This is the shipping desktop app, rebuilt to click through on the web. Same layout, same modules, same twelve-layer TRIS ranking. Every module in the sidebar opens, twenty-two of them, down to the CVE detail page where each scoring layer shows its own arithmetic. Nothing is installed and no data leaves your machine, because there is no data: every finding on screen is demo data.
Enter your email and we send you an unlock link. One click opens every module in the sidebar, including the CVE detail page, the campaign replay and the defense map. We send you the release notes when the product ships something worth reading, and nothing else.
Check your inbox. We sent an unlock link to . It works for 24 hours and opens the demo right here.
Nothing arrived, or wrong address?
We do not sell or share the list. Unsubscribe from any email. See the privacy policy.
You have 1,186 critical across 1,284 assets. TRIS ranks them below. Act on the top first.
CVE-2024-38077CVE-2025-0282CVE-2024-6387Add CVEs to track. Move them through states as you assess, assign, and resolve them.
FortiOS SSL VPN out-of-bounds write
SSH transport prefix truncation, Terrapin
libwebp heap buffer overflow in WebP decode
Docker Engine authorization plugin bypass
OpenSSH signal handler race, regreSSHion
Spring Framework data binding remote code execution
Jenkins CLI arbitrary file read
Windows Remote Desktop Licensing Service RCE
Ivanti Connect Secure stack buffer overflow
MOVEit Transfer SQL injection
PAN-OS GlobalProtect command injection
Citrix ADC and Gateway unauthenticated code injection
FortiManager fgfmd missing authentication
Exchange Server SSRF, ProxyLogon
HTTP/2 Rapid Reset denial of service
MSDT remote code execution, Follina
Apache Log4j2 JNDI remote code execution
Citrix NetScaler session token leak, CitrixBleed
FortiOS SSL-VPN heap buffer overflow
xz-utils backdoor in liblzma, no affected build in fleet
curl SOCKS5 heap overflow, no affected version shipped
Search 361,000+ CVEs by ID, keyword, product, or technology. The cache updates daily via NVD and CISA KEV.
| CVE | Severity | CVSS | TRIS | EPSS | KEV | Published | Summary |
|---|---|---|---|---|---|---|---|
| CVE-2021-44228 | Critical | 10.0 | T94 | 97% | KEV | Dec 10, 2021 | Apache Log4j2 JNDI remote code execution |
| CVE-2024-38077 | Critical | 9.8 | T92 | 62% | · | Jul 9, 2024 | Windows Remote Desktop Licensing Service remote code execution |
| CVE-2025-0282 | Critical | 9.0 | T88 | 89% | KEV | Jan 8, 2025 | Ivanti Connect Secure stack-based buffer overflow |
| CVE-2024-21762 | Critical | 9.8 | T84 | 91% | KEV | Feb 9, 2024 | FortiOS SSL VPN out-of-bounds write |
| CVE-2021-26855 | Critical | 9.8 | T76 | 97% | KEV | Mar 2, 2021 | Microsoft Exchange Server server-side request forgery |
| CVE-2024-41110 | Critical | 9.9 | T71 | 12% | · | Jul 24, 2024 | Docker Engine authorization plugin bypass |
| CVE-2023-34362 | Critical | 9.8 | T68 | 94% | KEV | Jun 2, 2023 | Progress MOVEit Transfer SQL injection |
| CVE-2022-22965 | Critical | 9.8 | T57 | 97% | KEV | Apr 1, 2022 | Spring Framework data binding remote code execution |
| CVE-2023-4863 | High | 8.8 | T49 | 31% | KEV | Sep 12, 2023 | libwebp heap buffer overflow in WebP decoding |
| CVE-2024-6387 | High | 8.1 | T38 | 8% | · | Jul 1, 2024 | OpenSSH signal handler race condition |
| CVE-2023-48795 | Medium | 5.9 | T22 | 2% | · | Dec 18, 2023 | SSH transport protocol prefix truncation |
Interactive graph showing how attackers chain vulnerabilities across your network assets.
847 open actions across 1,284 assets, ranked by real-world risk. Group them the way your team divides the work.
612 patchable now (a patch or upgrade is available) · 74 hosts remediated in the last 30 days
Start here
Patch: install the July 2024 cumulative update on every licensing host, then restart the service · Domain controllers in the corp.local forest run this role.
