惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
Apple Machine Learning Research
Apple Machine Learning Research
宝玉的分享
宝玉的分享
博客园 - 叶小钗
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 司徒正美
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - Franky
爱范儿
爱范儿
罗磊的独立博客
IT之家
IT之家
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
N
Netflix TechBlog - Medium
云风的 BLOG
云风的 BLOG
P
Proofpoint News Feed
U
Unit 42
Engineering at Meta
Engineering at Meta
WordPress大学
WordPress大学
博客园 - 三生石上(FineUI控件)
T
Tailwind CSS Blog
H
Help Net Security
博客园_首页
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
人人都是产品经理
人人都是产品经理

New in Feedly

Automatically collect Splunk Hunting Queries that match your requirements | Feedly Continuously collect Suricata rules matching your requirements | Feedly Enrich and triage Atlassian security releases in the Vulnerability Intel Agent | Feedly Enrich and triage Apple security releases in the Vulnerability Intel Agent | Feedly Feedly completes SOC 2 Type 2 examination | Feedly VirusTotal Integration: Triage IOCs Faster in Feedly | Feedly Connect Feedly to OpenCTI: Real-Time Threat Intel, Automated | Feedly Feedly Best Practices for CTI Teams | Feedly GreyNoise + Feedly Threat Intelligence: Enriching IoCs | Feedly 7 AI Prompts for Cyberattack Pattern Analysis | Feedly Navigate Feedly Faster with Go To | Feedly Navigate Feedly Faster with Go To Introducing Feedly ThreatBeats: Your daily intel jingles | Feedly Introducing Feedly ThreatBeats: Your daily intel jingles 6 Ways to Automate Threat Intelligence with the Feedly API | Feedly Get threat intelligence to your team fast, in the tools they already use | Feedly Tracking the cyber consequences of geopolitical events | Feedly Analyze your closed-source intelligence in Feedly | Feedly Cyberattack Insights Cards: A dynamic 360° attack view | Feedly Cyberattack Insights Cards: A dynamic 360° attack view 7 ways to prioritize CVEs by how they're exploited | Feedly Ask AI on Threat Actor Insights Cards: Accelerate adversary research with custom queries | Feedly Research IoCs with rich context in seconds, not hours | Feedly Surface top threats in CTI newsletters | Feedly The Scanner: Exploring Potential Futures | Feedly The Radar: Detecting emerging signals | Feedly Prompt Engineering: Newsletter template for real-time phishing trends | Feedly The Monitor: Tracking the known present | Feedly Startup Innovation Radar: A real-time startup database | Feedly The InsightOS architecture | Feedly
Feedly’s CVSS Estimate Score - Bridging the gap to enhanc...
Alessandro Magi · 2025-07-25 · via New in Feedly

The scoring challenge: 25,000+ CVEs await NVD analysis

Threat Intelligence teams often rely on the Common Vulnerability Scoring System (CVSS) to triage, assess, and escalate vulnerabilities impacting their technology stacks. However, there are sometimes delays in assigning a CVSS score by industry authorities, such as the National Vulnerability Database (NVD), which is maintained by the National Institute of Standards and Technology (NIST).

As the volume of CVEs has continued to increase year over year, the NVD has struggled to keep up with the increased demand for analysis and scoring. The following report, captured on June 18, 2025, from NIST, showcases the vulnerabilities awaiting analysis.

As a result, organizations face challenges including:

  • Delayed escalation of critical CVEs and inefficient remediation protocols: Without CVSS scores assigned, threat intelligence teams can struggle to prioritize, assess, and escalate CVEs to their vulnerability management team. As a result, it becomes difficult to determine which CVEs require immediate remediation, which can delay the vulnerability management team's deployment of efficient patch management protocols due to the postponed escalation of CVEs.
  • Wider exposure windows: The time-to-report and subsequent time-to-patch for CVEs increase the exposure window for organizations, leaving high-risk CVEs vulnerable to potential exploitation in the wild.
  • Compliance complications: Many organizations are required (such as by PCI-DSS) to address vulnerabilities above certain CVSS thresholds within specified timeframes. CVSS scoring delays can inadvertently cause organizations to miss compliance deadlines.

In response to these challenges, Feedly developed a CVSS estimate score to bridge the gap between CVE identification and CVSS score assignment, providing threat intelligence teams with an early warning system to monitor, assess, and prioritize CVEs with higher fidelity.

