CVE
Patrowl aggregates CVEs data from multiple public sources. Here's how it works:
CVE Collection: our tool Hears performs scraping on all relevant CVE sources.
Sync to back office : The data is centralized in our back office.
Display in Dashboard: CVEs are then fetched and listed on your Dashboard.
Each CVE is automatically linked to an asset thanks to its technology.
When you first arrive on the CVE page, you can see in the table the CVEs that are related to your organization, it means that assets in the organization have technologies that can be impacted by this CVE.
The following data is displayed in the table :
ID : unique identifier of the CVE
Severity : level of risk categorized as Low, Medium, High, or Critical
CVSS Score
Product : affected product name
β οΈ The number of listed products per CVE is limited to 10 to ensure readability.
Published at : date of official publication of the CVE
Threat Metadata : we use visual indicators to help prioritize CVEs based on risk context:
Exploitable: There is known public information on how to exploit the vulnerability.
In the Wild: Active exploitation has been observed, often based on detection logs (ex : from WAFs).
In the News: The vulnerability is getting media coverage or is trending online (ex : on Twitter).
KEV (CISA): The CVE appears in the CISA Known Exploited Vulnerabilities catalog, indicating it is a high-risk, widely targeted vulnerability.
Impacted assets : a link to the assets page that allows you to view only the assets that are related to a specific CVE.
Technologies
The following data is displayed in the table of technologies :
Vendor : the company or organization that develops or maintains the product (ex : Microsoft, Adobe).
Product : the specific software or hardware that was detected on an asset of the organization (ex : Wordpress, Apache HTTP Server).
Version : the particular release of the product β we do not always have this information (ex : Wordpress 5.7, jQuery 3.6.0)
CVE : a link to the CVE page that allows the user to view only the CVEs that are related to this technology
Assets : a link to the asset page that allows the user to see only the assets that uses this technology