Merged when the same application, weakness and window were reported by different tools. Open any row to see what each tool actually said.
How much of each feed was eventually judged a false positive. A static analyser is expected to be noisier than a pen tester.
Open flaws that WAF telemetry shows are being attacked. No scanner knows what is attacked; no WAF knows what is vulnerable.
The gap between the two critical columns is effort spent in the wrong place.