Threat intelligence CSIRT-led

CVE Search

Import vulnerability and platform-enumeration data into a local database, then search it through command-line, web and API interfaces.

By CIRCL and project contributors · Luxembourg

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Threat intelligence
Developer or maintainer
CIRCL and project contributors
Recorded country
Luxembourg
Product model
Open source
Deployment
Self-hosted
Software license
AGPL-3.0
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

CIRCL’s published tooling document identifies CIRCL as the CSIRT lead for CVE Search. Its current inventory still includes the project, which also has independent contributors.

Reported capabilities

  • Supports local CVE and CPE lookups.
  • Provides searchable vulnerability records through a web interface and API.

Scope and limits

CIRCL’s former public CVE Search service has been superseded by Vulnerability-Lookup. This record covers the separately maintained self-hosted project.

Inspect the research evidence 5 source observations
  1. identity / capabilities / deployment

    Upstream documentation describes import vulnerability and platform-enumeration data into a local database, then search it through command-line, web and API interfaces. It documents local installation.

    Read source
  2. origin / country

    CIRCL’s published tooling document identifies CIRCL as the CSIRT lead for CVE Search. Its current inventory still includes the project, which also has independent contributors.

    Read source
  3. license

    The upstream license file specifies AGPL-3.0.

    Read source
  4. maintenance

    Repository is not archived; its last recorded push was 2026-09-30. This is an activity signal, not a support guarantee.

    Read source
  5. origin / country

    CIRCL still includes CVE Search in its current project inventory.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.

A threat intelligence workflow for CSIRTs