CVEsafe has been acquired by DataDike. Same platform, stronger backing — datadike.com
Feature map

Everything CVEsafe does

A complete, technical inventory of the platform — every capability, in one table. Enterprise marks Enterprise-only features; New marks the latest additions.

AreaCapabilityWhat it does
DiscoverExternal footprint & subdomainsEnumerates public hosts under your domain via Certificate Transparency + DNS, and shows what's live.
LAN discoveryThe agent sweeps an internal range, fingerprints each host (OS, services, MAC vendor, SNMP) and classifies the device type (router, switch, printer, IP camera, NAS, Windows/Linux).
Asset inventoryEvery discovered device is registered and organized by /24 block, with live progress while sweeping.
Promote & bulk scanPromote any host to a CVE scan, or scan a whole network/block for CVEs via the agent.
Scan enginesPort & service discovery (TCP)Open ports and each one's service/version — top 100, full TCP or UDP.
CVE detection by service/versionMaps detected software to known CVEs, with CVSS.
Network vulnerability tests (NVTs)Tens of thousands of network checks (OpenVAS / Greenbone).
Known CVEs & misconfigurationsNuclei signatures, exposed admin panels, default credentials and technology fingerprinting.
Passive web analysisMissing security headers, insecure cookies and information leakage — without attacking.
Active web testingControlled requests that confirm SQL injection, XSS, command injection and path traversal.
TLS hardeningCertificate validation, weak protocols/ciphers, Heartbleed / ROBOT.
Authenticated scansInjects a bearer token, header, cookie or basic credential — scoped to the target host.
Host & device postureHost auditMissing Windows updates, SMBv1, RDP without NLA, firewall, Defender/AV, BitLocker, UAC, autologon and weak/Guest local accounts.
SNMP auditAuthenticated deep enumeration of a device plus weak/default community detection.
Automated internal pentest EnterpriseNetwork & AD checksSMB signing/NULL session, LDAP anonymous bind, SMBv1, MS17-010 (EternalBlue), BlueKeep, weak TLS, SNMP exposure.
Egress filtering testWhich outbound ports the network allows (C2 / exfiltration exposure), probed from inside.
Credential capture (LLMNR/NBNS/mDNS)Time-boxed name-resolution poisoning → capture NetNTLMv2 (redacted).
IPv6 DNS takeover (mitm6)DHCPv6 + IPv6 DNS spoofing to become the network resolver, then capture NetNTLMv2 (redacted).
Password sprayingOne password against a user list, one attempt per account per run (lockout-safe). No defaults.
NTLM relayDemonstrates relay exposure against a host without SMB signing — no data dump, no changes.
Hash crackingLocal crack of captured NetNTLMv2 to prove weak passwords; cleartext never stored.
Kerberoasting / AS-REPWith one domain credential, requests roastable tickets and cracks them locally.
AD CS audit (ESC1-ESC8)Certipy enumerates certificate templates vulnerable to privilege escalation. Enumeration only.
Layered consentScan → Intrusive → Active-Attack authorizations, each signed; redacted hashes, lockout-safe spraying, demonstrative relay.
Database audit New EnterpriseMicrosoft SQL Server (1433)Service exposure; sa/any account with an empty password (critical). Detection-only, lockout-safe.
Oracle Database (1521)TNS listener exposure; SID disclosure to unauthenticated probes.
MySQL / MariaDB (3306)Service exposure; account (often root) with an empty password (critical).
MongoDB (27017)Service exposure; database list readable without authentication (critical).
PostgreSQL (5432)Service exposure on the network. Scanned ports are configurable per run.
Live run & retest NewLive progressA real-time bar and stage label as the agent works through a scan.
Activity logA timestamped timeline of the attacker actions the agent took during the run.
SIEM exportDownload the timeline as JSON or CSV to correlate against your SIEM and measure detection gaps.
RetestRe-run the same target+engine in one click (inherits all consent/quota gates).
DeltaCompares a run to the previous one: New, Fixed and Still-open findings.
PrioritizeCVE + CVSS correlationEvery finding tied to its CVE and technical severity.
EPSS exploit probabilityChance of exploitation in the next 30 days (FIRST).
CISA KEV flagMarks CVEs actively exploited in the wild.
Risk score & A–F gradeOne priority per asset and per group.
Issues & lifecycleStateful, de-duplicated issuesWith status, owner, history and occurrence count.
Verify-on-rescanAuto-resolves an issue a re-scan no longer sees, reopens it if it returns.
Confirmed-exploitableFlags an issue when evidence proves exploitability.
Risk acceptanceWaive a finding (tracked separately, with who/when), out of the dashboard totals.
Reports & deliverablesConsolidated report & CSVBoard-ready report by email or shareable link, plus CSV export.
PDF & WordLocked PDF (all plans) and editable Word (.docx, paid).
Pentest-style reportExecutive summary, attack narrative, per-finding remediation, mapped to MITRE ATT&CK; plus a consolidated engagement report across hosts.
Compliance deliverablesISO/IEC 27001, PCI DSS v4, LGPD, HIPAA, SOC 2.
White-label proposalA branded technical proposal as a Word document.
Command Center & CLICommand CenterRisk overview with a severity layer sphere, per-engine and per-severity filters, and KPIs (findings, active cases, MTTR).
CLI consoleAn in-app, FortiGate-style command line (target / scan / issue / report / agent / org / go) over the same API.
SchedulingDaily, weekly or monthly recurring scans at the time you choose.
IntegrationsServiceNow (two-way)Opens incidents manually or above a severity threshold, with status sync.
Signed webhooksHMAC-signed JSON POST to Slack, Jira, Zendesk, SOAR and custom automations.
REST API + CLIAutomate organizations, targets, scans, issues and reports.
Security & accessMulti-tenant & RBACPer-organization isolation, RBAC roles, JWT + MFA login, encrypted credentials.
Audit logOrg-scoped trail of sign-ins, scans, downloads, member and configuration changes, with actor, IP and timestamp.
Proof of ownershipNew external targets must pass a DNS TXT challenge before scanning.
Privacy & limitsAbuse controls, plan limits, and a commitment that we never access or share your scan data.
White-label & MSPWhite-labelYour logo, name, accent color and favicon across the app and reports.
MSP / resellingCreate and manage client organizations that inherit your branding, and switch into a client's context.
Agent & platformWindows & Linux agentsSelf-updating, run as a service / systemd, auto-provision tooling (nmap/Npcap; pentest toolkit opt-in). The pentest runs on the customer's agent — never from our cloud.
Horizontal scalingAdd worker nodes, dedicated queues (incl. a separate OpenVAS lane) and a static frontend.
PlansFree, Basic, Premium, Professional and Enterprise (the automated pentest suite, billed per internal target pentested per month).

See it on your own assets

Spin up your first scan in minutes. No credit card to get started.

Start scanning free →