/ Best runtime scanner
FAQ External API

Runtime CVE scanner for installed software

Upload installed software. We map each product CPE → CVE and list known vulnerabilities.

  1. Pick OS
  2. Copy command
  3. Upload .txt
  4. View results
Loading command…

↳ Run the command, then upload the result file

Format: plain-text inventory (.txt) — package/app names with versions.

No client data stored. Matched against NVD — your file is not retained after the scan.

◈ Catalog preview in our DB (0 CVEs) — upload scan_results.txt to see matches for your system
Filter:
0 CVEs · page 1/1
CVE IDSeverityCVSSProductVersionPublishedPatch
No CVEs to show

NVD data · 2026-07-21 · No client data stored

How CVEScan works

Upload installed software. We map each product CPE → CVE and list known vulnerabilities.

  1. Pick your OS — Choose macOS, Linux, Windows, iPhone, or Android to get the right inventory command.
  2. Copy & run the command — Run a read-only command locally to list installed packages and versions into scan_results.txt.
  3. Upload your inventory — Upload the output file. Nothing is stored — the scan runs and client data is discarded.
  4. Match CPE → CVE — CVEScan resolves products to CPE and matches them against NVD for known CVEs with CVSS severity.

Scan modes

  • Local Programs — Upload installed software. We map each product CPE → CVE and list known vulnerabilities.
  • Browser — Enter a website URL. We probe public headers/HTML for stack signals and match related CVEs.
  • Network — Run nmap service detection, upload the XML report, and match exposed services to CVEs.

Privacy

No client data stored. Upload an inventory file, get matched CVEs from NVD — your scan_results.txt is not retained after the scan.

Read more in the CVEScan FAQ and External API docs.

© Viktor Hnativ 2026 · AI based · cvescan.app ·

LinkedIn · [email protected]

0 unique users