Prioritize CVEs by reachability

Vulnerabilities indexed on your external hosts — filter reachable vs. discovered-only, triage by workflow status, and bulk-update cases.

You're on the list. We'll reach out about enterprise access.

CVEs in BreachQuery

BreachQuery CVEs — vulnerability triage for acme.com external hosts

What CVEs delivers

Host-linked CVEs

Each CVE is tied to an IP or hostname discovered during monitoring.

Reachability filters

Separate reachable hosts (open ports) from discovered-only assets.

Severity badges

Critical, high, medium, and low severity at a glance.

Workflow triage

Open, Triaged, Mitigating, False positive, and Resolved states per CVE ticket.

Domain groups

CVEs grouped by monitored domain for multi-brand enterprises.

Bulk status updates

Select multiple CVE tickets and update workflow status in one action.

Three steps on CVEs

Hosts indexed

External scanning discovers IPs, ports, and service fingerprints.

CVEs matched

Known vulnerabilities are associated with each reachable host.

Patch what matters

Filter to reachable, critical CVEs and track remediation to resolved.

Built for enterprise teams

Vulnerability management

Feed reachable CVEs into patch cycles with clear host context.

Attack surface reduction

Deprioritize CVEs on hosts that aren't network-reachable.

Pen test follow-up

Verify scanner findings against continuous external indexing.

Investigation linkage

CVE cases roll up into Investigations metrics for leadership.

Common questions

What does reachable mean?

The host has open ports visible on the network — not just DNS discovery.

Where do CVEs come from?

Matched against service banners and exposure data indexed during monitoring.

Can I mark false positives?

Yes — set workflow status to False positive when a finding doesn't apply.

How do CVEs relate to the Breach Graph?

CVE nodes appear on the exposure and breach lanes of the attack path.

Request enterprise early access

Join the waitlist — be first to run CVEs for your organization.