Policies and findings · GraphQL type

RuleVulnerabilityCve type

One CVE a VULNERABILITY rule matched against an object.

Fields

Field Name Description
id - String! The CVE id, such as CVE-2024-12345.
severity - Severity The CVE's severity: its CVSS severity, raised when its EPSS score shows it's likely to be exploited in the next 30 days. Null when the CVE has neither a CVSS rating nor such a score.
cvssSeverity - Severity The CVE's CVSS severity alone, before any EPSS adjustment. Null when the CVE carries no CVSS rating.
cvssScore - Float The CVSS base score behind the CVSS severity. Null when the CVE carries no CVSS rating.
knownExploited - Boolean! True when the CVE is on the CISA Known Exploited Vulnerabilities catalog.
published - Time! When the CVE was published.

Used by

Example

Example

{
  "id": "xyz789",
  "severity": "INFORMATIONAL",
  "cvssSeverity": "INFORMATIONAL",
  "cvssScore": 987.65,
  "knownExploited": true,
  "published": "2021-10-07T18:23:25.829Z"
}