Help center

Vulnerabilities and exposure

Exposure scans and profiles, scan clearance, findings and dismissals, hosts and open ports, the software inventory, KEV/CVE alerts with verdicts, the watchlist.

Updated · 7 articles

"Exposure" is everything on the outside of a domain that an attacker could use: a known vulnerability in software the site runs, a service listening on a port it should not, a secret in a public file, a host nobody remembered. DomainGuard finds it with a container of open-source scanners plus its own checks, never sends traffic to a domain the account has not proven it controls, and labels every verdict by the evidence behind it.

Articles

Where

  • Web: Security (account-wide), and a domain's Vulnerabilities module.
  • iOS: a domain's Vulnerabilities module with three segments: Alerts, Software, Hosts. Vulnerabilities was a tab until 2026-09-02; it is a module now, so the domain is chosen by opening it.
  • API/MCP: /api/vuln-scan/*, /api/vulnapps/*, /api/scan/ports/:id; the vulnscan scope.

Common questions

Is a scan safe for my site? The templates are non-intrusive reads and the port probe is a connect test. Nothing exploits, writes or floods, and the scanners run only on domains the account has proven it controls.

Why does my domain say "0 findings" after only a Quick scan? A Quick scan reads what the site serves and nothing more. Prove ownership and run Standard for the active checks; until then the page says which profile ran.

In reading order

Articles in Vulnerabilities and exposure

  1. Exposure scans: profiles, tools and limitsThe five scan profiles, the scanners behind them (Nuclei, Subfinder, Trivy, Betterleaks, Naabu plus DomainGuard's own checks), allowances, and the schedule.Updated
  2. Scan clearance and ownership proofProve you control one domain on the account (DNS record, file, or an email link) and every domain is cleared for 90 days. Protected targets and authorisation.Updated
  3. Findings, carry-forward and dismissalsWhat a finding shows, why a finding from a heavier scan survives a lighter one, and the four reasons a finding, a software reading or an alert can be silenced.Updated
  4. Hosts and open portsEvery host a scan found, grouped by domain, with its services named by what the port means; the 128-port list; and why an empty list is not an all-clear.Updated
  5. Software inventory and vendorsWhat your scans proved the site runs, split into versioned software that can be checked and software only seen; confidence, detector and last-seen; and vendors.Updated
  6. KEV and CVE alerts with verdictsHow the CISA KEV and NVD feeds are ingested, why only new entries alert (watch-forward), the four exposure verdicts, the advisory page, and the global feed.Updated
  7. The software watchlistTrack a product so the next KEV or CVE against it alerts you: alert cadence, sources, severity filter, and the split between site software and device software.Updated

Still stuck?

Ask the people who run the scanner.

Send the domain and what you expected to see. We look at the same scan you are looking at and write back with what it means and what to change.