Vulnerability Report¶
[!NOTE] Required role:
compliance_manager,manageroraccount_admin
The Vulnerabilities report (Reports → Vulnerabilities) lists every known vulnerability affecting a project's or module's components, with filters by severity, status and confidence.
CVSS vs. EPSS chart¶
At the top of the report, a scatter chart plots every finding by its CVSS severity score against its EPSS score — the probability that the vulnerability will actually be exploited in the wild in the next 30 days. This helps you prioritize: a high-CVSS finding with a low EPSS score is lower real-world risk than a moderate finding EPSS ranks as likely to be exploited. The chart is included both on-screen and in the exported PDF, with a short legend explaining how to read EPSS scores.
📸 Screenshot: the CVSS vs. EPSS scatter chart above the findings table.
Treatments¶
Selecting one or more findings (or using the current filter) opens a Treatments menu with actions such as muting a finding and, where the integrations are available:
- Create CVD case — opens a pre-filled CVD case for the selected findings (requires the CVD integration and one of the Cases roles).
- Create CSAF — builds a CSAF/VEX advisory from the selected findings, optionally linking it to an open CVD case.