National Vulnerability Database
Software vulnerabilities, CVE details and affected versions
The U.S. National Vulnerability Database provides publicly reported security vulnerabilities, with recent product matches and CVE details, including CISA catalog status and affected versions when reported.
Your information
The vulnerability number, such as CVE-2021-44228, 2021-44228, or cve-2021-44228.
Example results
- Nvd Link
- nvd.nist.gov
- Severity
- Critical
- Cve Number
- CVE-2023-23397
- Cvss Score
- 9.8
- Cwe Number
- CWE-294
- Cvss Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Description
- Microsoft Outlook Elevation of Privilege Vulnerability
- Cvss Version
- 3.1
- Attack Method
- over the network, no login needed, no user action
- Weakness Type
- Authentication Bypass by Capture-replay
- Published Date
- 2023-03-14
- Last Modified Date
- 2026-06-17
- Known Exploited in the Wild
- Yes
- References
References Link Source www.cisa.gov- Affected Products
- Microsoft 365 apps: version unspecified
- Microsoft office: version 2019
- Microsoft office long term servicing channel: version 2021
- Microsoft outlook: version 2013 (sp1); version 2016
- Microsoft Office LTSC 2021: from 16.0.1 (see description or vendor notice for affected versions)
- Microsoft Outlook 2016: from 16.0.0.0 before 16.0.5387.1000
- Microsoft 365 Apps for Enterprise: from 16.0.1 (see description or vendor notice for affected versions)
- Microsoft Office 2019: from 19.0.0 (see description or vendor notice for affected versions)
- Microsoft Outlook 2013 Service Pack 1: from 15.0.0.0 before 15.0.5537.1000
About National Vulnerability Database
National Vulnerability Database (NVD) searches vulnerabilities by required product or vendor name, with optional severity and date filters.
Get vulnerability returns a CVE’s risk, affected products, weakness, attack conditions, dates, and references; it needs a CVE number.
Built by Fous from nvd.nist.gov, cisa.gov and cwe.mitre.org and checked automatically; it last passed a check on Sep 30, 2026. Fous is not affiliated with National Vulnerability Database.
Actions
Get vulnerability
1 credit per runGet one CVE’s description, risk score, attack conditions, affected products, weakness, exploitation listing, dates, and references. The exploitation flag reflects CISA’s known-exploited catalog; a no does not rule out exploitation. Some affected-product matches require other products or conditions.
Uses National Vulnerability Database and cwe.mitre.org.
What you provide
| Field | Type | Required | Description |
|---|---|---|---|
Cve Numbercve_number | Text | Required | The vulnerability number, such as CVE-2021-44228, 2021-44228, or cve-2021-44228.Example: 2023-23397 |
What you get
| Field | Type | Description |
|---|---|---|
Nvd Linknvd_link | Text | Example: https://nvd.nist.gov/vuln/detail/CVE-2023-23397 |
Severityseverity | Text | Example: Critical |
Cve Numbercve_number | Text | Example: CVE-2023-23397 |
Cvss Scorecvss_score | Number | Example: 9.8 |
Cwe Numbercwe_number | Text | Example: CWE-294 |
Referencesreferences | List | |
Linkreferences[].link | Text | Example: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397 |
Sourcereferences[].source | Text | Example: [email protected] |
Cvss Vectorcvss_vector | Text | Example: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Descriptiondescription | Text | Example: Microsoft Outlook Elevation of Privilege Vulnerability |
Cvss Versioncvss_version | Text | Example: 3.1 |
Attack Methodattack_method | Text | Example: over the network, no login needed, no user action |
Weakness Typeweakness_type | Text | Example: Authentication Bypass by Capture-replay |
Published Datepublished_date | Text | Example: 2023-03-14 |
Affected Productsaffected_products | List | |
Last Modified Datelast_modified_date | Text | Example: 2026-06-17 |
Known Exploited in the Wildknown_exploited_in_the_wild | Yes or no | Example: Yes |
Example result
For Cve Number: 2023-23397
{
"nvd_link": "https://nvd.nist.gov/vuln/detail/CVE-2023-23397",
"severity": "Critical",
"cve_number": "CVE-2023-23397",
"cvss_score": 9.8,
"cwe_number": "CWE-294",
"references": [
{
"link": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397",
"source": "[email protected]"
},
{
"link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-23397",
"source": "www.cisa.gov"
}
],
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"description": "Microsoft Outlook Elevation of Privilege Vulnerability",
"cvss_version": "3.1",
"attack_method": "over the network, no login needed, no user action",
"weakness_type": "Authentication Bypass by Capture-replay",
"published_date": "2023-03-14",
"affected_products": [
"Microsoft 365 apps: version unspecified",
"Microsoft office: version 2019",
"Microsoft office long term servicing channel: version 2021"
],
"last_modified_date": "2026-06-17",
"known_exploited_in_the_wild": true
}Search vulnerabilities
1 credit per runFind known vulnerabilities matching a product or vendor name, newest first. Includes published date, severity, affected versions when reported, and whether each CVE appears in CISA’s known exploited catalog. Keyword matches may include related products.
