Features 3 min read

Vulnerabilities

Track CVEs and vulnerabilities with severity scores, affected products, and related threat intelligence.

The Vulnerabilities page at /vulnerabilities aggregates CVE intelligence from across ThreatCluster's 8,000+ cybersecurity sources. Instead of checking multiple databases and advisories, you get a single view of what vulnerabilities are being actively discussed, exploited, and patched.

Vulnerability List

The main view shows a sortable, filterable list of CVEs with key details at a glance:

  • CVE ID -- The standard identifier (e.g., CVE-2024-3400).
  • Severity -- Critical, High, Medium, or Low, based on CVSS score.
  • CVSS Score -- The numeric score (0.0--10.0).
  • Affected vendor/product -- Which software or hardware is impacted.
  • Cluster count -- How many threat clusters reference this CVE, indicating how much active discussion or exploitation is happening.
  • Last seen -- When the CVE was most recently mentioned in a new article.

CVE Detail Pages

Click any CVE to open its detail page, which includes:

  • Severity and CVSS breakdown -- Base score with the full CVSS vector string.
  • Affected products -- List of vendors and products impacted.
  • Description -- Summary of the vulnerability.
  • Related clusters -- Every threat cluster where this CVE is mentioned, giving you full context on real-world exploitation, proof-of-concept availability, and patch status.
  • Timeline -- A chronological view showing when the CVE first appeared in threat intelligence and how coverage evolved.
Tip: The related clusters section is where ThreatCluster adds the most value. A CVE database tells you a vulnerability exists -- ThreatCluster shows you whether threat actors are actively exploiting it.

Filtering Vulnerabilities

Use the filter panel to narrow the list:

  • Severity -- Toggle Critical, High, Medium, and Low to show only the severities you care about.
  • Date range -- Focus on CVEs disclosed or discussed within a specific window.
  • Vendor/Product -- Filter by affected vendor (e.g., Microsoft, Cisco, Palo Alto Networks) or specific product names.
Note: Filtering by vendor/product is especially useful for patching prioritization. Filter to your organization's tech stack to see only the CVEs that affect you.

How ThreatCluster Enriches CVEs

ThreatCluster goes beyond basic CVE data by:

  • Linking to threat clusters -- Every CVE is connected to the clusters where it appears. You can see which threat actors are exploiting it, what campaigns use it, and whether exploit code is publicly available.
  • Mapping to MITRE ATT&CK techniques -- CVEs are mapped to the ATT&CK techniques they enable, so you can understand the tactical impact (e.g., a CVE that enables Initial Access via T1190).
  • Tracking discussion velocity -- The number of related clusters and articles shows how much attention a CVE is getting, which is often a better signal for patching urgency than CVSS score alone.

Tracking CVEs with Alerts

To monitor a specific CVE over time:

  1. Open the CVE detail page.
  2. Click Track as Keyword to add the CVE ID to your tracked keywords.
  3. You will receive alerts whenever new articles or clusters mention that CVE.

This is useful for vulnerabilities where you are waiting for a patch, monitoring for exploitation in the wild, or tracking a CVE through its disclosure lifecycle.

CVE Entity Pages vs. Vulnerability Page

ThreatCluster has two ways to view CVE information:

  • Vulnerability page (/vulnerabilities) -- The aggregated list view optimized for browsing, filtering, and prioritization across all CVEs.
  • CVE entity page -- The entity profile for a single CVE, accessible by clicking a CVE badge anywhere in the app. Shows the same detail as the CVE detail page but within the entity framework, including relationship graphs to other entities.

Both views link to the same underlying data. Use the Vulnerability page for broad triage and entity pages for deep-dive investigation.