How the service works
Search for a vendor, a product or a CVE identifier. Add a version
number to have it assessed against the affected ranges published by
the sources. The answer distinguishes between five outcomes:
confirmed affected, confirmed not affected, possibly affected,
no version data, and cannot be determined.
Important:
No results does not mean a system is safe. The service covers published vulnerabilities in its sources, and a vulnerability can exist without having been published yet.
How results are ordered
Actively exploited vulnerabilities (CISA KEV) come first, then
confirmed version matches, then the probability that the
vulnerability will actually be exploited (EPSS), then CVSS score,
then recency. Probability before theoretical severity is a
deliberate choice: a critical score that nobody exploits should
not outrank a medium one that is being exploited today. The
ordering is Berigo's editorial choice; every number shown is the
source's own.
Continuous monitoring
A search is a snapshot. New vulnerabilities are published every day, and
the ones that matter are rarely the ones you happened to search for.
With continuous monitoring you register your technology inventory with
us, encrypted, and we assess it against new vulnerabilities every day.
You hear from us when something actually affects you.
The point is the combination.
Anyone can list single vulnerabilities. We show whether your findings
together give an attacker a way in, a foothold and a route onward.
Small
Up to 50 assets
790 NOK/month
Daily assessment and email alerts.
Medium
51 to 250 assets
2 900 NOK/month
Combined risk map and prioritised alerts.
Large
251 to 1 000 assets
from 9 800 NOK/month
Attack chain analysis and a quarterly review with an adviser.
Extended
1 001 to 5 000 assets
from 24 800 NOK/month
Several environments, named adviser and monthly review.
By agreement
More than 5 000 assets
Requires consultation
Scope, complexity and number of environments decide the price. We map it together before we quote.
Book a consultation
Prices are from-prices within each band. The final price depends on the number of assets and how many environments are covered.
Your inventory is encrypted at rest with a key held outside the web root,
and is never shared or sent to external services. We are the data processor;
a processing agreement is part of the contract.
Get in touch
Try a free one-off analysis
Sources and freshness
CVE
i
CVE
Common Vulnerabilities and Exposures
×
What it is A reference number naming one specific vulnerability, for example CVE-2024-9474.
What it tells you Which vulnerability we are talking about, and in which product.
What it does NOT tell you Nothing about how serious it is, whether anyone is exploiting it, or whether it concerns you.
Why it matters Without a shared number, vendor, authority and tooling cannot discuss the same flaw.
Used with the others The number is the key. NVD, KEV and EPSS all describe the same CVE.
NVD
i
NVD
National Vulnerability Database
×
What it is A US register that fills in each CVE with structured detail.
What it tells you How serious the flaw is technically (CVSS, 0 to 10), and which versions are affected.
What it does NOT tell you Whether the vulnerability is actually being exploited, and how important the system is to your business.
Why it matters This is what decides whether your version is affected.
Used with the others CVSS says how bad it could get. KEV and EPSS say how likely it is to happen.
CWE
i
CWE
Common Weakness Enumeration
×
What it is A catalogue of kinds of mistakes, not individual flaws, such as "forgot to check the password".
What it tells you What kind of weakness lies behind the vulnerability.
What it does NOT tell you Anything about this vulnerability in your system. It describes the class, not the case.
Why it matters If the same mistake recurs at one vendor, that is a pattern to raise.
Used with the others CVE is the incident, CWE the type of cause. Use it to learn, not to triage.
CISA KEV
i
CISA KEV
Known Exploited Vulnerabilities
×
What it is A list from the US authorities of vulnerabilities observed in real attacks.
What it tells you That someone has actually used it against someone. No longer theory.
What it does NOT tell you Whether you are being attacked, or how much damage it would do to you.
Why it matters The strongest single signal there is: from "could happen" to "is happening".
Used with the others A KEV listing normally outweighs a high CVSS score on its own.
EPSS
i
EPSS
Exploit Prediction Scoring System
×
What it is A percentage estimate of how likely exploitation is within the next 30 days.
What it tells you How likely exploitation is, compared with every other known vulnerability.
What it does NOT tell you That it has happened (KEV answers that), or how much damage it does (CVSS).
Why it matters Most vulnerabilities are never exploited. EPSS separates out the few that will be.
Used with the others High EPSS plus KEV means urgency. High CVSS, low EPSS, unexposed can be scheduled.
How to read this together
No single value should be used on its own. A high CVSS score does not
mean a vulnerability is being exploited, and a low one does not mean it
is harmless. The four sources answer four different questions.
CVE names the specific vulnerability.
NVD adds severity and technical detail about it.
CWE describes the type of mistake behind it.
CISA KEV shows that it is already being exploited.
EPSS estimates how likely exploitation is soon.
The order that decides what is urgent
Do you actually have the product?
Is the version you run affected?
Is it listed in CISA KEV?
Does it have a high EPSS score?
Is the system reachable from the internet or from others?
How important is the system to the business?
Are there compensating controls already in place?
The first two questions are not about the vulnerability at all. They are
about you, and they remove most of the list before you start.
A short example
Fix this week
CVSS 6,5 (medium)
In CISA KEV: yes
EPSS: 94 per cent
A firewall facing the internet
Can be scheduled
CVSS 9,8 (critical)
In CISA KEV: no
EPSS: 0,04 per cent
A test server with no internet access
Sorted by CVSS alone, the one on the right comes first. It is the more
serious flaw in theory. But the one on the left is being used against
real organisations right now, and it sits where an attacker can reach
it. That is the one to fix first.
The critical one still has to be fixed. It just does not have to be
fixed today.
The service covers 113,269 vulnerabilities,
of which 1,670 are listed as actively exploited by CISA.
Actively exploited entries are included regardless of age. Latest source update:
2026-08-19 23:45 UTC.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE and the CVE logo are registered trademarks of The MITRE Corporation;
CVE records are used under the CVE Terms of Use .
CWE is a trademark of The MITRE Corporation, used per the
CWE Terms of Use .
KEV data from CISA (CC0).
Exploitation probability from EPSS , a FIRST.org project.
Open-source package data from OSV and the
GitHub Advisory Database (CC-BY 4.0).
Scores and vectors are shown as published by the sources. The ordering of
results is Berigo's own editorial assessment, described on the search page,
and is not NVD data. An empty result never means a system is safe.