Could not fetch data for the specified CVE ID. Please try again with a valid CVE identifier.
Severity is only half the question; whether anyone is actually exploiting it is the other half. This lookup puts the scoring next to the exploitation signals that decide whether something moves up your queue today.
These are format examples. Clicking one puts it in the search box — it does not run a search, so you choose when to spend a lookup.
These are the sections of the report, in the order you will meet them.
How bad it is if exploited. A static property of the vulnerability -- it says nothing about whether anyone is exploiting it, which is why it is never the whole answer.
The likelihood of exploitation in the next 30 days, and where that ranks against every other CVE. This is the number that separates a 9.8 nobody touches from a 7.5 being used right now.
Whether exploitation is known and observed, including CISA Known Exploited Vulnerabilities status. A KEV listing is as close to a decision as this page gives you.
Called out separately because it changes the response. A vulnerability known to be used in ransomware campaigns is an emergency in a way an equally scored one is not.
The products and versions in scope, so you can tell whether you are actually exposed rather than just alarmed.
Advisories, write-ups and public proof-of-concept code. Available exploit code shortens the window between disclosure and use considerably.
AI assistant — can make mistakes. Verify important results.