Vulnerability BI — sidebar hides with the toggle

Exposure DNA

The trait mix of the records in scope: what share state a network vector, no privileges, no interaction, or high impact.

Mode: Global CVE catalogue
0 CVEs in scope
Global CVE catalogue
Supports investigation
Investigate if present — not detected exposure.

Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.

Data sources, exact rule, and what is unknown

Powered by: public.canonical_findings (canonical vendor, product, version, evidence quality) in environment mode · public.cves via fetchCves in catalogue mode

Rule: Each radar axis is a plain share of the records in scope: % network attack vector, % no privileges required, % no user interaction, % high confidentiality, % high integrity, % high availability, and mean CIA impact.

Not known by this lens:
  • Recurring CVEs in a product are not treated as evidence of an architectural weakness.
  • In catalogue mode product presence is not confirmed on any asset.

Profile subject

All records in scope
Set a vendor or product filter to profile one subject

Subject CVEs

0

Most frequent vendor

Not assessed
0 records

Most frequent product

Not assessed
0 records
How this works — definitions, thresholds, and what to doShow

Each radar axis is a plain share of the records in scope, expressed as a percentage. Nothing is weighted or combined:

  • Network AV — share whose CVSS vector states a network or adjacent attack vector.
  • No priv req. — share stating no privileges required.
  • No user int. — share stating no user interaction.
  • High conf. / integ. / avail. — share with that impact metric set to High.
  • Avg CIA — mean CIA impact score × 100.

What this does not claim: a product with repeated CVEs is not thereby shown to have an architectural weakness — the shares describe published metadata only. Product presence on your assets is not assessed in catalogue mode.