My Findings

In the My Findings and Affected Assets section, the My Findings tab shows all active, new, or resurfaced findings for that initiative. Refine the results with the Query Builder.

The My Findings tab has the following columns, which you can customize using the Columns drop-down.

Column

Description

Plugin ID

The unique identifier for the Tenable plugin that detected the vulnerability.

Plugin Name

The name of the Tenable plugin that detected the finding.

CVEs

The Common Vulnerability and Exposure (CVE) identifier for the finding, as assigned by the CISA-sponsored CVE Program.

VPR

The Tenable-calculated Vulnerability Priority Rating (VPR) score from 0.1 to 10.

Note: A finding's VPR is based on the VPR of the plugin that identified it. When plugins are associated with multiple vulnerabilities, the highest VPR appears.

EPSS

The percentage likelihood that a vulnerability will be exploited, based on the third-party Exploit Prediction Scoring System (EPSS).

CVSSv2

The Common Vulnerability Scoring System (CVSS) v2 score for the finding.

CVSSv3

The Common Vulnerability Scoring System (CVSS) v3 score for the finding.

Affected Assets The count of assets affected by this vulnerability.

Affected Assets

In any findings row, click the drop-down > to reveal a table of assets on which that finding appears, with the following columns.

Column

Description

Image Name

The shortened name based on the repository that the image is from. For example, the repository docker.io/library/api-regression-db would have the image name library/api-regression-db.

Operating System

The name and version of the operating system running on the asset, for example Linux Kernel 3.13.

Findings Count

The number of findings on the asset.

Last Seen

Indicates the date when the asset last appeared on a scan.