| CVE | Verdict | CVSS | EPSS | KEV | Published | CWE | Description |
|---|
Type what's running. Get what's known.
A product and a version. The scanner never touches the host: it asks the NVD what is filed against that exact version, checks every configuration itself, scores the hits with EPSS, and shows the working. False positives are labelled, not deleted.
Verdicts
- exactThe NVD lists this exact version as vulnerable.
- rangeInside a version range the comparator can prove.
- anyThe record says "all versions". Often true. Sometimes lazy.
- condMatches, but only when running on a platform you didn't specify.
- maybeVersion compare not provable, or an update you didn't give.
- platformOnly named as the thing the real bug runs on. Hidden by default.
Cross-check
- nvdThe NVD's own matcher returned it; the local one couldn't reproduce why. Kept, flagged.
- localThorough mode: found by matching every record locally; the NVD's matcher didn't return it.
- unanalysedRecent CVE that mentions the product but has no CPE data yet. Nobody's matcher can see it.
Where the data goes
Your browser → services.nvd.nist.gov and api.first.org. Nothing in between, nothing logged here, nothing sent to the target.
Five NVD requests per thirty seconds without a key. An API key from nvd.nist.gov makes it fifty, and it stays in this browser.