Live CVE & Open-Source Vulnerability (OSV.dev) Exploit Inspector (2026)

Query Google's real-time OSV.dev Vulnerability Database by CVE ID, GHSA advisory, or package version (`npm`, `PyPI`, `Go`, `Maven`, `crates.io`) to inspect CVSS vectors, fixed versions, and CISA KEV status.

Live CVE & Open-Source Vulnerability (OSV.dev) Exploit Inspector — Interactive Console
Runs locally in your browser • Instant output
Famous CVE Presets:
1. Lookup by CVE / GHSA ID (GET /v1/vulns)
2. Query Package Ecosystem (POST /v1/query)
CVE-2021-44228 (GHSA-jfh8-c2jp-5v3q)

org.apache.logging.log4j:log4j-core (Maven)

CRITICAL • CVSS 10.0

Apache Log4j2 JNDI features used in configuration, log messages, and parameters do not protect against attacker-controlled LDAP and other JNDI related endpoints, enabling unauthenticated Remote Code Execution (RCE).

Affected Version Range
>= 2.0-beta9, < 2.15.0 (excluding 2.12.2, 2.12.3, 2.3.1)
Patched / Fixed Version
2.15.0 / 2.17.1+ (JNDI disabled by default)
Official References (Verified OSV.dev Advisory Database):
  • https://osv.dev/vulnerability/GHSA-jfh8-c2jp-5v3q
  • https://nvd.nist.gov/vuln/detail/CVE-2021-44228
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![Live CVE & Open-Source Vulnerability (OSV.dev) Exploit Inspector](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/live-cve-osv-vulnerability-lookup/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/live-cve-osv-vulnerability-lookup/">Live CVE & Open-Source Vulnerability (OSV.dev) Exploit Inspector — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: Live CVE & Open-Source Vulnerability (OSV.dev) Exploit Inspector

Quick Answer & 2026 Technical Summary (cve osv vulnerability lookup)Updated 2026 Standard

Traditional NVD CVE records use human-edited CPE (Common Platform Enumeration) strings that often struggle to map exact open-source package versions and git commit hashes. OSV (Open Source Vulnerabilities) aggregates advisories from GitHub (GHSA), PyPA, RustSec, Go, and NVD using precise machine-readable SemVer and git commit ranges keyed directly to package managers. Use this interactive cve osv vulnerability lookup above to test osv dev package vulnerability scanner, cve lookup tool online, and npm pypi go cve checker locally in your browser with zero server uploads.

Target Keyword Spec: cve osv vulnerability lookup | Modules: Live Google OSV.dev API Integration • Multi-Ecosystem Package Audit (npm, PyPI, Go, Cargo, Maven) • Exact Introduced vs Patched Version Timeline
Primary Focus: cve osv vulnerability lookup
Core Capability: osv dev package vulnerability scanner
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
Live Google OSV.dev API Integrationosv dev package vulnerability scannerQueries `api.osv.dev/v1` directly from your browser to fetch real-time vuln...Software Supply Chain & Dependency Triage
Multi-Ecosystem Package Audit (npm, PyPI, Go, Cargo, Maven)cve lookup tool onlineTest specific dependency versions (e.g., `lodash 4.17.15`, `urllib3 1.26.4`...Penetration Test Service Version Mapping
Exact Introduced vs Patched Version Timelinenpm pypi go cve checkerParses OSV `affected[].ranges` commit and SemVer event streams to highlight...DevSecOps Incident Response
Execution & Privacy Architecture100% Client-Side WebCrypto / JS Sandbox0 Bytes Sent to External ServersSafe for internal SOC & authorized lab artifacts
NIST SP 800-53 / OWASP AlignmentOWASP ASVS v4.0.3 / NIST CSF 2.0Deterministic Rule & Header VerificationMaps findings to actionable hardening controls
Cryptographic & Entropy StandardSHA-256 / AES-256-GCM / Argon2id≥ 128-bit Effective Security MarginMeets 2026 post-quantum & zero-trust baselines
In-Depth ZerosUniverse Tutorial

10 Best Cybersecurity & Vulnerability Scanning Tools in 2026

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use Live CVE & Open-Source Vulnerability (OSV.dev) Exploit Inspector

01

Choose CVE/Advisory ID Lookup or Package Ecosystem Scan

Toggle between searching a specific identifier (`CVE-2024-3094`, `GHSA-...`) or querying an open-source ecosystem (`npm`, `PyPI`, `Go`, `Maven`, `crates.io`).

