Microsoft Defender for Cloud

Download 0
Last updated Oct 5, 2026

defender-cloud-cve-findings

Lists vulnerabilities collected from Microsoft Defender for Cloud, one row per affected resource, so each row names the CVE, the asset that carries it and the version that closes it.

defender-cloud-cve-findings [profile=VALUE] [subscription=VALUE] [cve=VALUE] [severity=VALUE] [resource=VALUE] [software=VALUE] [exposed=VALUE] [locale=VALUE]
profile=VALUE
Optional. Profile identifier. Omit to read every registered tenant. e.g. mdc
subscription=VALUE
Optional. Azure subscription ID. e.g. 00000000-0000-0000-0000-000000000000
cve=VALUE
Optional. A single CVE identifier, to list every resource carrying it. e.g. CVE-2023-51385
severity=VALUE
Optional. Critical, High, Medium or Low. e.g. Critical
resource=VALUE
Optional. Substring of the resource name or ID, to list one machine's vulnerabilities. e.g. vm-app-01
software=VALUE
Optional. Substring of the vulnerable package name. e.g. openssl
exposed=VALUE
Optional. t to return only internet-reachable resources. e.g. t
locale=VALUE
Optional. Language of the recommendation title. Defaults to the console session's language; en returns Azure's original text. e.g. ko

Output fields

FieldTypeNameDescription
profileStringProfilee.g. mdc
cloud_accountStringSubscription IDe.g. 00000000-0000-0000-0000-000000000000
cloud_resource_nameStringResource nameThe asset carrying this vulnerability. e.g. vm-app-01
cloud_resource_typeStringResource typee.g. Microsoft.Compute/virtualMachines
cloud_resourceStringResource IDe.g. /subscriptions/.../providers/Microsoft.Compute/virtualMachines/vm-app-01
cve_idStringCVEe.g. CVE-2023-51385
cve_severityStringSeveritye.g. Critical
epss_scoreDoubleEPSS scoreProbability of exploitation in the next 30 days, 0 to 1. Severity says how bad a flaw would be; this says whether anyone is using it. e.g. 0.00278
epss_percentileDoubleEPSS percentileWhere the score sits among all CVEs, which is what makes it readable: 0.00278 is the 18th percentile. e.g. 0.18
cvss3_baseDoubleCVSS 3.xe.g. 9.8
cvss4_baseDoubleCVSS 4.0Absent on older CVEs, which carry only 3.x. e.g. 8.7
is_in_exploit_kitBooleanIn exploit kite.g. true
is_publicly_disclosedBooleanPublicly disclosede.g. true
software_nameStringPackagee.g. openssh-client
software_vendorStringVendore.g. canonical
detected_versionsArrayDetected versionsVersions found on this resource. e.g. ["1:8.9p1-3ubuntu0.4"]
fix_statusStringFix statuse.g. FixAvailable
fixed_versionStringFixed versionThe version that closes it on this resource, which is the actionable half of the row. e.g. 1:8.9p1-3ubuntu0.13
max_cvss_scoreDoubleMax CVSSHighest CVSS Defender reported on the finding this CVE came from. e.g. 9.8
is_internet_exposedBooleanInternet exposede.g. true
publishedDatePublishede.g. 2023-12-19 00:00:00
assessment_idStringRecommendation IDe.g. 11111111-1111-1111-1111-111111111111
assessment_nameStringRecommendationThe finding this CVE was reported under. e.g. Update openssh-client
row_keyStringRow keySHA-256 of the identity columns, stable across cycles. e.g. a1b2c3d4e5f6...
snapshot_idStringSnapshot IDThe collection cycle that last wrote this row. e.g. 00000000-0000-0000-...
updatedDateCollected ate.g. 2026-10-05 00:34:15