One CVE a VULNERABILITY rule matched against an object.
Fields
| Field Name | Description |
|---|---|
id - String!
|
The CVE id, such as CVE-2024-12345. |
severity - Severity
|
The CVE's severity: its CVSS severity, raised when its EPSS score shows it's likely to be exploited in the next 30 days. Null when the CVE has neither a CVSS rating nor such a score. |
cvssSeverity - Severity
|
The CVE's CVSS severity alone, before any EPSS adjustment. Null when the CVE carries no CVSS rating. |
cvssScore - Float
|
The CVSS base score behind the CVSS severity. Null when the CVE carries no CVSS rating. |
knownExploited - Boolean!
|
True when the CVE is on the CISA Known Exploited Vulnerabilities catalog. |
published - Time!
|
When the CVE was published. |
Used by
FindingTypeMetadataVulnerabilitytype: What a finding records from a VULNERABILITY evaluation.IssueTypeMetadataVulnerabilitytype: What an issue records from a VULNERABILITY evaluation.
Example
Example
{
"id": "xyz789",
"severity": "INFORMATIONAL",
"cvssSeverity": "INFORMATIONAL",
"cvssScore": 987.65,
"knownExploited": true,
"published": "2021-10-07T18:23:25.829Z"
}