Findings Filters
On the Findings page in Explore, use the Search bar to build filter queries that return the findings you need to see. For enhanced filtering, combine filters with Using Group By Options on the Findings Page.
Note: The Findings page always displays cumulative findings.
The following table lists the filters available on the Findings page. All filters apply to vulnerability findings.
| Filter | Description |
|---|---|
|
Accept Risk |
Whether the finding has an active accept-risk acknowledgement. Options: Yes, No. |
|
ACR Score |
(Requires Tenable Security Center+ license) Filters by the Tenable-defined Asset Criticality Rating (ACR) as an integer from 1 to 10. For more information, see Asset Criticality Rating in the Tenable One Vulnerability Management User Guide. |
| AES Severity |
(Requires Tenable Security Center+ license) Filters by the AES category of the AES calculated for the asset. For more information, see Asset Exposure Score in the Tenable One Vulnerability Management User Guide. |
| Application CPE | Allows a text string search to match against available CPEs. The filter may be set to search based on a contains, Exact Match, or Regex Filter filter. The Regex Filter is based on Perl-compatible regular expressions (PCRE). |
| Asset ID |
The unique identifier (UUID) of the asset where the finding was detected. |
| Asset Tag | Filters by the tag assigned to the asset. |
| CVE Category |
(Requires Vulnerability Intelligence license) Options: in_the_news, ransomware, emerging_threats, persistently_exploited, cisa_known_exploitable, recent_active_exploitation, top_50_vpr. |
| CVE ID |
The CVE identifier associated with the vulnerability. |
| CVSSv2 Base Score |
The CVSSv2 base score (intrinsic and fundamental characteristics of a vulnerability that are constant over time and user environments). |
| CVSSv2 Vector |
A CVSSv2-based text string containing metric:value pairs to describe vulnerability characteristics, for example AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. |
| CVSSv3 Base Score |
The CVSSv3 base score (intrinsic and fundamental characteristics of a vulnerability that are constant over time and user environments). |
| CVSSv3 Vector |
A CVSSv3-based text string containing metric:value pairs to describe vulnerability characteristics, for example AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. |
| CVSSv4 Base Score |
The CVSSv4 base score (intrinsic and fundamental characteristics of a vulnerability that are constant over time and user environments). |
| CVSSv4 Supplemental |
The CVSS v4 supplemental vector string. |
| CVSSv4 Threat Score |
Numeric CVSS v4 threat score. Supports the between operator. |
| CVSSv4 Threat Vector |
The CVSS v4 threat vector string. |
| CVSSv4 Vector |
The CVSS v4 base vector string. |
| DNS Name | The fully qualified domain name of the asset host. |
| EPSS Score |
The Exploit Prediction Scoring System (EPSS) probability score. Supports the between operator. |
| Exploit Available | Whether a known exploit exists for the vulnerability. Options: Yes, No. |
| Exploit Code Maturity |
Maturity of available exploit code (VPR key driver). Options: Functional, High, POC, Unproven. |
| Exploit Frameworks | The exploit framework(s) associated with the vulnerability. |
| Finding ID |
The unique identifier (vulnUUID) for the finding. |
| First Seen | The date the finding was first detected. Supports date range operators. |
| IAVM ID | The Information Assurance Vulnerability Management (IAVM) identifier for the vulnerability. |
| IP Addresses | The IPv4 address of the asset where the finding was detected. Supports CIDR notation. |
| Last Seen |
The date the finding was most recently detected. Supports date range operators. |
| MAC Addresses | The MAC address of the asset where the finding was detected. |
| Microsoft ID | The Microsoft security bulletin or advisory ID associated with the vulnerability. |
| Mitigated | Whether the finding has been remediated or patched. Options: Yes, No. |
| NetBIOS Name | The NetBIOS name of the asset where the finding was detected. |
| On CISA KEV | Whether the vulnerability appears on the CISA Known Exploited Vulnerabilities catalog (VPR key driver). Options: Yes, No. |
| Operating System | The operating system detected on the asset where the finding was identified. |
| Patch Published | The date a patch was published for the vulnerability. Supports date range operators. |
| Plugin Family | The plugin family that contains the plugin which identified the vulnerability. Active, passive, and Tenable One Web App Scanning families are distinguished by family ID range; passive families include a (Passive) suffix and Tenable One Web App Scanning families include a (WAS) suffix. |
| Plugin ID | The numeric ID of the Tenable Nessus plugin that identified the vulnerability. |
| Plugin Modified | The date the plugin was last updated. Supports date range operators. |
| Plugin Name | The name of the plugin that identified the vulnerability. |
| Plugin Output (Plugin Text) | The text output produced by the plugin when it detected the vulnerability. |
| Plugin Published | The date the plugin was originally published. Supports date range operators. |
| Plugin Type | The general type of plugin check. Options: active, passive, WAS. |
| Port | The port on the asset where the finding was detected. |
| Protocol | The network protocol associated with the finding. Options: Unknown, ICMP, TCP, UDP. |
| Recast Risk | Whether the finding has an active recast-risk override. Options: Yes, No. |
| Repository ID |
The repository that contains the finding. |
| Risk Factor | The CVSS v2 severity bucket. Options: Critical, High, Medium, Low, Info, None. |
| Severity | The vulnerability severity level. Multi-select. Options: Critical, High, Medium, Low, Info. |
| Targeted Industries | Industries where threat actors have observed attacks leveraging the CVE (VPR key driver). |
| Targeted Regions | Geographic regions where threat actors have observed attacks leveraging the CVE (VPR key driver). |
| VPR Score | The Vulnerability Priority Rating (VPR) score. Supports the between operator. |
| VPR Severity | The VPR severity category (VPR key driver). Options: Critical, High, Medium, Low, Info. |
| Vuln UUID (Finding ID) | The vulnUUID unique identifier for the finding. |
| Vulnerability Published | The date the vulnerability was publicly disclosed. Supports date range operators. |