Vulnerability BI — sidebar hides with the toggle

Silent Risk

Medium and low severity records whose own published metrics show high exploitability or impact. The threshold and every qualifying reason are printed per row.

Mode: Global CVE catalogue
0 CVEs in scope
Global CVE catalogue
Supports investigation
Investigate if present — not detected exposure.

Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.

Data sources, exact rule, and what is unknown

Powered by: public.cves via fetchCves · public.canonical_findings in environment mode

Rule: Included when CVSS severity is Medium or Low AND silent score ≥ 0.50, where silent score = 0.4 × exploitability + 0.4 × CIA impact + 0.2 × frictionless score. Every row shows CVSS, EPSS, KEV, exposure and criticality state.

Not known by this lens:
  • Asset exposure and criticality: Unknown — not collected unless a scan recorded them.
  • No claim is made about attacker behaviour; only about the recorded characteristics of the finding.

Records over threshold

0
Silent score ≥ 0.50

% of records in scope

0.0%

With high CIA impact

0

Network + no interaction

0
How this works — definitions, thresholds, and what to doShow

Inclusion rule: CVSS severity is Medium or Low and silent score ≥ 0.50, where

silent score = 0.4 × exploitability + 0.4 × CIA impact + 0.2 × frictionless score

  • exploitability = max(EPSS, mean of AC, PR, UI ease scores).
  • frictionless score = 0.35 × AV + 0.25 × AC + 0.20 × PR + 0.20 × UI.

Each row lists the named reasons it qualified, so no record appears here without a stated cause.

Not known here: whether the affected software is present, exposed or business-critical (Unknown — not collected unless a scan recorded it). No claim is made about attacker behaviour.