CVE Search
Look up any CVE and get the description, CVSS scores for every version published, CWE, affected products, references and dates, attributed to the source they came from.
Uses an external data sourceYour search term is sent to the public authority named on this page so the answer reflects current data.
Data source: NVD (NIST National Vulnerability Database)
Use the tool
One CVE, four authorities
No single source holds everything about a vulnerability. The NVD adds CVSS scores, CWE classifications and the product configurations (CPE) it has analysed. CVE.org holds the record as the assigning authority (CNA) published it. That record often exists days before NVD analysis, so it fills the gap when NVD has not caught up or cannot be reached. FIRST EPSS estimates how likely exploitation is in the next 30 days. CISA's KEV catalogue says whether exploitation has actually been observed. This search asks each one, and labels every value with the source it came from.
Missing data is not a clean result
Each source is reported with its own status. "Current" means it answered just now or within its cache window. "Stale copy" means it failed, and you are seeing the last good answer with the date it was fetched. "Unavailable" means it failed and there was no copy, so that part of the picture is unknown. A CVE is only ever described as "not in KEV" when the KEV catalogue itself was read. KEV status is never taken from the copy that NVD embeds in its own records.
Reading the scores
A CVE often has several CVSS scores: one from NVD (Primary) and others from the CNA or vendor (Secondary), sometimes in different CVSS versions. They can disagree, and all of them are shown. Version 4.0 vectors open in the CVSS 4.0 Calculator so you can apply threat and environmental metrics. Severity is not likelihood. Read the score next to the EPSS probability and the KEV status, or combine them in the Vulnerability Prioritization Calculator.
Exploit references are not links
References that the NVD tags as "Exploit" are shown as plain text, not clickable links. The tool never downloads or runs anything from them, and it does not make it one click to do so either.
Caching and fair use
CVE records and EPSS scores are cached for 12 hours and the KEV catalogue for 6. A last good copy is kept for 14 days as the fallback during outages. The NVD allows five requests per 30 seconds without an API key, and this tool paces its requests to stay inside that. A large batch may take a little longer rather than fail.
Frequently asked questions
Why does NVD say "Awaiting Analysis"?
NVD has received the CVE but not yet added its own scores and configurations. The description and any CNA-supplied score are shown from CVE.org in the meantime.
What does "Rejected" mean?
The identifier was reserved or published and later withdrawn, for example as a duplicate or because it turned out not to be a vulnerability. Do not track it.
Is the affected-products list exact?
It lists NVD's CPE match criteria with the version ranges as published. They are good for triage, but vendor advisories are authoritative for which of your builds are affected.
Do you store my searches?
No search history is kept. Public responses are cached in server memory, keyed by CVE id, and are not associated with you.
Sources and attribution
- NVD CVE API 2.0. This product uses the NVD API but is not endorsed or certified by the NVD.
- CVE Program (CVE.org). CVE records are © The MITRE Corporation, used under the CVE Terms of Use.
- FIRST EPSS
- CISA Known Exploited Vulnerabilities catalogue
Related tools
Rate this tool
Was this tool useful? Your feedback helps us improve it.