Skip to main content

Vulnerabilities

The Vulnerabilities tab lists the known CVEs affecting this endpoint, drawn from its installed software. (Licensed editions.)

How to get here

Open an endpoint (see Summary), then click the Vulnerabilities tab.

URL path: /inventory/endpoints/{id}?tab=vulnerabilities

The Vulnerabilities tab

The Vulnerabilities tab listing CVEs for the endpointThe Vulnerabilities tab listing CVEs for the endpoint

Filters on the left narrow the list by Module and Severity (Critical, High, Medium, Low).

ColumnWhat it shows
SeverityCritical / High / Medium / Low.
CVEThe CVE identifier (links to detail).
EPSSExploit Prediction Scoring System probability.
ExploitableWhether it's a CISA known-exploited vulnerability.
DescriptionWhat the CVE is.
ZiroScoreThe product's blended risk score.
CVSS3 Base ScoreCVSS v3 base score.
CVSS2 Base ScoreCVSS v2 base score.
PublishedWhen the CVE was published.

Many more CVSS3/CVSS4 detail columns are available via the column picker. The toolbar has Scan Now, Add Exceptions, and a list / card view toggle.

CVE details

Click a CVE to open its detail drawer- everything known about the vulnerability and how to fix it.

The CVE detail drawer with scores, CVSS metrics, references, fix recommendation, and MITRE ATT&CK mappingsThe CVE detail drawer with scores, CVSS metrics, references, fix recommendation, and MITRE ATT&CK mappings
  • Description of the vulnerability, with its EPSS probability and an Exploitable (Yes/No) indicator for CISA known-exploited CVEs.
  • NVD and CVE buttons open the official entries in a new tab.
  • A CVSS3 / CVSS2 / CVSS4 toggle (versions shown depend on what's scored) with the base score, vector string, and the metric breakdown- Severity, Impact Score, Attack Vector, Attack Complexity, Privileges Required, Scope, and the Confidentiality / Integrity / Availability impacts.
  • References- source links for the CVE (with View More).
  • Fix Recommendation- the related patches, KB articles, or resolved versions. When patches are available, Fix Now creates a patch deployment for this endpoint.
  • Taxonomy Mappings with MITRE ATT&CK- the tactics, techniques, and mitigations the CVE maps to (when threat intelligence is available).

Tips & troubleshooting

  • A CVE you've accepted still shows. Add it as an exception with Add Exceptions; manage exceptions under the Vulnerability module.
  • Counts look stale. Run Scan Now to re-evaluate against the latest feed.
  • Vulnerabilities- the fleet-wide Vulnerability module, the same CVEs across every endpoint.
  • SBOM- the software these CVEs come from.
  • Patch- patches that remediate them.