CVE Lookup
Look up a CVE vulnerability by ID, or find the latest CVEs for any product, with CVSS scores.
CVE Lookup
CVE IDs, such as CVE-2021-44228 (Log4Shell), name publicly known security vulnerabilities. Look one up to get its description, CVSS severity score, weakness type (CWE), affected products and versions, references and whether CISA lists it as actively exploited. Or search for a product, such as "wordpress" or "openssl 3.0", to see the newest CVEs that mention it. Data comes from the U.S. National Vulnerability Database (NVD).
How to use CVE Lookup
- Enter a CVE ID, or a product name and optionally a version.
- Click Search.
- For a search, the newest CVEs are listed first; click an ID for the full details.
When it comes in handy
- Checking how serious a vulnerability in a security report is.
- Seeing recent vulnerabilities in software you run, such as WordPress plugins or server software.
- Writing patch priorities and security advisories.
Frequently asked questions
- What do the CVSS scores mean?
- Scores run from 0 to 10: Low (0.1 to 3.9), Medium (4.0 to 6.9), High (7.0 to 8.9) and Critical (9.0 to 10). The score measures technical severity, not how likely you are to be attacked.
- What does "known exploited" mean?
- The vulnerability is on CISA's Known Exploited Vulnerabilities catalogue, meaning attackers are using it in the real world. Patch these first.
- Why is a brand new CVE missing?
- New CVEs can take days to be analysed and scored by NVD.