CVE Tools

Know which vulnerabilities actually matter to you.

Thousands of CVEs are published every month, and only a few are exploited. cve.tools ranks every record by real-world exploitation and shows you the ones that reach the software you run.

Your forecast, not everyone's weather.

A feed of every CVE is noise. Tell cve.tools what you run, and the thousands of new records each month shrink to the handful that land on your software.

  1. Add the products you run.

    Vendor, product and version, once. The example here has 2.

  2. Every new CVE is matched against them.

    Each record's affected products are checked against your list as it arrives, and re-checked when exploitation signals change.

  3. You hear only about what's exploited, or likely to be.

    CISA KEV, high EPSS and public exploit code raise an alert. Everything else stays out of your way.

Every reading comes from a named station.

The colour scale on this page is one scale. Each step on it is a signal from a specific source, and every CVE page shows which source said what.

Confirmed exploited

CISA KEV: attacks seen in the wild. 1,726 records.

Exploit code exists

GitHub PoC 29,620 · Exploit-DB 15,174 · Packet Storm 8,744 · Metasploit 112 · Nuclei 12. Scanner checks from Nuclei templates and OpenVAS.

Likely to be exploited

FIRST EPSS: the probability of exploitation activity in the next 30 days. 17,259 records score high.

Severity

CVSS base scores from NVD and vendor advisories.

Published

The record exists: NVD, CVE List V5, GHSA, CSAF vendor advisories, BDU.

Stations

NVD
CVE records, CVSS, affected products (CPE)
CVE List V5
CVEProject's canonical records
GitHub Security Advisories
GHSA package advisories
CISA KEV
Confirmed exploitation
FIRST EPSS
Exploitation probability
CSAF vendor advisories
Vendor-published fixes and scope
BDU (FSTEC)
Russian national vulnerability database
Exploit-DB
Public exploit code
GitHub PoC
Proof-of-concept repositories
Packet Storm
Exploits and advisories
Metasploit
Exploit modules
Nuclei templates
Scanner checks
OpenVAS checks
Scanner checks
MITRE ATT&CK
Attacker techniques

In all: 387,479 CVE records, 65,340 of them with public exploit code, 1,726 in CISA KEV.

The same data, wherever you work.

  • WebsiteSearch, CVE pages, trends, My Stack alerts.
  • REST APIThe records and signals above, as JSON.
  • MCP serverFor AI agents that triage on your behalf.
  • CLICheck from a terminal or a pipeline.
  • TelegramA channel for exploited and discussed CVEs.

Thousands more arrive every month. Watch the few that reach you.

Add your stack in a few minutes. It's free, and every one of the 387,479 CVE pages stays open without an account.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store