cvss
Safeguard articles tagged "cvss" — guides, analysis, and best practices for software supply chain and application security.
62 articles
What is a Vulnerability Assessment
A vulnerability assessment finds and ranks security weaknesses at scale — here's how it differs from a pentest, its five-step process, and reporting essentials.
What is an Application Vulnerability
A flaw in code, config, or a dependency that attackers can exploit. Learn the types, scoring, and how vulnerabilities differ from risk and threats.
What is a CVE (Common Vulnerabilities and Exposures)
A CVE is a unique ID for a known security flaw, but how it's assigned, scored, and disclosed is far messier than the name suggests.
Why EPSS scores matter for vulnerability management
EPSS scores predict real-world exploitation probability, something CVSS can't do. Here's why that matters for Prisma Cloud users, and how Safeguard uses it.
What is CVSS (Common Vulnerability Scoring System)
CVSS scores rate vulnerability severity from 0.0 to 10.0 — but a 9.8 doesn't mean exploitable in your app. Here's how the math and priorities really work.
What is EPSS (Exploit Prediction Scoring System)
EPSS scores every CVE's real-world exploit probability. Here's how the FIRST.org model works, how it differs from CVSS, and how to use it to triage faster.
What Does CVE Stand For? A Plain-Language Security Guide
CVE stands for Common Vulnerabilities and Exposures, the public catalog that gives every known security flaw a single, shareable name. Here is how the system works and why it matters.
CVSS vs EPSS vs KEV: A 2026 Prioritization Guide
How CVSS, EPSS, and CISA KEV combine into a defensible vulnerability prioritization model for 2026, with concrete thresholds and operational guidance.
Prioritising CVE Patches With Reachability, Not CVSS Alone
CVSS by itself produces a queue ordered by hypothetical severity. Reachability orders by actual exposure. Mixing the two correctly is where mature programs land.
What Is an EPSS Score? A Practical Security Guide
A practical guide to the EPSS score: what it measures, how the score and percentile differ, and how to use EPSS to prioritize which CVEs to fix first.
CVE Vulnerability Database: How the CVE and NVD System Actually Works
What the CVE vulnerability database is, how MITRE and the NVD divide the work, what a CVE record contains, and how to use it without drowning in noise.
NVD Full Form: What the National Vulnerability Database Is
The NVD full form is National Vulnerability Database, the U.S. government repository of known software vulnerabilities maintained by NIST. Here is what it contains and how to use it.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.