National Vulnerability Database
Software vulnerabilities, CVE details and affected versions
The U.S. National Vulnerability Database provides publicly reported security vulnerabilities, with recent product matches and CVE details, including CISA catalog status and affected versions when reported.
Your information
The vulnerability number, such as CVE-2021-44228, 2021-44228, or cve-2021-44228.
Example results
CVE-2023-23397
Microsoft Outlook Elevation of Privilege Vulnerability
Attack and weakness
- Attack conditions
- over the network, no login needed, no user action
- Weakness
- Authentication Bypass by Capture-replay
Affected products
Microsoft 365 apps: version unspecified
Microsoft office: version 2019
Microsoft office long term servicing channel: version 2021
Microsoft outlook: version 2013 (sp1); version 2016
Microsoft Office LTSC 2021: from 16.0.1 (see description or vendor notice for affected versions)
Microsoft Outlook 2016: from 16.0.0.0 before 16.0.5387.1000
Microsoft 365 Apps for Enterprise: from 16.0.1 (see description or vendor notice for affected versions)
Microsoft Office 2019: from 19.0.0 (see description or vendor notice for affected versions)
Microsoft Outlook 2013 Service Pack 1: from 15.0.0.0 before 15.0.5537.1000
References
www.cisa.gov
Open reference
About the National Vulnerability Database tool
National Vulnerability Database (NVD) searches vulnerabilities by required product or vendor name, with optional severity and date filters.
Get vulnerability returns a CVE’s risk, affected products, weakness, attack conditions, dates, and references; it needs a CVE number.
Built from nvd.nist.gov, cisa.gov and cwe.mitre.org. Last checked Sep 30, 2026.
Actions
Get vulnerability
1 creditGet one CVE’s description, risk score, attack conditions, affected products, weakness, exploitation listing, dates, and references. The exploitation flag reflects CISA’s known-exploited catalog; a no does not rule out exploitation. Some affected-product matches require other products or conditions.
Uses National Vulnerability Database and cwe.mitre.org.
What you provide
| Field | Type | Required | Description |
|---|---|---|---|
Cve Numbercve_number | Text | Required | The vulnerability number, such as CVE-2021-44228, 2021-44228, or cve-2021-44228.Example: 2023-23397 |
What you get
| Field | Type | Description |
|---|---|---|
Nvd Linknvd_link | Text | Example: https://nvd.nist.gov/vuln/detail/CVE-2023-23397 |
Severityseverity | Text | Example: Critical |
Cve Numbercve_number | Text | Example: CVE-2023-23397 |
Cvss Scorecvss_score | Number | Example: 9.8 |
Cwe Numbercwe_number | Text | Example: CWE-294 |
Referencesreferences | List | |
Linkreferences[].link | Text | Example: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397 |
Sourcereferences[].source | Text | Example: [email protected] |
Cvss Vectorcvss_vector | Text | Example: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Descriptiondescription | Text | Example: Microsoft Outlook Elevation of Privilege Vulnerability |
Cvss Versioncvss_version | Text | Example: 3.1 |
Attack Methodattack_method | Text | Example: over the network, no login needed, no user action |
Weakness Typeweakness_type | Text | Example: Authentication Bypass by Capture-replay |
Published Datepublished_date | Text | Example: 2023-03-14 |
Affected Productsaffected_products | List | |
Last Modified Datelast_modified_date | Text | Example: 2026-06-17 |
Known Exploited in the Wildknown_exploited_in_the_wild | Yes or no | Example: Yes |
Example result
For Cve Number: 2023-23397
{
"nvd_link": "https://nvd.nist.gov/vuln/detail/CVE-2023-23397",
"severity": "Critical",
"cve_number": "CVE-2023-23397",
"cvss_score": 9.8,
"cwe_number": "CWE-294",
"references": [
{
"link": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397",
"source": "[email protected]"
},
{
"link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-23397",
"source": "www.cisa.gov"
}
],
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"description": "Microsoft Outlook Elevation of Privilege Vulnerability",
"cvss_version": "3.1",
"attack_method": "over the network, no login needed, no user action",
"weakness_type": "Authentication Bypass by Capture-replay",
"published_date": "2023-03-14",
"affected_products": [
"Microsoft 365 apps: version unspecified",
"Microsoft office: version 2019",
"Microsoft office long term servicing channel: version 2021"
],
"last_modified_date": "2026-06-17",
"known_exploited_in_the_wild": true
}Search vulnerabilities
1 creditFind known vulnerabilities matching a product or vendor name, newest first. Includes published date, severity, affected versions when reported, and whether each CVE appears in CISA’s known exploited catalog. Keyword matches may include related products.
Uses National Vulnerability Database and cisa.gov.
