Zero-Day Research: Where to Find and Track Vulnerabilities
Staying current on vulnerabilities is a full-time job. Whether you are doing offensive research, running defense, or building exploits, you need reliable sources. Here is where to look.
Official databases
- NVD / CVE - nvd.nist.gov - The canonical source for vulnerability identifiers. Every CVE gets scored with CVSS. Useful for tracking, less useful for exploitation details. The NVD API is handy for automation.
- MITRE CVE - cve.mitre.org - The CVE numbering authority. CNAs (CVE Numbering Authorities) assign IDs here. Check this when NVD has not caught up yet.
- CISA KEV - Known Exploited Vulnerabilities catalog. If it is on this list, it is being actively exploited in the wild. Prioritize these for patching.
Vendor advisories
- Microsoft MSRC - Patch Tuesday advisories. Microsoft's security response center publishes detailed advisories with exploitability assessments.
- Google Project Zero - Blog and bug tracker. Some of the best vulnerability research published anywhere. Their 90-day disclosure policy means bugs go public on a predictable timeline.
- Apple Security Updates - Notoriously sparse on details but important for iOS/macOS vulns.
- Linux distro security trackers - Debian, Ubuntu, Red Hat all maintain their own CVE trackers with patch status.
Exploit databases
- Exploit-DB - exploit-db.com - Maintained by Offensive Security. Curated archive of public exploits and proof-of-concepts. The
searchsploitCLI tool mirrors this locally. - PacketStorm - packetstormsecurity.com - Exploits, advisories, and tools. Less curated than Exploit-DB but broader coverage.
- GitHub PoC repositories - Search GitHub for CVE IDs. Researchers frequently publish proof-of-concept code. Use Google dorks:
site:github.com "CVE-2024" poc
Bug bounty platforms
- HackerOne - Hacktivity feed shows disclosed reports. Great for learning what types of vulnerabilities are being found in real targets.
- Bugcrowd - Similar hacktivity feed. Different program selection than HackerOne.
Mailing lists and feeds
- oss-security - Linux/open-source vulnerability disclosures. Often has details before the CVE is published.
- Full Disclosure - The original vulnerability mailing list. Less active than its peak but still relevant.
- Security Twitter/Mastodon - Follow researchers. Zero-days frequently surface on social media before anywhere else. Key accounts: @tavaborern, @_JohnHammond, @staborern, @TheRegister.
Google dorking for vulns
Useful search operators for finding fresh advisories and PoCs:
# Find recent PoCs on GitHub
site:github.com "CVE-2024" "proof of concept" OR "poc" OR "exploit"
# Find advisories with exploit details
intitle:"security advisory" "remote code execution" filetype:txt
# Find researcher blogs with new findings
inurl:blog "zero-day" "responsible disclosure" 2024
The key is building a workflow that aggregates these sources. RSS feeds, custom scripts that poll NVD/GitHub APIs, or a threat intel platform that does it for you. Manually checking websites does not scale.