Why I built Vulnder
2025 set a record with 48,185 CVEs, a fifth more than the year before.1 Then 2026 doubled the monthly rate: Google's threat intelligence team counted 5,045 new vulnerabilities in January and 10,740 in August.2 Nobody reads that many. You shouldn't have to. Most of them don't touch what you run, and of the ones that do, only a few are being used by attackers.
Vulnder answers two questions about your stack: which new CVEs affect it, and which of those is anyone exploiting. Describe what you run in a sentence or drop in a lockfile, and you get the answer in seconds, in the order to fix things.
The usual way to triage is running out
For years, the answer to "which ones matter?" was the CVSS score that NIST added to each CVE in the National Vulnerability Database. In April 2026 NIST said it can't keep up. It now enriches CVEs on CISA's Known Exploited Vulnerabilities list, software the US government uses and critical software first. Everything else is listed without being scored straight away.3 The supply chain behind CVEs is fragile too: in April 2025 the CVE programme came within a day of losing its funding.4
A severity score was never a full answer anyway. It says how bad a bug would be, not whether anyone can reach it or is trying to. A missing score shouldn't read as "safe" either, so Vulnder says what it doesn't know.
AI cuts both ways
AI is now finding real bugs, and serious ones. Half the vulnerabilities AI found in Google's 2026 study lead to remote code execution, against about a quarter of CVEs overall.2 That's good news for defenders, and part of why the volume doubled.
The same tools help attackers. Google found that most of 2026's growth in exploitation came from known, already-disclosed bugs weaponised quickly, likely helped by AI reading patches and proof-of-concept code.2 VulnCheck found that 23% of the newly exploited bugs it tracked in the first half of 2026 were exploited on or before the day their CVE was published.5
Why prioritising matters more now
AI makes the order you fix things in matter more than it used to, for four reasons.
- Volume has outrun patching. Twice as many CVEs a month doesn't come with twice the people, change windows or downtime to patch them. Something has to come first, and something has to wait.
- Severity is stopping being a tiebreaker. When half of AI-found bugs lead to remote code execution, sorting by CVSS puts more and more of the list at the top. "Critical" stops telling you where to start. Whether anyone is exploiting a bug still does.
- The window has shrunk. Bugs are weaponised days after disclosure, sometimes before.2, 5 A monthly patch review can't keep up with that. You need to know the day a bug in your stack starts being exploited, not at the end of the month.
- Your fixers are getting faster too. Coding agents can now upgrade a dependency and open the pull request themselves. Point one at a raw CVE feed and it spends its effort in the wrong order. Give it a ranked list with the reasons and it starts where an attacker would.
Evidence beats severity
So Vulnder ranks by what's actually happening. Evidence of exploitation (CISA's catalog, or CISA reporting active exploitation) always comes first. Predictions of exploitation (EPSS, and NIST's LEV estimate) come next, then severity (CVSS). Every result says which signal decided its place, what else counted, and what data was missing. The scores only put results in order. They aren't probabilities.
What I wanted it to be
- Fast. A sentence, a lockfile or an SBOM in, a ranked answer out, in seconds.
- No account, nothing to install. Your stack lives in the link. The same link gives you a JSON feed, an Atom feed and a README badge.
- Keeps nothing. What you type and your stack aren't stored or logged, and lockfiles are read in your browser. Details.
- Honest. It never hides a match. It says how sure each match is and suggests a time to respond, not a deadline.
- AI where it helps, and nowhere else. A model reads your description. Code does the ranking, and every rule can be read. Where AI is used.
- Free and open. Apache 2.0, so you can run your own copy.
Pete Salmond (@fullymiddleaged). Bugs and ideas go to the issue tracker. If Vulnder is useful to you, a star on GitHub helps other people find it.
Sources
- Jerry Gamblin, 2025 CVE Data Review (1 January 2026)
- Google Threat Intelligence Group, Vulnerability Discovery and Exploitation Trends in the AI Era (1 October 2026)
- NIST, NIST Updates NVD Operations to Address Record CVE Growth (April 2026)
- The Record, CISA extends CVE program contract with MITRE (April 2025)
- VulnCheck, State of Exploitation 1H 2026 (28 July 2026)