02

Enter Your CVE ID or Package Name + Version

Type the vulnerability ID or enter a package name (e.g., `express`) and optional version (e.g., `4.17.1`) and click Query OSV Database.

03

Inspect Affected Ranges & Minimum Fixed Versions

Review the vulnerability summary, CWE classification, CVSS vector string, and the exact SemVer upgrade version that resolves the flaw.

04

Copy Upgrade CLI Commands or Export JSON Report

Copy the generated `npm install`, `pip install --upgrade`, or `go get` remediation command for your engineering team.

Key Capabilities & Technical Architecture

Live Google OSV.dev API Integration

Queries `api.osv.dev/v1` directly from your browser to fetch real-time vulnerability records by CVE/GHSA/OSV identifier or ecosystem package name and version.

Multi-Ecosystem Package Audit (npm, PyPI, Go, Cargo, Maven)

Test specific dependency versions (e.g., `lodash 4.17.15`, `urllib3 1.26.4`, `org.apache.logging.log4j:log4j-core 2.14.1`) to see every affecting advisory.

Exact Introduced vs Patched Version Timeline

Parses OSV `affected[].ranges` commit and SemVer event streams to highlight the exact version where a flaw was introduced and the minimum safe upgrade version.

CVSS Vector & Famous CVE Quick-Load Presets

Includes 1-click presets for Log4Shell (`CVE-2021-44228`), XZ Utils Backdoor (`CVE-2024-3094`), HTTP/2 Rapid Reset (`CVE-2023-44487`), and Next.js/React ecosystem advisories.

Practical Use Cases

Software Supply Chain & Dependency Triage

Verify whether a pinned npm, Python, or Go library version in your `package.json` or `requirements.txt` is affected by known CVEs and identify the non-breaking patch release.

Penetration Test Service Version Mapping

Cross-reference discovered software versions and CVE identifiers with upstream git commits, PoC advisories, and CVSS severity vectors.

DevSecOps Incident Response

Rapidly inspect breaking zero-day advisories (CVE, GHSA, RustSec, PySEC) in a clean dashboard with direct links to patches and NVD references.

Frequently Asked Questions (FAQs)

What is the difference between MITRE/NVD CVE records and Google's OSV.dev database?+

Traditional NVD CVE records use human-edited CPE (Common Platform Enumeration) strings that often struggle to map exact open-source package versions and git commit hashes. OSV (Open Source Vulnerabilities) aggregates advisories from GitHub (GHSA), PyPA, RustSec, Go, and NVD using precise machine-readable SemVer and git commit ranges keyed directly to package managers.

What is the difference between a CVE, a CWE, and the CISA KEV catalog?+

A CWE (Common Weakness Enumeration, like CWE-89 SQL Injection) describes the underlying category of software bug. A CVE (Common Vulnerabilities and Exposures, like CVE-2021-44228) identifies a specific publicly disclosed flaw in a specific product. The CISA KEV (Known Exploited Vulnerabilities) catalog lists the subset of CVEs confirmed to be actively exploited in the wild.

How do I know which version of a package fixes a listed vulnerability?+

In OSV records, each affected package entry contains an `events` array with `introduced` and `fixed` markers. Upgrading to at least the version listed next to the `fixed` marker ensures the patch commit is included in your build.

Why can a CVE have a high CVSS score but still be unexploitable in my application?+

This concept is known as 'Reachability'. A dependency may contain a vulnerable function (such as an unsafe XML parser or regex method), but if your application never imports or calls that specific code path with untrusted user input, the vulnerability is not reachable in your runtime context.

Does this lookup tool upload my private dependency manifests?+

No. Your browser sends a direct, anonymous HTTPS request containing only the single CVE ID or package name you typed to `https://api.osv.dev/v1`.