Arsenly
Tools
Free Tools
Pricing
Resources
Sign in Get started
← All tools

CVE Lookup

Reference & Reports

Look up a CVE in depth - CVSS, EPSS, CISA KEV, SSVC, CWE and exploit references - or list a product’s CVEs.

What is CVE Lookup?

CVE Lookup pulls the full CVE 5.0 record from the CIRCL vulnerability database and layers on the signals that actually drive prioritisation: the CVSS base score & vector (recovered from the CNA or the CISA ADP), the EPSS exploitation probability, whether the CVE is in the CISA Known Exploited Vulnerabilities catalog (actively exploited in the wild), the CISA SSVC decision, the CWE weakness class, affected products/versions, and references split into exploit / patch / advisory.

Enter a CVE id for the full picture, or a vendor/product to list its CVEs - sorted with actively-exploited (KEV) issues first, then by CVSS. It closes the loop between recon and exploitation: fingerprint a version, then see what is known - and what is being exploited - against it.

What you get

  • CVSS - base score, severity and vector (v4 / v3.1 / v3 / v2).
  • EPSS - the 30-day probability that the CVE will be exploited, with percentile.
  • CISA KEV - flags vulnerabilities under active exploitation (incl. ransomware use).
  • SSVC & CWE - CISA exploitation decision and the underlying weakness class.
  • Categorised references - exploit / PoC, patch and advisory links called out.
  • Product search - list a vendor/product’s CVEs, KEV-first then by CVSS.

Where it fits in your workflow

  • Triage a fingerprinted version: is there a CVE, and is it actively exploited?
  • Pull the exploit/PoC references and external links (NVD, MITRE, Exploit-DB, GitHub).
  • Build a prioritised known-vulnerability section for a report.
Use CVE Lookup

Run it from your dashboard.

Create free account Sign in Use via API

At a glance

CategoryReference & Reports
RunsServer-side
Token cost 2 / run (free tier)
Access Free
Status● Live

Frequently asked questions

What do EPSS and KEV add over CVSS?

CVSS rates theoretical severity. EPSS estimates the likelihood of exploitation in the next 30 days, and CISA KEV tells you it is *already* being exploited in the wild - together they prioritise what to fix/attack first far better than CVSS alone.

Does a matching CVE mean the target is exploitable?

Not necessarily - patches, backports and configuration can mitigate a CVE. Use the result as a lead to verify against the actual target.

Explore more tools →