Search or filter
Look up a CVE ID directly, or filter by severity, KEV status and EPSS to narrow the list.
Free · no signup · updated from NVD
Search the catalog with CVSS, EPSS and CISA KEV context. Know what to patch first before the next scanner export lands in your inbox.
CVE ID or keyword
4,385 CVEs
How it works
Look up a CVE ID directly, or filter by severity, KEV status and EPSS to narrow the list.
Each entry includes CVSS, EPSS, CWE, affected products, exploit references and triage notes.
Use KEV and EPSS together to decide what to patch first — then validate exposure in your stack.
Signals
Theoretical severity and real-world exploit probability side by side — so you stop chasing CVSS alone.
CPE strings and product names are searchable, so you can find every issue affecting apache, fortinet or your stack.
Exploit reference counts, emergent threat flags and why-exploitable summaries from Trusteed triage.
Questions
Need to see what is actually exposed on your perimeter? Start with a free scan.
Scan my attack surface →Entries are built from NVD catalog data enriched with EPSS scores, CISA KEV status, exploit references and Trusteed triage signals. The free tool shows the same intelligence layer we use inside the platform — without requiring a login.
CVSS measures theoretical severity. EPSS estimates how likely a CVE is to be exploited in the wild. A high CVSS with low EPSS may still matter on an exposed asset; a moderate CVSS on the KEV list should jump the queue.
It means the vulnerability appears on CISA's Known Exploited Vulnerabilities catalog — confirmed or expected active exploitation. If you run the affected product, treat it as urgent regardless of CVSS alone.
Yes. Keywords match CVE IDs, titles, descriptions and CPE strings. Try vendor names like apache, fortinet or product names from your stack.
No. This catalog helps you understand a CVE before or after a scan finds it. To see which issues actually affect your perimeter, run the free attack surface scan or use Trusteed CTEM for continuous coverage.
Also try the free SSL certificate check.
Map external assets, match products to CVEs and track fixes continuously with Trusteed CTEM.