Vulnerability Tracking

Pckgr automatically cross-references the software installed on your Windows devices with the National Vulnerability Database (NVD) to surface known CVEs and help you remediate them.

How It Works

When devices check in, the Pckgr agent reports every application installed on the machine. Pckgr matches each detected app to its catalog entry, which is linked to one or more NVD CPE identifiers. The installed version is then compared against published CVE ranges to determine whether the device is vulnerable.

  1. NVD sync - CVE data is fetched from the NVD on a daily schedule and stored locally.
  2. CPE matching - Each catalog package is mapped to NVD vendor/product pairs so the right CVEs are associated.
  3. Version evaluation - For every detected app, the installed version is checked against the CVE's affected version ranges.
  4. Rollup - Per-device CVE counts are aggregated into the security overview and dashboard alert.

Devices that haven't checked in within the tenant's dormant threshold are excluded from all vulnerability counts, so long-offline machines don't inflate the numbers. When any are excluded, the security overview shows how many.

Dashboard Alert

When any devices have known vulnerabilities, a security alert tile appears on the main dashboard showing the number of affected devices, critical CVE count, and total open instances. Click View Security to go to the full security page.

Security Overview

The security overview page provides a tenant-wide summary of application vulnerabilities.

Metrics

  • Vulnerable devices - Devices with at least one open CVE, out of total scanned
  • Critical CVE instances - Total critical-severity instances across all devices
  • Total open instances - Sum of all open CVE instances across vulnerable apps

Vulnerable Applications Table

Lists every application with known vulnerabilities. Sortable by name, affected device count, critical count, severity, and patchable status. Two toggles let you filter to patchable-only apps or include dismissed false positives.

Catalog Match Picker

If an app is linked to the wrong catalog entry, click the catalog match column to open a picker. Pckgr shows ranked candidates based on name, publisher, and architecture. You can also search the full catalog manually. Changing the match remaps every detected install of that app across all devices in your tenant.

Dismissals

Mark an application as a false positive to remove it from the dashboard alert and metric totals. Dismissed apps can be viewed and restored at any time using the Show dismissed toggle.

App Detail & Bulk Patching

Click any row in the vulnerable applications table to see which devices are affected and what can be fixed.

Per-Device Breakdown

The detail page shows each affected device with its installed version, open CVE count, critical count, how many CVEs the catalog's latest version fixes, and whether a job is already in flight.

One-Click Bulk Deploy

When the catalog has a version that fixes vulnerabilities, an Update N devices button appears. Clicking it queues an update job for every patchable device. Devices with an in-flight job are automatically skipped. If the app isn't yet in your managed apps, Pckgr adds it automatically with update-only intent.

Device Security Tab

Each device's detail page includes a Security tab showing vulnerabilities specific to that machine.

  • Each catalog-linked app with open CVEs appears as an expandable card with the total and critical CVE counts.
  • Expand to see individual CVEs with severity, patch status, affected version range, and a link to the NVD entry.
  • Patch status is shown per CVE: Fix in catalog, Fix published, No fix yet, or Patched.
  • When a fix is available, an Update to vX button queues the patch for that device directly.

Coverage & Limitations

  • Coverage depends on detected apps being matched to a catalog entry with a verified NVD CPE alias. Apps without a catalog link are not tracked.
  • CVE data is sourced from the NVD and refreshed daily. Zero-day vulnerabilities may not appear until they are published.
  • Version comparison is best-effort for non-standard version schemes. Ambiguous versions are treated conservatively (not flagged as vulnerable).
  • The feature currently tracks Windows desktop applications. Mobile and browser-extension CVEs are filtered out automatically.