Look up a CVE you actually care about. See the public observations behind it, dated and sourced, and exactly what the free tier gives you. Then take a key. No sales call, no credit card.
Type a CVE. ESIP returns the public observations it has recorded, dated and sourced, or tells you when it has none. No key required to look.
Try one of these: CVE-2021-44228 · CVE-2026-41940
The free tier shows you the observations and the dates: what changed, from which public source, and when. The commercial tier interprets those observations into a defensible verdict: the exposure state, where it is heading, how fast, and the narrative of why.
One representative CVE, the same for every visitor — the full free response beside the full commercial response, so you can see the exact delta. ESIP reports only what it can evidence: each side shows the sources and signals that actually fired on this CVE, not the full set ESIP tracks.
{
"data": {
"cve_id": "CVE-2026-41940",
"exposure_class_id": "CVE-2026-41940",
"attack_techniques": [
{
"technique_id": "T1078",
"technique_name": "Valid Accounts"
}
],
"cwe": [
{
"cwe_id": "CWE-306",
"name": "Missing Authentication for Critical Function",
"sources": [
{
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
]
}
],
"observation_events": [
{
"observation_type": "cisa_kev_inclusion",
"source_name": "CISA Known Exploited Vulnerabilities",
"observed_date": "2026-04-30",
"reference_id": null,
"kev_context": {
"known_ransomware_campaign_use": false,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"due_date": "2026-05-03"
},
"source_event_date": "2026-04-30"
},
{
"observation_type": "euvd_exploited_inclusion",
"source_name": "ENISA EUVD Exploited Vulnerabilities",
"observed_date": "2026-05-01",
"reference_id": null,
"kev_context": null,
"source_event_date": "2026-04-30"
},
{
"observation_type": "exploit_reference",
"source_name": "ExploitDB",
"observed_date": "2026-05-27",
"reference_id": "52574",
"kev_context": null,
"source_event_date": null
},
{
"observation_type": "exploit_reference",
"source_name": "GitHub PoC Repositories",
"observed_date": "2026-04-30",
"reference_id": "realawaisakbar/CVE-2026-41940-Exploit-PoC",
"kev_context": null,
"source_event_date": null
},
{
"observation_type": "exploit_reference",
"source_name": "Metasploit Framework Modules",
"observed_date": "2026-05-18",
"reference_id": "exploit/multi/http/cpanel_whm_auth_bypass_rce",
"kev_context": null,
"source_event_date": null
}
],
"detection_capability": null,
"nvd_published_date": "2026-04-29"
},
"meta": {
"schema_version": "1.2",
"snapshot_generated_at": "2026-07-20T03:01:07.485895Z",
"publication_identity": {
"content_hash": "3bc6c36323fc212157f7f42011793bbd3946c12a929ef799c41796725c254ad0",
"snapshot_generated_at": "2026-07-20T03:01:07.485895Z",
"git_commit_sha": "b7f7d3e573f3d3dc9673695015974cae5471bf93",
"schema_version": "1.2"
},
"attribution": "Data provided by ESIP / ZenzizenSec — www.exposuresignal.io",
"license_url": "https://github.com/zenzizensec/esip-data/blob/main/LICENSE_DATA.md"
}
} {
"exposure_class_id": "CVE-2026-41940",
"exposure_type": "cve",
"signal_id": "dd85a205-ee89-41d9-8340-30fb4ceb4c45",
"generated_at": "2026-04-30T18:36:23.291555Z",
"signal_version": 24,
"tier1_signals": [
{
"signal_type": "exploit_capability_emerging",
"fired_at": "2026-04-30T18:36:19.760395Z",
"source_id": "github_poc",
"source_trust_tier": "low",
"decay_expires_at": "2026-06-06T18:35:29.739880Z",
"change_driver": null,
"model_version": null
},
{
"signal_type": "exploitation_confirmed_in_wild",
"fired_at": "2026-04-30T18:58:53.831062Z",
"source_id": "cisa_kev",
"source_trust_tier": "verified",