Uses National Vulnerability Database and cisa.gov.
What you provide
| Field | Type | Required | Description |
|---|---|---|---|
Productproduct | Text | Required | Product and/or vendor name, such as Apache Tomcat.Example: Apache Tomcat |
Severityseverity | Text | Optional | Severity to include, such as critical; any includes unrated flaws.Example: Critical |
Max Resultsmax_results | Number | Optional | Maximum number of results, such as 20 (up to 100).Example: 3 |
Published Afterpublished_after | Date | Optional | Include vulnerabilities published on or after this date, such as 2025-01-01.Example: 2025-01-01 |
What you get
| Field | Type | Description |
|---|---|---|
Vulnerabilitiesvulnerabilities | List | |
Nvd Linkvulnerabilities[].nvd_link | Text | NVD vulnerability page.Example: https://nvd.nist.gov/vuln/detail/CVE-2026-24858 |
Severityvulnerabilities[].severity | Text | Severity in words, or Unknown when unrated.Example: Critical |
Cve Numbervulnerabilities[].cve_number | Text | CVE identifier.Example: CVE-2026-24858 |
Cvss Scorevulnerabilities[].cvss_score | Number | CVSS base score from 0 to 10 when available.Example: 9.8 |
Descriptionvulnerabilities[].description | Text | English-language vulnerability description.Example: A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through… |
Published Datevulnerabilities[].published_date | Date | Publication date.Example: 2026-01-27 |
Affected Versionsvulnerabilities[].affected_versions | Text | Affected product versions when reported.Example: Fortinet FortiSwitchManager: from 7.2.2 through 7.2.5; Fortinet FortiOS: from… |
Known Exploited in the Wildvulnerabilities[].known_exploited_in_the_wild | Yes or no | Whether this CVE appears in the CISA known exploited catalog.Example: Yes |
Example result
For Product: Zzxzznoexistentbrand98765, Max Results: 3
{
"vulnerabilities": []
}For developers
Run this workflow from your own code. In Studio, turn on Developer mode and create an API key.
# First set your key: export FOUS_API_KEY='YOUR_FOUS_API_KEY'
: "${FOUS_API_KEY:?Set FOUS_API_KEY before running this example}"
curl 'https://api.fous.com/v1/query' \
--fail-with-body --silent --show-error --max-time 120 \
-H "Authorization: Bearer $FOUS_API_KEY" \
-H 'Content-Type: application/json' \
--data-raw '{
"api": "@national-vulnerability-database",
"visibility": "public",
"operation": "get_vulnerability",
"version": 1,
"input": {
"cve_number": "2023-23397"
},
"response": {
"format": "json"
}
}'What you can do with it
- Find vulnerabilities affecting a product or vendor.
- Prioritize vulnerabilities by severity and publication date.
- Review affected versions when planning software updates.
- Check whether a CVE appears in CISA’s known exploited catalog.
- Investigate a CVE’s attack conditions and references.
Questions
Is Fous affiliated with National Vulnerability Database?
No. Fous is not affiliated with National Vulnerability Database. This workflow reads the public nvd.nist.gov website and returns its data.
How much does it cost?
Each run costs 1 credit. With pay-as-you-go, a credit costs 1¢; monthly plans cost less per credit.
Do I need a National Vulnerability Database account?
No. You only need a Fous account.
How current is the data?
Fous gets the data from nvd.nist.gov when you run it; repeating the same request within a day may return the saved result. Fous checks this workflow automatically; it last passed a check on Sep 30, 2026.
Which vulnerabilities affect a particular product or vendor?
Search vulnerabilities finds matches and returns severity, publication dates, affected versions when reported, and whether each CVE appears in CISA’s known exploited catalog.
What are the details for a specific CVE?
Get vulnerability returns the CVE’s description, risk score, attack conditions, affected products, weakness, dates, exploitation listing, and references.
Does a CVE appear in CISA’s known exploited catalog?
Get vulnerability reports whether the CVE appears in CISA’s known exploited catalog. A no does not rule out exploitation.