Look up any CVE for CVSS score, EPSS exploitation probability, CISA KEV status, description, affected products, and references. Uses NVD API v2 and FIRST.org.
Fetches CVSS score, EPSS exploitation probability, CISA KEV status, description, and affected products from NVD and FIRST.org.
Queries the National Vulnerability Database (NVD) maintained by NIST to search CVEs by keyword, CVE ID, or vendor/product. Returns severity scores, CVSS vectors, CWE classifications, and descriptions for matching vulnerabilities.
The NVD is the authoritative source for CVE data in the United States and is used by vulnerability management platforms, patch management systems, and security teams worldwide.
CVE data is most useful when combined with context about your environment. A critical CVSS score on software you don't run is irrelevant. A medium-severity CVE in a component exposed to the internet with a public exploit is urgent.
Use this tool to research CVEs that show up in scanner output, to check whether a specific software version has known vulnerabilities before deploying it, or to understand the technical details behind a vulnerability you've read about in a security advisory.