Vulnerabilities
Every weakness with a deadline and someone responsible
Record vulnerabilities from scans, penetration tests, vendor advisories or people who notice them. Each gets a fix deadline from its severity, an owner and a status, until it is fixed or the risk is consciously accepted.

How it works
Report it
Enter the title, severity, affected asset, how it was found and, if known, the CVE and CVSS score.
Get a deadline
Without a date, the deadline follows the severity: critical 7 days, high 30, medium 90, low 180.
Fix or accept
Move it to being fixed, fixed, risk accepted or false positive, and write what was done or why.
What changes for you
Overdue items stand out
The list counts open, overdue and critical vulnerabilities, and the responsible person is reminded.
Linked to your assets
See which systems carry the most weaknesses.
Decisions on record
Accepted risks keep their reason, which auditors ask for.
What it covers
- NIS2 21(2)(e)
- ISO 27001 A.8.8
Works together with
Questions
Who can report a vulnerability?
Everyone in the organization. Owners and admins set the status, deadline and who is responsible.
What about products under the CRA?
Manufacturers register their products with digital elements under Products (CRA), including the 24-hour reporting of exploited vulnerabilities.
Take control of your weaknesses
Record the findings of your last scan and give each one a deadline.
