The Vulnerability List shows every active CVE that affects at least one of your assets. Use its scores and exploitation signals to decide which CVEs to fix first.

Before You Start

  • Package: External Attack Surface Management (EASM).
  • Role: Admin or Member.

Where to Find It

Sidebar: EXTERNAL ATTACK SURFACE MANAGEMENT › VULNERABILITIES · Tab: VULNERABILITIES LIST · https://platform.deepinfo.com/app/easm/vulnerabilities

The EASM dashboard's GO TO VULNERABILITIES PAGE and the Global dashboard's TOTAL VULNERABILITIES card open it too. Vulnerabilities has three in-page tabs:

Tab What it holds Deep link
OVERVIEW Summary cards (see The OVERVIEW tab) /app/easm/vulnerabilities/overview
VULNERABILITIES LIST The CVEs, described on this page /app/easm/vulnerabilities
INSIGHTS Volume over time, exploitability and the top CVEs; see Vulnerability insights /app/easm/vulnerabilities/insights

Read the Screen

The VULNERABILITIES LIST tab on ALL VULNERABILITIES with the filter bar, result row, severity tabs and list, numbered 1 to 4.

The header breadcrumb reads EASM / VULNERABILITIES / VULNERABILITIES LIST.

  1. Filter bar: SEARCH (by CVE ID), the category chips CVE, CVSS, CWE, EPSS, CISA KEV, AFFECTED ASSETS, DATES and STATE, and the list and quick view icons.
  2. Result row: the number of vulnerabilities found, EXPORT and VIEW SETTINGS.
  3. Severity tabs with counts: ALL VULNERABILITIES, CRITICAL, HIGH, MEDIUM and LOW.
  4. The list, one row per CVE.
Column What it shows
CVE ID The CVE ID, a red EXPLOITABLE pill above it for CVEs in the CISA KEV catalogue, a Certain or Potential icon, and the CWE name and number. A danger indicator of up to three bars sits next to it
ASSETS How many of your assets it affects
SCORE/SEVERITY The CVSS base score and the severity
CLASSIFICATION A C/I/A chip with the impact on confidentiality, integrity and availability, one letter each (for example C/I/A: H/L/N; hover for details), and an OWASP chip
EPSS The CVE's EPSS value, as a percentage bar
FIRST SEEN DATE When it was first found on your assets, with the time since
LAST SEEN DATE When it was last found, with the time since

The danger indicator adds one bar each when the CVE is critical, when it is certain, and when it is in the CISA KEV catalogue.

Vulnerability list rows with EXPLOITABLE pills and the C/I/A tooltip open on one row.

Prioritize the List

  1. Start on the CRITICAL tab.
  2. Look for the red EXPLOITABLE pill: the CVE is in the CISA KEV catalogue.
  3. Sort the list. Select a column header (every column except CLASSIFICATION sorts), or open VIEW SETTINGS › Sort By and pick CVE ID, Assets, Score/Severity, EPSS, First Seen Date or Last Seen Date and a direction. Assets, Score/Severity and EPSS are the most useful for ranking.
  4. Open a CVE to see which assets it affects and, for a CVE in the CISA KEV catalogue, the required action (see below).
  5. On each affected asset, record your decision by changing the state. See Change the state of issues and vulnerabilities.

Filter the List

SEARCH matches the CVE ID. Each category chip opens Select field, where you pick one of its fields:

Chip Fields, for example
CVE CVE ID, CVE Published, CVE Last Modified
CVSS CVSS Version, CVSS Base Score, CVSS Base Severity, the impact on confidentiality, integrity and availability
CWE CWE ID, CWE OWASP Top 10 (2021), CWE Name
EPSS EPSS, EPSS Percentile, EPSS Date
CISA KEV CISA KEV Vendor/Project, Product, Vulnerability Name, Date Added, Required Action, Due Date, Known Ransomware Campaign Use
AFFECTED ASSETS The number of affected assets, in total and per asset type
DATES First Seen Date, Last Seen Date, Last Check Date
STATE The CVE's state

Then set the rule (Must, Must Not or Should), the operator and the Value. Text fields offer Equal, Wildcard, Fuzzy, Contains Any, Start With and Exists. Number fields, such as EPSS, use Between with a minimum and a maximum. Select APPLY. A chip with active conditions shows their number.

The rules work as in the API; see Search & filters.

The CISA KEV filter chip open with its Select field list of CISA KEV fields.

The EPSS filter chip with the EPSS field, the Must rule, the Between operator and the MINIMUM and MAXIMUM boxes.

Open a CVE

Select a row to open the CVE drawer. OPEN IN NEW TAB opens the CVE page.

