The primary objective of this software is to avoid doing direct lookups into public CVE databases. This reduces leaking sensitive queries and improves performance.

cve-search has a back-end to store vulnerabilities and related information. It comes with a web interface to search and manage vulnerabilities. Additionally, it has several tools to query the system and a web API interface.

cve-search is commonly used for password strength testing, security assessment, vulnerability management, or vulnerability scanning. Target users for this tool are pentesters, security professionals, and system administrators.


  • Application programming interface (API) available
  • Command line interface
  • Tool allows multiple integrations
  • Web interface

  • + More than 10 contributors
  • + More than 500 GitHub stars
  • + The source code of this software is available

Cve-search was created by Wim Remes. Currently the project is managed by Alexandre Dulaunoy, Pieter-Jan Moreels.


Cve-search is known to work on Linux.


Several dependencies are required to use cve-search.

  • Flask
  • Redis
  • Werkzeug
  • click
  • flask-login
  • flask-pymongo
  • irc
  • itsdangerous
  • jinja2
  • lxml
  • passlib
  • pymongo
  • python-dateutil
  • pytz
  • requests
  • six
  • sleekxmpp
  • tornado
  • whoosh
  • xlrd

OpenVAS is a framework of several services and tools offering a vulnerability scanning and vulnerability management solution.


ThreatPinch Lookup

ThreatPinch is a Chrome extension to perform information lookups on data artifacts like domain names, hashes, IP addresses, and more.



vFeed is a set of tools around correlated vulnerability and threat intelligence. It provides a database, API, and supporting tools to store vulnerability data.

