See it work, then get a key

See it work, then get a key.

Look up a CVE you actually care about. See the public observations behind it, dated and sourced, and exactly what the free tier gives you. Then take a key. No sales call, no credit card.


Look up any CVE

Type a CVE. ESIP returns the public observations it has recorded, dated and sourced, or tells you when it has none. No key required to look.

Try one of these: CVE-2021-44228 · CVE-2026-41940


The same CVE, two depths

The same CVE. Two depths.

The free tier shows you the observations and the dates: what changed, from which public source, and when. The commercial tier interprets those observations into a defensible verdict: the exposure state, where it is heading, how fast, and the narrative of why.

One representative CVE, the same for every visitor — the full free response beside the full commercial response, so you can see the exact delta. ESIP reports only what it can evidence: each side shows the sources and signals that actually fired on this CVE, not the full set ESIP tracks.

Free · schema 1.2 GET public.exposuresignal.io/v1/cves/CVE-2026-41940
{
  "data": {
    "cve_id": "CVE-2026-41940",
    "exposure_class_id": "CVE-2026-41940",
    "attack_techniques": [
      {
        "technique_id": "T1078",
        "technique_name": "Valid Accounts"
      }
    ],
    "cwe": [
      {
        "cwe_id": "CWE-306",
        "name": "Missing Authentication for Critical Function",
        "sources": [
          {
            "source": "disclosure@vulncheck.com",
            "type": "Secondary"
          }
        ]
      }
    ],
    "observation_events": [
      {
        "observation_type": "cisa_kev_inclusion",
        "source_name": "CISA Known Exploited Vulnerabilities",
        "observed_date": "2026-04-30",
        "reference_id": null,
        "kev_context": {
          "known_ransomware_campaign_use": false,
          "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
          "due_date": "2026-05-03"
        },
        "source_event_date": "2026-04-30"
      },
      {
        "observation_type": "euvd_exploited_inclusion",
        "source_name": "ENISA EUVD Exploited Vulnerabilities",
        "observed_date": "2026-05-01",
        "reference_id": null,
        "kev_context": null,
        "source_event_date": "2026-04-30"
      },
      {
        "observation_type": "exploit_reference",
        "source_name": "ExploitDB",
        "observed_date": "2026-05-27",
        "reference_id": "52574",
        "kev_context": null,
        "source_event_date": null
      },
      {
        "observation_type": "exploit_reference",
        "source_name": "GitHub PoC Repositories",
        "observed_date": "2026-04-30",
        "reference_id": "realawaisakbar/CVE-2026-41940-Exploit-PoC",
        "kev_context": null,
        "source_event_date": null
      },
      {
        "observation_type": "exploit_reference",
        "source_name": "Metasploit Framework Modules",
        "observed_date": "2026-05-18",
        "reference_id": "exploit/multi/http/cpanel_whm_auth_bypass_rce",
        "kev_context": null,
        "source_event_date": null
      }
    ],
    "detection_capability": null,
    "nvd_published_date": "2026-04-29"
  },
  "meta": {
    "schema_version": "1.2",
    "snapshot_generated_at": "2026-07-20T03:01:07.485895Z",
    "publication_identity": {
      "content_hash": "3bc6c36323fc212157f7f42011793bbd3946c12a929ef799c41796725c254ad0",
      "snapshot_generated_at": "2026-07-20T03:01:07.485895Z",
      "git_commit_sha": "b7f7d3e573f3d3dc9673695015974cae5471bf93",
      "schema_version": "1.2"
    },
    "attribution": "Data provided by ESIP / ZenzizenSec — www.exposuresignal.io",
    "license_url": "https://github.com/zenzizensec/esip-data/blob/main/LICENSE_DATA.md"
  }
}
84 lines · observations, ATT&CK & CWE, dated

Free — the facts. Which public sources saw it and when, the ATT&CK technique, the CWE weakness. You decide what it means.

Commercial — the verdict. Lifecycle stage, severity band, trend and velocity, corroboration strength, per-source decay windows, and the "what changed" narrative. The answer, with its evidence.

CVSS 4.09.3 CVSS 3.19.8

One score can hide disagreement. This CVE rates 9.3 under CVSS 4.0 and 9.8 under CVSS 3.1. The commercial tier returns every CVSS assertion, so you see the full severity range — not just whichever version happened to land in one feed.

Unlock the verdict →

What you walk away knowing

Every signal is built so you can say four things, and back all of them:


Pick the depth you need
Free. The public observations, dated and sourced. Enough to see what changed and build a daily check. A free key, issued on the spot.
Commercial. The full verdict, the change feed, the lifecycle history, and the pre-assembled narrative. Self-serve, with transparent pricing.
Enterprise. The commercial depth plus what a larger deployment needs: data residency, volume, procurement. Talk to us.
See full pricing →

Get a free key

Get a free key.

One field: your email. No credit card, no call. We'll email your free key shortly.


Your first request

A working call with your new key. Paste it and run it.

curl -H "X-API-Key: YOUR_KEY" \
  https://public.exposuresignal.io/v1/cves/CVE-2026-41940
Full reference →

Prefer email to an API? Get the weekly signal digest: the CVEs that moved, every Tuesday.

Subscribe →