Enter a CVE ID, IP address, Domain, Email, Phone Number, File Hash, or URL to scan/analyze threat intelligence data
Nothing searched yet

CVE lookup

Severity is only half the question; whether anyone is actually exploiting it is the other half. This lookup puts the scoring next to the exploitation signals that decide whether something moves up your queue today.

What you can paste

These are format examples. Clicking one puts it in the search box — it does not run a search, so you choose when to spend a lookup.

How to run one
  1. 1Paste the CVE ID into the box above. The type is already set to CVE on this page.
  2. 2Press Analyze. If the indicator is new to the platform it is queued for enrichment, and the page holds a progress view while that runs rather than telling you to come back later.
  3. 3Read the report top-down. The verdict is the headline; the sections below it are the evidence, and the evidence is the part worth your time.
  4. 4Pivot. Almost every value in the report is itself searchable, which is how one indicator becomes an investigation.
Where to go next
  • Browse every CVE for the affected vendor and product
  • Check whether malware in the corpus exploits it
  • Look at the ATT&CK techniques exploitation would produce
What comes back, and how to read it

These are the sections of the report, in the order you will meet them.

  1. 01CVSS base score and Severity

    How bad it is if exploited. A static property of the vulnerability -- it says nothing about whether anyone is exploiting it, which is why it is never the whole answer.

  2. 02EPSS probability and percentile

    The likelihood of exploitation in the next 30 days, and where that ranks against every other CVE. This is the number that separates a 9.8 nobody touches from a 7.5 being used right now.

  3. 03Exploitation

    Whether exploitation is known and observed, including CISA Known Exploited Vulnerabilities status. A KEV listing is as close to a decision as this page gives you.

  4. 04Ransomware campaign use

    Called out separately because it changes the response. A vulnerability known to be used in ransomware campaigns is an emergency in a way an equally scored one is not.

  5. 05Affected entries

    The products and versions in scope, so you can tell whether you are actually exposed rather than just alarmed.

  6. 06References and Exploit-DB

    Advisories, write-ups and public proof-of-concept code. Available exploit code shortens the window between disclosure and use considerably.