CVE Tools
Self-Check · powered by Nuclei

Are you actually vulnerable?

Confirm whether your systems are exposed — not just that a CVE exists. Paste a CVE ID and get a free, ready-to-run check in seconds.

Free · runs locally · no signup

36,604 CVEs you can self-check 503 in CISA KEV
nuclei — verify
$ nuclei -id CVE-2026-20253 -u https://your-target
[INF] Templates loaded for scan: 1
[CVE-2026-20253] [http] [critical] https://your-target
VULNERABLE — 1 match

What is Nuclei?

The free scanner behind every check on this page.

Free & open-source
Built by ProjectDiscovery. Thousands of community detection templates, MIT-licensed. You never pay.
Runs on your machine
No agent, no account, nothing sent to us. You run one command against your own target.
A clear yes / no
A template probes the host and tells you whether it is actually vulnerable — not just that the CVE exists.
$ nuclei -id CVE-2026-20253 -u https://your-target

That's the whole idea — each CVE here hands you this command, pre-filled. Install Nuclei ↗

How it works

1
Install Nuclei
One-time setup — the free binary runs on macOS, Linux and Windows.
2
Copy the check
We hand you the exact command for the CVE, pre-filled.
3
Run it on your host
Swap in your target and run. It checks, it does not exploit.
4
Patch what is confirmed
A hit is proof — prioritize the fix. Re-run to verify it held.

Latest high-severity CVEs you can verify

Newest critical/high vulnerabilities that ship a Nuclei template.

Trending CVEs to verify now

What the security world is discussing right now — and can be checked with Nuclei.

Frequently asked questions

Is Nuclei free?

Yes. Nuclei is free and open-source, maintained by ProjectDiscovery. There is nothing to buy to run the checks on this page.

Is it legal to scan?

Yes — when you scan systems you own or have permission to test. These checks verify your own exposure (detection), not attack others. Never run them against targets you do not control.

Do I need to be a security expert?

No. If you can paste a command into a terminal and swap in your own address, you can run a check. Each CVE gives you the exact command, ready to paste.

What does the check actually do?

It sends one or more requests to the target you specify and inspects the response to decide whether the vulnerability is present. Detection only — it does not change or break anything.

What if there is no template for my CVE?

Not every CVE has a published template yet. When one does not exist you cannot run an automated check here — a good moment to request a hands-on scan instead.

Nuclei vs a paid scan — what is the difference?

Running Nuclei yourself is free and fully in your control. A paid Scan is done for you — an external review of what is exposed, without you setting anything up.

Want the full picture without lifting a finger?
Request a complimentary external exposure review — we'll check what's exposed across your domain.
Request a scan