Vulnerability Search

Search by exact CVE, vulnerability wording, recognized software name, or product and version. Examples: Python 3.7, Adobe ColdFusion 2021, remote code execution, or CVE-2025-12345.

Search terms and exact CVE identifiers are sent to the public NVD API. Only public CVE identifiers — never uploaded company or asset data — are used for the other enrichment sources.

Start here

Actively exploited right now, ranked by EVULNABLE Risk. Search above for anything else.

Searches display the 8 newest NVD results at a time, with a link to the next 8. Recognized product/version searches use NVD CPE applicability data. Patch and workaround status is shown only when a connected source provides supporting guidance.

★ My Watchlist (0)

Saved only in this browser (localStorage) — no account, nothing sent to EVULNABLE. Clearing your browser data clears this too. The Excel and PDF exports are built right here in your browser from those saved items; nothing is sent to EVULNABLE for those either.

    Data sources & attribution

    CVE records, CVSS, weaknesses, products and references come from the NIST National Vulnerability Database. This product uses data from the NVD API but is not endorsed or certified by the NVD.

    Known-exploitation status is enriched from the CISA KEV Catalog; exploitation probability and percentile from FIRST.org's EPSS, used under FIRST's open data terms. Supplemental remediation and patch intelligence is provided by CyberSecurityTracker.ai.