"decay_expires_at": "2026-10-28T09:01:55.593763Z",
"change_driver": null,
"model_version": null
},
{
"signal_type": "exploit_likelihood_estimate_increased",
"fired_at": "2026-05-01T00:00:00Z",
"source_id": "first_epss",
"source_trust_tier": "verified",
"decay_expires_at": "2026-07-07T00:00:00Z",
"change_driver": "unclassified",
"model_version": null
},
{
"signal_type": "exploitation_confirmed_in_wild",
"fired_at": "2026-05-01T09:01:55.593763Z",
"source_id": "enisa_euvd_exploited",
"source_trust_tier": "high",
"decay_expires_at": "2026-10-28T09:01:55.593763Z",
"change_driver": null,
"model_version": null
},
{
"signal_type": "exploit_capability_emerging",
"fired_at": "2026-05-01T18:32:57.362203Z",
"source_id": "github_poc",
"source_trust_tier": "low",
"decay_expires_at": "2026-06-06T18:35:29.739880Z",
"change_driver": null,
"model_version": null
},
{
"signal_type": "exploit_capability_emerging",
"fired_at": "2026-05-02T06:33:31.537447Z",
"source_id": "github_poc",
"source_trust_tier": "low",
"decay_expires_at": "2026-06-06T18:35:29.739880Z",
"change_driver": null,
"model_version": null
},
{
"signal_type": "exploit_capability_emerging",
"fired_at": "2026-05-03T06:34:28.706485Z",
"source_id": "github_poc",
"source_trust_tier": "low",
"decay_expires_at": "2026-06-06T18:35:29.739880Z",
"change_driver": null,
"model_version": null
},
{
"signal_type": "exploit_likelihood_estimate_increased",
"fired_at": "2026-05-07T00:00:00Z",
"source_id": "first_epss",
"source_trust_tier": "verified",
"decay_expires_at": "2026-07-07T00:00:00Z",
"change_driver": "unclassified",
"model_version": null
},
{
"signal_type": "exploit_capability_emerging",
"fired_at": "2026-05-07T18:35:29.739880Z",
"source_id": "github_poc",
"source_trust_tier": "low",
"decay_expires_at": "2026-06-06T18:35:29.739880Z",
"change_driver": null,
"model_version": null
},
{
"signal_type": "exploit_likelihood_estimate_increased",
"fired_at": "2026-05-13T00:00:00Z",
"source_id": "first_epss",
"source_trust_tier": "verified",
"decay_expires_at": "2026-07-07T00:00:00Z",
"change_driver": "unclassified",
"model_version": null
},
{
"signal_type": "weaponized_exploitation_available",
"fired_at": "2026-05-18T16:01:27.571019Z",
"source_id": "metasploit",
"source_trust_tier": "high",
"decay_expires_at": "2026-07-26T04:00:44.757804Z",
"change_driver": null,
"model_version": null
},
{
"signal_type": "exploit_likelihood_estimate_increased",
"fired_at": "2026-05-19T00:00:00Z",
"source_id": "first_epss",
"source_trust_tier": "verified",
"decay_expires_at": "2026-07-07T00:00:00Z",
"change_driver": "unclassified",
"model_version": null
},
{
"signal_type": "exploit_likelihood_estimate_increased",
"fired_at": "2026-05-27T00:00:00Z",
"source_id": "first_epss",
"source_trust_tier": "verified",
"decay_expires_at": "2026-07-07T00:00:00Z",
"change_driver": "unclassified",
"model_version": null
},
{
"signal_type": "weaponized_exploitation_available",
"fired_at": "2026-05-27T04:00:44.757804Z",
"source_id": "exploitdb",
"source_trust_tier": "high",
"decay_expires_at": "2026-07-26T04:00:44.757804Z",
"change_driver": null,
"model_version": null
},
{
"signal_type": "exploit_likelihood_estimate_increased",
"fired_at": "2026-06-23T00:00:00Z",
"source_id": "first_epss",
"source_trust_tier": "verified",
"decay_expires_at": "2026-07-07T00:00:00Z",
"change_driver": "unclassified",
"model_version": null
}
],
"verdict": {
"lifecycle_stage": "Confirmed",
"entered_stage_at": "2026-04-30T18:59:02.744945Z",
"severity_score": 70,
"severity_band": "Critical",
"severity_band_range": {
"min": 70,
"max": 100
},
"attack_relevance": {
"primary": "Entry",
"secondary": null,
"technique_id": "T1078",