Then work down
Update: move both VPN appliances onto the vendor fixed build · Only route into the flat management VLAN.
Patch: stage the cumulative update on exch-01 during the Saturday window · Mailbox access for the whole company.
Update: pin the base image to a build past the authorization plugin fix, then redeploy the runner pool · Signing keys live on these hosts.
Showing the top 4 of 847 actions.
Agentless breach and attack simulation. Discover assets, validate defenses, prove exploitability.
Severe CVEs on your assets that BASzy has not proven yet. Click to test exploitability on the exact box. Proof, not a guess.
| Severity | Title | Module | Target | MITRE | CVE Link |
|---|---|---|---|---|---|
| CRITICAL EXPLOITABLE | Pre-auth stack overflow on the VPN appliance | http.ivanti_rce | vpn-edge-01 | T1190 | CVE-2025-0282 |
| CRITICAL EXPLOITABLE | SSRF to authenticated mailbox read | http.proxylogon | exch-01 | T1190 | CVE-2021-26855 |
| HIGH BLOCKED | SMB relay to the file server | smb.relay | fs01.corp.local | T1557.001 | Link CVE |
| MEDIUM UNREACHABLE | SSH transport downgrade | ssh.terrapin | dev-sandbox-11 | T1557 | CVE-2023-48795 |
Windows Remote Desktop Licensing Service remote code execution. Published Jul 9, 2024 · 48 assets affected · ranked first of 18,942 open findings.
Biggest movers: BASzy validation 12.0 · CVSS base 9.8 · Asset criticality 9.0 · Blast radius 8.5, and eight more.
| Hostname | IP | Product / version | Role | Status |
|---|---|---|---|---|
| dc01.corp.local ✓ BAS VALIDATED | 10.20.4.11 | Windows Server 2022 · RDL 10.0.20348 | Domain controller | Open |
| dc02.corp.local ✓ BAS VALIDATED | 10.20.4.12 | Windows Server 2022 · RDL 10.0.20348 | Domain controller | Open |
| rds-lic-01.corp.local ✓ BAS VALIDATED | 10.20.9.30 | Windows Server 2022 · RDL 10.0.20348 | Licensing · internet-exposed | Open |
| rds-lic-02.corp.local | 10.20.9.31 | Windows Server 2022 · RDL 10.0.20348 | Licensing · internet-exposed | Open |
| app-term-07.corp.local ✓ BAS BLOCKED | 10.20.12.7 | Windows Server 2019 · RDL 10.0.17763 | Terminal services | Open |
Showing 5 of 48 affected hosts. Three proved exploitable, one was stopped by a host firewall rule, the rest are untested.
Compromise of a single licensing host reaches 214 assets in two hops, because the service runs as SYSTEM and its machine account is trusted by the file tier. Four separate routes end at a domain controller.
Unauthenticated remote code execution against the licensing service. No credentials, no user interaction, reachable from the internet.
The service runs as SYSTEM, so the machine account authenticates outward. SMB signing is not required on the file tier.
Relay from the file tier reaches the domain controllers, where the same CVE is present and already proven.
Documented living-off-the-land intrusions into critical manufacturing, reaching domain admin through Windows service abuse. Sector match drawn from your org profile.
CISA advisory records this group exploiting internet-facing Windows services in manufacturing ahead of ransomware deployment.
Long history of terminal services abuse for initial access. No public reporting ties the group to this specific CVE, which is why confidence sits at 52%.
Matched on tradecraft, tooling and sector. A match raises the layer score, it is not an attribution.
Vulnerabilities that follow this fork curve reached weaponized, packaged exploit code in a median of 11 days.
