View your CVE Shields
The CVEs list in Explorer shows every CVE found across your organization's library inventory in one place, so you can prioritize which ones need attention. It combines severity and real-world exploitability signals with your current Contrast CVE Shield coverage.
This page describes the signals you need in addition to CVE Shield status to decide what to act on first. See Review Contrast CVE Shield states to learn what each status means.
Before you begin
An agent must be installed and configured on a service.
Your Java agent must be release 6.33.1 or later, or your Flex Agent must be release 2.2.2 or later for CVE Shield to report status from an agent.
Steps
In Northstar, in the left navigation, go to Explorer > CVEs.
Review your risk. You'll see the following details:
Column
What it tells you
CVE ID
Links to the CVE's public record.
CVE Shield
Whether this CVE has CVE Shield coverage in your organization: Configured or N/A.
Severity
The CVE's severity rating.
Max CVE Contrast score
The highest Contrast score for this CVE across every affected application. The Contrast score represents risk at a point in time, using data from Contrast's SAST, IAST, SCA, ADR, and Observability technologies.
Total CVE Shield status
A breakdown of how many application-and-environment combinations for this CVE are in each CVE Shield status.
Total applications
How many applications in your organization are affected.
Total environments
How many environments (Development, QA, Production) are affected.
Total library versions
How many distinct vulnerable library versions are still in use.
EPSS
The Exploit Prediction Scoring System (EPSS) probability that this CVE will be exploited.
KEV
Indicates the CVE is listed in CISA's Known Exploited Vulnerabilities catalog and has been actively exploited in the wild.
Prioritize what to act on
Look for CVEs that are critical or high severity, have a high EPSS score or a KEV flag, affect a wide blast radius of applications and environments, and are still marked N/A under CVE Shield. These are your highest-risk, least-protected CVEs.
Select a CVE ID to view its full details, including every affected application and library version. Use the Library issues tab to view issue details on how to remediate the vulnerability and identify which root library should be updated.
If a CVE's status doesn't match what you expect, confirm your agent release version is the minimum required for CVE Shield. See Before you begin above for details.
If you find a high-risk CVE without shield coverage, see customize protection by CVE to learn how to create an override for it.
See View issues with Northstar to learn how how CVE Shield status appears in the context of issue data, and how CVE Shield and ADR interact when both act on the same method.