<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Vulnerability Catalog</title><link>https://docs.sysdig.com/en/sysdig-secure/vulnerability-catalog/</link><description>Recent content on Vulnerability Catalog</description><language>en</language><lastBuildDate>Fri, 02 Oct 2026 16:14:40 +0100</lastBuildDate><image><url> https://docs.sysdig.com/icons/sysdig-horizontal.png</url><title>Vulnerability Catalog</title><link>https://docs.sysdig.com/en/sysdig-secure/vulnerability-catalog/</link><description>Sysdig logo</description></image><item><title>Vulnerability Catalog - Overview</title><link>https://docs.sysdig.com/en/sysdig-secure/vulnerability-catalog/#overview</link><description>The Vulnerability Catalog lists the CVEs that Sysdig tracks in its vulnerability database. Use it to answer two questions about a CVE before a scan finds it:</description><content:encoded><![CDATA[<p>The <strong>Vulnerability Catalog</strong> lists the CVEs that Sysdig tracks in its vulnerability database. Use it to answer two questions about a CVE before a scan finds it:</p>

<ul>

<li>Does Sysdig track this CVE?</li>

<li>Does this CVE affect my environment?</li>
</ul>


<p>Other Vulnerability Management pages show a CVE only after Sysdig matches it to a package in a scanned resource. On those pages, an empty result does not tell you if you are not affected or if Sysdig does not track the CVE. The Vulnerability Catalog answers the two questions separately.</p>]]></content:encoded><guid isPermaLink="false">Overview</guid></item><item><title>Vulnerability Catalog - Prerequisites</title><link>https://docs.sysdig.com/en/sysdig-secure/vulnerability-catalog/#prerequisites</link><description>To see Vulnerability Catalog in the Policies menu, the role also needs the Vulnerability Policy (Read) permission.</description><content:encoded><![CDATA[<ul>

<li>A role with the <strong>Scan Results</strong> (Read) permission. For more information, see <a href="/en/administration/role_permissions/">Detailed Role Permissions</a>.</li>
</ul>


<p>To see <strong>Vulnerability Catalog</strong> in the <strong>Policies</strong> menu, the role also needs the <strong>Vulnerability Policy</strong> (Read) permission.</p>]]></content:encoded><guid isPermaLink="false">Prerequisites</guid></item><item><title>Vulnerability Catalog - Supported Environments</title><link>https://docs.sysdig.com/en/sysdig-secure/vulnerability-catalog/#supported-environments</link><description>Deployment Vulnerability Catalog Page CVE Catalog API SaaS Available in all regions Available in all regions On-Premises Not available Available from version 7.10</description><content:encoded><![CDATA[<table>
	<thead>
			<tr>
					<th>Deployment</th>
					<th>Vulnerability Catalog Page</th>
					<th>CVE Catalog API</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td>SaaS</td>
					<td>Available in all regions</td>
					<td>Available in all regions</td>
			</tr>
			<tr>
					<td>On-Premises</td>
					<td>Not available</td>
					<td>Available from version 7.10</td>
			</tr>
	</tbody>
</table>]]></content:encoded><guid isPermaLink="false">Supported Environments</guid></item><item><title>Vulnerability Catalog - Access the Vulnerability Catalog</title><link>https://docs.sysdig.com/en/sysdig-secure/vulnerability-catalog/#access-the-vulnerability-catalog</link><description>Select Policies &amp;gt; Vulnerability Catalog. The entry is in the Attack Surface Policies section.</description><content:encoded><![CDATA[<p>Select <strong>Policies</strong> &gt; <strong>Vulnerability Catalog</strong>. The entry is in the <strong>Attack Surface Policies</strong> section.</p>]]></content:encoded><guid isPermaLink="false">Access the Vulnerability Catalog</guid></item><item><title>Vulnerability Catalog - Search for a CVE</title><link>https://docs.sysdig.com/en/sysdig-secure/vulnerability-catalog/#search-for-a-cve</link><description>Enter a CVE ID in the search box. You can enter a full ID, such as CVE-2025-1974, or the start of an ID, such as CVE-2025-19.</description><content:encoded><![CDATA[<p>Enter a CVE ID in the search box. You can enter a full ID, such as <code>CVE-2025-1974</code>, or the start of an ID, such as <code>CVE-2025-19</code>.</p>