Persistent asset registry, auto-populated from BAS scans, scanner imports and connectors. Assets are canonically deduped by tiered fingerprint, so one real host is one row no matter how many tools found it.
| Hostname / IP | OS | Criticality | Environment | CVEs | Critical | KEV | Public | Last seen |
|---|---|---|---|---|---|---|---|---|
| dc01.corp.local 10.20.4.11 | Windows Server 2022 | CRITICAL | production | 41 | 6 | 3 | · | 2026-08-15 |
| dc02.corp.local 10.20.4.12 | Windows Server 2022 | CRITICAL | production | 39 | 6 | 3 | · | 2026-08-15 |
| exch-01.corp.local 10.20.4.30 | Windows Server 2019 | CRITICAL | production | 57 | 9 | 5 | Yes | 2026-08-15 |
| vpn-edge-01 10.20.0.4 | Ivanti Connect Secure 22.6 | CRITICAL | production | 12 | 4 | 4 | Yes | 2026-08-15 |
| fs01.corp.local 10.20.6.10 | Windows Server 2019 | HIGH | production | 34 | 3 | 1 | · | 2026-08-14 |
| xfer-01.corp.local 10.20.7.20 | MOVEit Transfer 15.0 | HIGH | production | 9 | 2 | 2 | Yes | 2026-08-15 |
| app-tomcat-04 10.20.8.14 | Ubuntu 22.04 LTS | HIGH | production | 63 | 5 | 2 | Yes | 2026-08-15 |
| rds-lic-01.corp.local 10.20.9.30 | Windows Server 2022 | HIGH | production | 28 | 3 | 0 | Yes | 2026-08-15 |
| build-runner-03 10.20.11.23 | Ubuntu 24.04 LTS | HIGH | production | 47 | 4 | 0 | · | 2026-08-15 |
| dev-sandbox-11 10.30.2.11 | Ubuntu 22.04 LTS | LOW | development | 88 | 7 | 1 | · | 2026-08-13 |
Showing 10 of 1,284 assets. Note the last row: dev-sandbox-11 carries more CVEs than any host in the estate and the lowest TRIS weight of the ten. Counting findings puts it first. Counting risk does not.
Briefings, indicators of compromise and tracked adversaries, auto-synced from the signed cveasyai.com feed or carried in offline, then correlated against your own inventory.
| Asset | Indicator | Type | Severity | Match | Source | Seen |
|---|---|---|---|---|---|---|
| exch-01.corp.local | 185.174.100.17 | IPv4 | critical | outbound-session | briefing:proxylogon-resurgence | 2026-08-15 |
| vpn-edge-01 | update.ivanti-cdn[.]net | Domain | critical | dns-query | briefing:ivanti-jan-2025 | 2026-08-15 |
| build-runner-03 | 9f3c1e…a742 | SHA-256 | high | file-hash | bundle:2026-W33 | 2026-08-14 |
| app-tomcat-04 | 45.61.136.9 | IPv4 | high | inbound-scan | bundle:2026-W33 | 2026-08-14 |
| ws-4471.corp.local | invoices-secure[.]top | Domain | medium | dns-query | bundle:2026-W32 | 2026-08-12 |
| ws-2210.corp.local | 103.75.190.22 | IPv4 | medium | outbound-session | bundle:2026-W32 | 2026-08-11 |
| log-collector-02 | b71a44…09de | SHA-256 | low | file-hash | bundle:2026-W31 | 2026-08-09 |
Bundles are signed. Signatures are verified before anything is ingested, which is what makes the air-gapped import path safe to use.
Attributed to the Exchange server-side request forgery chain you still have open on exch-01. Targets your sector.
Documented use of the Log4j2 lookup chain against build infrastructure. You resolved that one in June, so it no longer moves a score.
Living-off-the-land tradecraft against critical manufacturing. Feeds L4 on three of your open findings including CVE-2024-38077.
Exploits internet-facing Windows services ahead of ransomware deployment, per the CISA advisory carried in the bundle.
Terminal services abuse for initial access. Sector overlap only, so the layer contribution is capped.
48 actors tracked, 18 of them active against manufacturing. Attribution confidence is carried into TRIS layer 4 rather than being rounded up to a yes.
Technique coverage from BAS scan results, crossed with the detection rules your SIEM actually has. Two questions most programs answer in two different tools, on two different quarters.
