Skip to content

Terminology Reference

SBOM (Software Bill of Materials) — A structured inventory of the components, libraries, and dependencies that make up a piece of software, submitted in CycloneDX or SPDX format.

VEX (Vulnerability Exploitability eXchange) — A formal statement declaring whether a known vulnerability actually affects a specific product, and if so, what action is being taken.

CVE (Common Vulnerabilities and Exposures) — A unique identifier assigned to a publicly known cybersecurity vulnerability.

CVSS (Common Vulnerability Scoring System) — A standardized numeric score (0–10) representing the severity of a vulnerability.

EPSS (Exploit Prediction Scoring System) — A probability score estimating the likelihood that a vulnerability will be exploited in the wild.

KEV (Known Exploited Vulnerabilities) — The CISA-maintained catalogue of vulnerabilities confirmed to have been exploited in real-world attacks.

Organization — A user managing products, vendors, customers, and vulnerability triage on the platform.

Vendor / Supplier — A company supplying software components or products to an organization, responsible for submitting SBOMs and responding to alerts.

Customer — A user who has deployed an organization's product and receives vulnerability notifications relevant to that deployment.

Deployment — A specific installation of a product, recorded by a customer with a version, environment, and status.

Triage Status — The internal review state of a vulnerability within an organization — Unreviewed, Reviewed, or Escalated.

Notification — A vulnerability alert sent by an organization to a customer or vendor, tracked from sent through to acknowledgment.

VEX Request — A customer's formal ask for an official exploitability assessment of a specific CVE against their deployment.

OpenVEX — The open, machine-readable document format used to exchange VEX statements between systems and scanners.