Essentials
Vulnerabilities
Discover how to obtain the list of vulnerabilities.
We are aware of the difficulty of obtaining a precise list of vulnerabilities actually applicable to a specific version.
The main objective behind Verdex is to quickly identify the vulnerabilities associated with the detected version.
The list of vulnerabilities is automatically displayed at the end of a successful scan, as well as in the output files.
To provide accurate vulnerabilities, Verdex relies on search-vulns.com CVE data and first.org EPSS data.
👉  Click on the screenshot below to enlarge
More CVE data are available in output files (see below).
Available CVE data
Here are CVE data available in Verdex output files:
- CVE ID (
CVE-YYYY-XXXX
) - Description
- CVSS score preferably v3.1 if available
- EPSS score from first.org API
- Vulnerable versions
- Is it a Known Exploited Vulnerability (KEV)
- Publication date
Here is data example for CVE-2022-4361
on Keycloak: