Vulnerability BI — sidebar hides with the toggle

Security glossary

Every term this app puts on a chart, in plain language — what it means, why it matters, and how it shows up here. Open “More” for the long version with examples.

CVE — Common Vulnerabilities and Exposures

Vulnerabilities

A public, unique ID for one specific security flaw in one specific product, so everyone talks about the same issue.

CWE — Common Weakness Enumeration

Vulnerabilities

The *type* of coding mistake behind a vulnerability, e.g. 'SQL injection'. Many CVEs share one CWE.

CVSS — Common Vulnerability Scoring System

Metrics

A 0–10 technical severity score for how bad a flaw is if exploited. It measures damage potential, not likelihood.

EPSS — Exploit Prediction Scoring System

Metrics

A 0–100% probability that a vulnerability will be exploited in the wild in the next 30 days.

CISA KEV — Known Exploited Vulnerabilities

Metrics

A government-maintained list of vulnerabilities confirmed to be exploited in real attacks right now.

Scan

Scans

One run of the collection agent against either a single machine (PC scan) or a range of addresses (network scan).

Host

Scans

One machine or network address that a scan looked at.

Finding

Scans

One observation from a scan — a package, service or open port — optionally paired with a candidate CVE.

Vendor / Product / Version

Concepts

The three-part identity used to line up something you run with the software a CVE affects.

Confidence score

Metrics

How strongly the app believes a CVE really applies to something a scan found, from 0% to 100%.

Data sources

Concepts

Where the vulnerability intelligence in this app comes from: NVD (NIST), MITRE CVE, OpenCVE, CISA KEV and EPSS (FIRST.org).

Published over time

Concepts

How many CVEs were published in each time bucket, with the bucket size chosen to match your selected range.