🔎 Look up a CVE
NVD details, CVSS, mitigations, and an AI summary — up to 10 free lookups/day.
Turn CVE findings into context-aware risk decisions
CVE Risk Analyzer transforms raw vulnerability scans into a context-adjusted, auditable
score-of-record: AI-assisted mitigation surveys, a deterministic risk engine, and live CVE
enrichment from NVD — without infrastructure identifiers ever leaving your boundary.
SOC-aware workflow · No infrastructure identifiers sent to the AI provider · Every score change audited
🛰️ Latest critical CVEs
CVSS ≥ 9.0, newest first
CVE-2026-47898
CVSS 9.8
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue af…
CVE-2026-12073
CVSS 9.8
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in a…
CVE-2026-58053
CVSS 9.9
Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's Ho…
CVE-2026-12415
CVSS 9.8
The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edi…
CVE-2026-48930
CVSS 9.8
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation i…
CVE-2026-53131
CVSS 9.4
In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui6…
🧭
AI-assisted mitigation surveys
Per-finding questions that adjust the score to the controls actually in place.
⚖️
Deterministic score-of-record
A reproducible risk number the model can advise on but never silently move.
📡
Live CVE enrichment from NVD
Authoritative CVSS, CWE, and descriptions fetched once and reused across assets.
📋
Audit-ready reporting
Every override carries who, when, and why — exported alongside the score.