Vulnerability BI — sidebar hides with the toggle

Vendor CVE concentration

How CVE records distribute across canonical vendor names. This is record volume and severity mix — not a supplier quality verdict.

Mode: Global CVE catalogue
0 CVEs in scope
Global CVE catalogue
Supports investigation
Investigate if present — not detected exposure.

Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.

Data sources, exact rule, and what is unknown

Powered by: public.cves via fetchCves · canonical vendor names via src/lib/vendor-aliases.ts

Rule: Rows are grouped by canonical vendor name. Mean priority = Σ Priority ÷ record count; critical density = critical records ÷ records; recurrence = records ÷ distinct CWEs. Raw localized vendor strings are kept for drill-down and never split a vendor total.

Not known by this lens:
  • Asset footprint per vendor: Unknown — not collected in catalogue mode.
  • Supplier remediation performance and contract context: Unknown — not collected
  • CVE volume alone is not a basis for procurement, consolidation or SLA decisions.

Vendors ranked

0

Most records

Not assessed

Highest critical density

0%

Highest CWE recurrence

Not assessed
How this works — definitions, thresholds, and what to doShow

Rows are grouped by canonical vendor name, so a vendor written differently in different records still counts once. Raw strings stay available on the underlying records.

  • Mean priority = sum of record priority ÷ record count.
  • Critical density = records with CRITICAL severity ÷ records.
  • Recurrence = records ÷ distinct CWEs seen for that vendor.

Not a supplier verdict. Asset footprint per vendor is Unknown — not collected in catalogue mode, and supplier remediation performance and contract context are unknown — not collected. CVE volume alone is not a basis for procurement, consolidation or SLA decisions.