# Vulnerability Insights

See how many vulnerabilities your assets have over time, how many assets are exposed to known-exploited CVEs, the average exploitability score and the highest-scoring CVEs.

Source: https://docs.deepinfo.com/guide/easm/vulnerability-insights/

Last updated: 2026-09-26

---
The **INSIGHTS** tab of Vulnerabilities shows your vulnerabilities over time, how exposed your assets are to
CVEs that are known to be exploited, the average exploitability, and the CVEs with the highest scores.

## Before You Start

- **Package:** External Attack Surface Management (EASM).
- **Role:** Admin or Member.

## Where to Find It

**Sidebar:** **EXTERNAL ATTACK SURFACE MANAGEMENT** › **VULNERABILITIES** · **Tab:** **INSIGHTS** · [https://platform.deepinfo.com/app/easm/vulnerabilities/insights](https://platform.deepinfo.com/app/easm/vulnerabilities/insights)

## Read the Screen

![The Vulnerabilities INSIGHTS tab with the four cards, SEVERITY, TIMELINE, AVERAGE EXPLOITABILITY SCORE and TOP VULNERABILITIES, numbered 1 to 5.](/img/guide/easm/vulnerability-insights-01.png)

1. **Cards:**

   | Card | What it shows |
   |---|---|
   | **TOTAL VULNERABILITIES** | The sum of your vulnerabilities per severity, with the change over the **LAST 30 DAYS** |
   | **KNOWN EXPLOITABLE** | Labelled **ACTIVELY EXPLOITABLE CVEs**, but it counts your assets affected by CVEs in the CISA KEV catalogue, not the CVEs |
   | **ACTIVE** | The number of active vulnerabilities, labelled **REQUIRE ATTENTION** |
   | **AVG. EXPLOITABILITY SCORE** | The average exploitability score of your vulnerabilities, as a percentage, labelled **AVERAGE SCORE** |

2. **SEVERITY:** your vulnerabilities per severity.
3. **TIMELINE:** vulnerabilities per severity over time, with a legend for **CRITICAL**, **HIGH**, **MEDIUM**,
   **LOW**, **UNKNOWN** and **NONE**. Choose the interval in the dropdown.
4. **AVERAGE EXPLOITABILITY SCORE:** the same average as the card, as a meter.
5. **TOP VULNERABILITIES:** the CVEs with the highest CVSS scores, with **CVE ID**, **ASSETS** and
   **SCORE/SEVERITY**. Select a row to open the CVE's page; see
   [Vulnerability details](/guide/easm/vulnerability-details/).

## Use the Page

- **Watch the trend:** on **TIMELINE**, check whether critical and high vulnerabilities go down as you fix them.
- **Gauge your exposure to known exploits:** **KNOWN EXPLOITABLE** shows how many assets are affected by CVEs in
  the CISA KEV catalogue. To list those CVEs, open **VULNERABILITIES LIST** and look for the red
  **EXPLOITABLE** pill.
- **Start with the worst:** open the CVEs in **TOP VULNERABILITIES** and check their affected assets.

## Good to Know

- **TOTAL VULNERABILITIES and ACTIVE can show different numbers.** **TOTAL VULNERABILITIES** matches the counts
  on the severity tabs of **VULNERABILITIES LIST**. **ACTIVE** matches the result count above that list (the
  number before **VULNERABILITIES FOUND**).
- **KNOWN EXPLOITABLE** counts assets, not CVEs.
- **TOP VULNERABILITIES** ranks CVEs by score and does not check their state, so it can include a CVE that is
  no longer active on your assets. Check the CVE's **ASSETS** tab.
- The timeline can show **UNKNOWN** and **NONE** severities. **VULNERABILITIES LIST** has no tab for them.
- The page is for reading only. It has no filters and no export.
- The Vulnerabilities **OVERVIEW** tab has the summary cards; see
  [Prioritize vulnerabilities](/guide/easm/vulnerabilities/).

## Do This With the API

- Vulnerabilities per severity: [Vulnerability Severity Stats](/reference/easm/vulnerability-severity-stats/)
- Per severity over time: [Vulnerability Severity Stats Timeline](/reference/easm/vulnerability-severity-stats-timeline/)
- Known-exploitable counts (CVEs and assets): [Vulnerability Known Exploitable Stats](/reference/easm/vulnerability-known-exploitable-stats/)
- Average exploitability: [Vulnerability Exploitability Score Stats](/reference/easm/vulnerability-exploitability-score-stats/)
- Active vulnerabilities: [Vulnerability Search](/reference/easm/vulnerability-search/)