Finds what exists and where it is misconfigured: cloud posture (CSPM and CIEM) plus agentless on-prem exposure mapping. This is the Discover stage of CTEM, upstream of and separate from BASzy validation.
| Provider | Rules | Accounts | Resources | Failing | Top failing control | Last run |
|---|---|---|---|---|---|---|
| AWS | 88 | 4 | 3,912 | 211 | Public S3 bucket policy allows cross-account read | 18m ago |
| Azure | 61 | 2 | 1,604 | 96 | Storage account permits unencrypted transfer | 18m ago |
| GCP | 55 | 1 | 742 | 38 | Service account holds project-wide editor role | 18m ago |
| On-prem | · | · | 1,284 | 63 | Management service reachable from an untrusted VLAN | 2h ago |
408 failing controls across 6,258 resources. Each one resolves to an owner and an asset before it reaches the queue, which is why the Command Center counts 1,284 machines rather than 6,258 rows.
Replay documented APT campaigns end to end against your real security stack. When a control blocks a step, the AI re-routes, exactly like the adversary would.
Step 4 is the whole point. A scripted simulation reports "blocked" and stops. The engine treated the block as information, re-planned, and reached the domain controller anyway. Your EDR did its job and the campaign still succeeded.
14 steps, cloud and on-prem, token theft into consent phishing
Volt Typhoon · living off the land11 steps, no binaries dropped, edge device into OT segment
Black Basta · access to encryption16 steps, broker access through to staged deployment
The campaign catalog, the technique-to-payload mapping and the adaptation logic are the product. We walk through them live against your stack rather than publishing them.
Book a walkthroughSee pricingCrafted web-request fuzzing for injection, request smuggling and differential response bugs. Every anomaly carries a reproducer, so a finding is something an engineer can run rather than a screenshot to argue about.
| Severity | Finding | Class | Endpoint | Signal |
|---|---|---|---|---|
| CRITICAL | Expression language injection in a template parameter | injection | /render?tpl= | timing + echo |
| HIGH | Request smuggling on a chunked transfer boundary | smuggling | /api/v2/upload | desync 8/8 |
| HIGH | Authorization differential between two role tokens | differential | /api/v2/reports | 200 vs 403 |
| MEDIUM | Verbose stack trace on a malformed multipart body | disclosure | /api/v2/import | len delta |
curl -sk 'https://app-tomcat-04.corp.local/render?tpl=%24%7B...' -H 'Cookie: JSESSIONID=...' --data-binary @payload.bin
python reproducer · finding 1import requests, sys; s = requests.Session(); s.headers.update({...}); r = s.post(TARGET, data=CRAFTED)
The generated proof-of-concept for your own targets is part of the licensed product. We will run it against a host you own on a call.
Book a walkthroughSee pricingFinds the unknowns on any host. Detection Scan runs the TRIS-prioritized KEV and template library for known-but-active exposures. 0-Day Audit uses app-behavior analysis and AI hypotheses to surface novel bugs that have no CVE yet, with a ready-to-file advisory.
Known-but-active exposures, ordered by TRIS rather than by template count. Answers "what is already public and reachable here".
Configure 0-Day AuditBehaviour-led hypotheses against an app that has no published CVE. Answers "what is wrong here that nobody has written up yet".
Configure Advisory draftA finding that survives triage produces a disclosure-ready writeup with affected versions, impact and a suggested fix.
View formatBehaviour class: deserialization reachable through an unauthenticated path. Hypothesis generated from response-timing clustering across 412 probes, then confirmed by a controlled second-order write.
Candidate 2 · xfer-01Behaviour class: path traversal past a normalisation routine that the vendor added in the fixed release for a different bug.
The behaviour classes, the hypothesis generator and the triage gate are not published. What is public: findings that survive go through coordinated disclosure, and the advisories carry our ORCID.
Talk to usOur researchThe analyst workflow. Three columns keyed to the SLA the band implies rather than to a severity label. Act inside 72 hours, attend within two weeks, track this quarter.
dc01.corp.local · production · crown jewel
vpn-edge-01 · production · internet-facing
exch-01.corp.local · production
build-runner-03 · production
xfer-01.corp.local · production
app-tomcat-04 · production
workstation fleet · 64 hosts
internal-jump-02 · production
dev-sandbox-11 · development
edge proxy tier · 6 hosts
CVE-2023-48795 carries a CVSS of 5.9 and sits in TRACK. CVE-2024-41110 carries a 9.9 and sits in ACT underneath a 9.8. The column is decided by the twelve layers, which is what makes the board a work plan rather than a sorted severity list.
