Findings & intelligence

Explore CVEs and vulnerability intelligence

Search the Secorvia CVE catalog and compare CVSS, EPSS, KEV, affected products, weaknesses, and local matches.

Reviewed

Before you start

The deployment needs a populated vulnerability catalog. Catalog entries and vulnerabilities matched to your resources are different views.

Search the catalog

Open Vulnerabilities. Search by CVE ID or description and filter severity. Sort by risk, publication date, or modification date depending on whether you are triaging urgency or reviewing a newly published issue.

Open the CVE details

Read Description, Aliases, Weaknesses (CWE), Affected Products, and References. Check Published, Modified, and Last Synced so you know the age of the source information.

Compare the available risk signals

CVSS describes severity, EPSS estimates exploitation probability over the next 30 days, and KEV identifies inclusion in the known exploited catalog. Inspect the available versions and dates. A missing enrichment value should not be interpreted as a zero-risk result.

Look for matches in your environment

Open Vulnerability Matches to see correlation with your discovered resources and images. A CVE existing in the global catalog does not mean your organization runs an affected product. Use the matching subject and installed version before planning remediation.

Where you are now

You can explain a CVE’s source signals and distinguish general intelligence from an organization-specific exposure.

WHEN SOMETHING LOOKS OFF

A few things to check

A CVE is absent

Check the spelling, clear severity filters, and ask the platform administrator to check intelligence synchronization if the catalog is stale.

CWE or enrichment is empty

The upstream catalog or mapping may not provide that relationship. Use the primary CVE references and do not infer a safe result.

PUT IT INTO PRACTICE

Make your next move in Secorvia.

Open the app and follow along with your own organization.

Open Secorvia