Rank what to work on next with a published four-factor score. Confirmed findings can be patched; candidates must be validated first; catalogue records are research.
Current, non-demo canonical findings for the active organisation and scan scope. Every row is backed by evidence collected from your own assets.
0 record(s) ranked in this mode. "Patch now" is reserved for confirmed environment findings.
Powered by: public.canonical_findings via listCanonicalFindings (confirmed rows only) · public.environment_findings via listEnvironmentFindings (candidate rows) · public.cves via fetchCves (severity, EPSS, KEV, CVSS vector)
Rule: Priority = 0.35 × (CVSS ÷ 10) + 0.25 × exploitability + 0.20 × CIA impact + 0.20 × operational reach. exploitability = max(EPSS, mean(AC, PR, UI)); CIA impact = mean(C, I, A) with High = 1, Low = 0.4, None/absent = 0; operational reach = mean(AV, PR, UI). Buckets: ≥ 0.72 Patch now, ≥ 0.52 Investigate, ≥ 0.32 Monitor, else Low.
Priority = 0.35 × severity (CVSS ÷ 10) + 0.25 × exploitability + 0.20 × CIA impact + 0.20 × operational reach.
Every ranked row below prints its four factor values and weighted contributions, so any score can be recomputed by hand.
Not part of the score: asset criticality (Unknown — not collected), service reachability in your network (Not assessed), compensating controls, patch availability.