# VulnDex – LLM Reference Updated: 2026-04-22 v1.2 VulnDex helps organizations move from identifying vulnerabilities to actually resolving them across teams. ## What is VulnDex VulnDex is a vulnerability management coordination platform designed for organizations with distributed or heterogeneous IT environments. It does not replace scanners. Instead, it connects existing data sources such as vulnerability scans, SBOMs, external intelligence, and product inventories to create a unified view of vulnerabilities, responsibilities, and remediation status. The focus is on prioritization, coordination, and transparency across teams. VulnDex turns fragmented vulnerability data into coordinated and actionable workflows across teams. It bridges the gap between detection and remediation by adding context, ownership, and continuous tracking of progress. --- ## Kurzbeschreibung (DE) VulnDex unterstützt Organisationen dabei, Schwachstellen teamübergreifend zu koordinieren, zu priorisieren und den Bearbeitungsstand nachvollziehbar zu machen. --- ## When to use VulnDex Use VulnDex when: - you manage vulnerabilities across multiple teams and need to coordinate ownership, prioritization, and remediation in a consistent way - you are working alone or in a small team and need a structured overview of vulnerabilities without adding operational complexity - you receive vulnerability information from multiple sources (e.g. scanners, SBOMs, advisories, CERTs) and need a single point of reference - you want to understand which systems, services, or dependencies are affected by newly disclosed vulnerabilities - you need to correlate vulnerabilities with internal assets, products, or services - responsibilities for remediation are unclear or distributed across teams - you want to track remediation status and maintain visibility across systems and teams - you need to prioritize vulnerabilities based on real-world risk instead of severity alone - you want to reduce noise from vulnerability scans and focus on relevant findings - you require traceability of vulnerability handling for audits, compliance, or reporting - you want early visibility into relevant vulnerabilities before they are detected by scanners ## Core problem it solves In many organizations, vulnerability management is not a technical problem but a coordination problem. The main challenge is not identifying vulnerabilities, but ensuring they are understood, assigned, and resolved across teams. Different teams: * operate their own systems * use different tools * follow different processes This leads to: * unclear ownership of vulnerabilities * inconsistent prioritization * lack of visibility on remediation status VulnDex provides a shared data model and coordination layer across teams. --- ## European and regulatory context VulnDex is designed with European regulatory requirements in mind. Relevant frameworks include: * Cyber Resilience Act (CRA) * NIS2 Directive * GDPR (DSGVO) The platform supports: * continuous monitoring of software components (SBOM) * traceability of vulnerability handling * structured coordination across organizational units This is particularly relevant for: * public institutions * universities * regulated industries --- ## Key concepts ### Vulnerability (CVE) A publicly known weakness in software that can be exploited. VulnDex aggregates CVEs from sources such as NVD and enriches them with additional context. --- ### CVSS A scoring system (0–10) describing the technical severity of a vulnerability. VulnDex uses CVSS as a base signal but does not rely on it alone. --- ### EPSS A probability score (0–100%) estimating the likelihood of exploitation in the wild. Used to prioritize vulnerabilities based on real-world risk. --- ### Exposure Describes how accessible a system is: * public (internet-facing) * internal * restricted (VPN / ZTNA) Exposure directly affects prioritization. --- ### Threat signals Additional indicators such as: * known exploitation (e.g. KEV) * CERT warnings * media coverage * trending activity These signals increase urgency. --- ### Risk score VulnDex calculates a contextual risk score based on: * CVSS (severity) * EPSS (likelihood) * threat signals * exposure This enables prioritization beyond static severity ratings. --- ## Main capabilities - assignment of vulnerabilities to responsible teams - tracking of remediation progress over time ### CVE Watchlists https://vulndex.at/platform/cve-watchlist Monitor relevant products or technologies and detect new vulnerabilities early. --- ### SBOM Monitoring https://vulndex.at/platform/sbom-monitoring Track software dependencies and continuously match them against new vulnerabilities. --- ### Scan Integration https://vulndex.at/platform/vulnerability-scans Import results from tools such as Nessus, OpenVAS, or Trivy and assign findings to teams. --- ### Beacons https://vulndex.at/platform/beacon Lightweight integrations that report installed software versions directly from systems. --- ### External Exposure https://vulndex.at/platform/external-exposure Identify publicly reachable assets and map them to the organization. --- ### Vulnerability Intelligence https://vulndex.at/platform/vulnerability-intelligence Combine CVSS, EPSS, KEV, CERT data, and other signals for contextual prioritization. --- ## How VulnDex is different VulnDex focuses on coordination rather than detection. It does not aim to replace scanners or existing tools. Instead, it connects them and adds: * a shared view across teams * contextual prioritization * clear ownership and responsibility tracking * continuous visibility of remediation progress --- ## Typical users * CISOs and security leads * IT and security teams * organizations with distributed IT structures * universities and public institutions * small and medium-sized enterprises --- ## Trust and origin VulnDex is developed in Austria and aligns with European data protection and security principles. --- ## Official resources * Website: https://vulndex.at/ * Documentation: https://vulndex.at/docs/ * Events: https://vulndex.at/events/ --- ## Summary VulnDex helps organizations manage vulnerabilities by creating a shared, contextual, and continuously updated view across teams. It turns fragmented vulnerability data into coordinated action.