Skip to content

Vulnerabilities

Vulnerability management that prioritises real risk

More than 200,000 daily-updated tests for web, network and cloud. Every vulnerability with EPSS, CISA KEV and exploit context, in one workflow through to remediation.

Vulnerability management that prioritises real risk
vulnerability tests, updated daily
200,000+
CVEs with EPSS, KEV and exploit context
140,000+
CIS-aligned checks for cloud accounts
500+
for an AI analysis of a vulnerability
≤ 30 s

Prioritise by exploitability, not only CVSS

CVSS says how bad a vulnerability could be. EPSS says how likely exploitation is, and CISA KEV says it is already being exploited.

Fix firstsorted by risk
1CVE-2024-21762vpn.beispiel-gmbh.atKEV
2CVE-2024-21410mail.beispiel-gmbh.atKEV
3TLS 1.0 enabledshop.beispiel-gmbh.atMedium

Visuals show sample data.

  • EPSS score and percentile

    The probability of exploitation in the next 30 days, per CVE.

  • CISA KEV and exploits

    KEV due date, ransomware flag, public exploits and proofs of concept.

  • Automatic escalation

    If EPSS exceeds 0.80 and an exploit exists, the alert severity goes up.

One vulnerability scan for every layer

External, internal and cloud results land in one list with the same fields, severities and statuses.

All findingsone list
External 31Internal 18Cloud 9
CVE-2024-21762vpn.beispiel-gmbh.atCritical
SMBv1 enabled192.0.2.14High
Storage account publicly accessibleMicrosoft AzureHigh
TLS 1.0 enabledmail.beispiel-gmbh.atMedium

Visuals show sample data.

From finding to fix, with evidence

AI explains and groups, the workflow tracks every finding through to the retest, and reports prove progress.

AI explanationself-hosted LLM
CVE-2024-21762vpn.beispiel-gmbh.atKEVCritical
Root cause
Outdated FortiOS version on the SSL VPN gateway.
Impact
Attackers can execute code without logging in.
Remediation
Update to FortiOS 7.0.14 or later.

Visuals show sample data.

Frequently asked questions

A scanner produces a list of findings at one point in time. Vulnerability management is the process around it: continuous scanning, prioritisation by actual risk, assignment to owners, status tracking, retests and evidence for auditors. blacklens.io covers both. Scans run automatically, and every finding carries status, comments, history and prioritisation signals such as EPSS and CISA KEV.

First vulnerability scan within 24 hours.

14 days free with the full feature set. We walk through the first findings and the prioritisation with you.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings