Glossary
One-line definitions for the labels Cybersecurity Tracker uses. Badge tooltips use these same definitions, and pressing a badge opens its definition and a link back here.
Priority
- Track
No signal currently raises the record above the baseline tier.
What to do this week: Review during routine vulnerability management.
Code contract:
pipeline/src/scoring.py:845-904- Track*
A public exploit, elevated exploitation probability, or Stakeholder-Specific Vulnerability Categorization (SSVC) verdict raises this record for closer watching.
What to do this week: Watch for exploitation and prepare the likely fix.
Code contract:
pipeline/src/scoring.py:845-904- Attend
The SSVC-style verdict calls for attention, but no confirmed exploitation signal sets an Act floor.
What to do this week: Plan remediation this week and confirm ownership.
Code contract:
pipeline/src/scoring.py:845-904- Act
Confirmed active exploitation or an SSVC-style Act verdict requires prompt action.
What to do this week: Prioritize remediation now and verify compensating controls.
Code contract:
pipeline/src/scoring.py:845-904- Act now
Ransomware association sets the top tier; active exploitation can also rise one tier through the end-of-life or open-exposure modifier.
What to do this week: Respond now and verify containment, remediation, and exposure.
Code contract:
pipeline/src/scoring.py:845-904
Evidence and timing
- Observed
The tracker directly observed the stated event or measurement in source data.
Code contract:
site/src/lib/trust.ts:1-17- Corroborating observation
An independent external source supports a claim but is not the primary record.
Code contract:
site/src/lib/sourcecopy.ts:27-31- Source reported
The named source asserted this fact, and the tracker is reporting that assertion.
Code contract:
site/src/lib/sourcecopy.ts:27-31- Self-reported
The subject or publisher supplied this information about itself.
Code contract:
site/src/lib/trust.ts:1-17- Unverified claim
A source made this claim, but the tracker has not confirmed the underlying event independently.
Code contract:
site/src/lib/trust.ts:1-17- Tracker computed
The tracker calculated this value deterministically from named inputs.
Code contract:
site/src/lib/sourcecopy.ts:27-31- Tracker inference
The tracker inferred this interpretation from source data, so it is not a source assertion.
Code contract:
site/src/lib/sourcecopy.ts:27-31- Source last published
When the source says it first published the item.
Code contract:
site/src/lib/trust.ts:19-46- Source last updated
When the source says it last updated the item.
Code contract:
site/src/lib/trust.ts:19-46- Tracker last fetched
When the tracker last retrieved this source successfully.
Code contract:
site/src/lib/trust.ts:19-46- This dataset exported at
The latest source or computation time represented in this tracker view.
Code contract:
site/src/lib/trust.ts:19-46- Last material change
When a tracked field with reader impact last changed.
Code contract:
site/src/lib/trust.ts:19-46
Exploitation and catalogs
- CISA KEV
Listed in the Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities catalog.
Code contract:
site/src/lib/exploitation-labels.ts:6-26- VulnCheck KEV
Listed in the VulnCheck Known Exploited Vulnerabilities catalog as observed exploitation.
Code contract:
site/src/lib/exploitation-labels.ts:6-26- ENISA EUVD
Listed as exploited in the European Union Agency for Cybersecurity European Vulnerability Database.
Code contract:
site/src/lib/exploitation-labels.ts:6-26- Tracked exploitation status
The strongest exploitation state supported by the tracker signals for this vulnerability.
Code contract:
site/src/lib/exploitation-labels.ts:19-26- Active exploitation
A tracked signal confirms exploitation in the wild and sets an Act floor.
Code contract:
pipeline/src/ssvc.py:312-320- Proof of concept
Public code or instructions demonstrate exploitation, which can set a Track* floor.
Code contract:
pipeline/src/scoring.py:845-888- Ransomware-associated
A tracked catalog links the vulnerability to ransomware activity, which sets Act now.
Code contract:
pipeline/src/scoring.py:845-888- CISA due date
The remediation deadline set for United States federal civilian agencies under a binding directive.
Code contract:
site/src/lib/vulntable.ts:164-168
Scoring inputs
- Priority score
A tier-major number used to sort vulnerabilities by tier first and then by urgency within that tier.
Code contract:
pipeline/src/scoring.py:1404-1586- CVSS
The Common Vulnerability Scoring System severity score reported by an identified source and version.
Code contract:
site/src/lib/vulnpanel.ts:1490-1510- EPSS
The Exploit Prediction Scoring System estimate of exploitation probability during its published horizon.
Code contract:
pipeline/src/scoring.py:1433-1444- SSVC-style verdict
A tracker-computed Stakeholder-Specific Vulnerability Categorization decision using named deployer inputs.
Code contract:
site/src/lib/vulnpanel.ts:1816-1870- Automatable
Whether exploitation can be reliably automated across targets under the SSVC decision model.
Code contract:
pipeline/src/ssvc.py:1-39- Technical impact
The SSVC input describing whether exploitation gives partial or total control of the affected system.
Code contract:
pipeline/src/ssvc.py:1-39- CWE
A Common Weakness Enumeration category describing the underlying weakness type.
Code contract:
pipeline/src/scoring.py:1404-1586- Product exposure
A product-class estimate that can raise an actively exploited or ransomware-associated item by one tier only when exposure is open.
Code contract:
pipeline/src/scoring.py:916-940- End of life
A product lifecycle flag that can raise an actively exploited item by at most one tier.
Code contract:
pipeline/src/scoring.py:889-904- Reach beyond component
A within-tier signal for impact that crosses the initially vulnerable component boundary.
Code contract:
pipeline/src/scoring.py:1404-1586- ENISA score
A severity score from the European Union Agency for Cybersecurity European Vulnerability Database, shown while NVD analysis is absent.
Code contract:
site/src/lib/vulntable.ts:560-585
Sources and standards
- CVE
A Common Vulnerabilities and Exposures identifier for one publicly disclosed vulnerability record.
Code contract:
pipeline/src/fetchers/structured.py:1- NVD
The United States National Vulnerability Database, used here as one source of vulnerability analysis.
Code contract:
pipeline/src/fetchers/structured.py:1- CNA
The CVE Numbering Authority that assigned or published information for the record.
Code contract:
site/src/lib/vulntable.ts:560-585- ADP
An Authorized Data Publisher that adds analysis to a CVE record without replacing the assigner.
Code contract:
site/src/lib/vulntable.ts:560-585- MITRE ATT&CK
The MITRE Adversarial Tactics, Techniques, and Common Knowledge catalog used for actor and technique mappings.
Code contract:
site/src/pages/actors/index.astro:188-192
Page badges
- Binding Operational Directive
A compulsory Cybersecurity and Infrastructure Security Agency direction for United States federal civilian agencies.
Code contract:
site/src/pages/directives.astro:20-34- Emergency Directive
An urgent Cybersecurity and Infrastructure Security Agency direction issued for a known or reasonably suspected information security threat.
Code contract:
site/src/pages/directives.astro:20-34- Active
The directive remains in force in the curated directive record.
Code contract:
site/src/pages/directives.astro:20-34- Superseded
A newer directive replaced this directive.
Code contract:
site/src/pages/directives.astro:20-34- Revoked
The issuing authority withdrew this directive.
Code contract:
site/src/pages/directives.astro:20-34- Retired
The curated record marks this directive as no longer active.
Code contract:
site/src/pages/directives.astro:20-34- Official action
A direct release or public record from a tracked government agency.
Code contract:
site/src/pages/takedowns.astro:182-184- Keyword match
A news story selected because an action word and a law-enforcement name occur together, not an official record.
Code contract:
site/src/pages/takedowns.astro:182-184