Evidence. Action. Clarity.

Clear priorities. Visible progress.

Understand the CVE. Focus your patching. Show the results. One platform connects technical evidence with the decisions your team needs to make.

Patch tracking and executive reports included from Pro.

CVE intelligenceVisual workspacesExecutive reporting
RealExploit / WorkspaceSAMPLE

SECURITY OVERVIEW

Your priorities, in focus.

30 days
Findings
24
Across 12 assets
Active P1
6
First in the queue
Verified
5
With recorded evidence

Active priorities

P1
6
P3
6
P4
3
Review
4

19 active findings · P2: 0

Remediation status

24findings
  • Active19
  • Verified5
A clear next stepReview 6 P1 findings with your asset owners.
Illustrative workspace · synthetic data, not live customer activity.
FOR SECURITY TEAMS. BUILT TO BE UNDERSTOOD.Follow the evidence

Seven public intelligence sources.The evidence behind the verdict.

  • CISA KEV
  • NIST NVD
  • FIRST EPSS
  • ExploitDB
  • Metasploit
  • Nuclei
  • GitHub PoCs

01 / A connected workflow

From the first signal
to the next decision.

Move from analysis to action with context that stays with the finding. Explore each stage below.

01Understand

An explainable verdict.

Bring a CVE from a scanner, SBOM or advisory. Review the verdict, score and contributing sources before deciding what to do.

See the verdict guide
02Prioritize

The context that matters.

Connect CVEs to assets, criticality and exposure. Filter priorities, assign responsibility and record maintenance plans in your workspace.

Open the console example Sign-in and a Pro, Team or Enterprise plan required.
03Demonstrate

Progress people can read.

Capture an executive snapshot with charts, period comparisons and your notes. Export a PDF or an editable PowerPoint for the next review.

Explore executive reports

Correct it where you see it

Your spreadsheet is
the starting point.

Preview CSV or Excel rows, correct classifications and validate before importing. After import, keep asset edits and association corrections in an auditable history.

IMPORT PREVIEW / EXAMPLE
AssetDEMO-001
CriticalitycritcalCritical
CVE analysisCalculated by the system
Asset context is editable. Verdicts come from the evidence.

Every change
keeps its story.

Track planned, applied, verified and reopened findings with notes, timestamps and verification evidence.

  1. Planned01
  2. Applied02
  3. Verified with evidence03

02 / Ready for the next review

The technical work.
The executive story.

Give decision-makers a view they can use: priorities, progress, comparisons and the next actions. Add your conclusions and keep the report fixed to a clear cutoff.

  • Charts and comparisons over 7, 30 or 90 days
  • Saved snapshots with filters and author notes
  • PDF to share. Editable PowerPoint to present.

Sample reports in Spanish, with synthetic data. No account needed.

REALEXPLOITSAMPLE / 01

EXECUTIVE SNAPSHOT

Security, in perspective.

Cutoff: 2026-09-13 · 30-day view

Assets
12
Active P1
6
Verified
5

Verification events

Previous period3
Current period7

Recorded events, not a historical inventory balance.

01
Next decision

Review the maintenance window for active P1 findings.

Illustrative layout using the downloadable sample data.

03 / Evidence you can explain

A clear verdict.
The reasoning behind it.

Defined rules combine public intelligence into a reviewable score and verdict. Use the same evidence in the console and your integrations.

ACTIVELY_EXPLOITED

Confirmed exploitation listed in CISA KEV.

WEAPONIZED

A Metasploit module or high EPSS indicates elevated exploitability.

POC_AVAILABLE

Public exploit, proof-of-concept or detection evidence.

THEORETICAL

No public exploit signals currently observed.

NOT_APPLICABLE

Rejected or reserved CVE; no exploitability score.

UNKNOWN

Reserved fallback for insufficient evidence.

A verdict supports your decision. Your exposure and business context still matter.

REST APIResponse excerpt
GET /v1/cves/CVE-2021-44228/verdict
Authorization: Bearer <YOUR_API_KEY>

{
  "cve_id": "CVE-2021-44228",
  "status": "analyzed",
  "verdict": "ACTIVELY_EXPLOITED",
  "score": 95,
  "score_version": 1,
  "reasoning": [
    "Listed in CISA KEV (Known Exploited Vulnerabilities)"
  ],
  "signals": {
    "in_kev": true,
    "has_metasploit_module": true
  }
}

04 / Fits the way you work

A shared language
for every security decision.

Start with a single investigation. Connect the workflow as your needs grow.

For analysts

Investigate a CVE, inspect its signals and revisit the evidence in your lookup history.

See web access plans

For engineering teams

Bring verdicts into scripts, bulk analysis and webhook workflows. Keep your own tools connected to the evidence.

Explore bulk analysis

For security leaders

Review priorities and recorded progress with your team. Bring an executive report to the next decision.

See the executive view

Less friction. More clarity.

Make the next decision
with the evidence in view.

Choose your capacity. Keep the workflow clear.

7-Day PassAnalystProTeamEnterprise