Features

Everything CVEsafe does

One asset in — discovery, the right checks, real exploitability and the fix in your workflow. The whole platform, in one table.

AreaCapabilityWhat it doesWhat you get
DiscoverExternal footprint & subdomainsEnumerates every public host under your domain via Certificate Transparency + DNS, and shows what's live.A live inventory of shadow IT — before attackers find it.
LAN discovery & device inventoryThe agent sweeps your internal range and classifies each host — router, switch, printer, IP camera, NAS, Windows/Linux — with OS, services, MAC vendor and SNMP.An auto-classified map of what's really on your network.
ScanPort & service discovery (TCP)Finds open TCP ports and each one's service/version — top 100, full TCP or UDP.Your exposed surface, mapped.
CVE detection by service/versionMatches detected services and versions to known CVEs, with CVSS.Know which software puts you at risk.
Network vulnerability tests (NVTs)Tens of thousands of network checks mapped to fixable CVEs.Deep, broad network coverage.
Known CVEs & misconfigurationsSignatures for known CVEs, exposed admin panels, default credentials and technology fingerprinting.The obvious holes, caught first.
Passive web analysisMissing security headers, insecure cookies and information leakage — without attacking.Safe-in-production web hygiene.
Active web testingControlled requests that confirm SQL injection, XSS, command injection and path traversal.Real, proven web vulnerabilities.
TLS certificate validationChecks validity, issuer, hostname, self-signed and chain problems.No surprise certificate outages.
Weak TLS protocols & ciphersFlags TLS 1.0/1.1, RC4, weak Diffie-Hellman and obsolete crypto.Modern, compliant TLS.
Heartbleed / ROBOTTargeted checks for well-known TLS flaws.Famous exploits, closed.
Authenticated scansInjects a bearer token, header, cookie or basic credential — scoped to the target host.Finds vulnerabilities behind the login.
PrioritizeCVE + CVSS correlationTies every finding to its CVE and technical severity score.Context, not raw alerts.
EPSS exploit probabilityAdds the 0–100% chance of exploitation in the next 30 days (FIRST).Focus on what's actually likely to be hit.
CISA KEV flagMarks CVEs known to be actively exploited in the wild.Patch the proven-dangerous first.
Risk score & A–F gradeCombines it all into one priority per asset and per group.One number leadership understands.
Go deeperHost posture auditPer-machine checks: missing Windows updates, SMBv1, RDP without NLA, firewall, Defender, BitLocker, UAC and weak local accounts.Hardening gaps perimeter scans never see.
SNMP auditAuthenticated deep enumeration of a device, plus weak/default community detection.Real visibility into network gear.
Scheduled scansDaily, weekly or monthly recurring runs at the time you choose.Always-current coverage, hands-off.
Manage & integrateIssue lifecycle & de-duplicationFindings roll up into stateful, de-duplicated issues with status, owner and history.One real backlog, not noise.
Verify-on-rescanAuto-resolves an issue a re-scan no longer sees, and reopens it if it returns.A backlog that reflects reality.
ServiceNow (two-way)Opens incidents — manually or above a severity threshold — with two-way status sync.Tickets in the system your team lives in.
Signed webhooksHMAC-signed JSON POST to Slack, Jira, Zendesk, SOAR and custom automations.Wire CVEsafe into any workflow.
Reports & CSV exportConsolidated, board-ready report by email or shareable link, plus CSV export.Share results and feed your pipeline.
Multi-tenant & access controlPer-organization isolation, RBAC roles, encrypted credentials, JWT + MFA login.Enterprise-grade control over who sees what.

See it on your own assets

Spin up your first scan in minutes. No credit card to get started.

Start scanning free →