<p>The search finds every CVE ID that contains the text you enter. For example, <code>CVE-2026-9198</code> also finds <code>CVE-2026-91980</code>. To find one CVE, enter its full ID and select its row.</p>

<p>If the text starts with <code>CVE</code> but cannot be part of a valid CVE ID, the page does not search. It shows <strong>That doesn&rsquo;t look like a valid CVE ID</strong>. CVE IDs use the format <code>CVE-YYYY-NNNN</code>.</p>]]></content:encoded><guid isPermaLink="false">Search for a CVE</guid></item><item><title>Vulnerability Catalog - Understand the Results</title><link>https://docs.sysdig.com/en/sysdig-secure/vulnerability-catalog/#understand-the-results</link><description>Each row is one CVE. The table shows these columns:</description><content:encoded><![CDATA[<p>Each row is one CVE. The table shows these columns:</p>
<table>
	<thead>
			<tr>
					<th style="text-align: left">Column</th>
					<th style="text-align: left">Description</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><strong>CVE</strong></td>
					<td style="text-align: left">The CVE ID, with its description below it.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Severity</strong></td>
					<td style="text-align: left">The severity that the vendor in the <strong>Vendor</strong> column reports.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Vendor</strong></td>
					<td style="text-align: left">The source of the severity, such as Sysdig, Red Hat, or NVD.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>EPSS Score</strong></td>
					<td style="text-align: left">The probability that attackers exploit the CVE in the next 30 days. The cell is empty when no EPSS score exists.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Exploit</strong></td>
					<td style="text-align: left">Shows <strong>Exploitable</strong> when a public exploit is known.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Fixable</strong></td>
					<td style="text-align: left">Shows <strong>Has Fix</strong> when at least one affected package has a fixed version.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Publish Date</strong></td>
					<td style="text-align: left">The date when the CVE was published.</td>
			</tr>
	</tbody>
</table>

<p>The table loads 50 rows at a time. Select <strong>Load 50 more</strong> to see more rows. You cannot sort the table.</p>

<p>The page URL keeps your search and filters. Copy the URL to share the same view.</p>]]></content:encoded><guid isPermaLink="false">Understand the Results</guid></item><item><title>Vulnerability Catalog - Filter the Results</title><link>https://docs.sysdig.com/en/sysdig-secure/vulnerability-catalog/#filter-the-results</link><description>Select Reset to clear the filters.</description><content:encoded><![CDATA[<table>
	<thead>
			<tr>
					<th style="text-align: left">Filter</th>
					<th style="text-align: left">Values</th>
					<th style="text-align: left">Description</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><strong>Severity</strong></td>
					<td style="text-align: left"><code>Critical</code>, <code>High</code>, <code>Medium</code>, <code>Low</code>, <code>Negligible</code></td>
					<td style="text-align: left">Shows CVEs with the selected severities.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Fix Available</strong></td>
					<td style="text-align: left"><code>True</code>, <code>False</code></td>
					<td style="text-align: left">Shows CVEs that have a fix, or CVEs that do not.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Exploitable</strong></td>
					<td style="text-align: left"><code>True</code>, <code>False</code></td>
					<td style="text-align: left">Shows CVEs that have a known public exploit, or CVEs that do not.</td>
			</tr>
	</tbody>
</table>

