Understanding the Cyberwatch vulnerability database

The foundation of detection

The vulnerability database is the technical foundation upon which Cyberwatch detection relies. It aggregates published CVEs, vendor security advisories, and threat intelligence sources such as the CISA-KEV catalog and CERT-FR alerts to identify flaws that are actually being exploited in the real world.

Broad technology coverage

The database covers all perimeters analyzed by Cyberwatch: operating systems, middleware, databases, open-source components (via SCA), container images, and industrial OT equipment. This breadth of coverage allows for the detection of vulnerabilities on everything from a Windows server to an industrial PLC or an npm dependency.

Continuous updates

The database is updated continuously to incorporate newly published CVEs as well as reports of actively exploited vulnerabilities. For air-gapped environments completely disconnected from the Internet, the database is updated manually via dedicated media, ensuring the system remains fully isolated while maintaining an up-to-date detection database.

From detection to prioritization

Each detected vulnerability is then enriched by Cyberwatch's contextual scoring, which cross-references CVSS, EPSS, and the business criticality of the affected asset to transform a simple list of CVEs into a prioritized, actionable plan for security teams.