VulnTrack Report
Yocto Logo Compatible
Report generated: — Packages: — Issues: —
Load cve-summary.json to view
Summary
Packages
Issues
Sources
Products & Fixes
SBOM

Summary & Analysis

Load a Yocto cve-summary.json (local). This report summarizes package vulnerabilities found during your build.

Details

Build schema version
Affected packages
Total CVE issues
Unpatched / Ignored

Top CVEs (by severity)

CVE Severity Summary Status
Tip: Click any CVE to open the detailed CVE view (Yocto + NVD + EPSS).

Priority Visualization

Vulnerable Packages

CVSS Snapshot

Highest CVSS v3
Highest CVSS v2
Most common vector
Notes
Yocto JSON does not include EPSS/KEV/exploit info by default.

Packages

Click a package to drill down. Shows counts by severity derived from CVSS. (Local-only)

Package Details

Select a package to see its issues.

Issues

CVE Severity Package Version Status

Issue Details

Click an issue row to view details.
Tip: Click any row to open the full CVE view.

Sources

Displays reference links found in Yocto issues (if present in issue.link).
CVE Package Reference
Load cve-summary.json to populate this view.

Products & Fixes

Derived locally from Yocto package name/version/layer + issue status (Patched / Unpatched / Ignored).
Package Version Layer Worst status Top CVEs (by score)
Load cve-summary.json to populate this view.
“Worst status” is computed as: Unpatched > Ignored > Patched.

SBOM

Load CycloneDX JSON or SPDX JSON. Everything stays local in your browser.
Format
Components
Dependency edges
Top licenses
Component Version License
Load an SBOM JSON to populate this view.

Component Details

Click a component row to view details and dependencies.
Open in NVD
CVE-—
Status:
Published: — • Modified: — • EPSS: —

Executive Summary

Description (NVD)

References

Risk snapshot

CVSS Base (v3.x)
Vector
CVSS Base (v2)
EPSS (30d)

Affected in this build (Yocto)

Package Version Layer Status Severity

Developer tips