What you provide
| Field | Type | Required | Description |
|---|---|---|---|
Productproduct | Text | Required | Product and/or vendor name, such as Apache Tomcat.Example: Apache Tomcat |
Severityseverity | Text | Optional | Severity to include, such as critical; any includes unrated flaws.Example: Critical |
Max Resultsmax_results | Number | Optional | Maximum number of results, such as 20 (up to 100).Example: 3 |
Published Afterpublished_after | Date | Optional | Include vulnerabilities published on or after this date, such as 2025-01-01.Example: 2025-01-01 |
What you get
| Field | Type | Description |
|---|---|---|
Vulnerabilitiesvulnerabilities | List | |
Nvd Linkvulnerabilities[].nvd_link | Text | NVD vulnerability page.Example: https://nvd.nist.gov/vuln/detail/CVE-2026-86247 |
Severityvulnerabilities[].severity | Text | Severity in words, or Unknown when unrated.Example: High |
Cve Numbervulnerabilities[].cve_number | Text | CVE identifier.Example: CVE-2026-86247 |
Cvss Scorevulnerabilities[].cvss_score | Number | CVSS base score from 0 to 10 when available.Example: 7.4 |
Descriptionvulnerabilities[].description | Text | English-language vulnerability description.Example: Race condition within a thread vulnerability in Apache Tomcat Native allowed… |
Published Datevulnerabilities[].published_date | Date | Publication date.Example: 2026-09-23 |
Affected Versionsvulnerabilities[].affected_versions | Text | Affected product versions when reported.Example: Apache Software Foundation Apache Tomcat Native: from 2.0.0 through 2.0.15… |
Known Exploited in the Wildvulnerabilities[].known_exploited_in_the_wild | Yes or no | Whether this CVE appears in the CISA known exploited catalog.Example: No |
Example result
For Product: Apache Tomcat
{
"vulnerabilities": [
{
"nvd_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-86247",
"severity": "High",
"cve_number": "CVE-2026-86247",
"cvss_score": 7.4,
"description": "Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations.\n\n\n\nThis issue affects Apache Tomcat…",
"published_date": "2026-09-23",
"affected_versions": "Apache Software Foundation Apache Tomcat Native: from 2.0.0 through 2.0.15; Apache Software Foundation Apache Tomcat Native: from 1.3.0 through 1.3.8",
"known_exploited_in_the_wild": false
},
{
"nvd_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-86246",
"severity": "Critical",
"cve_number": "CVE-2026-86246",
"cvss_score": 9.1,
"description": "Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE…",
"published_date": "2026-09-23",
"affected_versions": "Apache Software Foundation Apache Tomcat Native: from 2.0.0 through 2.0.15; Apache Software Foundation Apache Tomcat Native: from 1.3.0 through 1.3.8",
"known_exploited_in_the_wild": false
}
]
}For developers
Call it from your code with one request. Change the values in input to run it on new data. To get an API key, open Developers at the bottom of Studio, turn on Developer mode and go to API keys.
curl 'https://api.fous.com/v1/query' \
--fail-with-body --silent --show-error --max-time 180 \
-H "Authorization: Bearer YOUR_API_KEY" \
-H 'Content-Type: application/json' \
--data-raw '{
"api": "@national-vulnerability-database",
"visibility": "public",
"operation": "get_vulnerability",
"version": 1,
"input": {
"cve_number": "2023-23397"
},
"response": {
"format": "json"
}
}'What you can do with it
- Find vulnerabilities affecting a product or vendor.
- Prioritize vulnerabilities by severity and publication date.
- Review affected versions when planning software updates.
- Check whether a CVE appears in CISA’s known exploited catalog.
- Investigate a CVE’s attack conditions and references.
Questions about National Vulnerability Database
Can I run it with my own inputs?
Yes. Change the inputs in Studio and press Run, or send new inputs from your code, or ask a connected AI assistant.
Can I call this National Vulnerability Database tool as an API?
Yes. Send a POST request to /v1/query with your Fous API key and the inputs, and get JSON back.
How much does it cost?
Each completed run costs 1 credit. Failed runs without a completed receipt are free; completed work can remain charged if delivery is interrupted. With pay as you go, a credit costs 1¢. Monthly plans cost less per credit.
Do I need a National Vulnerability Database account?
No. You only need a Fous account.
How current is the data?
Fous gets the data from nvd.nist.gov when you run it. Some results are reused for up to 24 hours, and results that use your account or key are never reused. It was last verified on Sep 30, 2026.
Which vulnerabilities affect a particular product or vendor?
Search vulnerabilities finds matches and returns severity, publication dates, affected versions when reported, and whether each CVE appears in CISA’s known exploited catalog.
What are the details for a specific CVE?
Get vulnerability returns the CVE’s description, risk score, attack conditions, affected products, weakness, dates, exploitation listing, and references.
Does a CVE appear in CISA’s known exploited catalog?
Get vulnerability reports whether the CVE appears in CISA’s known exploited catalog. A no does not rule out exploitation.