"technique_name": "Valid Accounts",
"tactic": "defense-evasion",
"tactic_display": "Defense Evasion",
"technique_count": 1,
"mapping_confidence": "Medium",
"mapping_source": "esip",
"cwe_basis": [
{
"cwe_id": "CWE-306",
"cwe_name": "Missing Authentication for Critical Function",
"rule_id": "6ffac454-7b99-42b6-afa1-ae8bc0f50d62",
"abstraction": "Base"
}
]
},
"confidence": "Verified",
"remediation_available": true
},
"evidence": {
"what_changed": "Weaponized exploit detected (ExploitDB 52574)",
"supporting_signals": [
"exploit_capability_emerging",
"exploitation_confirmed_in_wild",
"exploit_likelihood_estimate_increased",
"weaponized_exploitation_available"
],
"source_count": 6,
"highest_trust_source": "verified"
},
"cve_metadata": {
"title": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
"description": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
"cvss_score": 9.3,
"cvss_version": "4.0",
"cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"cvss_assertions": [
{
"source": "disclosure@vulncheck.com",
"type": "Secondary",
"version": "4.0",
"score": 9.3,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
},
{
"source": "disclosure@vulncheck.com",
"type": "Secondary",
"version": "3.1",
"score": 9.8,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"cvss_contested": false,
"published_date": "2026-04-29T16:16:25.037000Z",
"nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41940"
},
"cwe": [
{
"cwe_id": "CWE-306",
"name": "Missing Authentication for Critical Function",
"sources": [
{
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
]
}
],
"compound_risk": {
"output_class": "amplified_confidence",
"strength_tier": "Strong",
"contributing_signal_types": [
"epss_delta",
"kev_inclusion",
"weaponized_exploit_available"
],
"contributing_source_ids": [
"cisa_kev",
"enisa_euvd_exploited",
"exploitdb",
"first_epss",
"metasploit"
],
"detected_at": "2026-04-30T18:59:02.744945+00:00"
},
"temporal_context": {
"current_trend": "Stable",
"trend_drivers": [],
"latest_material_change": "weaponized_exploitation_available",
"latest_material_change_source": "exploitdb",
"latest_material_change_at": "2026-05-27T04:00:44.757804Z",
"time_since_last_material_change_days": 55,
"signal_velocity": "Low",
"threat_age_days": 82,
"weaponization_age_days": 64,
"exploitation_phase": "pending",
"context_version": 24,
"trend_rules_version": "ff6a3dbf04287900ec0b503fed2327ee08a9e5431bd3d19d7a27e1df13d76c1d"
},
"_meta": {
"signal_schema_version": "1.9",
"generated_at": "2026-07-21T01:58:42.772153Z",
"next_decay_event_at": "2026-06-06T18:35:29.739880Z",
"degraded_sources": 0,
"cache_serving_stale": false,
"api_request_id": "171d7563-ba46-4dc0-bf3b-7e309796075c"
}
} Free — the facts. Which public sources saw it and when, the ATT&CK technique, the CWE weakness. You decide what it means.
Commercial — the verdict. Lifecycle stage, severity band, trend and velocity, corroboration strength, per-source decay windows, and the "what changed" narrative. The answer, with its evidence.
One score can hide disagreement. This CVE rates 9.3 under CVSS 4.0 and 9.8 under CVSS 3.1. The commercial tier returns every CVSS assertion, so you see the full severity range — not just whichever version happened to land in one feed.
Every signal is built so you can say four things, and back all of them:
One field: your email. No credit card, no call. We'll email your free key shortly.
A working call with your new key. Paste it and run it.
curl -H "X-API-Key: YOUR_KEY" \ https://public.exposuresignal.io/v1/cves/CVE-2026-41940Full reference →
Prefer email to an API? Get the weekly signal digest: the CVEs that moved, every Tuesday.
Subscribe →