WHAT THIS IS — KEV covers what's known exploited. This scores everything else: the hundreds of thousands
of CVEs that never enter KEV but still need triage. It loads slim per-year bundles you host (CVSS + EPSS + exploit-availability,
joined offline), ranks them by a scoring lens you choose, and renders an SSVC decision per finding. The two judgment factors
— Automatable and Mission & Well-being — are yours to set, because CISA's tree defines them as stakeholder calls, not
values a tool can compute. Each decision emits the canonical CISAv1/E:/A:/T:/M:/ vector so it verifies against
CISA's own calculator. Observable factors (Exploitation, Technical Impact) are pre-filled from the data and stay editable.
1
Load
select year(s) and load
INITIATE DATA LOADING — select year(s) below
2
Score & triage
EPSS × CVSS
EPSS only
CVSS only
Exploit-weighted
0
SSVC: Act
0
Attend
0
Track*
0
Track
0
Loaded
Nothing loaded yet. Load one or more years above.
GHOST — Grounded Handling Of Sourced Threat-intel · Tool 59 · build 2026.08.01-C
CVSS from CVEProject/cvelistV5 · EPSS from FIRST.org · exploit-availability from Exploit-DB · SSVC per CISA's published decision tree (CISAv1 vector). This tool computes no CVSS itself — it displays the authoritative vector-derived value and never presents a composite as a CVSS score.