Vulnerability BI — sidebar hides with the toggle

Priority Action Matrix

Rank what to work on next with a published four-factor score. Confirmed findings can be patched; candidates must be validated first; catalogue records are research.

Mode: Global CVE catalogue
0 CVEs in scope
My environment
Supports action
Patch now

Current, non-demo canonical findings for the active organisation and scan scope. Every row is backed by evidence collected from your own assets.

0 record(s) ranked in this mode. "Patch now" is reserved for confirmed environment findings.

Data sources, exact rule, and what is unknown

Powered by: public.canonical_findings via listCanonicalFindings (confirmed rows only) · public.environment_findings via listEnvironmentFindings (candidate rows) · public.cves via fetchCves (severity, EPSS, KEV, CVSS vector)

Rule: Priority = 0.35 × (CVSS ÷ 10) + 0.25 × exploitability + 0.20 × CIA impact + 0.20 × operational reach. exploitability = max(EPSS, mean(AC, PR, UI)); CIA impact = mean(C, I, A) with High = 1, Low = 0.4, None/absent = 0; operational reach = mean(AV, PR, UI). Buckets: ≥ 0.72 Patch now, ≥ 0.52 Investigate, ≥ 0.32 Monitor, else Low.

Not known by this lens:
  • Asset criticality: Unknown — not collected
  • Network reachability of the affected service: Not assessed
  • Review candidates can never appear in the Patch now bucket.

Patch now

0

Investigate urgently

0

Monitor closely

0

Low priority

0
How this works — definitions, thresholds, and what to doShow

Priority = 0.35 × severity (CVSS ÷ 10) + 0.25 × exploitability + 0.20 × CIA impact + 0.20 × operational reach.

  • exploitability = max(EPSS, mean of AC, PR, UI ease scores).
  • CIA impact = mean of C, I, A where High = 1, Low = 0.4, None or absent = 0.
  • operational reach = mean of AV, PR, UI ease scores.
  • Buckets: ≥ 0.72 Patch now · ≥ 0.52 Investigate urgently · ≥ 0.32 Monitor closely · below that Low priority.

Every ranked row below prints its four factor values and weighted contributions, so any score can be recomputed by hand.

Not part of the score: asset criticality (Unknown — not collected), service reachability in your network (Not assessed), compensating controls, patch availability.