All tools › Assess

Inventory

Know what you run, and which of it is actively exploited.

Register systems and assets, import an SBOM, and see which of them match vulnerabilities that are being exploited now, prioritised by real exposure rather than CVSS alone. A critical score on an isolated test rig is not the same as one on a public API.

Using Inventory needs a RiskWoven account: sign in with your email and a one-time code.

What you get

An asset register matched against CISA's actively-exploited vulnerability catalog, stating plainly what is and is not being checked.

Microsoft Exchange Server — recognised
   Checked against CISA's actively-exploited catalog by name.
   NOT checked against the full CVE corpus.

   CVE-2026-21410 · due 2026-09-04 · known ransomware use: Known
   Exploitation probability 42.1% over 30 days (FIRST EPSS estimate)

internal-billing-service — unmatched
   Recorded but not being checked. An absence of findings here means it was
   not looked at, not that it is unaffected.

Illustrative extract showing the shape and depth of the output. Not captured customer work, and not a template you receive — your document is written from your own answers.

What is checked, and what is not

Checked automatically

  • Matching is exact. A near miss produces no match, because a wrong product match attaches another product's vulnerabilities to your asset.
  • A truncated or implausibly small feed is refused rather than trusted, so a bad download cannot look like a clean result.
  • Every record names what was not retrieved, so a missing field reads as unknown rather than as absence of risk.

Not checked: your responsibility

  • The full CVE corpus. Coverage is the actively-exploited catalog plus package dependencies imported from an SBOM.
  • Anything you have not told us about. The register is only as complete as what you entered or imported.
  • Whether a listed vulnerability is actually exploitable in your configuration.

Who it is for

Whoever owns the asset list and the patch queue.

With a free account

  • The asset register, SBOM import, and matching against the CISA actively-exploited catalog.

Paid

  • AI remediation advice on a finding: Not included in anything on sale today. If you need it, email hello@riskwoven.com and we will set it up for you.

Prices in US dollars, one-time, exclusive of tax. Full detail on pricing.

Related tools

See all tools