Findings Filters

On the Findings page in Explore, use the Search bar to build filter queries that return the findings you need to see. For enhanced filtering, combine filters with Using Group By Options on the Findings Page.

Note: The Findings page always displays cumulative findings.

The following table lists the filters available on the Findings page. All filters apply to vulnerability findings.

Filter Description

Accept Risk

Whether the finding has an active accept-risk acknowledgement. Options: Yes, No.

ACR Score

(Requires Tenable Security Center+ license) Filters by the Tenable-defined Asset Criticality Rating (ACR) as an integer from 1 to 10.

For more information, see Asset Criticality Rating in the Tenable One Vulnerability Management User Guide.

AES Severity

(Requires Tenable Security Center+ license) Filters by the AES category of the AES calculated for the asset.

For more information, see Asset Exposure Score in the Tenable One Vulnerability Management User Guide.

Application CPE Allows a text string search to match against available CPEs. The filter may be set to search based on a contains, Exact Match, or Regex Filter filter. The Regex Filter is based on Perl-compatible regular expressions (PCRE).
Asset ID

The unique identifier (UUID) of the asset where the finding was detected.

Asset Tag Filters by the tag assigned to the asset.
CVE Category

(Requires Vulnerability Intelligence license) Options: in_the_news, ransomware, emerging_threats, persistently_exploited, cisa_known_exploitable, recent_active_exploitation, top_50_vpr.

CVE ID

The CVE identifier associated with the vulnerability.

CVSSv2 Base Score

The CVSSv2 base score (intrinsic and fundamental characteristics of a vulnerability that are constant over time and user environments).

CVSSv2 Vector

A CVSSv2-based text string containing metric:value pairs to describe vulnerability characteristics, for example AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

CVSSv3 Base Score

The CVSSv3 base score (intrinsic and fundamental characteristics of a vulnerability that are constant over time and user environments).

CVSSv3 Vector

A CVSSv3-based text string containing metric:value pairs to describe vulnerability characteristics, for example AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

CVSSv4 Base Score

The CVSSv4 base score (intrinsic and fundamental characteristics of a vulnerability that are constant over time and user environments).

CVSSv4 Supplemental

The CVSS v4 supplemental vector string.

CVSSv4 Threat Score

Numeric CVSS v4 threat score. Supports the between operator.

CVSSv4 Threat Vector

The CVSS v4 threat vector string.

CVSSv4 Vector

The CVSS v4 base vector string.

DNS Name The fully qualified domain name of the asset host.
EPSS Score

The Exploit Prediction Scoring System (EPSS) probability score. Supports the between operator.

Exploit Available Whether a known exploit exists for the vulnerability. Options: Yes, No.
Exploit Code Maturity

Maturity of available exploit code (VPR key driver). Options: Functional, High, POC, Unproven.

Exploit Frameworks The exploit framework(s) associated with the vulnerability.
Finding ID

The unique identifier (vulnUUID) for the finding.

First Seen The date the finding was first detected. Supports date range operators.
IAVM ID The Information Assurance Vulnerability Management (IAVM) identifier for the vulnerability.
IP Addresses The IPv4 address of the asset where the finding was detected. Supports CIDR notation.
Last Seen

The date the finding was most recently detected. Supports date range operators.

MAC Addresses The MAC address of the asset where the finding was detected.
Microsoft ID The Microsoft security bulletin or advisory ID associated with the vulnerability.
Mitigated Whether the finding has been remediated or patched. Options: Yes, No.
NetBIOS Name The NetBIOS name of the asset where the finding was detected.
On CISA KEV Whether the vulnerability appears on the CISA Known Exploited Vulnerabilities catalog (VPR key driver). Options: Yes, No.
Operating System The operating system detected on the asset where the finding was identified.
Patch Published The date a patch was published for the vulnerability. Supports date range operators.
Plugin Family The plugin family that contains the plugin which identified the vulnerability. Active, passive, and Tenable One Web App Scanning families are distinguished by family ID range; passive families include a (Passive) suffix and Tenable One Web App Scanning families include a (WAS) suffix.
Plugin ID The numeric ID of the Tenable Nessus plugin that identified the vulnerability.
Plugin Modified The date the plugin was last updated. Supports date range operators.
Plugin Name The name of the plugin that identified the vulnerability.
Plugin Output (Plugin Text) The text output produced by the plugin when it detected the vulnerability.
Plugin Published The date the plugin was originally published. Supports date range operators.
Plugin Type The general type of plugin check. Options: active, passive, WAS.
Port The port on the asset where the finding was detected.
Protocol The network protocol associated with the finding. Options: Unknown, ICMP, TCP, UDP.
Recast Risk Whether the finding has an active recast-risk override. Options: Yes, No.
Repository ID

The repository that contains the finding.

Risk Factor The CVSS v2 severity bucket. Options: Critical, High, Medium, Low, Info, None.
Severity The vulnerability severity level. Multi-select. Options: Critical, High, Medium, Low, Info.
Targeted Industries Industries where threat actors have observed attacks leveraging the CVE (VPR key driver).
Targeted Regions Geographic regions where threat actors have observed attacks leveraging the CVE (VPR key driver).
VPR Score The Vulnerability Priority Rating (VPR) score. Supports the between operator.
VPR Severity The VPR severity category (VPR key driver). Options: Critical, High, Medium, Low, Info.
Vuln UUID (Finding ID) The vulnUUID unique identifier for the finding.
Vulnerability Published The date the vulnerability was publicly disclosed. Supports date range operators.