Help Centre

Read the evidence correctly

The catalogue is designed to make uncertainty visible. This page explains where each conclusion comes from and which conclusions the data cannot support.

Evidence model

Source precedence and provenance

BlackTree prefers direct, structured vendor evidence for product status and remediation. Vendor-authored CNA records, vendor CSAF, official CVE records, CISA, ENISA, NIST, national authorities and FIRST each contribute different fields. The report links back to the source so that a claim can be checked.

1Vendor CSAF and vendor-authored CNAAffected products, fixed products and remediation2CVE.org, CISA and ENISACanonical record, exploitation and European context3NIST, FIRST and national authoritiesEnrichment, prediction and local guidance4BlackTree assessmentOperational interpretation with visible evidence gaps
Field meaning

Do not collapse different signals

CVSS
Technical severity under a defined scoring vector. It is not an exploitation forecast or patch deadline.
EPSS
A probability estimate for exploitation in the next 30 days. It changes over time and is not confirmation of exploitation.
KEV
Confirmation that the catalogue authority has evidence of exploitation. Absence from KEV does not prove no exploitation.
Public exploit
A source references public exploit or proof-of-concept material. BlackTree does not imply that every reference is reliable or weaponised.
Patch available
An authoritative patch reference, fixed product state or vendor-authored solution exists. Applicability can still differ by product branch.
Awaiting fix
No verified fix was found in the current structured evidence. It does not prove that a vendor webpage has no newer instruction.
Freshness

Updates and retained evidence

The status bar shows the latest successful core-source refresh. Individual records can have different upstream update times. Failed optional sources retain their last known good data and are shown as delayed or degraded rather than silently cleared.

National advisories

Source wording and complete advisory fields

Country reports preserve the authority’s published content instead of translating or paraphrasing it. BlackTree localises navigation, headings and explanatory labels, then displays all retained user-facing advisory fields. For CSAF sources this includes document and vulnerability notes, product states, scores, remediations, threats, flags, involvement records, acknowledgements, references and source metadata.

Some authorities publish mixed-language documents. A document may declare Dutch, German or another local language while embedding an English CVE summary supplied by a vendor. BlackTree shows the source-language label and prefers a CVE-specific local narrative when the authority supplied one, but it does not invent a translation for source text that remains English.

Inventory matching

What stays in the browser and what is sent

The selected SBOM and VEX files are read and parsed locally by the browser. The original files are not uploaded. When you choose Match inventory, the browser sends a bounded request containing normalized component identifiers and optional VEX statements. Those identifiers are needed to compare the inventory with catalogue records.

The request and result are not written to the catalogue database and are not retained by default. Clearing local data removes the selected file state and visible result from the page. A JSON export is created only when you explicitly choose the export action.

Accepted SBOM
CycloneDX 1.4 to 1.6 and SPDX 2.2 to 2.3 JSON.
Accepted VEX
CycloneDX VEX, CSAF 2.x and OpenVEX JSON.
File limit
5 MB per selected file. Multiple files can be combined in one browser session.
Not accepted
PDF reports, spreadsheets, XML SBOMs, raw scan output, host inventories or credentials.
Boundaries

What the catalogue cannot know

  • Your installed products, versions, exposure, compensating controls or business impact.
  • Whether a public exploit works safely or reliably in your environment.
  • Whether an unlisted vendor page contains a newer unstructured instruction.
  • Whether a search engine has crawled or indexed a particular URL.
  • Whether missing CVSS, EPSS, KEV, product or national guidance means low risk.
  • Whether applying a vendor update is operationally safe for your systems.
Privacy and safe use

Use the right input for each tool

The multi-CVE function accepts public CVE identifiers only and does not retain the submitted list or result. Do not paste hostnames, IP addresses, usernames, incident evidence or credentials into public catalogue search or multi-CVE input.

Inventory applicability is the dedicated SBOM and VEX workflow. It parses original files in the browser and submits normalized component evidence only when you start matching. Do not use either workflow as a substitute for your organisation’s approved asset, vulnerability and change-management systems.