~/cve-explorer ☕ Support me apps ← about me

🌐 Language

📤 Share this CVE

██████╗ ██╗ ██╗ ███████╗ ███████╗ ██╗ ██╗ ██████╗ ██╗ ██████╗ ██████╗ ███████╗ ██████╗ ██╔════╝ ██║ ██║ ██╔════╝ ██╔════╝ ╚██╗██╔╝ ██╔══██╗ ██║ ██╔═══██╗ ██╔══██╗ ██╔════╝ ██╔══██╗ ██║ ██║ ██║ █████╗ █████╗ ╚███╔╝ ██████╔╝ ██║ ██║ ██║ ██████╔╝ █████╗ ██████╔╝ ██║ ╚██╗ ██╔╝ ██╔══╝ ██╔══╝ ██╔██╗ ██╔═══╝ ██║ ██║ ██║ ██╔══██╗ ██╔══╝ ██╔══██╗ ╚██████╗ ╚████╔╝ ███████╗ ███████╗ ██╔╝ ██╗ ██║ ███████╗╚██████╔╝ ██║ ██║ ███████╗ ██║ ██║ ╚═════╝ ╚═══╝ ╚══════╝ ╚══════╝ ╚═╝ ╚═╝ ╚═╝ ╚══════╝ ╚═════╝ ╚═╝ ╚═╝ ╚══════╝ ╚═╝ ╚═╝

CVE Vulnerability Explorer — free CVE lookup & search

Search CVEs in real-time — NVD + CISA KEV active exploits + EPSS exploit probability — Priority Quadrant for triage
—Results
—Critical
—CISA KEV
—Avg EPSS
CRITICAL HIGH MEDIUM LOW 7d 14d 30d 90d 1y All time 🔥 KEV only EPSS ≥ 0%
Ready — search or load today's CVEs
🔍 Search for CVEs by keyword, vendor, product, or CVE-ID.
Or click "Today's CVEs" to see what was published today.

CVSS × EPSS Priority Quadrant

Critical Priority
Severe / Low Exploit
Exploited / Lower CVSS
Low Priority
EPSS Exploit Probability → CVSS Severity →

CVE Publication Heatmap — Last 90 Days

Loading heatmap data...
Less
More

▸ Understanding CVE Vulnerability Data

🛡️

What is a CVE?

A Common Vulnerabilities and Exposures (CVE) is a unique identifier assigned to a publicly known security flaw. The NVD maintains over 300,000 CVEs with severity scores, affected products, and references. CVE-IDs follow the format CVE-YYYY-NNNNN.
🎯

CVSS vs EPSS — Why Both Matter

CVSS measures theoretical severity (0–10). EPSS predicts real-world exploit probability (0–100%). A CVE can be CVSS 9.8 but EPSS 2% (severe but rarely exploited). Combining both in the Priority Quadrant gives you actual triage priority.
⚠️

CISA KEV — Actively Exploited

The CISA Known Exploited Vulnerabilities catalog lists CVEs confirmed to be actively exploited in the wild. US federal agencies must remediate KEV entries by the listed deadline. If a CVE is on KEV, it's not theoretical — attackers are using it now.

▸ How to Look Up a CVE and Decide What to Patch First

CVE lookup in 5 steps

  1. Search by CVE ID (e.g. CVE-2021-44228), vendor, product or keyword — or load Today’s CVEs to see what was published today.
  2. Filter by CVSS severity (Critical, High, Medium, Low), publication date (7 days to all time), KEV only or a minimum EPSS score.
  3. Expand a CVE to read the NVD description, CVSS vector, CWE weakness, affected products and references, plus its EPSS score and CISA KEV due date.
  4. Triage with the Priority Quadrant: CVEs in the top-right (high CVSS and high EPSS) go first, followed by anything on the KEV list.
  5. Track & share: add your vendors to My Stack to highlight matches, export results as JSON, or share a CVE as a link or image card.

CVSS severity ratings explained

RatingCVSS scoreWhat it usually means
Critical9.0 – 10.0Often remote, unauthenticated, full compromise
High7.0 – 8.9Serious impact, may need some access or user action
Medium4.0 – 6.9Limited impact or harder to exploit
Low0.1 – 3.9Minor impact, difficult conditions
None0.0No security impact

These are the qualitative ranges used by CVSS v3.x and v4.0. A CVSS score describes how bad a flaw could be — not how likely it is to be attacked. That is why this CVE explorer puts EPSS (the probability of exploitation in the next 30 days, published daily by FIRST) and CISA KEV (confirmed exploitation in the wild) right next to it.

