CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
About

Glossary

One-line definitions for the labels Cybersecurity Tracker uses. Badge tooltips use these same definitions, and pressing a badge opens its definition and a link back here.

Priority

Track

No signal currently raises the record above the baseline tier.

What to do this week: Review during routine vulnerability management.

Code contract: pipeline/src/scoring.py:845-904

Track*

A public exploit, elevated exploitation probability, or Stakeholder-Specific Vulnerability Categorization (SSVC) verdict raises this record for closer watching.

What to do this week: Watch for exploitation and prepare the likely fix.

Code contract: pipeline/src/scoring.py:845-904

Attend

The SSVC-style verdict calls for attention, but no confirmed exploitation signal sets an Act floor.

What to do this week: Plan remediation this week and confirm ownership.

Code contract: pipeline/src/scoring.py:845-904

Act

Confirmed active exploitation or an SSVC-style Act verdict requires prompt action.

What to do this week: Prioritize remediation now and verify compensating controls.

Code contract: pipeline/src/scoring.py:845-904

Act now

Ransomware association sets the top tier; active exploitation can also rise one tier through the end-of-life or open-exposure modifier.

What to do this week: Respond now and verify containment, remediation, and exposure.

Code contract: pipeline/src/scoring.py:845-904

Evidence and timing

Observed

The tracker directly observed the stated event or measurement in source data.

Code contract: site/src/lib/trust.ts:1-17

Corroborating observation

An independent external source supports a claim but is not the primary record.

Code contract: site/src/lib/sourcecopy.ts:27-31

Source reported

The named source asserted this fact, and the tracker is reporting that assertion.

Code contract: site/src/lib/sourcecopy.ts:27-31

Self-reported

The subject or publisher supplied this information about itself.

Code contract: site/src/lib/trust.ts:1-17

Unverified claim

A source made this claim, but the tracker has not confirmed the underlying event independently.

Code contract: site/src/lib/trust.ts:1-17

Tracker computed

The tracker calculated this value deterministically from named inputs.

Code contract: site/src/lib/sourcecopy.ts:27-31

Tracker inference

The tracker inferred this interpretation from source data, so it is not a source assertion.

Code contract: site/src/lib/sourcecopy.ts:27-31

Source last published

When the source says it first published the item.

Code contract: site/src/lib/trust.ts:19-46

Source last updated

When the source says it last updated the item.

Code contract: site/src/lib/trust.ts:19-46

Tracker last fetched

When the tracker last retrieved this source successfully.

Code contract: site/src/lib/trust.ts:19-46

This dataset exported at

The latest source or computation time represented in this tracker view.

Code contract: site/src/lib/trust.ts:19-46

Last material change

When a tracked field with reader impact last changed.

Code contract: site/src/lib/trust.ts:19-46

Exploitation and catalogs

CISA KEV

Listed in the Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities catalog.

Code contract: site/src/lib/exploitation-labels.ts:6-26

VulnCheck KEV

Listed in the VulnCheck Known Exploited Vulnerabilities catalog as observed exploitation.

Code contract: site/src/lib/exploitation-labels.ts:6-26

ENISA EUVD

Listed as exploited in the European Union Agency for Cybersecurity European Vulnerability Database.

Code contract: site/src/lib/exploitation-labels.ts:6-26

Tracked exploitation status

The strongest exploitation state supported by the tracker signals for this vulnerability.

Code contract: site/src/lib/exploitation-labels.ts:19-26

Active exploitation

A tracked signal confirms exploitation in the wild and sets an Act floor.

Code contract: pipeline/src/ssvc.py:312-320

Proof of concept

Public code or instructions demonstrate exploitation, which can set a Track* floor.

Code contract: pipeline/src/scoring.py:845-888

Ransomware-associated

A tracked catalog links the vulnerability to ransomware activity, which sets Act now.

Code contract: pipeline/src/scoring.py:845-888

CISA due date

The remediation deadline set for United States federal civilian agencies under a binding directive.

Code contract: site/src/lib/vulntable.ts:164-168

Scoring inputs

Priority score

A tier-major number used to sort vulnerabilities by tier first and then by urgency within that tier.

Code contract: pipeline/src/scoring.py:1404-1586

CVSS

The Common Vulnerability Scoring System severity score reported by an identified source and version.

Code contract: site/src/lib/vulnpanel.ts:1490-1510

EPSS

The Exploit Prediction Scoring System estimate of exploitation probability during its published horizon.

Code contract: pipeline/src/scoring.py:1433-1444

SSVC-style verdict

A tracker-computed Stakeholder-Specific Vulnerability Categorization decision using named deployer inputs.

Code contract: site/src/lib/vulnpanel.ts:1816-1870

Automatable

Whether exploitation can be reliably automated across targets under the SSVC decision model.

Code contract: pipeline/src/ssvc.py:1-39

Technical impact

The SSVC input describing whether exploitation gives partial or total control of the affected system.

Code contract: pipeline/src/ssvc.py:1-39

CWE

A Common Weakness Enumeration category describing the underlying weakness type.

Code contract: pipeline/src/scoring.py:1404-1586

Product exposure

A product-class estimate that can raise an actively exploited or ransomware-associated item by one tier only when exposure is open.

Code contract: pipeline/src/scoring.py:916-940

End of life

A product lifecycle flag that can raise an actively exploited item by at most one tier.

Code contract: pipeline/src/scoring.py:889-904

Reach beyond component

A within-tier signal for impact that crosses the initially vulnerable component boundary.

Code contract: pipeline/src/scoring.py:1404-1586

ENISA score

A severity score from the European Union Agency for Cybersecurity European Vulnerability Database, shown while NVD analysis is absent.

Code contract: site/src/lib/vulntable.ts:560-585

Sources and standards

CVE

A Common Vulnerabilities and Exposures identifier for one publicly disclosed vulnerability record.

Code contract: pipeline/src/fetchers/structured.py:1

NVD

The United States National Vulnerability Database, used here as one source of vulnerability analysis.

Code contract: pipeline/src/fetchers/structured.py:1

CNA

The CVE Numbering Authority that assigned or published information for the record.

Code contract: site/src/lib/vulntable.ts:560-585

ADP

An Authorized Data Publisher that adds analysis to a CVE record without replacing the assigner.

Code contract: site/src/lib/vulntable.ts:560-585

MITRE ATT&CK

The MITRE Adversarial Tactics, Techniques, and Common Knowledge catalog used for actor and technique mappings.

Code contract: site/src/pages/actors/index.astro:188-192

Page badges

Binding Operational Directive

A compulsory Cybersecurity and Infrastructure Security Agency direction for United States federal civilian agencies.

Code contract: site/src/pages/directives.astro:20-34

Emergency Directive

An urgent Cybersecurity and Infrastructure Security Agency direction issued for a known or reasonably suspected information security threat.

Code contract: site/src/pages/directives.astro:20-34

Active

The directive remains in force in the curated directive record.

Code contract: site/src/pages/directives.astro:20-34

Superseded

A newer directive replaced this directive.

Code contract: site/src/pages/directives.astro:20-34

Revoked

The issuing authority withdrew this directive.

Code contract: site/src/pages/directives.astro:20-34

Retired

The curated record marks this directive as no longer active.

Code contract: site/src/pages/directives.astro:20-34

Official action

A direct release or public record from a tracked government agency.

Code contract: site/src/pages/takedowns.astro:182-184

Keyword match

A news story selected because an action word and a law-enforcement name occur together, not an official record.

Code contract: site/src/pages/takedowns.astro:182-184

Glossary