Runtime CVE scanner for installed software
Upload installed software. We map each product CPE → CVE and list known vulnerabilities.
- Pick OS →
- Copy command →
- Upload .txt →
- View results
Loading command…↳ Run the command, then upload the result file
Format: plain-text inventory (.txt) — package/app names with versions.
No client data stored. Matched against NVD — your file is not retained after the scan.
Filter:
0 CVEs · page 1/1
| CVE ID | Severity | CVSS | Product | Version | Published | Patch | |
|---|---|---|---|---|---|---|---|
| No CVEs to show | |||||||
How CVEScan works
Upload installed software. We map each product CPE → CVE and list known vulnerabilities.
- Pick your OS — Choose macOS, Linux, Windows, iPhone, or Android to get the right inventory command.
- Copy & run the command — Run a read-only command locally to list installed packages and versions into scan_results.txt.
- Upload your inventory — Upload the output file. Nothing is stored — the scan runs and client data is discarded.
- Match CPE → CVE — CVEScan resolves products to CPE and matches them against NVD for known CVEs with CVSS severity.
Scan modes
- Local Programs — Upload installed software. We map each product CPE → CVE and list known vulnerabilities.
- Browser — Enter a website URL. We probe public headers/HTML for stack signals and match related CVEs.
- Network — Run nmap service detection, upload the XML report, and match exposed services to CVEs.
Privacy
No client data stored. Upload an inventory file, get matched CVEs from NVD — your scan_results.txt is not retained after the scan.
Read more in the CVEScan FAQ and External API docs.