← All use cases
Use case · Free + Commercial

Vulnerability Analysts

Filter overnight changes against your patch backlog before you open your VM platform.

Every morning, before Sarah opens her vulnerability management platform, she wants the same answer: of the 20,000 findings her scanner returned, which handful actually changed overnight? Not which are severe (the scanner already told her that), but which ones something in the real world just moved on. A Metasploit module appeared. A government exploitation confirmation landed. Evidence accumulated.

Those CVEs go to the top of today’s queue before she opens a single ticket.

Sarah's scanner found 20,000 vulnerabilities. ESIP tells her which five changed while she was sleeping.

Free tier
What you get
The daily snapshot. Every CVE's observation events with dates: KEV inclusions, exploit references from Metasploit, ExploitDB and GitHub PoC, and the ATT&CK technique.
What you do
A short script filters the snapshot twice: CVEs whose exploitation-confirmed event carries today's or yesterday's date, and CVEs that gained a weaponized exploit reference in the same window. Then it cross-references her patch backlog.
Outcome
A flagged list of what materially moved overnight: four CVEs today, maybe twelve on a busy morning. She decides the order. A simple implementation that has run unchanged ever since.
  • Daily snapshot
  • Live API at public.exposuresignal.io
  • Free API key
Commercial
What you get
The change feed. Not CVEs that gained an observation, but CVEs whose verdict changed. Each entry carries lifecycle_stage, current_trend, signal_velocity, compound_risk, and a pre-assembled evidence.what_changed narrative.
What it does for you
She queries /v1/signals/changes since yesterday. This morning: 11 entries. Three escalated Active to Confirmed, one Confirmed to Declining, two gained new compound risk. CVE-2026-41940 shows lifecycle Active to Confirmed, trend Escalating, velocity High, what_changed “Metasploit module detected: cpanel_whm_auth_bypass_rce,” compound_risk Strong.
Outcome
A ranked list, not a flagged one: the three that escalated to Confirmed first, the two with new compound risk next, the rest by velocity. It tells her what changed, in what direction, how fast, and why it's urgent today rather than yesterday.
  • Change feed: verdict-level, not observation-level
  • lifecycle_stage · current_trend · signal_velocity
  • evidence.what_changed, pre-assembled
  • compound_risk strength tier

The free tier gives you observable facts. The commercial platform turns those facts into an explainable exposure signal: what changed, why it matters, and what to do next.

Get a free key See pricing →