Am I actually vulnerable?
Paste a CVE ID and get the exact detection check to run against your own systems — a ready-to-run Nuclei command or the OpenVAS NVT OID with a GMP query to confirm a host is affected.
Latest high-severity CVEs you can verify
Newest critical/high vulnerabilities a scanner can check — Nuclei or OpenVAS.
GEO my WP <= 4.5.5.3 - Unauthenticated Local File Inclusion
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local files via a POST Request in a public url.
LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion
pre-authentication remote code execution
TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer
Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit ...
Trending CVEs to verify now
What the security world is discussing right now — and can be checked with a scanner.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
Anonymous user token generation exposure in JFrog Artifactory
PaperCut MF/NG: Authentication Bypass
Microsoft Exchange Server Remote Code Execution Vulnerability
WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Arbitrary File Upload vulnerability
Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access
Frequently asked questions
How do I check whether a host is affected by a CVE?
Enter the CVE ID above. If a scanner covers it, we hand you the exact check to run against your own target — a ready-to-run Nuclei command and/or the OpenVAS NVT OID with a GMP query to confirm the NVT is in your feed.
Is there a Nuclei template for this CVE, and how do I run it?
When an official ProjectDiscovery template exists we give you the template ID and a copy-ready command (nuclei -id <CVE> -u <target>). If no template is published yet, we say so plainly rather than fabricate one.
What is the OpenVAS NVT OID for a CVE and how do I confirm it?
We list the detecting NVT OID(s) and a GMP query (get_nvts nvt_oid=...) so you can confirm the NVT is present in your Greenbone feed at your feed version before trusting a clean result.
Does a positive detection mean the host is exploitable?
No. These are detection checks — they fingerprint the vulnerable condition (service, version, reachable endpoint), not exploitability. Cross-reference CISA KEV and EPSS to judge real-world risk.
What if no scanner covers the CVE I'm checking?
Not every CVE has a published Nuclei or OpenVAS check. When neither covers it, we tell you and point you to the affected products so you can check manually — or run a managed external scan and we'll confirm exposure for you.