netVigilance Vulnerability intelligence since 2004
about · since 2004

What this site is

netvigilance.com tracks vulnerabilities that are already being attacked. Every record comes from the CISA Known Exploited Vulnerabilities catalog — 1,703 of them as of 2026-09-09 — which means exploitation has been confirmed in the wild, not merely predicted. Alongside it sits the original netVigilance advisory archive: 53 documents published between 2004 and 2015, kept at their original addresses.

The site is static. It stores no personal data, runs no advertising, and sells nothing. What it costs to run is a build pipeline and a CDN.

Where the name comes from

netVigilance, Inc. was a vulnerability assessment vendor. It operated from 2004 until the middle of the following decade, and it no longer exists. Nothing on this site is for sale, and no part of the former company is trading.

Its research team published security advisories on flaws it found in third-party software — mostly web applications of the era: SQL injection, cross-site scripting and path traversal in CMSes, forums and web-facing tools. Many of those findings received CVE identifiers. The company scored every vulnerability it published against CVSS 2.0, compared its scoring with the National Vulnerability Database, and reported the discrepancies back to NIST.

What it built

The commercial products are listed here as historical record. All of them are discontinued, none are supported, and no downloads are offered.

ProductWhat it was
SecureScout NX Vulnerability management with a distributed scanning architecture
SecureScout SP Multi-user vulnerability assessment for enterprise applications
SecureScout Perimeter External scanning of internet-facing hosts, later with PCI reporting
EagleBox, EasyBox Appliance packagings of the scanner
WinRT Windows Request Tracker, a ticketing system for handling findings
WinHoneyd A Windows port of the Honeyd honeypot — its page is archived here

Why the old pages are still online

The advisories are referenced by NVD, MITRE, CISA bulletins, Gentoo security announcements, vendor release notes, academic papers and mailing list archives. Those references were written once and will not be updated. Removing the pages would silently break them, and break the trail behind a CVE for anyone following it years later.

So every advisory keeps its original address, in each of the three URL forms the site used over the years, and its original text. Nothing has been rewritten to look better in hindsight. Where a product page once stood and no longer serves any purpose, its address now leads here rather than to an error.

The same applies to ScoutNews, the weekly bulletin the company sent out from 2004: the full surviving run is back online as the original PDFs.

Browse the archive →

How the current site works

Records are fetched at build time from CISA, with severity scores from NVD and exploitation probability from FIRST. Nothing is fetched while you read a page. The catalogue rebuilds twice a day, because the remediation countdowns are calculated when the site is built rather than in your browser.

Machine-readable output is available without asking anyone — the catalogue with CVSS and EPSS already joined, per-record JSON, and an RSS feed of new entries; the data page describes all of it. Numbers derived from the dataset live at KEV in numbers.

netVigilance is an independent tracker. It is not affiliated with CISA, NIST or FIRST, and it does not speak for them.

Corrections to the archive, questions about the data, or anything else: get in touch.