Dashboard
Last sync: 2026-06-28 06:42 UTC
3,847
Active Findings
2,104 distinct CVEs
142
Critical
12 exploited (KEV)
891
High
31 exploited (KEV)
1,624
Medium
1,190
Low
423
Aged > 90 Days
Across 178 assets
718
Unactioned CVEs
No triage status set
⏰ Overdue
past SLA deadline
KEV Exploited
CISA Known Exploited
Verification Failed
RemFlow fix not confirmed
📤 No findings sent to RemFlow yet. Use "Remediate via RemFlow" from CVE detail to start the pipeline.
Severity Distribution
Total Active
Critical 142
High 891
Medium 1,624
Low 1,190
Known Exploited Vulnerabilities (CISA KEV)
Critical
12
High
31
Medium
5
Findings
CVECheck / PluginAssetPortSeverityStateKEVDays to DueFirst Seen
Apache Log4j Remote Code Execution WEB-PROD-03 443/tcp Critical Active 2026-02-14
Windows Print Spooler Elevation DC-PROD-01 445/tcp High Active 2026-01-08
OpenSSL X.509 Certificate Parsing APP-PROD-07 8443/tcp Medium Active 2025-11-20
Linux Kernel Privilege Escalation DB-PROD-02 22/tcp High Active 2026-03-05
Microsoft Exchange Server RCE EXCH-PROD-01 443/tcp Critical Fixed 2026-04-12
Showing 5 of 3,847 findings — counts frozen between imports
Disposition Breakdown — Active Findings
🖥️ Top Server Roles — Vulnerabilities by Role
🪦 End of Life Risk — OS & Software
0
🪦 EOL Now
0
⏳ Approaching (≤180d)
0
✅ Supported
0
❓ Unknown OS

📊 Security Posture Overview

—%
Overall Score
— (—)
Patch Compliance
0%
Auto-Remediation
0%
KEV Response
0%
Finding Resolution
0%
SLA Compliance
0%
CVE-2026-12345 Critical CVSS 9.8 ⚠ KEV

Apache Log4j Remote Code Execution (Log4Shell)

Apache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker-controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.

Exploited: 2021-12-10 Due: 2021-12-24 Ransomware: Yes
AssetCheck / PluginPortStateStatusOwnerFirst SeenLast Observed
Apache Log4j Remote Code Execution443/tcpActiveOpenjsmith2026-02-142026-06-28
Apache Log4j Remote Code Execution443/tcpActiveOpen2026-02-142026-06-28
Log4j Detected (Windows Agent)8080/tcpActiveRisk Acceptedmwilson2026-03-012026-06-27
Apache Log4j (Linux RPM Check)8080/tcpActiveOpen2026-03-152026-06-28
Log4j Vulnerability Scan (Scanner)8443/tcpActiveOpen2026-04-202026-06-25
AssetIPOSEOL StatusSiteOwnerActive CVEsCriticalHighLast Seen
10.23.4.17Ubuntu 22.04 LTS✅ SupportedUS-East (nyc1)Platform Engineering473142026-06-28
10.23.1.4Windows Server 2022✅ SupportedUS-East (nyc1)Infrastructure325112026-06-27
10.23.8.55RHEL 9.3✅ SupportedEU-Central (fra1)Database & Storage28282026-06-28
10.23.2.12Windows Server 2022✅ SupportedUS-West (sfo1)Infrastructure19162026-06-26
10.23.5.88Ubuntu 22.04 LTS✅ SupportedUS-East (nyc1)Application Services414122026-06-28
Solution / RemediationCVEsAssetsSeverity Range
Upgrade Apache Log4j to version 2.17.1 or later212Critical
Apply Microsoft Security Update KB5012345 for Print Spooler334High
Upgrade OpenSSL to 3.0.12+ / 1.1.1w+518Medium
Deploy updated kernel package: linux-image-5.15.0-91-generic422High
Install Microsoft Exchange Server SU CU23 Jan 202613Critical
Infrastructure
Core network, domain controllers, DNS, DHCP
1,204
Total
48
Critical
312
High
24
KEV
Platform Engineering
Kubernetes, container registry, CI/CD pipelines
892
Total
31
Critical
204
High
18
KEV
Security Operations
SOC, incident response, threat hunting
673
Total
22
Critical
156
High
8
KEV
Application Services
Web apps, APIs, middleware, messaging
541
Total
19
Critical
98
High
13
KEV
Database & Storage
RDBMS, NoSQL, SAN/NAS, backup infrastructure
387
Total
15
Critical
89
High
3
KEV
End-User Computing
VDI, workstations, MDM, printing
150
Total
7
Critical
32
High
2
KEV
Endpoint Engineering
macOS MDM, macOS fleet, endpoint compliance, Zero Trust
218
Total
8
Critical
47
High
6
KEV

Infrastructure

Core network, domain controllers, DNS, DHCP

Scope: tags env=production function=infra  |  Sites: US-East, US-West, EU-Central

1,204
Total
↓ 18 vs last month
48
Critical
↓ 3 vs last month
312
High
↓ 7 vs last month
526
Medium
↓ 5 vs last month
318
Low
↓ 3 vs last month
203
Unactioned
↓ 12 vs last month
89
Aged > 90d
↓ 4 vs last month
67 assets in scope
AssetIPOSSiteActive CVEsCriticalHighLast Seen
10.23.1.4Windows Server 2022US-East (nyc1)325112026-06-27
10.23.1.5Windows Server 2022US-East (nyc1)28492026-06-28
10.23.2.12Windows Server 2022US-West (sfo1)19162026-06-26
10.23.1.10RHEL 9.3US-East (nyc1)15252026-06-28
10.23.0.1PAN-OS 11.1US-East (nyc1)12032026-06-27
🚨 Exceptions — Active Risk Acceptances
CVEAssetJustificationAccepted ByAccepted AtExpiresDays Left
📄 Vulnerability Scanner Import CSV Import
📥
Drop Vulnerability Scanner .csv export here
or click to browse — .csv files only
💻 SCCM / PDQ Device Export CSV Import
📥
Drop SCCM or PDQ .csv export here
or click to browse — .csv files only
🔗 Import Summary & Enrichment

No data imported yet. Upload vulnerability scan and device export CSV files above.