Fix guidance per finding, written against the product and version actually installed on your host rather than against the vendor advisory in the abstract.
Steps: stage the July 2024 cumulative update on the licensing hosts, restart the Remote Desktop Licensing service, then re-run the BASzy module to confirm the exploit no longer lands · Rollback: uninstall the update and restore the service state snapshot taken at step 1.
14 steps, pre-flight snapshot, staged rings, verify gate
Runbook: appliance firmware9 steps, failover aware, config diff before and after
Runbook: container base image11 steps, registry pin, redeploy, drift check
Dispatch runs through Intune, Automox, Tanium, Jamf or your own webhook, never straight at the machine. The runbook set and the orchestration tiers ship with the licensed build.
How it worksSee pricingEvery closed CVE is sealed with an HMAC-signed attestation. Auditors verify offline. No certificate authority, no network call, and content-addressed identifiers so a record cannot be rewritten after the fact.
poff:3f9c1a7e42b8…d17a
Verify
poff:88b0e5cc19f2…4c63
Verify
poff:c14d77a90be6…9e28
Verify
poff:5a02be4417cd…b8f1
Verify
poff:9d3f0c2b7a45…1f70
Verify
A revoked attestation stays in the ledger. Nothing is deleted and nothing is rewritten, which is what makes the export usable as evidence rather than as a report.
Reports for stakeholders, auditors and engineering teams. Each one downloads as a printable HTML document and stays available under Recent. Generated locally, so the data never leaves the install to produce them.
Posture, trend, and the decisions you need from the leadership team. Two pages.
Generate Technical findingsEvery open finding with TRIS, affected hosts, validation state and the fix. For the engineers doing the work.
Generate Attack simulation writeupWhat BASzy ran, what landed, what was blocked, and the detection gaps that came out of it.
Generate Patch complianceSLA attainment by band and by owner, with the Proof-of-Fix attestations attached.
Generate Compliance mappingFindings mapped to CIS, PCI DSS, NIST 800-53, SOC 2, HIPAA and ISO 27001 controls.
Generate Remediation roadmapSequenced plan with effort, dependency, and the risk removed at each step.
Generate| Report | Type | Scope | Generated | Size |
|---|---|---|---|---|
| board-quarterly-2026Q3 | Executive summary | Demo Workspace | 3h ago | 412 KB |
| findings-manufacturing | Technical findings | Demo Workspace | Yesterday | 2.1 MB |
| baszy-campaign-hafnium | Attack simulation | 10.20.0.0/24 | 2 days ago | 876 KB |
| patch-sla-july | Patch compliance | Demo Workspace | Aug 1 | 340 KB |
Burndown, mean time to remediate and SLA attainment, measured against the TRIS band rather than against CVSS, so the trend tracks risk removed instead of tickets closed.
The two upticks are scanner onboarding, not regressions. W25 added the Qualys import and W31 added Falcon, and each one brought hosts the other tools had never seen. Deduplication is why the line resumes instead of resetting.
Monthly executive digest. Written by the local model, HMAC-signed, audit-ready. Generated on this machine, so nothing about the estate leaves the install to produce it.
Exposure fell 31% this month, driven mainly by the licensing-service remediation that closed 48 findings across the domain tier. Two items need a decision from this group: the appliance refresh, currently the only route into the flat management VLAN, and the detection coverage gap on privilege escalation, where our own simulation reaches domain admin without generating an alert…
What it reads like against a real estate is the only version worth judging. We generate one on a call, or from your own scanner export.
Book a walkthroughSee pricingFindings arrive from the tools you already run, land on one asset graph, and leave again as tickets, webhooks and alerts. Nothing here replaces a scanner. It reconciles them.
Vendor, auth mode, field mapping, schedule, dedup key, rate limits
Identity providersVendor, auth mode, field mapping, schedule, dedup key, rate limits
SIEM and loggingVendor, auth mode, field mapping, schedule, dedup key, rate limits
Which products we support, how each one authenticates and how its fields map onto the asset graph is the work that took the longest, so it is shared under a call rather than on a marketing page. Tell us your stack and we will confirm coverage in the first ten minutes.
