THIRD-PARTY RISK / PUBLIC INTELLIGENCE
Know the exposure.
Document the decision.
A vendor review workspace connecting public vulnerability evidence with business context.
Portfolio exercise. Real public vulnerability records; fictional inventory, ownership, and business context. This is not a rating of these vendors or evidence of a breach. Use sample notes only.
Loading the published feed snapshot…
Optional, unencrypted browser storage. Use fictional notes only. Saves profiles and review history, not feed snapshots. No account, cross-device sync, or tamper-proof audit log.
Saving is off.
01 / BUSINESS CONTEXT
Vendor watchlist
Open a vendor to review its profile and due diligence.
02 / INVESTIGATE & RECORD
High-impact threats. Clear consequences.
| Finding / potential impact | Public signals | Applicability / priority | Owner / target |
|---|
No findings match these filters.
High / Critical focus: CISA KEV entries with CVSS ≥ 7.0, drawn from up to two recent entries per product. Product-name matching suggests candidates; it does not verify affected versions. No results does not mean no risk.
03 / EVIDENCE & LIMITATIONS
Keep the reasoning visible.
This view includes known-exploited vulnerabilities rated High or Critical (CVSS ≥ 7.0). Lower scores and missing severity are excluded from the queue and report, but counted above. This filter does not make excluded vulnerabilities safe. Potential business consequences are illustrative and depend on deployment context.
All candidates start as Potentially affected. An analyst must check versions, configuration, exposure, and vendor advisories before confirming applicability.
Confirmed affected KEV findings become Urgent. A low EPSS score does not override known exploitation. Accepting risk retains its priority and requires a justification, reviewer, and review date.
CVSS describes technical severity. EPSS estimates exploitation in the wild within 30 days, not an organization's breach probability. Vulnerability counts do not constitute a vendor risk score.
Business context is fictional. Due diligence starts unreviewed; controls cannot be inferred from public CVEs. Deadline dates are analyst-entered, not regulatory mandates.
Enable optional browser saving to retain reviews and profiles after reload. Otherwise, edits stay in this tab only. Export an assessment for a separate copy. Feed refresh preserves reviews for matching CVEs; no continuous background monitoring is enabled.
Feed provenance
The initial view uses a published snapshot. Refresh requests public feeds from your browser and can take 1–3 minutes. Blocked or unavailable enrichment stays unknown. A failed CISA refresh preserves the prior snapshot. Data older than seven days is flagged for refresh.
CISA KEV data ↗ · NVD API ↗ · FIRST EPSS ↗