NVD gives you the current record. CASCA gives you the record over time.
A snapshot is one verified generation of the public record. Receipts cite its generation identifier.
CASCA shows a range whose width reflects source-scoped product evidence, differing severity assessments, and exploit-signal coverage. As evidence resolves, the range narrows; a wide range communicates uncertainty directly.
Environment-specific exploitation and asset context remain separate inputs.
Evidence current through Aug 27, 2026, 6:09 PM UTCHow priority is built
- Exploitation (CISA KEV), 0–40. Direct CISA KEV membership supports this range. Catalog silence leaves exploitation status unassessed.
- Exploit likelihood (EPSS), 0–20. The exact probability, model, and score date stay attached.
- Severity (CVSS), 0–25. Distinct eligible assessments remain side by side by role, version, and source. CASCA never averages CVSS.
- Affected products, 0–15. Accepted source scope and mappings drive this range; universal product recall lies outside the metric.
Search and triage
An empty query starts with a bounded CISA KEV cohort ordered by retained priority and CVE ID. Enter a CVE identifier or text to search beyond that starting point. The result is a bounded working set rather than a corpus-wide ranking. Minimum eligible CVSS, CISA KEV-only filtering, and date or score ordering use CVE-ID tie-breaking inside the retrieved pool: at most 500 rows for an empty query and at most 50 rows for an exact or text query. Source-scoped severity remains null and is counted only when a minimum filter excludes it, never assigned zero. This view searches CVE identifiers and retained record text.
Coverage limits are evidence
CASCA states source boundaries, source-reported product scope, exploit-signal coverage, and differing assessments instead of filling gaps with zero. Evidence gaps carry zero safety or unaffected inference, and a bounded record is more useful than an unstated completeness claim.
Time and replay
Observation time records when CASCA first registered an artifact. Provider event time records what the source said. Applicability validity is a separate interval. The current and immediately prior record can be replayed from a dated link; broader reconstruction remains outside the public contract.
Changed events
External events are new source assertions: KEV additions, updates, or removals; significant EPSS movement; new or revised CVSS; advisory updates; corrections; and withdrawn or replaced records. Internal events are reprocessing, re-ingestion, policy reruns, or lineage changes with no upstream delta. They are hidden unless “Show pipeline events” is selected.
An EPSS model change, or a daily rescore touching more than 20% of scored CVEs, becomes one site notice. Per-CVE movements are suppressed and the new model values become the next baseline.
Conflicts and corrections
CASCA keeps source assessments separate and treats derivative mirrors as one origin. Differing eligible assertions remain visible. Corrections preserve the earlier dated view.