Looking at this link: https://www.cvedetails.com/vulnerability-list/vendor_id-45/product_id-6117/Apache-Struts.html
Its clear that CVE-2017-5638 (already entered) is so severe that it trumps any prior entry. But in many cases, Security teams will evaluate and look at mitigations. If the database is not fully populated, they may risk accept a newer vulnerability and never know about an older one. For victims to be truly useful, it should approach 100% accuracy imho. But that depends
@jasinner
Is the idea of this tool to be a quick supplemental to a primary use tool?