Well-known CVEs to explore

  • CVE-2021-44228 — Log4Shell: Apache Log4j 2 JNDI lookup remote code execution
  • CVE-2024-3094 — XZ Utils backdoor: malicious code planted in the xz/liblzma compression library
  • CVE-2024-6387 — regreSSHion: OpenSSH server signal-handler race condition
  • CVE-2024-3400 — PAN-OS GlobalProtect: Palo Alto Networks firewall command injection
  • CVE-2023-4966 — Citrix Bleed: NetScaler ADC & Gateway session token leak
  • CVE-2023-34362 — MOVEit Transfer: SQL injection exploited in mass data-theft campaigns
  • CVE-2021-26855 — ProxyLogon: Microsoft Exchange Server SSRF
  • CVE-2017-0144 — EternalBlue: Windows SMBv1 remote code execution used by WannaCry
  • CVE-2014-0160 — Heartbleed: OpenSSL TLS heartbeat memory disclosure
  • CVE-2014-6271 — Shellshock: GNU Bash environment-variable command injection

Popular vendor & product searches

CVE vs. CWE vs. CVSS vs. EPSS vs. KEV

  • CVE — the ID of one specific vulnerability (CVE-YYYY-NNNNN), assigned by a CVE Numbering Authority.
  • CWE — the type of weakness behind it, such as CWE-79 (cross-site scripting) or CWE-787 (out-of-bounds write).
  • CVSS — a 0–10 severity score calculated from the attack vector, complexity, privileges and impact.
  • EPSS — a 0–100% probability that the CVE will be exploited in the next 30 days.
  • CISA KEV — the Known Exploited Vulnerabilities catalog: proof that attackers are already using it.

▸ Frequently Asked Questions

Is this data real-time?+

Yes. Every search queries the NVD API v2.0 directly from your browser. CISA KEV data is loaded on page start. EPSS scores are fetched on-demand when you expand a CVE. No server-side caching — you always see the latest data.

How do I look up a CVE by its ID?+

Type the CVE ID — for example CVE-2021-44228 — into the search box and press Enter. The explorer pulls the record from the NVD and shows its CVSS score and vector, CWE weakness, affected products and references, together with its EPSS score and whether it is on the CISA KEV list. Every CVE has its own shareable link, such as ?cve=CVE-2021-44228.

What is a good or bad EPSS score?+

EPSS (Exploit Prediction Scoring System) is maintained by FIRST and estimates the probability that a CVE will see exploitation activity in the next 30 days. Scores are updated daily. Most published CVEs score below 1%, so a CVE with an EPSS score in the double digits is far more likely than average to be attacked and deserves attention — even if its CVSS score is only Medium.

What is the difference between CVSS and EPSS?+

CVSS measures how severe a vulnerability is if it gets exploited (0–10). EPSS measures how likely it is to be exploited (0–100%). A large share of CVEs are rated High or Critical, so CVSS alone produces a patch list that is far too long. Combining both — as the Priority Quadrant does — lets you focus on the vulnerabilities that are both severe and likely to be used by attackers.

Why does a recent CVE show no CVSS score?+

Scoring can lag behind publication. Since April 2026 NIST prioritises NVD enrichment for CVEs in the CISA KEV catalog, software used by the US federal government and critical software, and no longer routinely adds its own score when the reporting CNA already supplied one. Other CVEs can stay unscored for a while. Until a score appears, use EPSS and KEV status to judge urgency.

How often is the CISA KEV catalog updated?+

CISA adds entries whenever it has reliable evidence of active exploitation — often several times a week. The explorer loads the latest official KEV feed every time you open the page, and shows each entry’s due date and whether it is known to be used in ransomware campaigns.

Is the CVE Explorer free? Do I need an account or API key?+

It is completely free: no signup, no API key and nothing to install. Everything runs in your browser and queries the public NVD, CISA and FIRST APIs directly. Your My Stack list is stored locally in your browser and never sent to a server.

How is this different from searching the NVD website?+

The NVD shows one data source at a time. The CVE Explorer combines NVD details, CISA KEV exploitation status and FIRST EPSS scores in a single view, and adds the CVSS × EPSS Priority Quadrant, a 90-day publication heatmap, top vendor and CWE statistics, stack monitoring, JSON export and shareable CVE cards.

Can I monitor my own products?+

Yes! Use the My Stack panel to add vendor or product names. Any CVE matching your stack entries will be highlighted with a green border in the results. Your stack is saved in localStorage and persists across sessions.

What does the Priority Quadrant show?+

It plots each CVE with CVSS severity on the Y-axis and EPSS exploit probability on the X-axis. The top-right quadrant (high CVSS + high EPSS) = patch immediately. Top-left = severe but unlikely to be exploited. Bottom-right = lower severity but actively exploited. This is how security teams should prioritize patching.

Why is NVD slow or rate-limited?+

The NVD public API allows 5 requests per 30 seconds without an API key. This tool throttles requests accordingly. If you hit limits, wait 30 seconds. For heavier usage, request a free NVD API key.