Methodology
The Nullsec Score is a prioritization model designed to identify vulnerabilities that may deserve faster attention.
Scores range from 0 to 100.
Signals considered
The model currently evaluates several public signals, including:
- Inclusion in the CISA Known Exploited Vulnerabilities catalog
- Known ransomware exploitation
- CVSS severity
- Recency
- NVD analysis status
Priority levels
| Score | Priority |
|---|---|
| 90–100 | Immediate |
| 75–89 | Urgent |
| 60–74 | High |
| 40–59 | Watch |
| 0–39 | Low |
A high Nullsec Score does not automatically mean that every organization is affected.
Actual risk depends on factors including the affected product, deployed version, exposure, configuration and available mitigations.
Data sources
Nullsec uses public vulnerability information from sources including:
- CISA Known Exploited Vulnerabilities
- National Vulnerability Database
Nullsec does not replace vendor security advisories or organization-specific risk assessment.