Manage and remediate endpoint vulnerabilities

To manage and remediate endpoint vulnerabilities, I use the Compliance vulnerability module.

But what vulnerabilities will I find?
How can I enable more types of vulnerabilities, such as those in third-party apps?
Can I see the vulnerabilities detected by CISA KEV there, or only in the CyberFOCUS Analytics report? What if I wanted to see vulnerabilities in IBM DB2, Apache Tomcat, etc.?

Thanks!