Half the vulnerabilities AI found in Google's 2026 study lead to remote code execution, against about a quarter of CVEs overall.2 That's good news for defenders, and part of why the volume doubled.

The same tools help attackers. Google found that most of 2026's growth in exploitation came from known, already-disclosed bugs weaponised quickly, likely helped by AI reading patches and proof-of-concept code.2 VulnCheck found that 23% of the newly exploited bugs it tracked in the first half of 2026 were exploited on or before the day their CVE was published.5

Why prioritising matters more now

AI makes the order you fix things in matter more than it used to, for four reasons.

Evidence beats severity

So Vulnder ranks by what's actually happening. Evidence of exploitation (CISA's catalog, or CISA reporting active exploitation) always comes first. Predictions of exploitation (EPSS, and NIST's LEV estimate) come next, then severity (CVSS). Every result says which signal decided its place, what else counted, and what data was missing. The scores only put results in order. They aren't probabilities.

What I wanted it to be

Pete Salmond (@fullymiddleaged). Bugs and ideas go to the issue tracker. If Vulnder is useful to you, a star on GitHub helps other people find it.

Sources

  1. Jerry Gamblin, 2025 CVE Data Review (1 January 2026)
  2. Google Threat Intelligence Group, Vulnerability Discovery and Exploitation Trends in the AI Era (1 October 2026)
  3. NIST, NIST Updates NVD Operations to Address Record CVE Growth (April 2026)
  4. The Record, CISA extends CVE program contract with MITRE (April 2025)
  5. VulnCheck, State of Exploitation 1H 2026 (28 July 2026)