Skip to content

Vulnerability Report

[!NOTE] Required role: compliance_manager, manager or account_admin

The Vulnerabilities report (Reports → Vulnerabilities) lists every known vulnerability affecting a project's or module's components, with filters by severity, status and confidence.

CVSS vs. EPSS chart

At the top of the report, a scatter chart plots every finding by its CVSS severity score against its EPSS score — the probability that the vulnerability will actually be exploited in the wild in the next 30 days. This helps you prioritize: a high-CVSS finding with a low EPSS score is lower real-world risk than a moderate finding EPSS ranks as likely to be exploited. The chart is included both on-screen and in the exported PDF, with a short legend explaining how to read EPSS scores.

📸 Screenshot: the CVSS vs. EPSS scatter chart above the findings table.

Treatments

Selecting one or more findings (or using the current filter) opens a Treatments menu with actions such as muting a finding and, where the integrations are available:

  • Create CVD case — opens a pre-filled CVD case for the selected findings (requires the CVD integration and one of the Cases roles).
  • Create CSAF — builds a CSAF/VEX advisory from the selected findings, optionally linking it to an open CVD case.