Skip to content

National Vulnerability Database

Software vulnerabilities, CVE details and affected versions

Back to tools

The U.S. National Vulnerability Database provides publicly reported security vulnerabilities, with recent product matches and CVE details, including CISA catalog status and affected versions when reported.

Get vulnerability

Get one CVE’s description, risk score, attack conditions, affected products, weakness, exploitation listing, dates, and references. The exploitation flag reflects CISA’s known-exploited catalog; a no does not rule out exploitation. Some affected-product matches require other products or conditions.

Your information

The vulnerability number, such as CVE-2021-44228, 2021-44228, or cve-2021-44228.

1 credit per completed run

The same inputs also work from your code or an AI assistant. See For developers.

Example results

CVE-2023-23397

Microsoft Outlook Elevation of Privilege Vulnerability

CVSS score9.8Version 3.1
CriticalYes
PublishedMar 14, 2023
Last updatedJun 17, 2026
View in NVD

Attack and weakness

Attack conditions
over the network, no login needed, no user action
Weakness
Authentication Bypass by Capture-replay

Affected products

  • Microsoft 365 apps: version unspecified

  • Microsoft office: version 2019

  • Microsoft office long term servicing channel: version 2021

  • Microsoft outlook: version 2013 (sp1); version 2016

  • Microsoft Office LTSC 2021: from 16.0.1 (see description or vendor notice for affected versions)

  • Microsoft Outlook 2016: from 16.0.0.0 before 16.0.5387.1000

  • Microsoft 365 Apps for Enterprise: from 16.0.1 (see description or vendor notice for affected versions)

  • Microsoft Office 2019: from 19.0.0 (see description or vendor notice for affected versions)

  • Microsoft Outlook 2013 Service Pack 1: from 15.0.0.0 before 15.0.5537.1000

References

Choose an action

About the National Vulnerability Database tool

National Vulnerability Database (NVD) searches vulnerabilities by required product or vendor name, with optional severity and date filters.

Get vulnerability returns a CVE’s risk, affected products, weakness, attack conditions, dates, and references; it needs a CVE number.

Built from nvd.nist.gov, cisa.gov and cwe.mitre.org. Last checked Sep 30, 2026.

Actions

Get vulnerability

1 credit

Get one CVE’s description, risk score, attack conditions, affected products, weakness, exploitation listing, dates, and references. The exploitation flag reflects CISA’s known-exploited catalog; a no does not rule out exploitation. Some affected-product matches require other products or conditions.

Uses National Vulnerability Database and cwe.mitre.org.

What you provide

FieldTypeRequiredDescription
Cve Numbercve_numberTextRequiredThe vulnerability number, such as CVE-2021-44228, 2021-44228, or cve-2021-44228.Example: 2023-23397

What you get

FieldTypeDescription
Nvd Linknvd_linkTextExample: https://nvd.nist.gov/vuln/detail/CVE-2023-23397
SeverityseverityTextExample: Critical
Cve Numbercve_numberTextExample: CVE-2023-23397
Cvss Scorecvss_scoreNumberExample: 9.8
Cwe Numbercwe_numberTextExample: CWE-294
ReferencesreferencesList
Linkreferences[].linkTextExample: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397
Sourcereferences[].sourceTextExample: [email protected]
Cvss Vectorcvss_vectorTextExample: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
DescriptiondescriptionTextExample: Microsoft Outlook Elevation of Privilege Vulnerability
Cvss Versioncvss_versionTextExample: 3.1
Attack Methodattack_methodTextExample: over the network, no login needed, no user action
Weakness Typeweakness_typeTextExample: Authentication Bypass by Capture-replay
Published Datepublished_dateTextExample: 2023-03-14
Affected Productsaffected_productsList
Last Modified Datelast_modified_dateTextExample: 2026-06-17
Known Exploited in the Wildknown_exploited_in_the_wildYes or noExample: Yes

Example result

For Cve Number: 2023-23397

JSON
{
  "nvd_link": "https://nvd.nist.gov/vuln/detail/CVE-2023-23397",
  "severity": "Critical",
  "cve_number": "CVE-2023-23397",
  "cvss_score": 9.8,
  "cwe_number": "CWE-294",
  "references": [
    {
      "link": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397",
      "source": "[email protected]"
    },
    {
      "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-23397",
      "source": "www.cisa.gov"
    }
  ],
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "description": "Microsoft Outlook Elevation of Privilege Vulnerability",
  "cvss_version": "3.1",
  "attack_method": "over the network, no login needed, no user action",
  "weakness_type": "Authentication Bypass by Capture-replay",
  "published_date": "2023-03-14",
  "affected_products": [
    "Microsoft 365 apps: version unspecified",
    "Microsoft office: version 2019",
    "Microsoft office long term servicing channel: version 2021"
  ],
  "last_modified_date": "2026-06-17",
  "known_exploited_in_the_wild": true
}

Search vulnerabilities

1 credit

Find known vulnerabilities matching a product or vendor name, newest first. Includes published date, severity, affected versions when reported, and whether each CVE appears in CISA’s known exploited catalog. Keyword matches may include related products.

