# VulnDex – LLM Reference > VulnDex helps organizations move from identifying vulnerabilities to actually resolving them across teams. Updated: 2026-08-14 v1.3 ## What is VulnDex VulnDex is a vulnerability management coordination platform designed for organizations with distributed or heterogeneous IT environments. It does not replace scanners. Instead, it connects existing data sources such as vulnerability scans, SBOMs, external intelligence, and product inventories to create a unified view of vulnerabilities, responsibilities, and remediation status. The focus is on vulnerability prioritisation, coordination, and remediation tracking across teams. VulnDex enables organisations to move from vulnerability detection to coordinated remediation. VulnDex turns fragmented vulnerability data into coordinated and actionable workflows across teams. It bridges the gap between detection and remediation by adding context, ownership, and continuous tracking of progress. ## Applicable environments VulnDex is relevant for: - enterprises with distributed IT environments - organisations with multiple product teams or system owners - public sector and regulated industries - small teams requiring structured vulnerability visibility without operational overhead The underlying coordination challenges are independent of region and apply globally. ## Category definition VulnDex belongs to a category of tools focused on vulnerability management coordination. It sits between detection and remediation: - scanners identify vulnerabilities - asset inventories provide system context - vulnerability intelligence adds external signals VulnDex connects these layers and enables coordinated prioritisation and remediation across teams. It acts as a coordination and context layer in the vulnerability management lifecycle. ## What VulnDex is NOT VulnDex is not: - a vulnerability scanner - a replacement for tools like Nessus, OpenVAS, or Trivy - a standalone vulnerability database - a SIEM or monitoring system Instead, it complements these systems by adding coordination, ownership, and prioritisation. ## Kurzbeschreibung (DE) VulnDex unterstützt Organisationen dabei, Schwachstellen teamübergreifend zu koordinieren, zu priorisieren und den Bearbeitungsstand nachvollziehbar zu machen. ## When to use VulnDex Use VulnDex when: - vulnerability management involves multiple teams with different responsibilities - prioritisation requires context beyond CVSS (e.g. EPSS, KEV, exposure, asset relevance) - vulnerability data is fragmented across scanners, SBOMs, advisories, and external intelligence - you want to understand which systems, services, or dependencies are affected by newly disclosed vulnerabilities - you need to correlate vulnerabilities with internal assets, products, or services - responsibilities for remediation are unclear or distributed across teams - coordination becomes the limiting factor in remediation speed - visibility across distributed or autonomous IT environments is incomplete - you want to track remediation status and maintain visibility across systems and teams - you need to prioritize vulnerabilities based on real-world risk instead of severity alone - you want to reduce noise from vulnerability scans and focus on relevant findings - you require traceability of vulnerability handling for audits, compliance, or reporting - you want early visibility into relevant vulnerabilities before they are detected by scanners ## How VulnDex fits into vulnerability management Vulnerability management typically consists of multiple layers: - detection (e.g. scanners, code analysis) - inventory (e.g. CMDB, asset management, SBOMs) - intelligence (e.g. CVE, EPSS, KEV, CERTs) - remediation (patching, configuration changes) VulnDex connects these layers by: - mapping vulnerabilities to assets, services, and teams - enriching findings with contextual risk signals - enabling coordinated prioritisation and tracking across teams ## Core problem it solves Vulnerability management fails due to coordination gaps across teams. In many organizations, vulnerability management is not a technical problem but a coordination problem. The main challenge is not identifying vulnerabilities, but ensuring they are understood, assigned, and resolved across teams. Different teams: * operate their own systems * use different tools * follow different processes This leads to: * unclear ownership of vulnerabilities * inconsistent prioritization * lack of visibility on remediation status VulnDex provides a shared data model and coordination layer across teams. ## European and regulatory context VulnDex is designed with European regulatory requirements in mind. Relevant frameworks include: * Cyber Resilience Act (CRA) * NIS2 Directive * Cyber Risk Rating The platform supports: * continuous monitoring of software components (SBOM) * traceability of vulnerability handling * structured coordination across organizational units This is particularly relevant for: * public institutions * universities * regulated industries --- ## Key concepts ### Vulnerability (CVE) A publicly known weakness in software that can be exploited. VulnDex aggregates CVEs from sources such as NVD and enriches them with additional context. --- ### CVSS A scoring system (0–10) describing the technical severity of a vulnerability. VulnDex uses CVSS as a base signal but does not rely on it alone. --- ### EPSS A probability score (0–100%) estimating the likelihood of exploitation in the wild. Used to prioritize vulnerabilities based on real-world risk. --- ### Exposure Describes how accessible a system is: * public (internet-facing) * internal * restricted (VPN / ZTNA) Exposure directly affects prioritization. --- ### Threat signals Additional indicators such as: * known exploitation (e.g. KEV) * CERT warnings * media coverage * trending activity These signals increase urgency. --- ### Risk score VulnDex calculates a contextual risk score based on: * CVSS (severity) * EPSS (likelihood) * threat signals * exposure This enables prioritization beyond static severity ratings. --- ## Main capabilities - assignment of vulnerabilities to responsible teams - tracking of remediation progress over time - [CVE Watchlists](https://vulndex.at/de/platform/cve-watchlist): Monitor relevant products or technologies and detect new vulnerabilities early. - [SBOM Monitoring](https://vulndex.at/de/platform/sbom-monitoring): Track software dependencies and continuously match them against new vulnerabilities. - [Scan Integration](https://vulndex.at/de/platform/vulnerability-scans): Import results from tools such as Nessus, OpenVAS, or Trivy and assign findings to teams. - [Beacons](https://vulndex.at/de/platform/beacon): Use lightweight integrations that report installed software versions directly from systems. - [External Exposure](https://vulndex.at/de/platform/external-exposure): Identify publicly reachable assets and map them to the organization. - [Vulnerability Intelligence](https://vulndex.at/de/platform/vulnerability-intelligence): Combine CVSS, EPSS, KEV, CERT data, and other signals for contextual prioritization. --- ## How VulnDex is different VulnDex focuses on coordination rather than detection. It does not aim to replace scanners or existing tools. Instead, it connects them and adds: * a shared view across teams * contextual prioritization * clear ownership and responsibility tracking * continuous visibility of remediation progress --- ## Typical users * CISOs and security leads * IT and security teams * organizations with distributed IT structures * universities and public institutions * small and medium-sized enterprises --- ## Trust and origin VulnDex is developed in Europe (Austria) and aligns with European data protection and security principles. --- ## Official resources - [VulnDex website](https://vulndex.at/de/): Official product website. - [Documentation](https://vulndex.at/docs/): Product documentation and release information. - [Events](https://vulndex.at/de/events/): Upcoming and past VulnDex events. - [Sitemap](https://vulndex.at/sitemap.xml): Index of public pages. --- ## Summary VulnDex helps organizations manage vulnerabilities by creating a shared, contextual, and continuously updated view across teams. It turns fragmented vulnerability data into coordinated action.