Six vulnerability databases, side by side.
Sweep once.
Know every CVE.
Type a package or a CVE ID and CVEsweep asks six databases in parallel — every advisory, every severity, and the exact version that fixes it.
- 6databases
- ~1sper search
- ✓fix versions included
- ⊘no account needed
Why CVEsweep
-
Six databases, one answer
NVD, OSV.dev, GitHub Advisory, CIRCL, OSS Index and Snyk — queried in parallel, not one at a time.
-
About your package, not the keyword
Results are scoped to the package you asked for, so “express” never drags in “Express Checkout”.
-
The fixing version, highlighted
Every advisory lists the affected ranges and the first version that fixes it.
-
CVE IDs work too
Paste a CVE ID and see every source that reports it, side by side.
-
Fast by design
Six parallel fan-outs with a short server-side cache — repeat searches come back instantly.
-
No account, no tracking
No sign-up, no cookies, nothing stored about you. Type, read, go.
The six databases
- NVDNIST
The official U.S. vulnerability catalogue.
- OSV.devGoogle
Open, distributed vulnerability data for open-source ecosystems.
- GitHub Advisorypowers npm audit
npm advisories, from the registry you install from.
- CIRCLEU aggregator
An aggregated European vulnerability feed.
- OSS IndexSonatype
Supply-chain security intelligence.
- SnykSnyk
A security vendor's vulnerability database.
How it works
- 1
Type what you know
A package name, package@version, or a CVE ID.
- 2
We sweep six databases
All six sources are queried in parallel and merged into one answer.
- 3
Read the fix
Severity, affected versions and the first version that closes the hole.