ZeroWatch
Zero-Day Vulnerability Inventory
ZeroWatch is an initiative to build and maintain a structured, up-to-date inventory of confirmed zero-day vulnerabilities — bringing transparency to a phenomenon that, despite its critical impact, has no consolidated public reference today.
Initiative
ZeroWatch was created to address a structural gap in the vulnerability ecosystem: no official, comprehensive zero-day inventory exists today — neither at the national nor the international level. Existing databases (NVD, CISA KEV…) catalog known vulnerabilities without systematically distinguishing those exploited before a patch was available.
The goal is to maintain a continuously updated, structured inventory of confirmed zero-days, cross-referenced with threat actor intelligence, CVSS scoring, exploitation probability, and market pricing data — providing a single, documented reference point for researchers, analysts, and practitioners.
This work is conducted as part of a PhD research project on vulnerability management prioritization through graph learning, with the broader ambition of contributing to greater transparency around the zero-day phenomenon.
Definition — What is a Zero-Day?
A zero-day is a vulnerability exploited in the wild — meaning used in real attacks against real targets — before or simultaneously with the availability of an official vendor patch. This definition is strict: an old vulnerability exploited years after its publication and patch is not a zero-day. It is an N-day, an opportunistic attack vector targeting unpatched systems.
This distinction is central to ZeroWatch's classification methodology. Each CVE is evaluated against precise criteria: documented exploitation evidence, timing relative to patch availability, and source quality and consistency.
Methodology
Collectors continuously monitor major open-source threat intelligence feeds: security bulletins, alert feeds, exploited vulnerability catalogs, and researcher publications. Each signal is normalized, scored, and linked to the CVEs it references.
An AI agent analyzes each CVE and its associated sources, applying the strict zero-day definition. It produces a classification (confirmed / potential / rejected), a confidence score, and an analyst note summarizing its reasoning. Distinguishing zero-days from N-days is at the core of its decision process.
A human analyst reviews the AI classifications, confirming, correcting, or rejecting each CVE based on source articles, severity scores, and reference database information. The final inventory only presents zero-days validated with sufficient confidence.
Each confirmed zero-day is enriched with available official data: CVSS v4/v3/v2 scores, exploitation probability (EPSS), affected products per source, CWEs, and known threat actor associations. The inventory is refreshed automatically on an hourly basis.
⚠ Current Limitations
ZeroWatch is a research initiative, not a commercial product. The inventory relies exclusively on open-source intelligence: it does not have the real-time detection capabilities of government agencies such as CISA or ANSSI, and is not a substitute for authoritative official feeds.
The primary objective is to document and inventory known zero-days and bring more transparency to the phenomenon — not to replace existing security operations tooling.
False positives and false negatives are possible. Classification is continuously improved through analyst review and cross-source validation.
Data Sources
Contact
For questions, classification error reports, or academic collaboration, feel free to reach out directly.
myriam.ouraou@zerowatch.fr