Uses National Vulnerability Database and cisa.gov.

What you provide

FieldTypeRequiredDescription
ProductproductTextRequiredProduct and/or vendor name, such as Apache Tomcat.Example: Apache Tomcat
SeverityseverityTextOptionalSeverity to include, such as critical; any includes unrated flaws.Example: Critical
Max Resultsmax_resultsNumberOptionalMaximum number of results, such as 20 (up to 100).Example: 3
Published Afterpublished_afterDateOptionalInclude vulnerabilities published on or after this date, such as 2025-01-01.Example: 2025-01-01

What you get

FieldTypeDescription
VulnerabilitiesvulnerabilitiesList
Nvd Linkvulnerabilities[].nvd_linkTextNVD vulnerability page.Example: https://nvd.nist.gov/vuln/detail/CVE-2026-86247
Severityvulnerabilities[].severityTextSeverity in words, or Unknown when unrated.Example: High
Cve Numbervulnerabilities[].cve_numberTextCVE identifier.Example: CVE-2026-86247
Cvss Scorevulnerabilities[].cvss_scoreNumberCVSS base score from 0 to 10 when available.Example: 7.4
Descriptionvulnerabilities[].descriptionTextEnglish-language vulnerability description.Example: Race condition within a thread vulnerability in Apache Tomcat Native allowed…
Published Datevulnerabilities[].published_dateDatePublication date.Example: 2026-09-23
Affected Versionsvulnerabilities[].affected_versionsTextAffected product versions when reported.Example: Apache Software Foundation Apache Tomcat Native: from 2.0.0 through 2.0.15…
Known Exploited in the Wildvulnerabilities[].known_exploited_in_the_wildYes or noWhether this CVE appears in the CISA known exploited catalog.Example: No

Example result

For Product: Apache Tomcat

JSON
{
  "vulnerabilities": [
    {
      "nvd_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-86247",
      "severity": "High",
      "cve_number": "CVE-2026-86247",
      "cvss_score": 7.4,
      "description": "Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations.\n\n\n\nThis issue affects Apache Tomcat…",
      "published_date": "2026-09-23",
      "affected_versions": "Apache Software Foundation Apache Tomcat Native: from 2.0.0 through 2.0.15; Apache Software Foundation Apache Tomcat Native: from 1.3.0 through 1.3.8",
      "known_exploited_in_the_wild": false
    },
    {
      "nvd_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-86246",
      "severity": "Critical",
      "cve_number": "CVE-2026-86246",
      "cvss_score": 9.1,
      "description": "Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default  including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE…",
      "published_date": "2026-09-23",
      "affected_versions": "Apache Software Foundation Apache Tomcat Native: from 2.0.0 through 2.0.15; Apache Software Foundation Apache Tomcat Native: from 1.3.0 through 1.3.8",
      "known_exploited_in_the_wild": false
    }
  ]
}

For developers

Call it from your code with one request. Change the values in input to run it on new data. To get an API key, open Developers at the bottom of Studio, turn on Developer mode and go to API keys.

cURL
curl 'https://api.fous.com/v1/query' \
  --fail-with-body --silent --show-error --max-time 180 \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H 'Content-Type: application/json' \
  --data-raw '{
  "api": "@national-vulnerability-database",
  "visibility": "public",
  "operation": "get_vulnerability",
  "version": 1,
  "input": {
    "cve_number": "2023-23397"
  },
  "response": {
    "format": "json"
  }
}'

What you can do with it

  • Find vulnerabilities affecting a product or vendor.
  • Prioritize vulnerabilities by severity and publication date.
  • Review affected versions when planning software updates.
  • Check whether a CVE appears in CISA’s known exploited catalog.
  • Investigate a CVE’s attack conditions and references.

Questions about National Vulnerability Database

Can I run it with my own inputs?

Yes. Change the inputs in Studio and press Run, or send new inputs from your code, or ask a connected AI assistant.

Can I call this National Vulnerability Database tool as an API?

Yes. Send a POST request to /v1/query with your Fous API key and the inputs, and get JSON back.

How much does it cost?

Each completed run costs 1 credit. Failed runs without a completed receipt are free; completed work can remain charged if delivery is interrupted. With pay as you go, a credit costs 1¢. Monthly plans cost less per credit.

Do I need a National Vulnerability Database account?

No. You only need a Fous account.

How current is the data?

Fous gets the data from nvd.nist.gov when you run it. Some results are reused for up to 24 hours, and results that use your account or key are never reused. It was last verified on Sep 30, 2026.

Which vulnerabilities affect a particular product or vendor?

Search vulnerabilities finds matches and returns severity, publication dates, affected versions when reported, and whether each CVE appears in CISA’s known exploited catalog.

What are the details for a specific CVE?

Get vulnerability returns the CVE’s description, risk score, attack conditions, affected products, weakness, dates, exploitation listing, and references.

Does a CVE appear in CISA’s known exploited catalog?

Get vulnerability reports whether the CVE appears in CISA’s known exploited catalog. A no does not rule out exploitation.

All Security toolsBrowse all tools