CVEFinder.io scans websites to identify detected technologies, vulnerable npm dependencies, and known CVEs. It addresses the need for fast vulnerability intelligence on external web properties by performing technology and dependency detection without requiring login for basic use.
The service offers single scans and bulk scans with a maximum of 20 URLs. Anonymous scans are public while free sign-up enables private scans. Previously scanned URLs do not count toward daily limits. It detects technologies with version and confidence scores, as shown in example results for items such as Nginx 1.14.0 at 95 percent confidence, Node.js 14.17.0 at 88 percent, Express 4.17.1 at 75 percent, and React 17.0.2 at 100 percent. npm dependency analysis examines package.json files to list packages along with associated CVEs, for example identifying three CVEs in lodash 4.17.15, one in minimist 1.2.0, and zero in react 17.0.2. Detected CVEs include severity ratings and summaries such as critical issues for CVE-2025-55182 in React Server Components and CVE-2017-20005 in Nginx.
CVEFinder.io also provides search access to a CVE database. Aggregate statistics on the site track total CVEs, products, vendors, scans, and exploits. The tool is delivered as a web-based service with options for both public anonymous results and registered-user private scans.
In the LLM eval & observability space, CVEFinder.io takes a focused approach. It focuses on identifying known vulnerabilities and insecure dependencies on any public website without manual analysis. It is built as a B2B product for security researchers and developers. A free plan is available. It ships for the web.
CVEFinder.io first shipped in 2024. Key capabilities include Website Scanning, Technology Detection, and Dependency Analysis.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Same category — not a similarity match