Where confirmed finding priority concentrates, grouped by canonical vendor, product and version, with duplicate evidence collapsed.
Current, non-demo canonical findings for the active organisation and scan scope. Every row is backed by evidence collected from your own assets.
0 product group(s) in this mode. Ranking shows where finding priority concentrates; it does not prove a patch removes that risk.
Powered by: public.canonical_findings grouped by canonical vendor/product/version · public.cves via fetchCves for severity, KEV and EPSS
Rule: Group key = canonical vendor + product + version. Risk weight = Σ Priority of the distinct confirmed findings in the group. Duplicate evidence rows for the same asset + product + version + CVE collapse to one finding before summing.
Group key = canonical vendor + product + version. In My environment mode the rows come from canonical findings, one per asset + product + version + CVE, so repeated evidence for the same software never inflates a total.
Risk weight = the sum of the priority scores of the distinct findings in the group. % of total is that weight over the sum of all group weights in scope.
What this does not say: it ranks concentration only. Patch availability and fixed versions are Unknown — not collected, so a high row is a candidate for investigation, not a proven risk reduction.