This method is used to get the exploitability details of a vulnerability. Exploitation determines the present state of exploitation of the vulnerability. It does not predict future exploitation or measure feasibility or ease of adversary development of future exploit code; rather, it acknowledges available information at time of analysis. As the current state of exploitation often changes over time, answers are timestamped. Sources that can provide public reporting of active exploitation include the vendor’s vulnerability notification, SecPod’s Malware Vulnerability Enumeration, Google Project Zero, CISA KEVs, the National Vulnerability Database (NVD) and links therein and reliable threat reports that list either the CVE-ID or common name of the vulnerability.
post
https://saner.secpod.com/RPWebService/getRiskExploitabilityDetails
