Godwit AI Labs Talk to us

Home › Free tools › Vulnerability scan prioritiser

Thousands of findings. Which ones first?

Drop in your vulnerability scanner’s export. It picks out the flaws attackers are actually using today, from CISA’s exploited list, flags those used in ransomware and on internet-facing addresses, and turns the rest into a patch plan: today, this week, this month, later. Read in your browser.

Or paste the export, or a list of CVE IDs
  • The scan never leaves this browser
  • CISA’s exploited list, refreshed every fortnight
  • Try it offline: it still works
HOW TO GET IT

Export the scan

Every scanner exports to CSV. Include the CVE column; the host and severity columns make the plan sharper.

  1. Open the scanIn Nessus or Tenable, open the finished scan.
  2. Report, then CSVChoose Report (or Export), CSV, and keep the CVE, Host, Risk and CVSS columns.
  3. Drop the file inThe .nessus XML format is not read; use CSV.

What happens to it: it is read in your browser and dropped once the report is drawn. Nothing is uploaded, and our copy of your details carries only the counts, never a host, an address or a CVE.

QUESTIONS

Asked often

The questions people search for before they run the check.

Which vulnerabilities should I patch first?

The ones attackers are already exploiting. CISA's Known Exploited Vulnerabilities list names them, and flags those used in ransomware. Patch those first, internet-facing systems before internal ones, then critical flaws not yet exploited, then the rest in the monthly cycle.

What is the CISA KEV catalogue?

The US Cybersecurity and Infrastructure Security Agency's list of vulnerabilities with confirmed exploitation in real attacks, each with the date it was added and whether it is known to be used in ransomware campaigns. It is free and updated as new exploitation is seen.

Why not just patch by CVSS score?

CVSS measures how bad a flaw could be, not whether anyone is using it. Most critical-rated flaws are never exploited, while some exploited ones score lower. Ranking by exploitation first puts the effort where attacks actually happen.

Which scanners does this read?

CSV exports from Nessus and Tenable, OpenVAS and Greenbone, Qualys, Rapid7 and Microsoft Defender Vulnerability Management, or any CSV with a CVE column. A plain list of CVE IDs works too.

Is my scan uploaded?

No. It is read in your browser and dropped once the report is drawn. If you ask for the report, we keep your details and a one-line summary with the counts, never a host or a CVE.

Patch what attackers use, first

Exploiting unpatched flaws is now the most common way into a network. Fixing the few on the exploited list, quickly, does more than fixing a thousand by score.