Continuous Threat Exposure Management, built around risk you can actually act on.
Most vulnerability tools hand you a wall of CVSS scores and call it prioritization. CVEasy scores every CVE against your environment with TRIS — a 12-layer risk framework (patent pending) that folds in exploit availability, asset exposure, business context, and threat-actor activity — then tells you the handful that actually matter this week.
- CVEasy — a desktop CTEM platform that scans your environment, scores every finding with the full 12-layer TRIS engine, and turns a flood of CVEs into a short, ordered fix list with plain-English remediation.
- TRIS — Threat & Risk Intelligence Scoring. Twelve layers of context beyond CVSS: EPSS, KEV, exploit maturity, asset exposure, reachability, and real business impact.
- BASzy — breach-and-attack simulation that proves whether a finding is actually reachable in your environment before you spend a cycle on it.
We ship a free public slice of the work every quarter — no signup, MIT licensed.
| Repo | What it is |
|---|---|
| cveasy-chatbot-pentest | Free CLI to pentest any deployed AI chatbot. Six attack classes, 37 probes, single readable Python file. |
| threat-intel-payloads | Quarterly drops of attack-payload manifests with TRIS-lite scoring and reproducible labs. |
Every team running vuln management has the same problem: too many CVEs, not enough context. A CVSS score tells you a bug is bad. It doesn't tell you whether it matters to you. CVEasy started as a passion project to fix exactly that, and grew into a full platform. The mission hasn't changed — make CVEs easy.
Built by practitioners. Continuously updated. Come see it →