Syft produces an SBOM — the inventory of every package inside an artifact, in CycloneDX or SPDX format. On its own it finds no vulnerabilities; it answers the prior question, what is actually in here?
That question is the one that turns a newly published CVE from a week-long audit into a grep. It is also increasingly a contractual requirement rather than a nice-to-have.