CVE Tools

Know what your company exposes.

A CVE feed says what is vulnerable somewhere. An authorized check says what is reachable on your systems, and what to do about it first.

The scope of the assessment
  1. Subject

    What is reachable under your domain: websites, APIs, sign-in pages and exposed services

  2. Scope
  3. Contact
  4. Authorization
  5. Result

    A reply from the team to agree scope, price and timing. After the check: the evidence, what to do first and how to verify the fix.

Nothing is scanned when you send this, and it commits you to nothing. Privacy policy

The public record answers what the flaw is, whether it is exploited, and whether a public check exists.

An authorized check answers whether your hosts run it, whether it is reachable, and what to fix first.

No account needed. Only send systems you own or are authorized to discuss.

How a check runs

Nothing is scanned when you send the sheet. Everything after it is agreed first, then authorized, then tested.

  1. You

    Send the sheet

    Your domain and a work email are enough to start. Name a CVE or other systems if you have them.

  2. The CVE Tools team

    Agree the scope

    Which systems, which checks, the price and the timing, in writing, before anything is tested.

  3. You

    Authorize the testing

    Active testing starts only after your separate, explicit written authorization for the agreed scope.

  4. A specialist

    Check within the scope

    Confirm the product, version, configuration and reachability on your systems, not on a CVE feed.

  5. You get

    The evidence and the next step

    What was observed, what it does and does not prove, what to do first, and how to verify the fix.

A finding should lead somewhere.

Each finding goes from what was observed to the evidence, what it does not prove, and a step your team can take and verify.

Illustrative finding, not a customer report

System
admin.example.com, an administration sign-in page reachable from the public internet.
Observation
The page answers requests from any address. The product and its version are read from the response.
Evidence
The requests and responses, timestamped, sent from the address agreed for testing.
Not proven
A reachable page is not a vulnerability, and a CVE that matches the version is not proof it can be exploited here.
Next step
If public access is not needed, restrict it to the admin network or VPN. If it must stay public, review its access controls and patch level.
Verify the fix
Send the same request from outside after the change and confirm it is refused.

People behind the assessments.

Personal qualifications held by the specialists who carry out the checks. They are not certifications of CVE Tools as a company.

  • OSCP
  • OSWP
  • OSWA
  • HTB CPTS
  • C|EH Master
  • ISO/IEC 27001 Lead Auditor

Keep watch, or take a closer look.

You can ask for one assessment without a monitoring subscription.

  • Regular external checks

    Follow what changes across your internet-facing systems, and the status of the issues already found.

  • Specialist assessment

    Investigate one network, web application or API in depth, including access controls and application logic.

A few practical questions.

Does submitting a domain start a scan?

No. It sends a request to the CVE Tools team. We contact you to agree which systems to assess, the approach and the expected results. Active testing requires your explicit authorization.

What does an assessment cost?

The scope, price and timing are agreed before work begins. Sending a request does not commit you to purchasing an assessment or subscribing to monitoring.

Can you check a specific CVE?

Tell us which CVE concerns you. We first establish whether the affected product, version and configuration are relevant to your systems, and agree which checks are appropriate.

Is this a penetration test or regular monitoring?

You can discuss either. Regular external checks help track changes over time. A penetration test is a separately scoped assessment that can investigate attack paths and application logic in more depth.

Do I need an account or software to send a request?

No. Start with your company domain and work email. Any access or setup required for the assessment is discussed when agreeing its scope.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store