🔎 Look up a CVE
NVD details, CVSS, mitigations, and an AI summary — up to 10 free lookups/day.
Turn CVE findings into context-aware risk decisions
CVE Risk Analyzer transforms raw vulnerability scans into a context-adjusted, auditable
score-of-record: AI-assisted mitigation surveys, a deterministic risk engine, and live CVE
enrichment from NVD — without infrastructure identifiers ever leaving your boundary.
SOC-aware workflow · No infrastructure identifiers sent to the AI provider · Every score change audited
🛰️ Latest critical CVEs
CVSS ≥ 9.0, newest first
CVE-2026-67614
CVSS 9.8
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated re…
CVE-2026-68431
CVSS 9.1
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requests The receive path…
CVE-2026-14526
CVSS 9.8
The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. T…
CVE-2026-67342
CVSS 9.8
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafa…
CVE-2026-67341
CVSS 9.8
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attack…
CVE-2026-67340
CVSS 9.8
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTrigger…
What you get
🧭
AI-assisted mitigation surveys
Per-finding questions that adjust the score to the controls actually in place.
⚖️
Deterministic score-of-record
A reproducible risk number the model can advise on but never silently move.
📡
Live CVE enrichment from NVD
Authoritative CVSS, CWE, and descriptions fetched once and reused across assets.
📋
Audit-ready reporting
Every override carries who, when, and why — exported alongside the score.