Medium and low severity records whose own published metrics show high exploitability or impact. The threshold and every qualifying reason are printed per row.
Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.
Powered by: public.cves via fetchCves · public.canonical_findings in environment mode
Rule: Included when CVSS severity is Medium or Low AND silent score ≥ 0.50, where silent score = 0.4 × exploitability + 0.4 × CIA impact + 0.2 × frictionless score. Every row shows CVSS, EPSS, KEV, exposure and criticality state.
Inclusion rule: CVSS severity is Medium or Low and silent score ≥ 0.50, where
silent score = 0.4 × exploitability + 0.4 × CIA impact + 0.2 × frictionless score
Each row lists the named reasons it qualified, so no record appears here without a stated cause.
Not known here: whether the affected software is present, exposed or business-critical (Unknown — not collected unless a scan recorded it). No claim is made about attacker behaviour.