Analyse your whole asset list at once

Searching finds one product at a time. Upload your inventory as CSV, Excel or JSON and every asset is checked against the same sources, with actively exploited vulnerabilities first.

  • Severity, exploitation probability and known exploitation per asset
  • Combined risk: which findings reinforce each other
  • Processed in memory. Nothing is written to our database.

How the service works

Search for a vendor, a product or a CVE identifier. Add a version number to have it assessed against the affected ranges published by the sources. The answer distinguishes between five outcomes: confirmed affected, confirmed not affected, possibly affected, no version data, and cannot be determined.

Important: No results does not mean a system is safe. The service covers published vulnerabilities in its sources, and a vulnerability can exist without having been published yet.

How results are ordered

Actively exploited vulnerabilities (CISA KEV) come first, then confirmed version matches, then the probability that the vulnerability will actually be exploited (EPSS), then CVSS score, then recency. Probability before theoretical severity is a deliberate choice: a critical score that nobody exploits should not outrank a medium one that is being exploited today. The ordering is Berigo's editorial choice; every number shown is the source's own.