Findings & intelligence
Explore CVEs and vulnerability intelligence
Search the Secorvia CVE catalog and compare CVSS, EPSS, KEV, affected products, weaknesses, and local matches.
Reviewed
Before you start
The deployment needs a populated vulnerability catalog. Catalog entries and vulnerabilities matched to your resources are different views.
Search the catalog
Open Vulnerabilities. Search by CVE ID or description and filter severity. Sort by risk, publication date, or modification date depending on whether you are triaging urgency or reviewing a newly published issue.
Open the CVE details
Read Description, Aliases, Weaknesses (CWE), Affected Products, and References. Check Published, Modified, and Last Synced so you know the age of the source information.
Compare the available risk signals
CVSS describes severity, EPSS estimates exploitation probability over the next 30 days, and KEV identifies inclusion in the known exploited catalog. Inspect the available versions and dates. A missing enrichment value should not be interpreted as a zero-risk result.
Look for matches in your environment
Open Vulnerability Matches to see correlation with your discovered resources and images. A CVE existing in the global catalog does not mean your organization runs an affected product. Use the matching subject and installed version before planning remediation.
Where you are now
You can explain a CVE’s source signals and distinguish general intelligence from an organization-specific exposure.
WHEN SOMETHING LOOKS OFF
A few things to check
A CVE is absent
Check the spelling, clear severity filters, and ask the platform administrator to check intelligence synchronization if the catalog is stale.
CWE or enrichment is empty
The upstream catalog or mapping may not provide that relationship. Use the primary CVE references and do not infer a safe result.
PUT IT INTO PRACTICE
Make your next move in Secorvia.
Open the app and follow along with your own organization.