Risk & operationsVulnerabilities

Vulnerabilities

Vulnerability tracker with Overview and findings tabs — severity, owner, due date, evidence, and KiteCyber CVEs.

Where it lives

Sidebar → Vulnerabilities (/vulnerabilities)

In-page tabs

Totals, severity breakdown, open vs overdue. Critical/High + Open rows are highlighted. Overdue due dates show an amber badge. Missing owner is called out.

Fields

FieldValues
SeverityCritical, High, Medium, Low
StatusOpen, In Progress, Closed
SourceKiteCyber, Qualys, Nessus, Pen Test, Manual, Internal, Burp Suite, SonarQube, Other
EvidenceFile attachments on the finding

KiteCyber sync also writes compliance gaps (disk encryption, AV, firewall, password, screen lock, USB) and CVEs from installed apps. Manual findings are not overwritten.

Log or sync findings

Add a finding, or sync from KiteCyber.

Assign owner and due date

Unowned Critical/High items stay highlighted until someone owns them.

Attach evidence

Proof of fix or exception. Close the finding when the risk is accepted or remediated.

Admins write; viewers read. Closed items drop out of overdue calculations.