CVE Intelligence Search
Search CVEs by identifier or keyword, filter by time window and severity, sort every result column, and preserve the current table view during export.
DarkMatter Software · Built with DarkForge IDE
A standalone Linux vulnerability intelligence workstation for CVE search, local caching, project dependency analysis, defensive assessment, evidence-based correlation, and professional reporting.
Vulnerability Intelligence
CVE Explorer combines public vulnerability data with a local intelligence cache and project-aware evidence analysis designed for real software and systems work.
Search CVEs by identifier or keyword, filter by time window and severity, sort every result column, and preserve the current table view during export.
Use NIST NVD as the primary CVE source and optionally enrich results with CISA Known Exploited Vulnerabilities and FIRST EPSS probability data.
Store retrieved intelligence locally in SQLite for fast cached searches, offline review, assessment correlation, and repeatable analysis.
Inspect local Python, Go, and PHP dependency manifests without executing project code, then correlate declared dependencies against cached vulnerability intelligence.
Perform authorized TCP service discovery, banner collection, HTTP header inspection, TLS certificate review, and conservative CVE correlation against exposed services.
Export structured JSON for future import workflows and polished standalone HTML reports for searches and defensive assessments.
DarkMatter Evidence Engine
CVE Explorer separates the severity of a vulnerability from the strength of the evidence that a specific project or target is actually affected.
Defensive Assessment
The assessment engine is deliberately conservative. It collects non-invasive service evidence and treats CVE correlations as investigative leads unless stronger applicability evidence exists.
The default scanner identity is visible and configurable:
DarkMatter CVE Scanner/1.0 (Vulnerability Assesment Scanner)
The scanner does not attempt passwords, exploit payloads, destructive requests, authentication bypasses, or stealth behavior. Remote assessment is intended only for systems you own or are explicitly authorized to test.
Standalone Linux Release
Clean standalone build with its own local user-data storage. DarkForge compatibility remains in the source project, but DarkForge is not required to run the standalone application.
Frequently Asked Questions
No. The standalone release runs independently. The project retains DarkForge compatibility for development and integration, but normal users do not need DarkForge installed.
No. An NVD API key is optional and can be entered in Settings. User credentials and configuration remain local to the user's data directory.
No. It inspects supported dependency manifests such as requirements.txt, go.mod, and composer.json without importing, compiling, or executing the inspected project.
No. CVE Explorer separates related intelligence from applicability. Package-name matches remain informational until stronger product and version evidence supports a more confident finding.
Yes, when you own the target or have explicit authorization to assess it. The scanner performs conservative service discovery and fingerprint collection rather than exploitation.
The standalone application stores runtime settings, presets, cached CVEs, and assessment history in the user's local application-data location instead of shipping user data inside the distribution.