Findings Columns

On the Findings page in Explore, the available columns depend on the active Group By selection. You can show or hide columns using the column chooser. Column visibility and order do not persist across page reloads.

None

Column Description

ACR

(Requires Tenable Security Center+ license) The Tenable-defined Asset Criticality Rating (ACR) as an integer from 1 to 10.

For more information, see Asset Criticality Rating in the Tenable One Vulnerability Management User Guide.

AES

(Requires Tenable Security Center+ license) The AES category of the AES calculated for the asset.

For more information, see Asset Exposure Score in the Tenable One Vulnerability Management User Guide.

Asset Name

The name of the asset where the finding was detected.

CGI Scan Enabled

Whether the scan policy had CGI scanning enabled.

DNS Name

The DNS hostname of the asset.

EPSS

The Exploit Prediction Scoring System probability score for the vulnerability.

Finding ID

The unique identifier (vulnUUID) for the finding.

Host ID

The asset UUID (host UUID).

IP Addresses The IPv4 address(es) of the asset.
MAC Addresses The MAC address of the asset.
NetBIOS Name The NetBIOS name of the asset.
Paranoid Scan Enabled

Whether the scan policy had paranoid scanning enabled.

Plugin Family The plugin family that contains the plugin which identified the vulnerability.
Plugin ID The numeric ID of the Tenable Nessus plugin that identified the vulnerability.
Plugin Name The name of the plugin that identified the vulnerability.
Port The port on the asset where the finding was detected.
Protocol The network protocol associated with the finding.
Repository The repository that contains the finding.
Severity The vulnerability severity level (Critical, High, Medium, Low, Info).
Tenable ID The Tenable UUID for the finding.
Thorough Scan Enabled Whether the scan policy had thorough scanning enabled.
VPR The Vulnerability Priority Rating (VPR) score for the vulnerability.

Asset

Column Description

ACR

(Requires Tenable Security Center+ license) The Tenable-defined Asset Criticality Rating (ACR) as an integer from 1 to 10.

For more information, see Asset Criticality Rating in the Tenable One Vulnerability Management User Guide.

AES

(Requires Tenable Security Center+ license) The AES category of the AES calculated for the asset.

For more information, see Asset Exposure Score in the Tenable One Vulnerability Management User Guide.

Asset ID The unique identifier (UUID) of the asset.

Asset Name

The name of the asset where the finding was detected.

Critical

The count of Critical severity findings on the asset.

DNS

The DNS hostname of the asset.

First Seen

The date the asset was first seen.

High

The count of High severity findings on the asset.

Info The count of Info severity findings on the asset.
IP Addresses The IPv4 address(es) of the asset.
Last Seen The date the asset was most recently seen.
Low The count of Low severity findings on the asset.
MAC The MAC address of the asset.
Medium The count of Low severity findings on the asset.
NetBIOS The NetBIOS name of the asset.
Operating System The operating system detected on the asset.
Repository The repository that contains the asset's findings.
Score The aggregate risk score for the asset.
Total Aggregate risk score for the asset.
UUID The asset UUID.

Asset Tag

Column Description

Asset Tag

The name of the asset tag.

Critical

The count of Critical severity findings on the asset.

High

The count of High severity findings on the asset.

Info The count of Info severity findings on the asset.
Low The count of Low severity findings on the asset.
Medium The count of Low severity findings on the asset.
Score The aggregate risk score for the asset.
Total Aggregate risk score for the asset.

CVE

Column Description
CVE ID The CVE identifier.
CVSS v2 The CVSS v2 base score for the CVE.
CVSS v3 The CVSS v3 base score for the CVE.
CVSS v4 The CVSS v4 base score for the CVE.
EPSS The EPSS probability score for the CVE.
Severity The severity level of the CVE.
Total Total count of findings associated with the CVE.
VPR The Vulnerability Priority Rating (VPR) score for the CVE.

IAVM

Column Description
CVSS v2 The CVSS v2 base score for the IAVM.
CVSS v3 The CVSS v3 base score for the IAVM.
CVSS v4 The CVSS v4 base score for the IAVM.
EPSS The EPSS probability score for the IAVM.
IAVM The IAVM identifier.
Severity The severity level of the IAVM.
Total Total count of findings associated with the IAVM.
VPR The Vulnerability Priority Rating (VPR) score for the IAVM.

Operating System

Column Description

Critical

The count of Critical severity findings on the operating system.

Detection Method How the operating system was detected.

High

The count of High severity findings on the operating system.

Info The count of Info severity findings on the operating system.
Low The count of Low severity findings on the operating system.
Medium The count of Low severity findings on the operating system.
Operating System The name of the operating system.
Score The aggregate risk score for the operating system.
Total Total count of findings across all severities for this operating system.

Severity

Column Description

Count

The number of findings at this severity level.

Severity The severity level (Critical, High, Medium, Low, Info).

Vulnerability (Plugin)

Column Description

EPSS

The EPSS probability score for the plugin.

Last Modified The date the plugin was last modified.
Patch Date The date a patch was published for the vulnerability.
Plugin Family The plugin family.
Plugin ID The numeric ID of the plugin.
Plugin Name The name of the plugin.
Plugin Publish Date The date the plugin was originally published.
Severity The vulnerability severity level (Critical, High, Medium, Low, Info).
Total Total count of findings for this plugin across all assets.
VPR The Vulnerability Priority Rating (VPR) score for the vulnerability.
Vulnerability Publish Date The date the vulnerability was publicly disclosed.