Know what your company exposes.
A CVE feed says what is vulnerable somewhere. An authorized check says what is reachable on your systems, and what to do about it first.
The public record answers what the flaw is, whether it is exploited, and whether a public check exists.
An authorized check answers whether your hosts run it, whether it is reachable, and what to fix first.
No account needed. Only send systems you own or are authorized to discuss.
How a check runs
Nothing is scanned when you send the sheet. Everything after it is agreed first, then authorized, then tested.
- You
Send the sheet
Your domain and a work email are enough to start. Name a CVE or other systems if you have them.
- The CVE Tools team
Agree the scope
Which systems, which checks, the price and the timing, in writing, before anything is tested.
- You
Authorize the testing
Active testing starts only after your separate, explicit written authorization for the agreed scope.
- A specialist
Check within the scope
Confirm the product, version, configuration and reachability on your systems, not on a CVE feed.
- You get
The evidence and the next step
What was observed, what it does and does not prove, what to do first, and how to verify the fix.
A finding should lead somewhere.
Each finding goes from what was observed to the evidence, what it does not prove, and a step your team can take and verify.
Illustrative finding, not a customer report
- System
- admin.example.com, an administration sign-in page reachable from the public internet.
- Observation
- The page answers requests from any address. The product and its version are read from the response.
- Evidence
- The requests and responses, timestamped, sent from the address agreed for testing.
- Not proven
- A reachable page is not a vulnerability, and a CVE that matches the version is not proof it can be exploited here.
- Next step
- If public access is not needed, restrict it to the admin network or VPN. If it must stay public, review its access controls and patch level.
- Verify the fix
- Send the same request from outside after the change and confirm it is refused.
People behind the assessments.
Personal qualifications held by the specialists who carry out the checks. They are not certifications of CVE Tools as a company.
- OSCP
- OSWP
- OSWA
- HTB CPTS
- C|EH Master
- ISO/IEC 27001 Lead Auditor
Keep watch, or take a closer look.
You can ask for one assessment without a monitoring subscription.
Regular external checks
Follow what changes across your internet-facing systems, and the status of the issues already found.
Specialist assessment
Investigate one network, web application or API in depth, including access controls and application logic.
A few practical questions.
Does submitting a domain start a scan?
No. It sends a request to the CVE Tools team. We contact you to agree which systems to assess, the approach and the expected results. Active testing requires your explicit authorization.
What does an assessment cost?
The scope, price and timing are agreed before work begins. Sending a request does not commit you to purchasing an assessment or subscribing to monitoring.
Can you check a specific CVE?
Tell us which CVE concerns you. We first establish whether the affected product, version and configuration are relevant to your systems, and agree which checks are appropriate.
Is this a penetration test or regular monitoring?
You can discuss either. Regular external checks help track changes over time. A penetration test is a separately scoped assessment that can investigate attack paths and application logic in more depth.
Do I need an account or software to send a request?
No. Start with your company domain and work email. Any access or setup required for the assessment is discussed when agreeing its scope.