Back to site
Intelligence

CVE Stack Analyzer

Select your technology stack and discover vulnerabilities published in the last 90 days. Live data from NVD — National Vulnerability Database.

NVD API activeLast 90 days • CVSS v3.1
Note: results are based on keyword search, not CPE/version-specific matching. Use as a quick indicator, not as a precise assessment of your installed stack.
EDR / Endpoint
SIEM / SOC
Firewall / Network
Cloud Platform
Identity / IAM
OS / Platform
Stack selected: 0 products

How it works

Read this before you act on the output

This is an indicator, and the difference between an indicator and an inventory is the difference between a hint and a decision.

Common questions

How current is the data
It is read live from NVD each time you run an analysis, with brief caching. NVD itself takes time to enrich a record after disclosure, so a very recent CVE may appear without a score yet.
Why is my product not in the list
The selector covers common enterprise products across endpoint, SIEM, network, cloud, identity and operating systems. It is a starting set, not the NVD catalogue, which runs to thousands of entries.
Do you record what I select
No. The selection lives in the page and is not stored or associated with you. Only the product keyword travels to the proxy, never anything identifying.
Can I use it for an audit
Not as evidence. An assessor will ask for output from an authenticated scanner tied to an asset inventory. This is useful earlier than that: to see whether a stack deserves a closer look at all.
What should I do with a critical result
Check whether the version you run is actually affected, whether the component is reachable from outside, and whether the vendor has published a fix. If those three answers are unclear, that is precisely the point at which a conversation is worth more than another tool.