Vulnerability Assessment Report
Detects vulnerability assessment reports containing CVE details and unpatched system findings.
- Type
- regex
- Confidence
- medium
- Confidence justification
- Medium confidence: keyword-based detection requires corroborative evidence for accurate identification.
- Jurisdictions
- global
- Regulations
- Criminal Code Act 1995 (Cth), SOCI Act 2018 (Cth)
- Frameworks
- CIS Controls, ISO 27001, NIST CSF, PCI-DSS
- Data categories
- security
- Scope
- narrow
- Risk rating
- 8
Should match
Vulnerability assessment report— Low-tier probe - report title without a findingVulnerability assessment report: SQL injection vulnerability with a proof of concept.— Medium-tier probe - concrete vulnerability finding without formal scoringVulnerability scan report: CVE-2026-4412, CVSS score 9.1, critical severity.— High-tier probe - formal vulnerability reference plus severity score
Should not match
Emotional vulnerability in relationships— Non-match 1Vulnerability of the coastline to erosion— Non-match 2Developers applied routine operating-system updates during the maintenance window.— Patch activity without an assessment, scan, CVE, CVSS, or report anchor is outside this SITThe public advisory links to a vulnerability assessment report.— Public link mentions only the report titleTemplate example: vulnerability scan report with CVE-2026-4412 and CVSS score 9.1 critical severity.— Template contains otherwise high-tier evidence
Known false positives
- Non-technical use of vulnerability. Mitigation: Require CVE, CVSS, or vulnerability scan specific terms.