What this tool checks
- CVSS score and vector (v4.0, v3.x, v2)
- Severity
- Description and CWE class
- Affected vendors, products and version ranges
- Reference links
- Whether it's in the CISA KEV catalog
How to use it
- 01
Enter a CVE ID (CVE-2024-3400) or a product name (fortios, confluence).
- 02
Press Search; product searches list the most recent matches.
- 03
Click a CVE ID in the list to open its details.
Technical details
Data sources
Vulnerability details come from the NIST NVD API 2.0 and exploitation data from the CISA Known Exploited Vulnerabilities catalog. Results are cached for a few hours.
CVSS isn't enough
CVSS measures technical severity, not the likelihood of exploitation. A medium-severity vulnerability in KEV can be more urgent than a critical one that has never been exploited.
Version ranges
Affected products are read from CPE matches. “< 1.2.3” means every version before that release is affected.
Frequently asked questions
What is KEV?
CISA's catalog of vulnerabilities confirmed to be exploited in real attacks. Vulnerabilities on this list should be fixed first.
Why does a newly published CVE have no score?
NVD analysis can take several days. In the meantime, the vendor's own advisory is the most reliable source.
How do I know whether my system is affected?
Compare the product and version you run with the affected version ranges. For a full inventory and vulnerability management, see our vulnerability management service.
Are descriptions translated?
NVD publishes descriptions in English only; we show the original text unchanged.