Workspace IndexDev Notes › CVE, NVD and the zero-day — the clock between discovery and patch

#188PoC

CVE, NVD and the zero-day — the clock between discovery and patch

A zero-day is a vulnerability with no patch available, and the CVE/NVD system is the public clock tracking it from disclosure to fix — the window during which everyone is exposed and priced.

Not yet scoped.

Why

The PoC traces one CVE's lifecycle (report → embargo → disclosure → patch → exploitation) and the exploit market around it, framing patch latency as the real risk metric.

How it works

Not yet built.

← All Dev Notes · Workspace Index · Top ↑

CVE·NVD와 제로데이 — 발견과 패치 사이의 시계

제로데이는 패치가 없는 취약점이고, CVE/NVD 체계는 공개부터 수정까지 그것을 추적하는 공개 시계입니다 — 모두가 노출되고 값이 매겨지는 창입니다.

아직 범위 미정.

이 PoC는 한 CVE의 수명주기(신고 → 엠바고 → 공개 → 패치 → 악용)와 그 주변 익스플로잇 시장을 추적하여, 패치 지연을 진짜 리스크 지표로 규정합니다.

동작 방식

아직 만들지 않음.

← 전체 개발 노트 · 워크스페이스 인덱스 · 맨 위 ↑