Features
Everything CVEsafe does
One asset in — discovery, the right checks, real exploitability and the fix in your workflow. The whole platform, in one table.
| Area | Capability | What it does | What you get |
|---|---|---|---|
| Discover | External footprint & subdomains | Enumerates every public host under your domain via Certificate Transparency + DNS, and shows what's live. | A live inventory of shadow IT — before attackers find it. |
| LAN discovery & device inventory | The agent sweeps your internal range and classifies each host — router, switch, printer, IP camera, NAS, Windows/Linux — with OS, services, MAC vendor and SNMP. | An auto-classified map of what's really on your network. | |
| Scan | Port & service discovery (TCP) | Finds open TCP ports and each one's service/version — top 100, full TCP or UDP. | Your exposed surface, mapped. |
| CVE detection by service/version | Matches detected services and versions to known CVEs, with CVSS. | Know which software puts you at risk. | |
| Network vulnerability tests (NVTs) | Tens of thousands of network checks mapped to fixable CVEs. | Deep, broad network coverage. | |
| Known CVEs & misconfigurations | Signatures for known CVEs, exposed admin panels, default credentials and technology fingerprinting. | The obvious holes, caught first. | |
| Passive web analysis | Missing security headers, insecure cookies and information leakage — without attacking. | Safe-in-production web hygiene. | |
| Active web testing | Controlled requests that confirm SQL injection, XSS, command injection and path traversal. | Real, proven web vulnerabilities. | |
| TLS certificate validation | Checks validity, issuer, hostname, self-signed and chain problems. | No surprise certificate outages. | |
| Weak TLS protocols & ciphers | Flags TLS 1.0/1.1, RC4, weak Diffie-Hellman and obsolete crypto. | Modern, compliant TLS. | |
| Heartbleed / ROBOT | Targeted checks for well-known TLS flaws. | Famous exploits, closed. | |
| Authenticated scans | Injects a bearer token, header, cookie or basic credential — scoped to the target host. | Finds vulnerabilities behind the login. | |
| Prioritize | CVE + CVSS correlation | Ties every finding to its CVE and technical severity score. | Context, not raw alerts. |
| EPSS exploit probability | Adds the 0–100% chance of exploitation in the next 30 days (FIRST). | Focus on what's actually likely to be hit. | |
| CISA KEV flag | Marks CVEs known to be actively exploited in the wild. | Patch the proven-dangerous first. | |
| Risk score & A–F grade | Combines it all into one priority per asset and per group. | One number leadership understands. | |
| Go deeper | Host posture audit | Per-machine checks: missing Windows updates, SMBv1, RDP without NLA, firewall, Defender, BitLocker, UAC and weak local accounts. | Hardening gaps perimeter scans never see. |
| SNMP audit | Authenticated deep enumeration of a device, plus weak/default community detection. | Real visibility into network gear. | |
| Scheduled scans | Daily, weekly or monthly recurring runs at the time you choose. | Always-current coverage, hands-off. | |
| Manage & integrate | Issue lifecycle & de-duplication | Findings roll up into stateful, de-duplicated issues with status, owner and history. | One real backlog, not noise. |
| Verify-on-rescan | Auto-resolves an issue a re-scan no longer sees, and reopens it if it returns. | A backlog that reflects reality. | |
| ServiceNow (two-way) | Opens incidents — manually or above a severity threshold — with two-way status sync. | Tickets in the system your team lives in. | |
| Signed webhooks | HMAC-signed JSON POST to Slack, Jira, Zendesk, SOAR and custom automations. | Wire CVEsafe into any workflow. | |
| Reports & CSV export | Consolidated, board-ready report by email or shareable link, plus CSV export. | Share results and feed your pipeline. | |
| Multi-tenant & access control | Per-organization isolation, RBAC roles, encrypted credentials, JWT + MFA login. | Enterprise-grade control over who sees what. |
See it on your own assets
Spin up your first scan in minutes. No credit card to get started.
Start scanning free →