Skip to content
View CVEasy's full-sized avatar

Block or report CVEasy

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
CVEasy/README.md

CVEasy AI

Continuous Threat Exposure Management, built around risk you can actually act on.

Most vulnerability tools hand you a wall of CVSS scores and call it prioritization. CVEasy scores every CVE against your environment with TRIS — a 12-layer risk framework (patent pending) that folds in exploit availability, asset exposure, business context, and threat-actor activity — then tells you the handful that actually matter this week.

cveasyai.com  ·  Threat Intel Feed  ·  This Week in Exposure →


What we build

  • CVEasy — a desktop CTEM platform that scans your environment, scores every finding with the full 12-layer TRIS engine, and turns a flood of CVEs into a short, ordered fix list with plain-English remediation.
  • TRIS — Threat & Risk Intelligence Scoring. Twelve layers of context beyond CVSS: EPSS, KEV, exploit maturity, asset exposure, reachability, and real business impact.
  • BASzy — breach-and-attack simulation that proves whether a finding is actually reachable in your environment before you spend a cycle on it.

Free & open, from the same shop

We ship a free public slice of the work every quarter — no signup, MIT licensed.

Repo What it is
cveasy-chatbot-pentest Free CLI to pentest any deployed AI chatbot. Six attack classes, 37 probes, single readable Python file.
threat-intel-payloads Quarterly drops of attack-payload manifests with TRIS-lite scoring and reproducible labs.

Why it exists

Every team running vuln management has the same problem: too many CVEs, not enough context. A CVSS score tells you a bug is bad. It doesn't tell you whether it matters to you. CVEasy started as a passion project to fix exactly that, and grew into a full platform. The mission hasn't changed — make CVEs easy.

Built by practitioners. Continuously updated. Come see it →

Pinned Loading

  1. cveasy-chatbot-pentest cveasy-chatbot-pentest Public

    Free CLI tool for AI chatbot pentest. 6 attack classes (system prompt extraction, prompt injection, jailbreak). Single Python file. MIT licensed. From CVEasy AI.

    Python 4

  2. cveasy-forge cveasy-forge Public

    The CVEasy open lab — runnable security harnesses, red-team probes, and experiments. Good-faith open source from CVEasy AI.

    Python 1

  3. cveasy-mcp cveasy-mcp Public

    MCP server for CVEasy AI — connect Claude Desktop & Claude Code to your live CVEasy install. Thin client over the CVEasy REST API.

    TypeScript 2