Select your technology stack and discover vulnerabilities published in the last 90 days. Live data from NVD — National Vulnerability Database.
Every query goes to the National Vulnerability Database run by NIST, the public reference catalogue for disclosed vulnerabilities. Nothing on this page connects to your network, reads your configuration or asks for credentials. You pick products from a list and the tool asks NVD what has been published about them.
The results deliberately cover a recent window rather than the whole history of a product. A list of everything ever published for Windows Server is not information, it is noise. Ninety days answers a different and more useful question: what has changed lately that I might have missed.
The request is proxied server-side, so NIST sees the site and not you. Responses are cached briefly so that the same lookup does not hit the upstream API twice, which also keeps the tool responsive when several people use it at once.
Each entry carries the base score assigned by the publishing authority, mapped to the usual four bands. That score describes the vulnerability in the abstract, not in your environment: the same CVE can be urgent on an internet-facing box and irrelevant on an isolated segment.
This is an indicator, and the difference between an indicator and an inventory is the difference between a hint and a decision.