Exploit-aware prioritization
Patch what attackers can reach first
Put exposed, exploitable CVEs ahead of the backlog.
The question
Is this CVE exposed, exploitable, or both?
A CVSS score cannot tell you whether the affected service is live on the internet. FullHunt shows the host and service beside its Exploit Prediction Scoring System (EPSS) score and CISA Known Exploited Vulnerabilities (KEV) status. Public exploit records stay with the finding.
How it works
01
Start with the exposed service
Find the public host, port, and detected technology behind the vulnerability.
02
Match the CVE
Confirm that FullHunt observed the affected service on that host.
03
Check the exploit evidence
Compare its EPSS score, CISA KEV status, and available public exploits.
04
Open the right ticket
Send the host, service, CVE, and exploit evidence to the team that owns the asset.
The records behind the answer
Host and service
The public host, open port, and service FullHunt observed.
Exploit likelihood
The Exploit Prediction Scoring System (EPSS) score for the CVE.
Known exploitation
Whether the CVE appears in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Public exploits
Available exploit and proof-of-concept records for analyst review.
Turn the CVE backlog into a patch queue.
Analysts can work in the FullHunt Console or send each record to a ticketing system, SIEM, or webhook.
What you get
- A finding tied to the host and service where it was observed
- EPSS and CISA KEV data beside the CVE
- Public exploit records available to the analyst
- API and webhook delivery for the remediation queue
See which exposed CVEs need attention.
Run an assessment against your public attack surface and inspect the supporting records.