Prioritisation
Known Exploit Priority (KEV + EPSS)
A server turns up dozens of vulnerabilities and every one has a CVSS score. But CVSS tells you how bad a vulnerability could be, not whether anyone is actually exploiting it. Specula ranks what it finds using CISA's actively-exploited catalogue and FIRST's exploit probability score.
Order: ransomware > KEV > EPSS > CVSS
Vulnerabilities known to be used in ransomware campaigns come first, then those confirmed as exploited, then those with a high probability score. CVSS is the last tiebreaker.
The order genuinely changes things
Measured: a CVSS 5.3 vulnerability at 98.6% EPSS outranks a CVSS 9.8 one at 79.7%. Both numbers sit side by side on screen, so you can audit the ranking yourself.
Catalogue daily, evaluation on read
The catalogues sync every day, but matching happens the moment you look. A vulnerability added yesterday doesn't wait for the server to be rescanned.
CVE-2024-3400
EPSS 98.6% · CVSS 5.3
CVE-2023-44487
EPSS 94.1% · CVSS 7.5
CVE-2024-21762
EPSS 79.7% · CVSS 9.8
Ranked on field data · CVSS last
Its limits
If a catalogue has never synced, the screen does not say “not exploited” — the counter stays empty and a warning appears. Detection comes from the open port banner, so a distribution that backported the patch may already be fixed; that note travels with the finding.
Other features
Run this check on your own domain.
Add a domain and Specula finishes the first scan within minutes. No credit card needed.