The top of the drawer shows the score and severity, the CERTAIN or POTENTIAL flag, the CVE ID, the CWE, the C/I/A chip and, for a new finding, a NEW badge. For a CVE in the CISA KEV catalogue, an EXPLOITABLE strip and a CISA KEV block follow, with ADDED TO KEV, REMEDIATION DUE, REQUIRED ACTION, SHORT DESCRIPTION and NOTES.

The drawer's tabs are icons down the side; hover over an icon to see its name.

Tab What it shows
OVERVIEW Under VULNERABILITY INFO: VENDOR, EPSS SCORE, PUBLISHED DATE, LAST MODIFIED DATE and the CVE description
ASSETS Your assets where the CVE is active, with FIRST SEEN, LAST SEEN and a STATE chip you can change. EXPORT downloads the list
CISA KEV CATALOG The CISA KEV entry: VENDOR / PROJECT, PRODUCT, DATE ADDED, KNOWN RANSOMWARE USE, SHORT DESCRIPTION, REQUIRED ACTION and notes, with a RANSOMWARE badge when ransomware use is known
IMPACT PROFILE Confidentiality, integrity and availability impact
WEAKNESS IDENTITY The CWE with its description, impact badges and CAPEC references
CVSS METRICS The CVSS vector and its values, Exploitability, Impact, Base score and Severity
AFFECTED PRODUCT The affected products, with PRODUCT TYPE, VENDOR, VERSION, ALL AFFECTED VERSIONS and ALL CPE NAMES
REFERENCES Reference links, each with its source and tags such as EXPLOIT

VENDOR shows the first affected product listed for the CVE, with the number of others. For the full list, open AFFECTED PRODUCT.

The top of the CVE drawer for a CVE in the CISA KEV catalogue, with the EXPLOITABLE strip and the CISA KEV block.

The ASSETS tab of the CVE drawer with the CHANGE STATUS menu open on an asset's state chip.

The CVE Page

The CVE page (breadcrumb EASM / VULNERABILITIES / CVE ID) has the same header and three tabs. See Vulnerability details for the full page.

  • OVERVIEW: INFO (VENDOR / PRODUCT, EPSS SCORE, PUBLISHED DATE, LAST MODIFIED DATE), CVSS SCORE on a 0–10 gauge, and AFFECTED ASSETS with a count per asset type.
  • ASSETS: ASSET NAME, STATE, FIRST SEEN and LAST SEEN, with chips to show one asset type. Change an asset's state from its STATE chip.
  • VULNERABILITY INFO: IMPACT PROFILE, WEAKNESS IDENTITY, ATTACK PROFILE, DETECTION & FORENSICS, AFFECTED PRODUCT and META INFO.

Export the List

  1. Select EXPORT. The DOWNLOAD dialog opens.
  2. Choose the RECORDS: ALL exports all active CVEs. FILTERED is offered when filters are applied and exports what you see: the current tab, your filters and your sort.
  3. Choose the FILE FORMAT, CSV or JSON, and select DOWNLOAD.

For the other options in the dialog, see Browse your asset inventory.

Quick View

Select the quick view icon for a CVE list on the left and the selected CVE's full page on the right, with OPEN IN NEW TAB. The left list shows each CVE's score, its ID and an EXP. pill for CISA KEV CVEs. Use LOAD MORE to page through.

The OVERVIEW Tab

The Vulnerabilities OVERVIEW tab with its summary cards and the most critical and most seen vulnerability tables.

Card What it shows
TOTAL VULNERABILITIES With a change chip and LAST 30 DAYS
SEVERITY STATS The count for the severities CRITICAL, HIGH and MEDIUM
AVERAGE EXPLOITABILITY SCORE As a percentage
KNOWN EXPLOITABLE VULN. In red: the number of assets affected by known-exploitable vulnerabilities
MOST CRITICAL VULNERABILITIES CVE ID and SCORE/SEVERITY
MOST SEEN VULNERABILITIES CVE ID and ASSETS

The severity tabs of the VULNERABILITIES LIST show the count of every severity.

States, Colours and Scores

Signal Scale Meaning
SCORE/SEVERITY 0–10 The CVSS base score (version 3, or version 2 when there is no version 3 score)
EPSS percentage The CVE's EPSS value
EXPLOITABLE / EXP. yes or no The CVE is in the CISA KEV catalogue
Certain flag "This vulnerability has been verified through testing and confirmed as valid."
Potential flag "This vulnerability has been identified through testing but not yet confirmed."
NEW badge First detected on your assets in the last 7 days

These scales are not the security score. See How security scores work.

Good to Know

  • The list shows active CVEs only.
  • You cannot change a state from the list rows. Open the CVE and change it per asset on the ASSETS tab.
  • KNOWN EXPLOITABLE VULN. counts affected assets, not CVEs.
  • VIEW SETTINGS also sets the page size (25, 50, 75 or 100) and, under SHOWN, the visible columns.

Do This With the API

Last updated