CVE Search

Look up any CVE and get the description, CVSS scores for every version published, CWE, affected products, references and dates, attributed to the source they came from.

Uses an external data source

Your search term is sent to the public authority named on this page so the answer reflects current data.

Data source: NVD (NIST National Vulnerability Database)

Use the tool

Up to 20 per search. Only the identifiers are sent - to NVD, CVE.org, FIRST and CISA.

One CVE, four authorities

No single source holds everything about a vulnerability. The NVD adds CVSS scores, CWE classifications and the product configurations (CPE) it has analysed. CVE.org holds the record as the assigning authority (CNA) published it. That record often exists days before NVD analysis, so it fills the gap when NVD has not caught up or cannot be reached. FIRST EPSS estimates how likely exploitation is in the next 30 days. CISA's KEV catalogue says whether exploitation has actually been observed. This search asks each one, and labels every value with the source it came from.

Missing data is not a clean result

Each source is reported with its own status. "Current" means it answered just now or within its cache window. "Stale copy" means it failed, and you are seeing the last good answer with the date it was fetched. "Unavailable" means it failed and there was no copy, so that part of the picture is unknown. A CVE is only ever described as "not in KEV" when the KEV catalogue itself was read. KEV status is never taken from the copy that NVD embeds in its own records.

Reading the scores

A CVE often has several CVSS scores: one from NVD (Primary) and others from the CNA or vendor (Secondary), sometimes in different CVSS versions. They can disagree, and all of them are shown. Version 4.0 vectors open in the CVSS 4.0 Calculator so you can apply threat and environmental metrics. Severity is not likelihood. Read the score next to the EPSS probability and the KEV status, or combine them in the Vulnerability Prioritization Calculator.

Exploit references are not links

References that the NVD tags as "Exploit" are shown as plain text, not clickable links. The tool never downloads or runs anything from them, and it does not make it one click to do so either.

Caching and fair use

CVE records and EPSS scores are cached for 12 hours and the KEV catalogue for 6. A last good copy is kept for 14 days as the fallback during outages. The NVD allows five requests per 30 seconds without an API key, and this tool paces its requests to stay inside that. A large batch may take a little longer rather than fail.

Frequently asked questions

Why does NVD say "Awaiting Analysis"?

NVD has received the CVE but not yet added its own scores and configurations. The description and any CNA-supplied score are shown from CVE.org in the meantime.

What does "Rejected" mean?

The identifier was reserved or published and later withdrawn, for example as a duplicate or because it turned out not to be a vulnerability. Do not track it.

Is the affected-products list exact?

It lists NVD's CPE match criteria with the version ranges as published. They are good for triage, but vendor advisories are authoritative for which of your builds are affected.

Do you store my searches?

No search history is kept. Public responses are cached in server memory, keyed by CVE id, and are not associated with you.

Sources and attribution

What this tool can and cannot tell you. It reports what the named source held when it was queried. Where that source has no record, the answer is unknown rather than safe - an absent entry is not evidence of absence.

Security guidance here follows current published sources - OWASP, MDN, the relevant RFCs, NIST, CISA, FIRST and MITRE - which are linked beside the specific claims they support.

Rate this tool

Was this tool useful? Your feedback helps us improve it.

No ratings yet — be the first to rate this tool.
Your rating (required)
0 / 2000

Please do not include passwords, payment details or other sensitive information.

Your feedback is sent privately to the A2Z.Tools team and will not be posted publicly.