How Feedly estimates CVSS

Feedly uses a multifaceted approach built on machine learning models to estimate CVSS scores. The estimate is calculated based on the vulnerability type, description, attack complexity, and exploit info.

Data sourcing and CVE enrichment

  • Feedly collects and enriches CVE data from a variety of sources including NVD, ENISA, vendor advisories, and other high-trust OSINT sources to gather proof-of-exploit (PoE) information.
  • This assessment operates in near real-time, providing instant CVE insights as information emerges from these trusted sources.

Feedly continues to update its CVSS Estimate until the NVD assigns an official score; thereafter, it no longer updates the CVSS estimate. Security teams should use Feedly’s CVSS estimate as an interim measure and switch to the official score once available.

CVSS prediction process

When an article appears in Feedly, it is assessed by a series of machine learning models to analyze and predict CVSS based on the attack vector, vulnerability description, and past CVEs with confirmed CVSS scores. Knowing these past attack vectors and their relationship with CVSS scoring based on years of collected data.

Machine learning process

Feedly deploys a system of machine learning models trained on historical data where the inputs are articles mentioning the CVE. The predicted outputs represent the NVD CVSS categories which are used to calculate CVSS scores. Feedly will assess and score weighted vocabulary, historical datapoints, and patterns across articles mentioning specific CVEs to arrive at aggregated CVSS estimate scores. Feedly's CVSS Estimate system contains the following structured process:

1. Data extraction and scoring

Feedly AI builds and maintains a comprehensive dataset derived from thousands of past CVE reports. Each data point is scored based on its “importance” in relation to CVSS scoring. These associations enable machine learning models to rapidly identify vulnerabilities that are more likely to be severe, based on the data points collected in CVE and trusted OSINT reporting.

2. Probability estimation

Feedly AI then predicts the probability of a specified outcome, in this case, the likelihood that a CVE has a High (7.0-10.0), Medium (4.0-6.9), or Low (0.1-3.9) CVSS score. It assesses against historical data, determining which patterns of data are indicative of a respective score. This machine learning engine calculates the probability that a CVE belongs to one of these categories based on the weighting of these words ingested from source inputs.

3. Decision aggregation

Lastly, Feedly AI assesses combinations of data points collected and aggregates the predictions to determine a final CVSS Estimate. This machine learning model can capture complex patterns in data to arrive at a final estimated score.

Where to access CVSS Estimate scores in Feedly

Feedly’s CVSS Estimate appears in both CVE Insights Cards and the Vulnerability Dashboard, providing threat intelligence teams with a way to better track and monitor vulnerabilities impacting their technology stacks.

Vulnerability Dashboard

Enable the CVSS Estimate column in your Vulnerability Dashboard to view Feedly’s estimated CVSS score for each CVE. As shown in the image below, even when an official score hasn’t been published yet, Feedly provides an estimated CVSS to help you assess severity early.

This feature is especially useful when scanning multiple CVEs at once and applying the dashboard filters to highlight only the most relevant vulnerabilities and their estimated impact.

CVE Insights Cards

When deep-diving into a specific CVE, the CVE Timeline in Feedly's Insights Cards offers valuable context, including the CVSS Estimate Score. In the example below, Feedly flagged the CVSS as HIGH even before NVD officially assigned it a score of 8.8.

CVE Insights Cards are free and publicly available. Even if you're not a Feedly customer, you can explore them at feedly.com/cve to get a full 360° view of any CVE you're tracking.

In short...

In sectors where early warning systems are crucial for effective threat response, threat intelligence teams can bridge the gap between official CVSS Score assignments using Feedly’s CVSS Estimate capability, moving towards near-real-time assessment of vulnerability-related threats. By combining CVE data enrichment, machine learning models, and data-driven severity predictions, Feedly’s CVSS Estimate enables teams to efficiently identify, assess, and escalate critical vulnerabilities, facilitating faster and informed decision-making to protect their organization’s critical technology stack.

Try Feedly's CVSS Estimate Score on the Vulnerability Dashboard

If you would like to explore CVSS Estimate scores further, please contact Feedly’s Threat Intelligence Advisory team via Enterprise support at enterprise@feedly.com or start a free trial.

Start Free Trial