ShadowTrackr

Vulnerability Management

Which vulnerabilities, on which assets, need attention right now

Your external attack surface never holds still. Servers get reconfigured, certificates rotate, and the software running behind them changes constantly — Microsoft IIS becomes Debian with nginx, TeamCity gets replaced with Jenkins, and somewhere in the mix there's shadow IT nobody remembers provisioning. Even organizations with a solid asset inventory struggle to keep up with what's actually running on it.

All of that exposed software can carry vulnerabilities — some serious, some largely irrelevant, some actively being exploited, others with no proof-of-concept in sight yet. ShadowTrackr's vulnerability management helps you cut through that noise: it tells you which vulnerabilities, on which assets, need attention right now, and which ones can wait.

From “is it out there” to “is it on us”

When a new vulnerability makes headlines — a Juniper flaw, a Citrix CVE, whatever it is this week — the first question is always the same: do we have this running somewhere? In ShadowTrackr, that's a single query away. If you want ongoing visibility instead of one-off checks, you can set up an automated daily report tracking specific CVEs across your attack surface in minutes.

Where to find your vulnerabilities

ShadowTrackr surfaces vulnerability data in several places, depending on what you're trying to answer:

All of these can be scoped further: filter by tag, extend the lookback period, or restrict to CVEs on the CISA KEV list or flagged in advisories from your national NCSC. The report library has examples to get you started.

Prioritizing with the ShadowTrackr CVSS score

Not every CVE deserves the same urgency, and the published CVSS score from MITRE or NVD doesn't tell the whole story — most notably, it doesn't account for whether a vulnerability is actively being exploited. ShadowTrackr maintains its own continuously updated CVSS v4 score that does. Sorting by shadowtrackr_cvss_score instead of cvss_score in the cves and cves_asset indexes is the fastest way to see which of your assets carry real, current risk rather than theoretical severity.

Read the full breakdown of how and why our score differs →

Matching software to vulnerabilities accurately

Knowing a CVE exists is only useful if you know it applies to what you're actually running. Vulnerability feeds describe affected versions inconsistently — <12.1, “all versions before 14,” 4.3–4.5, and dozens of other formats, sometimes within the same feed. ShadowTrackr's matching engine is built specifically to parse these variants and match them precisely against the software detected on your assets. We also track select non-CVE sources, such as WordPress's own insecure/outdated version disclosures, which don't always receive a formal CVE but still represent real risk.

Reducing false positives

A system can appear vulnerable from the internet while actually already being patched. These false positives waste time and erode trust in scan results, so we work to eliminate as many as possible automatically — and where we can't, we make it easy for you to mark them yourself.

Automatically suppressed examples

Manual review, when automation isn't possible: Not every false positive can be caught automatically. Where it can't, you can mark a CVE as a false positive directly from the relevant website, certificate, or host page — keeping your reports clean and your team focused on what's actually actionable.

Full transparency: Every false positive — automated or manually marked — is visible under the vulnerabilities menu. Nothing is suppressed silently.

Find out which vulnerabilities on your assets actually need attention now.