Skip to content
Private Beta ·invite-only access. Reach out to get in.
Risk Heatmap

Your whole estate, ranked by where the risk actually is

Every tile is a slice of your estate. Its area is how many open CVEs sit in it; its colour is how much of that pile is critical. Nothing to install and nothing to scan — you describe your stack, and the map draws itself from the same matcher that decides what lands in your inbox.

CVEs analysed
16,368
categories
19
critical
6,334
flagged major
3,415
the map · grouped by category

16,368 analysed CVEs, laid out by area

share criticalarea = CVE countbar = severity split

Area and heat are independent, and that is the point. Web is the biggest pile at 6,457 CVEs, but Cloud burns hotter — 54% of it is critical against 38%. A big calm tile never outranks a small one that is genuinely on fire. Categories too small to carry a label are pooled into a single tile and named in full in the ledger underneath.

This is the real corpus, not a mock-up — the tiles are laid out from the same table the product reads. Signed in, the same map is drawn from the CVEs matched to your stack.

Web6,457
Applications4,834
Systems1,260
Infrastructure777
IoT749
Networks624
Cloud427
ERP420
AI/ML266
Cryptography200
Mobile181
Hardware82
CRM74
OT/ICS7
Privilege Escalation6
Uncategorised1
Telecommunications1
Authentication Bypass1
Network1
severity mix · whole corpus

The colour scale, and why it lives at the top end

This is the whole analysed corpus on one bar. It is deliberately lopsided: low-severity disclosures are filtered out upstream before analysis, so what reaches the map is the severe end of the feed rather than a representative sample of everything CVE.org publishes.

the final 0.50% — 82 CVEs — magnified to full width
critical
6,334
38.70% · CVSS 9.0 – 10.0
high
9,952
60.80% · CVSS 7.0 – 8.9
medium
1
0.01% · CVSS 4.0 – 6.9
low
81
0.49% · CVSS 0.1 – 3.9

Exactly one medium-severity CVE in 16,368. That is what upstream filtering does to a feed, and it is worth saying out loud: your own map will lean the same way. We would rather show you the lopsided bar than pad the middle of the scale to make the picture look balanced.

the same map · grouped by stack

Once you list what you run, the tiles become your technologies

Add technologies to your stack and the map regroups around them instead of around vulnerability categories. Same layout, same colour scale, different question: not what kind of bug is out there, but which of my things is on fire.

Below is a worked example. The eight technologies are real entries from the corpus and every count is the number of analysed CVEs naming that product as affected — it is what this map would look like for an estate running exactly these things.

Google Chrome carries more CVEs than Oracle Coherence — 100 against 66 — so it takes more of the canvas. Coherence still reads as the emergency: 55 of its 66 are critical, against 22 of Chrome’s 100. Size tells you how much work; colour tells you how urgent.

triage

The map shrinks as you work

Tiles are sized on outstanding work, not on everything that ever arrived. Every CVE carries a status of its own, and the status decides whether it still counts against you.

counted on the map
1openthe default for anything matched
2in progresssomeone is on it
drops out of the view
3risk acceptedacknowledged, not actioned
4archivedparked, still on file
5 / xclosedleaves the map entirely
keyboardjk move open the CVEh heatmaps stack/⌘K command palette15 set status

Triage is a sequence of keystrokes rather than a hunt for buttons. The four triage statuses are a paid-plan feature; closing a CVE works on every plan.

what feeds the colour

Three signals behind every tile

CVSS
16,368 scored

Severity for every analysed CVE. Some upstream records give a severity word rather than a number; we read those at the floor of their CVSS band instead of dropping them from the map.

EPSS
99.4% coverage

A probability of exploitation in the next thirty days, carried by 16,264 of the 16,368 CVEs in this corpus. A background worker resyncs the scores daily, so the ordering follows the threat rather than the disclosure date.

CISA KEV
135 in this corpus

CISA’s Known Exploited Vulnerabilities catalogue — 1,694 entries — is resynced hourly; 135 of them appear in this corpus right now. In the dashboard’s severity × exploit-probability view, a cell holding one of them carries a small red KEV badge in its corner, so exploited-in-the-wild is never just another shade of red.

analyses per month

What flows into the map. The busiest month so far carried 3,360 analysed disclosures — roughly 112 a day.

Jan – Sep
1,098
Jan
1,066
Feb
1,781
Mar
1,376
Apr
1,224
May
2,181
Jun
3,183
Jul
3,360
Aug
1,025
Sep
Hatched bar is the month still in progress.
the rest of the platform

Add your stack and the map draws itself

Severity is read from CVSS, and the exploited-in-the-wild flag comes from the CISA KEV catalogue, refreshed continuously.

Start free