██████╗ ██╗ ██╗ ███████╗ ███████╗ ██╗ ██╗ ██████╗ ██╗ ██████╗ ██████╗ ███████╗ ██████╗
██╔════╝ ██║ ██║ ██╔════╝ ██╔════╝ ╚██╗██╔╝ ██╔══██╗ ██║ ██╔═══██╗ ██╔══██╗ ██╔════╝ ██╔══██╗
██║ ██║ ██║ █████╗ █████╗ ╚███╔╝ ██████╔╝ ██║ ██║ ██║ ██████╔╝ █████╗ ██████╔╝
██║ ╚██╗ ██╔╝ ██╔══╝ ██╔══╝ ██╔██╗ ██╔═══╝ ██║ ██║ ██║ ██╔══██╗ ██╔══╝ ██╔══██╗
╚██████╗ ╚████╔╝ ███████╗ ███████╗ ██╔╝ ██╗ ██║ ███████╗╚██████╔╝ ██║ ██║ ███████╗ ██║ ██║
╚═════╝ ╚═══╝ ╚══════╝ ╚══════╝ ╚═╝ ╚═╝ ╚═╝ ╚══════╝ ╚═════╝ ╚═╝ ╚═╝ ╚══════╝ ╚═╝ ╚═╝
CVE Vulnerability Explorer — free CVE lookup & search
Search CVEs in real-time — NVD + CISA KEV active exploits + EPSS exploit probability — Priority Quadrant for triage
—Results
—Critical
—CISA KEV
—Avg EPSS
CRITICAL
HIGH
MEDIUM
LOW
7d
14d
30d
90d
1y
All time
🔥 KEV only
EPSS ≥ 0%
Search for CVEs by keyword, vendor, product, or CVE-ID.
Or click "Today's CVEs" to see what was published today.
Or click "Today's CVEs" to see what was published today.
CVSS × EPSS Priority Quadrant
Critical Priority
Severe / Low Exploit
Exploited / Lower CVSS
Low Priority
CVE Publication Heatmap — Last 90 Days
Loading heatmap data...
Less
More
▸ Understanding CVE Vulnerability Data
What is a CVE?
A Common Vulnerabilities and Exposures (CVE) is a unique identifier assigned to a publicly known security flaw. The NVD maintains over 300,000 CVEs with severity scores, affected products, and references. CVE-IDs follow the format CVE-YYYY-NNNNN.
CVSS vs EPSS — Why Both Matter
CVSS measures theoretical severity (0–10). EPSS predicts real-world exploit probability (0–100%). A CVE can be CVSS 9.8 but EPSS 2% (severe but rarely exploited). Combining both in the Priority Quadrant gives you actual triage priority.
CISA KEV — Actively Exploited
The CISA Known Exploited Vulnerabilities catalog lists CVEs confirmed to be actively exploited in the wild. US federal agencies must remediate KEV entries by the listed deadline. If a CVE is on KEV, it's not theoretical — attackers are using it now.
▸ How to Look Up a CVE and Decide What to Patch First
CVE lookup in 5 steps
- Search by CVE ID (e.g. CVE-2021-44228), vendor, product or keyword — or load Today’s CVEs to see what was published today.
- Filter by CVSS severity (Critical, High, Medium, Low), publication date (7 days to all time), KEV only or a minimum EPSS score.
- Expand a CVE to read the NVD description, CVSS vector, CWE weakness, affected products and references, plus its EPSS score and CISA KEV due date.
- Triage with the Priority Quadrant: CVEs in the top-right (high CVSS and high EPSS) go first, followed by anything on the KEV list.
- Track & share: add your vendors to My Stack to highlight matches, export results as JSON, or share a CVE as a link or image card.
CVSS severity ratings explained
| Rating | CVSS score | What it usually means |
|---|---|---|
| Critical | 9.0 – 10.0 | Often remote, unauthenticated, full compromise |
| High | 7.0 – 8.9 | Serious impact, may need some access or user action |
| Medium | 4.0 – 6.9 | Limited impact or harder to exploit |
| Low | 0.1 – 3.9 | Minor impact, difficult conditions |
| None | 0.0 | No security impact |
These are the qualitative ranges used by CVSS v3.x and v4.0. A CVSS score describes how bad a flaw could be — not how likely it is to be attacked. That is why this CVE explorer puts EPSS (the probability of exploitation in the next 30 days, published daily by FIRST) and CISA KEV (confirmed exploitation in the wild) right next to it.
