Free Security Tool

CVE Lookup

Search the National Vulnerability Database by keyword or CVE ID. View CVSS scores, affected products, and remediation references. No signup required.

What is a CVE?

A CVE (Common Vulnerabilities and Exposures) is a unique identifier assigned to a publicly known cybersecurity vulnerability. Maintained by MITRE Corporation and cataloged in the National Vulnerability Database (NVD), each CVE entry includes a description, severity score, affected software versions, and references to patches or workarounds. CVE IDs follow the format CVE-YYYY-NNNNN (e.g., CVE-2021-44228 for the Log4Shell vulnerability).

Understanding CVSS Scores

CRITICAL
9.0 - 10.0
Exploit immediately
HIGH
7.0 - 8.9
Patch urgently
MEDIUM
4.0 - 6.9
Plan remediation
LOW
0.1 - 3.9
Monitor and track

Popular CVE Searches

Frequently Asked Questions

What is a CVE?

A CVE is a standardized identifier for a publicly known cybersecurity vulnerability. Each CVE has a unique ID (e.g., CVE-2021-44228), a severity score, and details about affected software.

What is a CVSS score?

CVSS rates vulnerability severity from 0-10. Critical (9.0+) means immediate exploitation risk. High (7.0-8.9) requires urgent patching. Medium (4.0-6.9) should be planned. Low (0.1-3.9) can be monitored.

Where does this data come from?

This tool queries the National Vulnerability Database (NVD), maintained by NIST. It is the authoritative source for CVE data, CVSS scores, and affected product information.

Is this tool free?

Yes, completely free with no signup required. For automated CVE scanning across your entire infrastructure, try a free CyberOrbit assessment.