Analytic lenses. Each one states whether it describes vulnerabilities confirmed on your own assets, candidates awaiting validation, or the public CVE catalogue. Catalogue lenses never tell you to patch — they tell you what to investigate if the product is present.
A published four-factor score; only confirmed findings can say patch now.
Where confirmed finding priority concentrates by product and version.
Every record prints its inputs, weights and arithmetic.
Four review queues with the rule that placed each record.
Medium and low severity records whose own metrics say otherwise.
Prerequisites each record states in its CVSS vector.
How many of your assets share the same affected product.
Stages CVSS can assess, and the six it cannot.
The trait mix of the records in scope, as plain shares.
Which weakness classes recur, with unmapped records reported.
Record volume by canonical vendor — not a supplier verdict.
When the catalogue published and updated these records.
How the character of records changed across a dated window.