Check your stackNamed partnersSee pricingScheduled pulls from the scanners and consoles you run. Credentials are encrypted at rest on this machine, scoped per workspace, and never transmitted anywhere except to the vendor endpoint they belong to.
| Connector | Auth | Endpoint | Scope | Schedule | Last sync |
|---|---|---|---|---|---|
| connector-a | API key | https://… | read:assets read:vulns | every 6h | 6m ago |
| connector-b | OAuth 2 | https://… | read:findings | every 6h | 6m ago |
| connector-c | Token | https://… | read:devices | every 12h | 2h ago |
The per-vendor configuration is exactly the sort of thing that should not be sitting on a website, ours or anyone's. We set yours up with you.
Set one up with usHow it is builtcveasy-ai-v1 runs on this machine. Remediation guidance, report narrative and triage suggestions are generated locally, which is what lets the whole product work with the network cable pulled out.
Composition, sourcing and the distillation gate that promotes a candidate
Eval harnessRubric, scoring weights, and the promotion thresholds a candidate must clear
Serving profileQuantisation, context budget and the memory envelope on Apple silicon
The benchmark results and the methodology are public. What went into the model and how a candidate gets promoted are not.
Benchmark resultsAsk us directlyWorkspace, business context and data handling. The org profile matters more than it looks: asset criticality and sector feed layers 4 and 5, so a blank profile deflates every score in the estate.
Sector, size, revenue per hour and risk appetite. Drives layers 4, 5 and 12. Currently set to manufacturing.
Edit profile Business contextCrown-jewel assets, environments and owners. Without it, a domain controller scores like a laptop.
Edit context WorkspacesOne tenant per client or per business unit. Findings, assets and scores are scoped and never merged across them.
Manage Data locationEverything lives in a local SQLite database on this machine. There is no CVEasy cloud to opt out of.
Show path TelemetryOff, and there is no switch to turn it on. The app makes no outbound call except to the feeds and connectors you configure.
Verify LicensePer-install, offline-verifiable. Editions gate feature surface rather than asset count, so the price does not grow with your own discovery.
ManageCommand Center. Every open finding ranked by TRIS across twelve layers, not by CVSS alone.
Click a highlighted sidebar item, press ⌘K for the palette, or open CVE-2024-38077 from the queue
Every number in the demo is the result of two data sets being put next to each other. Most programs own both halves already and never join them, because the halves live in different products. Here they live in one.
CVSS tells you how bad a bug could be in a lab. BASzy tells you whether it works on your box, in your configuration, with your controls running. Only one of those is a statement about you. On the CVE detail page you can see the moment they diverge: a 9.8 with no KEV listing outranks a 9.9, because the engine landed the exploit on two domain controllers and nothing stopped it.
Open the CVE detail pageThe usual splitScanner gives you severity. Pen test gives you proof, once a year, for a sample. Nobody reconciles the two, so the queue stays sorted by the number that was never about your environment.
Breach simulation vendors tell you which attacks succeeded. Detection vendors tell you which rules you own. The interesting answer is the overlap, and specifically the cells where the attack works and no rule fires. That is the defense map. Four gap classes, one screen, and the orange cells are the ones that should ruin your afternoon.
Open the defense mapThe usual splitBAS platform in one tab, SIEM content inventory in another, and an ATT&CK spreadsheet somebody maintains by hand between audits.
Nessus, InsightVM, VMDR, Falcon, Intune and BASzy discovery each name the same server differently, and each counts it again. 4,912 raw host records collapse to 1,284 canonical assets on a tiered fingerprint before anything is counted, scored or reported. Every metric downstream is therefore a number of machines rather than a number of rows.
Open the inventoryThe usual splitEach tool reports its own asset count, all of them are wrong, and the board sees whichever one was exported last.
A threat feed on its own is a list of strangers: addresses, domains and hashes with no bearing on anything you own. Correlated against the canonical asset table it turns into seven of your hostnames, each carrying the briefing that named the indicator and the date it was seen. That is the difference between reading intel and using it.
Open threat intelThe usual splitFeed subscription in one place, asset database in another, and an analyst pasting IPs into a search bar when something makes the news.
What you are looking at. Every label, column and status word here is lifted from the shipping build, so the demo goes stale the day the app changes and we re-cut it. The findings are fabricated. The product screenshots in the docs are from a real install.