<p>Select <strong>Reset</strong> to clear the filters.</p>]]></content:encoded><guid isPermaLink="false">Filter the Results</guid></item><item><title>Vulnerability Catalog - Interpret an Empty Result</title><link>https://docs.sysdig.com/en/sysdig-secure/vulnerability-catalog/#interpret-an-empty-result</link><description>A search with no results shows one of these messages:</description><content:encoded><![CDATA[<p>A search with no results shows one of these messages:</p>
<table>
	<thead>
			<tr>
					<th style="text-align: left">Message</th>
					<th style="text-align: left">Meaning</th>
					<th style="text-align: left">What to do</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><strong>No Vulnerabilities Found</strong></td>
					<td style="text-align: left">Sysdig does not track a CVE that matches your search.</td>
					<td style="text-align: left">Check the ID. If the CVE is new, search again later. If the CVE affects a distribution or ecosystem that Sysdig does not cover, Sysdig cannot raise findings for it. See <a href="/en/sysdig-secure/vulnerability-feed/">Vulnerability Feeds</a>.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Narrow your filters</strong></td>
					<td style="text-align: left">Sysdig tracks the CVE, but your filters hide it.</td>
					<td style="text-align: left">Select <strong>Reset</strong>, or change the filters that the message names.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>That doesn&rsquo;t look like a valid CVE ID</strong></td>
					<td style="text-align: left">The text is not a valid CVE ID.</td>
					<td style="text-align: left">Correct the ID.</td>
			</tr>
	</tbody>
</table>]]></content:encoded><guid isPermaLink="false">Interpret an Empty Result</guid></item><item><title>Vulnerability Catalog - Review a CVE</title><link>https://docs.sysdig.com/en/sysdig-secure/vulnerability-catalog/#review-a-cve</link><description>Select a row to open the CVE Details drawer. The content of the drawer depends on whether the CVE is in your environment.</description><content:encoded><![CDATA[<p>Select a row to open the CVE Details drawer. The content of the drawer depends on whether the CVE is in your environment.</p>

<p><strong>The CVE is in your environment.</strong> The drawer is the same as the drawer on the Vulnerability Findings page, with the <strong>Highlights</strong>, <strong>Remediate</strong>, and <strong>Impacted Resources</strong> tabs. For more information, see <a href="/en/cve-360/">View CVE Details</a>.</p>

<p><strong>The CVE is not in your environment.</strong> The drawer shows the <strong>Highlights</strong> tab only. The <strong>All Affected Resources Summary</strong> section shows <strong>No Findings Found</strong>. This means that Sysdig tracks the CVE but found no matching package in your scanned resources. The tab also shows these sections:</p>
<table>
	<thead>
			<tr>
					<th style="text-align: left">Section</th>
					<th style="text-align: left">Content</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><strong>Description</strong></td>
					<td style="text-align: left">The CVE description.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>CVE Summary</strong></td>
					<td style="text-align: left">Severity and its vendor, Exploitable and Fixable tags, CISA KEV status and due date, use in ransomware, disclosure date, EPSS score, and EPSS percentile.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Security Feeds</strong></td>
					<td style="text-align: left">The CVSS score and vector that each vendor reports for the CVE.</td>
			</tr>
	</tbody>
</table>]]></content:encoded><guid isPermaLink="false">Review a CVE</guid></item><item><title>Vulnerability Catalog - Use the CVE Catalog API</title><link>https://docs.sysdig.com/en/sysdig-secure/vulnerability-catalog/#use-the-cve-catalog-api</link><description>Use the CVE Catalog API to look up CVEs from your own tools. It gives the same data as the Vulnerability Catalog page.</description><content:encoded><![CDATA[<p>Use the CVE Catalog API to look up CVEs from your own tools. It gives the same data as the Vulnerability Catalog page.</p>

<p>To check if Sysdig tracks a CVE, send a GET request with the CVE ID:</p>
<div class="highlight">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">curl -X GET -H <span class="s1">&#39;Authorization: Bearer &lt;API_TOKEN&gt;&#39;</span> <span class="s1">&#39;https://&lt;HOSTNAME&gt;/secure/vulnerability/v1beta1/cves/CVE-2025-1974&#39;</span>
</span></span></code></pre></div>
<p>The response contains the data from each vendor and the affected packages. The API returns <code>404</code> when Sysdig does not track the CVE.</p>

<p>To list CVEs, send a GET request to <code>/secure/vulnerability/v1beta1/cves</code>. All parameters are optional. When you use more than one, the API returns the CVEs that match all of them.</p>

<ul>

<li><code>query</code>: A CVE ID, or part of one. For example, <code>query=CVE-2025-19</code>.</li>

<li><code>severity</code>: <code>critical</code>, <code>high</code>, <code>medium</code>, <code>low</code>, or <code>negligible</code>. Repeat the parameter to select more than one severity.</li>

<li><code>cvssMin</code>, <code>cvssMax</code>: The CVSS base score range, from <code>0</code> to <code>10</code>.</li>

