For AppSec and engineering

Prioritize vulnerabilities
with production evidence.

Bring observed execution, affected workloads, and available fixes into the same review. Give engineering the context behind the next remediation decision.

app.primod.io / vulnerabilities

Vulnerability Funnel

47 of 52 images inspectedLast updated 6s ago
5,279Total Packages
2,759Static CVEs
141Function ExecutedRuntime activity observed3,412 spans in the last 1 hour
18Active CVEs
17Fix Available

From inventory to observed execution · evidence levels shown only where the finding supports them · Illustrative vulnerability workflow

01

Separate inventory from runtime evidence.

An installed package, a loaded library, and an observed function call describe different levels of activity. Review the evidence available for each finding rather than treating every inventory result as equally urgent.

02

Open the finding behind the number.

Inspect the affected workload and the runtime evidence associated with a vulnerability. Where supported and captured, call-stack context gives developers a more specific place to investigate.

app.primod.io / vulnerabilities / CVE-2024-21907
CRITICAL CVSS 7.5CVE-2024-219078/10/2026, 9:55:09 PM

Vulnerable Newtonsoft.Json code executed

Upgrade Newtonsoft.Json to 13.0.1 or later to remediate CVE-2024-21907

Present

Detected in runtime

Executed

Code executed

Exploited

Not observed

Impacted

No impact detected

Contained

Not contained

Nodelima-default
Poddotnet-vuln-api-6bb7d4b879-drh5x
Containerdotnet-vuln-api
Namespacedotnet-vuln-ns

Call stack · Newtonsoft.Json.JsonConvert.DeserializeObject

6Newtonsoft.Json.Serialization.JsonSerializerInternalReader.DeserializeNewtonsoft.Json.dll:0
7Newtonsoft.Json.JsonSerializer.DeserializeInternalNewtonsoft.Json.dll:0
8Newtonsoft.Json.JsonConvert.DeserializeObjectTRIGGER
9Program/<>c.<<Main>$>b__0_3DotnetVulnApp.dll:0

Example finding · Illustrative vulnerability workflow

03

Make the next patch decision explainable.

Review the affected version, available fix information, and workload history. Combine that evidence with severity, exposure, and your remediation policy to decide what to address next.

app.primod.io / vulnerabilities / CVE-2024-21907 / fix
ACTION REQUIRED

Upgrade Newtonsoft.Json: the vulnerable function was observed executing in production. Example fix information.

INSTALLED (VULNERABLE)
12.0.3
FIX AVAILABLE
13.0.1+

The vulnerable function Newtonsoft.Json.JsonConvert.DeserializeObject was observed executing in a live request.

Where it ran

Nodelima-default
Poddotnet-vuln-api-6bb7d4b879-drh5x
Containerdotnet-vuln-api
Import pathNewtonsoft.Json
BinaryN/A
Namespacedotnet-vuln-ns

Call stack

STACK TRACE (5 OF 24)
1Newtonsoft.Json.JsonTextReader.ParseValue
Newtonsoft.Json.dll:0
2Newtonsoft.Json.JsonTextReader.ParseObject
Newtonsoft.Json.dll:0
3Newtonsoft.Json.Linq.JTokenWriter.WriteToken
Newtonsoft.Json.dll:0
4Newtonsoft.Json.Serialization.JsonSerializerInternalReader.CreateJToken
Newtonsoft.Json.dll:0
5Newtonsoft.Json.Serialization.JsonSerializerInternalReader.CreateValueIn…
Newtonsoft.Json.dll:0
View full 24-frame call stack

Example fix information · call-stack excerpt where captured

04

Keep uncertainty visible.

A workload may not have exercised a vulnerable path during observation. Missing execution evidence is not proof of safety, and execution alone is not proof of exploitation.

app.primod.io / workloads / demo-springboot

Activity Timeline

Every detection, version change and remediation for this workload, in the selected period.

Aug 10, 2026 09:58:19 PMRemediated · CVE-2024-21733 · 9.0.99 (patched-1)
Aug 10, 2026 09:58:19 PMRemediated · CVE-2023-45648 · 9.0.99 (patched-1)
Aug 10, 2026 09:58:19 PMRemediated · CVE-2021-33037 · 9.0.99 (patched-1)
Aug 10, 2026 09:58:19 PMRemediated · CVE-2021-43980 · 9.0.99 (patched-1)
Aug 10, 2026 09:58:19 PMVersion changed · CVE-2025-66614 · cve-2022-42889 → patched-1

Version History

Every image version this workload has run, and how long each was live.

Aug 10, 2026 09:57:19 PMdocker.io/library/demo-springboot-vuln:patched-1Still runningsha256:36b0d9560f7f93ec8c1532ebe8f7cb6a8936f8e2dd26073eb74adcfb133e8d6b
Aug 10, 2026 09:37:19 PMdocker.io/library/demo-springboot-vuln:cve-2022-42889Ran until Aug 10, 2026 09:57:19 PMsha256:d85a0a2ea3bfb6eb472fa976dc7bd6a06a928100d64934631471786968 6b0f11
Aug 10, 2026 09:33:19 PMdocker.io/library/demo-springboot-vuln:patched-1Ran until Aug 10, 2026 09:37:19 PMsha256:36b0d9560f7f93ec8c1532ebe8f7cb6a8936f8e2dd26073eb74adcfb133e8d6b

Finding history and image versions · reference workload

Questions teams ask.

Can we stop patching vulnerabilities that were not observed?
No. Use runtime evidence to inform prioritization alongside your existing risk and remediation requirements.
Does Primod replace inventory scanning?
Inventory and runtime evidence answer different questions. This workflow uses both to inform a finding review.

Bring context to your vulnerability backlog.

Request a demo