Documentation menu

Guides

CVE database

Search the vulnerability database behind your findings.

CVE database in the app’s sidebar gives you direct access to the vulnerability database boring.tools matches against — the same OSV data, refreshed every five minutes. Use it to look up an advisory you read about, or to check whether a package has known issues before you add it.

Searching

Type an advisory id (GHSA-…), a CVE id (CVE-2026-…) or a package name. You can narrow the results by:

  • Ecosystem — the package ecosystems present in the database
  • Minimum severity — a CVSS score threshold
  • Published — a date range
  • Hide withdrawn — leave out advisories that were withdrawn

Results are sorted by publication date or by severity.

Advisory details

An advisory page shows the summary and full description, the CVSS score and vector, publication and modification dates, aliases, the affected packages with their vulnerable and fixed version ranges, and links to references such as the original report and patches.

Advisories vs. CVE ids

A CVE id names a vulnerability; an advisory describes it for one ecosystem. The same CVE is often published in several advisories — for example by GitHub and by an ecosystem’s own database. boring.tools shows each advisory separately, and findings reference the advisory id, with the CVE id listed as an alias.