Drop in your vulnerability scanner’s export. It picks out the flaws attackers are actually using today, from CISA’s exploited list, flags those used in ransomware and on internet-facing addresses, and turns the rest into a patch plan: today, this week, this month, later. Read in your browser.
Or paste the export, or a list of CVE IDs
The scan never leaves this browser
CISA’s exploited list, refreshed every fortnight
Try it offline: it still works
Example report
186 findings · 71 hosts
7 to fix first
Today: VPN flaw used in ransomware!
This week: Log4Shell on 3 hosts!
173 findings can wait●
More in the full report●●●
Reading the scan in your browser
Grouping findings by flaw
Checking each against CISA’s exploited list
Putting them in order
Patch priorities
The exploited list in this tool is more than two weeks old. Newly exploited flaws may be missing; the order is still right for those it knows.
1 Summary
What the scan holds
2 The checks
3 The patch plan
4 Hosts with the most to fix
5 What this could not check
Prioritised against CISA’s Known Exploited Vulnerabilities catalogue. Read in your browser; the scan was never sent to us. Guidance, not a penetration test; see the terms.
HOW TO GET IT
Export the scan
Every scanner exports to CSV. Include the CVE column; the host and severity columns make the plan sharper.
Open the scanIn Nessus or Tenable, open the finished scan.
Report, then CSVChoose Report (or Export), CSV, and keep the CVE, Host, Risk and CVSS columns.
Drop the file inThe .nessus XML format is not read; use CSV.
Open the reportIn Greenbone, Scans, Reports, and open the report.
Download as CSV ResultsThe download arrow, then the “CSV Results” format.
Drop the file inSeveral CVEs on one line are read as separate flaws.
QualysReports, scan report, download as CSV. The header lines above the table are skipped.
Microsoft DefenderVulnerability management, Weaknesses or the device inventory, Export; or the DeviceTvmSoftwareVulnerabilities table from advanced hunting.
Anything elseAny CSV with a CVE column works, and so does a plain list of CVE IDs.
What happens to it: it is read in your browser and dropped once the report is drawn. Nothing is uploaded, and our copy of your details carries only the counts, never a host, an address or a CVE.
QUESTIONS
Asked often
The questions people search for before they run the check.
Which vulnerabilities should I patch first?
The ones attackers are already exploiting. CISA's Known Exploited Vulnerabilities list names them, and flags those used in ransomware. Patch those first, internet-facing systems before internal ones, then critical flaws not yet exploited, then the rest in the monthly cycle.
What is the CISA KEV catalogue?
The US Cybersecurity and Infrastructure Security Agency's list of vulnerabilities with confirmed exploitation in real attacks, each with the date it was added and whether it is known to be used in ransomware campaigns. It is free and updated as new exploitation is seen.
Why not just patch by CVSS score?
CVSS measures how bad a flaw could be, not whether anyone is using it. Most critical-rated flaws are never exploited, while some exploited ones score lower. Ranking by exploitation first puts the effort where attacks actually happen.
Which scanners does this read?
CSV exports from Nessus and Tenable, OpenVAS and Greenbone, Qualys, Rapid7 and Microsoft Defender Vulnerability Management, or any CSV with a CVE column. A plain list of CVE IDs works too.
Is my scan uploaded?
No. It is read in your browser and dropped once the report is drawn. If you ask for the report, we keep your details and a one-line summary with the counts, never a host or a CVE.
Godwit AI Labs
This report is available as a branded PDF, and the patch plan as a CSV. Use the download buttons on the page,
or ask us at godwit-tech.com/contact.
Patch what attackers use, first
Exploiting unpatched flaws is now the most common way into a network. Fixing the few on the exploited list, quickly, does more than fixing a thousand by score.