Skip to main content
The Vulnerabilities module is Kikimora’s central repository for security findings. It continuously aggregates flaws and exposures from every source the platform has: automated web application scans such as Qualys, endpoint monitoring agents such as Wazuh, external exposure discovery engines, and manual security testing. Editing a finding that originated from a web scan or agent does not create a duplicate. On subsequent scans, Kikimora updates the existing entry instead.

Lifecycle and statuses

Each vulnerability moves through a lifecycle marked by a colored status badge:

Severity and impact

Findings are graded into standard impact levels from their CVSS score:

Kikimora Score

The Kikimora Score refines standard CVSS metrics with asset criticality, exposure, active threat intelligence, and environment context — so two findings that share a CVSS score can rank very differently in your environment.

Time to Resolve

Time to Resolve (TTR) measures the elapsed duration between a vulnerability’s first detection and its closure. Use it to track SLA compliance and remediation efficiency.