Skip to content

Data collected

CVEs Live

CVE lookup

Type a CVE ID to get, on one sheet, whether it is being exploited (CISA KEV), how likely exploitation is (EPSS) and every published CVSS, plus affected versions and references from the CVE record.

The identifier is sent from your browser to cveawg.mitre.org (CVE Program) and api.first.org (FIRST). KEV status comes from the catalog on this site.

Latest additions to CISA KEV

The 60 most recent KEV entries have a page of their own, collected on 3 Oct 2026.

What a CVE record contains

A CVE record is the public entry for one vulnerability, kept by the CVE Program. It is written by the organisation that assigned the identifier, a CVE Numbering Authority (CNA), which is usually the vendor of the product. The record is the primary source; databases such as the NVD copy it and add their own analysis.

The fields that matter when you triage

  • Affected products and versions. Structured ranges such as “from 2.0 before 2.17.1”. This is what tells you whether your installed version is in scope.
  • Description. One paragraph by the CNA on what goes wrong and what an attacker gains.
  • CVSS. The CNA’s own severity assessment, when it provides one. Other organisations, such as CISA’s enrichment programme, can attach theirs to the same record.
  • References. Links to the vendor advisory, the patch and technical write-ups.
  • State and dates. PUBLISHED or REJECTED, when the record was published and when it last changed.

What the record does not say

Whether the vulnerability is being exploited. That comes from two other sources shown on the sheet: the CISA KEV catalog, which lists confirmed exploitation, and EPSS, which estimates its probability. A record with a critical score and neither signal is usually less urgent than a medium one that is in KEV.

Questions

What is a CVE identifier?

A CVE ID is the public name of one vulnerability, in the form CVE-year-number, for example CVE-2021-44228. The year is when the ID was reserved or published, and the number has four or more digits. IDs are assigned by CVE Numbering Authorities, mostly vendors and coordinators, under the CVE Program.

Why can the NVD and the vendor show different CVSS scores for the same CVE?

Each one scores independently. The organisation that assigned the CVE publishes its own assessment in the CVE record, and the NVD analysts may publish another. They can use different CVSS versions or judge an attack condition differently. This site shows every published assessment with its source and does not pick a winner.

Why does a recent CVE have no CVSS score?

The NVD has had a backlog in analysing new CVEs, so a record can stay for weeks without an NVD score. When the assigning organisation included a score in the CVE record, it is shown here with that source; when nobody has published one, the sheet says so.

What do "affected" and "unaffected" version entries mean?

They are statements made in the CVE record by the assigning organisation. "Affected from 2.0 before 2.17.1" means versions starting at 2.0 and lower than 2.17.1 are vulnerable. The words and bounds are copied from the record; the vendor advisory remains the reference for which version to install.

Where does the lookup get its data?

From the CVE Program record API (cveawg.mitre.org) and the FIRST EPSS API, both asked directly from your browser when you search, and from the CISA KEV catalog kept on this site. The time of the catalog collection is shown on the page.

Related sections