Synchronized NVD + CISA KEV records

CVE Database

Search medium-to-critical vulnerability records by CVE ID, title, product, severity, year, or known-exploited status.

Catalog records
268,233
medium through critical
Critical
41,589
highest-impact records
CISA KEV
1,425
known exploited
Agent-ready
268,233
bounded composed plans

Prefer a plain HTML index of records with stable reviewed guidance or complete evidence enrichment? Browse the canonical records below.

Canonical remediation records

Reviewed and evidence-qualified CVEs

40 records have stable human review or complete, source-linked enrichment and are eligible for search indexing.

Browse the no-JavaScript archive by publication year. Ready to act on a finding? Use the AI vulnerability remediation playbooks, vulnerable dependency workflow, or CVE intelligence intake gate.

Reviewed reference library

Historical reviewed CVEs

Foundational vulnerabilities outside the rolling catalog window remain available as human-reviewed remediation recipes with verification and rollback guidance.

Fast lanes

Start with the queue that matters.

Each link opens a shareable filter. Refine by publication year, title, product, or an exact CVE ID in the catalog.

Two access paths / one evidence contract

Readable by humans. Retrievable by agents.

The browser and MCP surfaces resolve against the same synchronized catalog and retain the same source, authority, and uncertainty boundaries.

Human path

Investigate before you remediate.

Open an exact record, establish whether the affected product and version are present, then review risk, remediation, verification, references, and stop conditions.

Search the database

Agent path

Retrieve bounded context, not a permission slip.

Use read-only MCP tools for discovery and exact records. Every composed plan includes scoped actions, target hints, verification, and prohibited operations.

recipes_cve_searchrecipes_cve_get
Connect through MCP

Methodology

A transparent path from source to action.

The catalog favors bounded, reviewable work over false certainty. Each layer declares where its information came from and what it can safely support.

  1. 01

    Synchronize source facts

    Medium, high, and critical CVEs are synchronized from NVD. CISA KEV status is attached independently for exploitation priority.

  2. 02

    Compose a safe plan

    Deterministic ecosystem archetypes add exposure checks, bounded actions, prohibited operations, verification, and stop conditions.

  3. 03

    Enrich with provenance

    Where evidence supports it, AI adds supplemental context with the model, sources, gaps, uncertainty, and status shown explicitly.