Summary & Analysis
Load a Yocto
cve-summary.json (local). This report summarizes package vulnerabilities found during your build.
Details
Build schema version
—
Affected packages
—
Total CVE issues
—
Unpatched / Ignored
—
Top CVEs (by severity)
| CVE | Severity | Summary | Status |
|---|
Tip: Click any CVE to open the detailed CVE view (Yocto + NVD + EPSS).
Priority Visualization
Vulnerable Packages
CVSS Snapshot
Highest CVSS v3
—
Highest CVSS v2
—
Most common vector
—
Notes
Yocto JSON does not include EPSS/KEV/exploit info by default.
Packages
Click a package to drill down. Shows counts by severity derived from CVSS. (Local-only)
Package Details
Select a package to see its issues.
Issues
| CVE | Severity | Package | Version | Status |
|---|
Issue Details
Click an issue row to view details.
Tip: Click any row to open the full CVE view.
Sources
Displays reference links found in Yocto issues (if present in
issue.link).
| CVE | Package | Reference |
|---|---|---|
| Load cve-summary.json to populate this view. | ||
Products & Fixes
Derived locally from Yocto package name/version/layer + issue status (Patched / Unpatched / Ignored).
| Package | Version | Layer | Worst status | Top CVEs (by score) |
|---|---|---|---|---|
| Load cve-summary.json to populate this view. | ||||
“Worst status” is computed as: Unpatched > Ignored > Patched.
SBOM
Load CycloneDX JSON or SPDX JSON. Everything stays local in your browser.
Format
—
Components
—
Dependency edges
—
Top licenses
—
| Component | Version | License |
|---|---|---|
| Load an SBOM JSON to populate this view. | ||
Component Details
Click a component row to view details and dependencies.
CVE-—
Status: —
—
Published: — • Modified: — • EPSS: —
Executive Summary
—
Description (NVD)
—
References
—
Risk snapshot
CVSS Base (v3.x)
—
Vector
—
CVSS Base (v2)
—
EPSS (30d)
—
Affected in this build (Yocto)
| Package | Version | Layer | Status | Severity |
|---|