ZeroWatch

Zero-Day Vulnerability Inventory

ZeroWatch is an initiative to build and maintain a structured, up-to-date inventory of confirmed zero-day vulnerabilities — bringing transparency to a phenomenon that, despite its critical impact, has no consolidated public reference today.

Initiative

ZeroWatch was created to address a structural gap in the vulnerability ecosystem: no official, comprehensive zero-day inventory exists today — neither at the national nor the international level. Existing databases (NVD, CISA KEV…) catalog known vulnerabilities without systematically distinguishing those exploited before a patch was available.

The goal is to maintain a continuously updated, structured inventory of confirmed zero-days, cross-referenced with threat actor intelligence, CVSS scoring, exploitation probability, and market pricing data — providing a single, documented reference point for researchers, analysts, and practitioners.

This work is conducted as part of a PhD research project on vulnerability management prioritization through graph learning, with the broader ambition of contributing to greater transparency around the zero-day phenomenon.

Definition — What is a Zero-Day?

A zero-day is a vulnerability exploited in the wild — meaning used in real attacks against real targets — before or simultaneously with the availability of an official vendor patch. This definition is strict: an old vulnerability exploited years after its publication and patch is not a zero-day. It is an N-day, an opportunistic attack vector targeting unpatched systems.

This distinction is central to ZeroWatch's classification methodology. Each CVE is evaluated against precise criteria: documented exploitation evidence, timing relative to patch availability, and source quality and consistency.

Methodology

1
Automated monitoring & collection

Collectors continuously monitor major open-source threat intelligence feeds: security bulletins, alert feeds, exploited vulnerability catalogs, and researcher publications. Each signal is normalized, scored, and linked to the CVEs it references.

2
AI-assisted classification

An AI agent analyzes each CVE and its associated sources, applying the strict zero-day definition. It produces a classification (confirmed / potential / rejected), a confidence score, and an analyst note summarizing its reasoning. Distinguishing zero-days from N-days is at the core of its decision process.

3
Human validation

A human analyst reviews the AI classifications, confirming, correcting, or rejecting each CVE based on source articles, severity scores, and reference database information. The final inventory only presents zero-days validated with sufficient confidence.

4
Enrichment & continuous update

Each confirmed zero-day is enriched with available official data: CVSS v4/v3/v2 scores, exploitation probability (EPSS), affected products per source, CWEs, and known threat actor associations. The inventory is refreshed automatically on an hourly basis.

⚠ Current Limitations

ZeroWatch is a research initiative, not a commercial product. The inventory relies exclusively on open-source intelligence: it does not have the real-time detection capabilities of government agencies such as CISA or ANSSI, and is not a substitute for authoritative official feeds.

The primary objective is to document and inventory known zero-days and bring more transparency to the phenomenon — not to replace existing security operations tooling.

False positives and false negatives are possible. Classification is continuously improved through analyst review and cross-source validation.

Data Sources

CVE Intelligence
CISA KEV
Official US catalog of known exploited vulnerabilities
Google Project Zero
Zero-days discovered and documented by Google
NVD — NIST
US national vulnerability database, official CVSS scores
CIRCL VulnerabilityLookup
CVSS v4.0, affected products, CNA data
ENISA EUVD
European Union Vulnerability Database
Zero Day Initiative (ZDI)
Bug bounty program — coordinated disclosures
FIRST EPSS
Exploit Prediction Scoring System — 30-day exploitation probability
Security media
BleepingComputer, The Hacker News, SecurityWeek, Dark Reading…
Threat Actor Intelligence
SocRadar
Threat actor profiles, CVE associations and campaign tracking
ETDA
Thailand ETDA APT group database — actor names, TTPs, countries
Zero-Day Market
Crowdfense
Acquisition program — published payout ranges by platform and impact
Op-Zero
Russian broker — public price lists for mobile and desktop 0-days

Contact

For questions, classification error reports, or academic collaboration, feel free to reach out directly.

myriam.ouraou@zerowatch.fr