Am I actually vulnerable?
Paste a CVE ID and get the exact detection check to run against your own systems — a ready-to-run Nuclei command or the OpenVAS NVT OID with a GMP query to confirm a host is affected.
Latest high-severity CVEs you can verify
Newest critical/high vulnerabilities a scanner can check — Nuclei or OpenVAS.
WordPress FormCraft plugin <= 3.9.15 - Server Side Request Forgery (SSRF) vulnerability
Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78)
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
Authentication Bypass in the SmartConsole Login Process Using an Application Token
Kirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apis
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
Trending CVEs to verify now
What the security world is discussing right now — and can be checked with a scanner.
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make...
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 an...
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Frequently asked questions
How do I check whether a host is affected by a CVE?
Enter the CVE ID above. If a scanner covers it, we hand you the exact check to run against your own target — a ready-to-run Nuclei command and/or the OpenVAS NVT OID with a GMP query to confirm the NVT is in your feed.
Is there a Nuclei template for this CVE, and how do I run it?
When an official ProjectDiscovery template exists we give you the template ID and a copy-ready command (nuclei -id <CVE> -u <target>). If no template is published yet, we say so plainly rather than fabricate one.
What is the OpenVAS NVT OID for a CVE and how do I confirm it?
We list the detecting NVT OID(s) and a GMP query (get_nvts nvt_oid=...) so you can confirm the NVT is present in your Greenbone feed at your feed version before trusting a clean result.
Does a positive detection mean the host is exploitable?
No. These are detection checks — they fingerprint the vulnerable condition (service, version, reachable endpoint), not exploitability. Cross-reference CISA KEV and EPSS to judge real-world risk.
What if no scanner covers the CVE I'm checking?
Not every CVE has a published Nuclei or OpenVAS check. When neither covers it, we tell you and point you to the affected products so you can check manually — or run a managed external scan and we'll confirm exposure for you.