Well-known CVEs to explore
CVE-2021-44228— Log4Shell: Apache Log4j 2 JNDI lookup remote code executionCVE-2024-3094— XZ Utils backdoor: malicious code planted in the xz/liblzma compression libraryCVE-2024-6387— regreSSHion: OpenSSH server signal-handler race conditionCVE-2024-3400— PAN-OS GlobalProtect: Palo Alto Networks firewall command injectionCVE-2023-4966— Citrix Bleed: NetScaler ADC & Gateway session token leakCVE-2023-34362— MOVEit Transfer: SQL injection exploited in mass data-theft campaignsCVE-2021-26855— ProxyLogon: Microsoft Exchange Server SSRFCVE-2017-0144— EternalBlue: Windows SMBv1 remote code execution used by WannaCryCVE-2014-0160— Heartbleed: OpenSSL TLS heartbeat memory disclosureCVE-2014-6271— Shellshock: GNU Bash environment-variable command injection
Popular vendor & product searches
- Microsoft CVEs
- Fortinet CVEs
- Cisco CVEs
- Ivanti CVEs
- Palo Alto Networks CVEs
- VMware CVEs
- Citrix CVEs
- Apple CVEs
- Google Chrome CVEs
- Linux kernel CVEs
- Apache CVEs
- WordPress CVEs
- Atlassian CVEs
- SAP CVEs
- Oracle CVEs
- OpenSSH CVEs
CVE vs. CWE vs. CVSS vs. EPSS vs. KEV
- CVE — the ID of one specific vulnerability (CVE-YYYY-NNNNN), assigned by a CVE Numbering Authority.
- CWE — the type of weakness behind it, such as CWE-79 (cross-site scripting) or CWE-787 (out-of-bounds write).
- CVSS — a 0–10 severity score calculated from the attack vector, complexity, privileges and impact.
- EPSS — a 0–100% probability that the CVE will be exploited in the next 30 days.
- CISA KEV — the Known Exploited Vulnerabilities catalog: proof that attackers are already using it.
▸ Frequently Asked Questions
Is this data real-time?
Yes. Every search queries the NVD API v2.0 directly from your browser. CISA KEV data is loaded on page start. EPSS scores are fetched on-demand when you expand a CVE. No server-side caching — you always see the latest data.
How do I look up a CVE by its ID?
Type the CVE ID — for example CVE-2021-44228 — into the search box and press Enter. The explorer pulls the record from the NVD and shows its CVSS score and vector, CWE weakness, affected products and references, together with its EPSS score and whether it is on the CISA KEV list. Every CVE has its own shareable link, such as ?cve=CVE-2021-44228.
What is a good or bad EPSS score?
EPSS (Exploit Prediction Scoring System) is maintained by FIRST and estimates the probability that a CVE will see exploitation activity in the next 30 days. Scores are updated daily. Most published CVEs score below 1%, so a CVE with an EPSS score in the double digits is far more likely than average to be attacked and deserves attention — even if its CVSS score is only Medium.
What is the difference between CVSS and EPSS?
CVSS measures how severe a vulnerability is if it gets exploited (0–10). EPSS measures how likely it is to be exploited (0–100%). A large share of CVEs are rated High or Critical, so CVSS alone produces a patch list that is far too long. Combining both — as the Priority Quadrant does — lets you focus on the vulnerabilities that are both severe and likely to be used by attackers.
Why does a recent CVE show no CVSS score?
Scoring can lag behind publication. Since April 2026 NIST prioritises NVD enrichment for CVEs in the CISA KEV catalog, software used by the US federal government and critical software, and no longer routinely adds its own score when the reporting CNA already supplied one. Other CVEs can stay unscored for a while. Until a score appears, use EPSS and KEV status to judge urgency.
How often is the CISA KEV catalog updated?
CISA adds entries whenever it has reliable evidence of active exploitation — often several times a week. The explorer loads the latest official KEV feed every time you open the page, and shows each entry’s due date and whether it is known to be used in ransomware campaigns.
Is the CVE Explorer free? Do I need an account or API key?
It is completely free: no signup, no API key and nothing to install. Everything runs in your browser and queries the public NVD, CISA and FIRST APIs directly. Your My Stack list is stored locally in your browser and never sent to a server.
How is this different from searching the NVD website?
The NVD shows one data source at a time. The CVE Explorer combines NVD details, CISA KEV exploitation status and FIRST EPSS scores in a single view, and adds the CVSS × EPSS Priority Quadrant, a 90-day publication heatmap, top vendor and CWE statistics, stack monitoring, JSON export and shareable CVE cards.
Can I monitor my own products?
Yes! Use the My Stack panel to add vendor or product names. Any CVE matching your stack entries will be highlighted with a green border in the results. Your stack is saved in localStorage and persists across sessions.
What does the Priority Quadrant show?
It plots each CVE with CVSS severity on the Y-axis and EPSS exploit probability on the X-axis. The top-right quadrant (high CVSS + high EPSS) = patch immediately. Top-left = severe but unlikely to be exploited. Bottom-right = lower severity but actively exploited. This is how security teams should prioritize patching.
Why is NVD slow or rate-limited?
The NVD public API allows 5 requests per 30 seconds without an API key. This tool throttles requests accordingly. If you hit limits, wait 30 seconds. For heavier usage, request a free NVD API key.