🌐 CISA KEV Catalog Live Feed

Loading KEV catalog...

🏷️ Snipe-IT Asset Management API REST API
Sample CSV Formats
Vulnerability Scanner CSV columns:
Plugin ID, CVE, CVSS, Risk, Host, Protocol, Port, Name, Synopsis, Description, Solution, See Also, Plugin Output
SCCM/PDQ CSV columns:
Name, OperatingSystem, ADSite, ADOU, LastLogonUser, Manufacturer, Model, SystemRole, IsVirtual, Processor, Memory, DiskSpace
Users
UserUsernameRoleTeamsLast Login
DA
David Admin
david Admin All 2026-06-28 07:12
JS
Jane Smith
jsmith User Infrastructure, Platform Engineering 2026-06-28 06:55
MW
Mike Wilson
mwilson User Security Operations 2026-06-27 14:30
RK
Rachel Kim
rkim User Application Services 2026-06-27 10:18
Authentication
Mode: Local (username/password) OIDC not configured
Set OIDC_ISSUER, OIDC_CLIENT_ID, OIDC_CLIENT_SECRET env vars to enable OIDC.
⏰ SLA Due-Date Policy

Non-KEV vulnerability findings are assigned a severity-based due date measured from first detection (firstSeen). KEV-matched findings use the CISA BOD 22-01 federal deadline.

days
days
days
days
Changelog
2026-07-24 — v6.2.0
🚨 Phase 2.2 — Expiring Risk Acceptances: Structured exception records with justification, accepted_by, expires_at, and optional compensating controls. Risk Accepted now requires a modal form with inline validation (min 20-char justification). Auto-expiry engine checks every 60s and reverts expired exceptions to Open with audit trail entries. New "Exceptions" sidebar page shows all active risk acceptances sorted by expiry with color coding (<30d red, <60d amber). Export CSV button for exception reports. Max exception duration capped at 365 days.
2026-07-24 — v6.1.0
⏰ SLA/due-date engine: severity-based due dates (Critical=15d, High=30d, Medium=90d, Low=180d), CISA KEV BOD 22-01 deadlines, overdue tracking with dashboard stat card, "Days to Due" column with red/amber/green color coding, overdue filter in dropdown, SLA breach penalty in executive grade (>10% overdue docks 1 grade, >25% docks 2), configurable SLA policy on Admin page with persistence via localStorage.
2026-07-24 — v6.0.0
🌐 Live CISA KEV JSON feed integration with auto-fetch, localStorage caching, cross-referencing with imported findings, KEV badge with CISA tooltip (dateAdded, dueDate, requiredAction, ransomware use), KEV feed card on Data Sources page with Refresh Now button, graceful fallback to hardcoded KEV data when offline. All KEV counts now update from live data.
2026-07-24 — v5.0.0
🏷️ Snipe-IT REST API asset import: API config card on Data Sources page, connection test, paginated hardware fetch, asset enrichment (assigned user, purchase date, warranty status), warranty detection (Active/Expiring Soon/Expired), warranty filter on Assets page, and per-asset Snipe-IT detail card.
2026-07-24 — v4.0.0
Executive page rebuild: team assignment engine (Endpoint/Factory/Networking/Servers), SVG trend line chart, team breakdown cards with severity bars, Top 5 CVEs table, auto-generated risk summary, and executive report export. All vanilla JS + inline SVG.
2026-07-24 — v3.0.0
🪦 End of Life detection engine with comprehensive OS/software EOL database, fuzzy-matching, EOL summary card on Dashboard, EOL Status column/filter on Assets page, and per-asset EOL detail view.
2026-06-25 — v2.4.0
Added vendor/family classification view with ordered regex rules. Per-asset plugin name storage to fix last-write-wins bug across platforms.
2026-06-18 — v2.3.1
Fixed access control audit: 9 unguarded team-scoped endpoints now enforce check_team_access. Team detail now shows period-over-period deltas.
2026-06-10 — v2.3.0
Executive dashboard with trend snapshots. Recently-fixed view driven by fixed_at transition timestamp. OS backfill from endpoint inventory.
2026-06-02 — v2.2.0
Teams config with shared scope helper. Precomputed stats tables with memory+disk caching. Background cache warm at startup.
2026-05-15 — v2.1.0
Streaming CSV importer with batched executemany. Asset tags junction table. Solutions view and change-request draft assembler.
2026-05-01 — v2.0.0
Initial release: scanner importer, KEV feed, dashboard, findings list, CVE detail with per-asset status tracking.
🔄 Security Tool Pipeline
ShieldView
idle
Source of truth
Vulnerability scanning
🚀
RemFlow
idle
Remediation workflow
Deployment orchestration
TheValidator
idle
Post-deployment verification
Validation reporting