Vulnerability Catalog
Overview
The Vulnerability Catalog lists the CVEs that Sysdig tracks in its vulnerability database. Use it to answer two questions about a CVE before a scan finds it:
- Does Sysdig track this CVE?
- Does this CVE affect my environment?
Other Vulnerability Management pages show a CVE only after Sysdig matches it to a package in a scanned resource. On those pages, an empty result does not tell you if you are not affected or if Sysdig does not track the CVE. The Vulnerability Catalog answers the two questions separately.
Prerequisites
- A role with the Scan Results (Read) permission. For more information, see Detailed Role Permissions.
To see Vulnerability Catalog in the Policies menu, the role also needs the Vulnerability Policy (Read) permission.
Supported Environments
| Deployment | Vulnerability Catalog Page | CVE Catalog API |
|---|---|---|
| SaaS | Available in all regions | Available in all regions |
| On-Premises | Not available | Available from version 7.10 |
Access the Vulnerability Catalog
Select Policies > Vulnerability Catalog. The entry is in the Attack Surface Policies section.
Search for a CVE
Enter a CVE ID in the search box. You can enter a full ID, such as CVE-2025-1974, or the start of an ID, such as CVE-2025-19.
The search finds every CVE ID that contains the text you enter. For example, CVE-2026-9198 also finds CVE-2026-91980. To find one CVE, enter its full ID and select its row.
If the text starts with CVE but cannot be part of a valid CVE ID, the page does not search. It shows That doesn’t look like a valid CVE ID. CVE IDs use the format CVE-YYYY-NNNN.
Understand the Results
Each row is one CVE. The table shows these columns:
| Column | Description |
|---|---|
| CVE | The CVE ID, with its description below it. |
| Severity | The severity that the vendor in the Vendor column reports. |
| Vendor | The source of the severity, such as Sysdig, Red Hat, or NVD. |
| EPSS Score | The probability that attackers exploit the CVE in the next 30 days. The cell is empty when no EPSS score exists. |
| Exploit | Shows Exploitable when a public exploit is known. |
| Fixable | Shows Has Fix when at least one affected package has a fixed version. |
| Publish Date | The date when the CVE was published. |
The table loads 50 rows at a time. Select Load 50 more to see more rows. You cannot sort the table.
The page URL keeps your search and filters. Copy the URL to share the same view.
Filter the Results
| Filter | Values | Description |
|---|---|---|
| Severity | Critical, High, Medium, Low, Negligible | Shows CVEs with the selected severities. |
| Fix Available | True, False | Shows CVEs that have a fix, or CVEs that do not. |
| Exploitable | True, False | Shows CVEs that have a known public exploit, or CVEs that do not. |
Select Reset to clear the filters.
Interpret an Empty Result
A search with no results shows one of these messages:
| Message | Meaning | What to do |
|---|---|---|
| No Vulnerabilities Found | Sysdig does not track a CVE that matches your search. | Check the ID. If the CVE is new, search again later. If the CVE affects a distribution or ecosystem that Sysdig does not cover, Sysdig cannot raise findings for it. See Vulnerability Feeds. |
| Narrow your filters | Sysdig tracks the CVE, but your filters hide it. | Select Reset, or change the filters that the message names. |
| That doesn’t look like a valid CVE ID | The text is not a valid CVE ID. | Correct the ID. |
Review a CVE
Select a row to open the CVE Details drawer. The content of the drawer depends on whether the CVE is in your environment.
The CVE is in your environment. The drawer is the same as the drawer on the Vulnerability Findings page, with the Highlights, Remediate, and Impacted Resources tabs. For more information, see View CVE Details.
The CVE is not in your environment. The drawer shows the Highlights tab only. The All Affected Resources Summary section shows No Findings Found. This means that Sysdig tracks the CVE but found no matching package in your scanned resources. The tab also shows these sections:
| Section | Content |
|---|---|
| Description | The CVE description. |
| CVE Summary | Severity and its vendor, Exploitable and Fixable tags, CISA KEV status and due date, use in ransomware, disclosure date, EPSS score, and EPSS percentile. |
| Security Feeds | The CVSS score and vector that each vendor reports for the CVE. |
Use the CVE Catalog API
Use the CVE Catalog API to look up CVEs from your own tools. It gives the same data as the Vulnerability Catalog page.
To check if Sysdig tracks a CVE, send a GET request with the CVE ID:
curl -X GET -H 'Authorization: Bearer <API_TOKEN>' 'https://<HOSTNAME>/secure/vulnerability/v1beta1/cves/CVE-2025-1974'
The response contains the data from each vendor and the affected packages. The API returns 404 when Sysdig does not track the CVE.
To list CVEs, send a GET request to /secure/vulnerability/v1beta1/cves. All parameters are optional. When you use more than one, the API returns the CVEs that match all of them.
query: A CVE ID, or part of one. For example,query=CVE-2025-19.severity:critical,high,medium,low, ornegligible. Repeat the parameter to select more than one severity.cvssMin,cvssMax: The CVSS base score range, from0to10.publishedAfter,publishedBefore: The publish date range, in RFC 3339 format. For example,2026-09-01T00:00:00Z.hasExploit,hasKev,hasFix:trueorfalse.limit: The number of CVEs in each response. The maximum is100.cursor: Thenextvalue from the previous response. Use it to get the next page.
The API needs the same permission as the page. When you send too many requests, the API returns 429.
For the full API reference, see the Vulnerability Management section of the Next Gen API docs. For the regional hostnames and how to authenticate, see Sysdig API.
Data Sources and Updates
The Vulnerability Catalog uses the same vulnerability data as Sysdig scans. It covers the operating system distributions and language ecosystems in Vulnerability Feeds.
- Each time Sysdig updates its vulnerability data, it also rebuilds the catalog. The page shows the new data within about 90 minutes.
- Sysdig syncs its vulnerability feeds about every 8 hours, and at least once a day. A CVE that a vendor published in the last few hours can be missing. For more information, see Vulnerability Feed Synchronization Interval.
- The catalog contains CVE IDs only. An advisory without a CVE ID, such as a GitHub advisory with only a GHSA ID, does not appear.
- The catalog shows the current metadata of each CVE. It does not keep earlier values.
- The severity in the catalog comes from one vendor. The severity of a finding for the same CVE can come from a different feed, so the two values can differ.
Limitations
- The catalog does not show which of your resources a CVE affects. The CVE Details drawer adds this information when the CVE is in your environment.
- The page filters by severity, fix, and exploit only. The API also filters by CISA KEV, CVSS score, and publish date.
- The catalog does not show advisories that Sysdig has not yet processed.
- The catalog does not show when Sysdig added a CVE.