
Vulnerability management platform that imports scanner reports, enriches with CISA KEV and Exploit-DB intelligence, and provides contextual risk scoring for prioritized remediation.
A comprehensive vulnerability management platform that analyzes security scan reports, enriches vulnerability data with exploit intelligence, and provides actionable risk scoring for prioritized remediation.
*** The use of the CVE Enrichment process on the first upload those slow down the upload process, It will only try to enrich vulnerabilities uploaded that are marked as exploitable from your scans but timing can vary significatly depending on the uploaded file size.***

The dashboard provides an at-a-glance view of your security posture with:
Browse, filter, and sort vulnerabilities by:

Detailed view including:

Option A: Using the installer
node --version
npm --version
Option B: Use a Stable Node Version (Recommended)
nvm install 22.12.0
nvm use 22.12.0
Option C: Using winget (Windows Package Manager)
winget install OpenJS.NodeJS.LTS
winget install Git.Git
Option D: Using Chocolatey
choco install nodejs-lts
choco install git
Using Homebrew:
brew install node
brew install git
Or download the installer from https://nodejs.org
Verify installation:
node --version
npm --version
# Using NodeSource repository for latest LTS
curl -fsSL https://deb.nodesource.com/setup_lts.x | sudo -E bash -
sudo apt-get install -y nodejs git
# Verify
node --version
npm --version
macOS / Linux:
git clone https://github.com/jrokz2315/exploit-mapper.git
cd exploit-mapper
Windows (Command Prompt):
git clone https://github.com/jrokz2315/exploit-mapper.git
cd exploit-mapper
Windows (PowerShell):
git clone https://github.com/jrokz2315/exploit-mapper.git
cd exploit-mapper
All platforms:
npm run install:all
Or install manually:
macOS / Linux:
npm install
cd server && npm install
cd ../client && npm install
cd ..
Windows (Command Prompt):
npm install
cd server && npm install
cd ..\client && npm install
cd ..
Windows (PowerShell):
npm install
cd server; npm install
cd ..\client; npm install
cd ..
Note (Windows): If you encounter errors with
better-sqlite3, you may need to install the Windows build tools:npm install --global windows-build-toolsOr install Visual Studio Build Tools with the "Desktop development with C++" workload from https://visualstudio.microsoft.com/visual-cpp-build-tools/
Development mode (with hot reload) — all platforms:
npm run dev
This starts both the backend server (port 3000) and frontend dev server (port 5173).
Production mode — all platforms:
# Build the client
npm run build
# Start the server
npm start
Open your browser and navigate to:
http://localhost:5173http://localhost:3000On first run, a default admin account is created:
adminAdmin123!You will be prompted to change this password on first login.
exploit-mapper/
├── client/ # React frontend
│ ├── src/
│ │ ├── components/ # Reusable UI components
│ │ ├── pages/ # Page components
│ │ └── App.jsx # Main app component
│ ├── package.json
│ └── vite.config.js
├── server/ # Express backend
│ ├── src/
│ │ ├── db/ # Database schema and connection
│ │ ├── middleware/ # Auth middleware
│ │ ├── routes/ # API routes
│ │ └── services/ # Business logic
│ ├── data/ # SQLite database (gitignored)
│ ├── uploads/ # Temporary upload storage (gitignored)
│ └── package.json
├── package.json # Root package with scripts
├── .gitignore
├── LICENSE
├── CONTRIBUTING.md
└── README.md
| Method | Endpoint | Description |
|---|---|---|
POST | /api/auth/login | User login |
POST | /api/auth/logout | User logout |
GET | /api/auth/me | Get current user |
POST | /api/auth/change-password | Change password |
| Method | Endpoint | Description |
|---|---|---|
GET | /api/dashboard/summary | Dashboard metrics |
GET | /api/dashboard/risk | Risk breakdown |
GET | /api/dashboard/trends | Historical trends |
GET | /api/dashboard/executive-summary | Executive summary |