<li><code>publishedAfter</code>, <code>publishedBefore</code>: The publish date range, in RFC 3339 format. For example, <code>2026-09-01T00:00:00Z</code>.</li>

<li><code>hasExploit</code>, <code>hasKev</code>, <code>hasFix</code>: <code>true</code> or <code>false</code>.</li>

<li><code>limit</code>: The number of CVEs in each response. The maximum is <code>100</code>.</li>

<li><code>cursor</code>: The <code>next</code> value from the previous response. Use it to get the next page.</li>
</ul>


<p>The API needs the same permission as the page. When you send too many requests, the API returns <code>429</code>.</p>

<p>For the full API reference, see the <strong>Vulnerability Management</strong> section of the Next Gen API docs. For the regional hostnames and how to authenticate, see <a href="/en/developer-tools/sysdig-api/">Sysdig API</a>.</p>]]></content:encoded><guid isPermaLink="false">Use the CVE Catalog API</guid></item><item><title>Vulnerability Catalog - Data Sources and Updates</title><link>https://docs.sysdig.com/en/sysdig-secure/vulnerability-catalog/#data-sources-and-updates</link><description>The Vulnerability Catalog uses the same vulnerability data as Sysdig scans. It covers the operating system distributions and language ecosystems in Vulnerability Feeds.</description><content:encoded><![CDATA[<p>The Vulnerability Catalog uses the same vulnerability data as Sysdig scans. It covers the operating system distributions and language ecosystems in <a href="/en/sysdig-secure/vulnerability-feed/">Vulnerability Feeds</a>.</p>

<ul>

<li>Each time Sysdig updates its vulnerability data, it also rebuilds the catalog. The page shows the new data within about 90 minutes.</li>

<li>Sysdig syncs its vulnerability feeds about every 8 hours, and at least once a day. A CVE that a vendor published in the last few hours can be missing. For more information, see <a href="/en/sysdig-secure/vulnerability-feed/#vulnerability-feed-synchronization-interval">Vulnerability Feed Synchronization Interval</a>.</li>

<li>The catalog contains CVE IDs only. An advisory without a CVE ID, such as a GitHub advisory with only a GHSA ID, does not appear.</li>

<li>The catalog shows the current metadata of each CVE. It does not keep earlier values.</li>

<li>The severity in the catalog comes from one vendor. The severity of a finding for the same CVE can come from a different feed, so the two values can differ.</li>
</ul>]]></content:encoded><guid isPermaLink="false">Data Sources and Updates</guid></item><item><title>Vulnerability Catalog - Limitations</title><link>https://docs.sysdig.com/en/sysdig-secure/vulnerability-catalog/#limitations</link><description>The catalog does not show which of your resources a CVE affects. The CVE Details drawer adds this information when the CVE is in your environment. The page filters by severity, fix, and exploit only. The API also filters by CISA KEV, CVSS score, and publish date. The catalog does not show advisories that Sysdig has not yet processed. The catalog does not show when Sysdig added a CVE.</description><content:encoded><![CDATA[<ul>

<li>The catalog does not show which of your resources a CVE affects. The CVE Details drawer adds this information when the CVE is in your environment.</li>

<li>The page filters by severity, fix, and exploit only. The API also filters by CISA KEV, CVSS score, and publish date.</li>

<li>The catalog does not show advisories that Sysdig has not yet processed.</li>

<li>The catalog does not show when Sysdig added a CVE.</li>
</ul>]]></content:encoded><guid isPermaLink="false">Limitations</guid></item><item><title>Vulnerability Catalog - Related Content</title><link>https://docs.sysdig.com/en/sysdig-secure/vulnerability-catalog/#related-content</link><description>View CVE Details Vulnerability Findings Vulnerability Feeds Sysdig API</description><content:encoded><![CDATA[<ul>

<li><a href="/en/cve-360/">View CVE Details</a></li>

<li><a href="/en/vulnerability-findings/">Vulnerability Findings</a></li>

<li><a href="/en/sysdig-secure/vulnerability-feed/">Vulnerability Feeds</a></li>

<li><a href="/en/developer-tools/sysdig-api/">Sysdig API</a></li>
</ul>]]></content:encoded><guid isPermaLink="false">Related Content</guid></item></channel></rss>