Search the National Vulnerability Database for CVEs by keyword or CVE ID. Filter by CVSS severity to quickly find critical vulnerabilities affecting your stack.
Related free tools
Paste a lockfile and check every package against the OSV database.
Score a vulnerability with CVSS v3.1 or v4.0 and see how each metric moves the number.
Work out which versions a ^, ~ or range actually includes.
Read next
What a 9.8 really means, why base score alone misleads, and how to prioritise with reachability and exploit data.
AquilaX SCA maps your full dependency graph — including transitive packages — against NVD, OSV and GitHub Advisories continuously, then Securitron AI ranks what is reachable so you fix the 3 that matter, not the 300 that do not.
Free plan is permanent · unlimited scans · GitHub, GitLab, Bitbucket & Azure DevOps