CVEHawkPowered by Devora
CVEHawk

CVEHawk

Eleven vulnerability intelligence sources correlated into one decision.

Do I need to stop what I’m doing, right now? That’s the only question that matters when a CVE lands on your desk. CVEHawk answers it in about a second — with no API key, no subscription, and no cloud.

Windows 10/11 · v3.1.0 · free · no API key, no account

0
Intelligence sources
0
API keys required
0
Export formats
0
Tests passing
The problem

CVSS 9.8 doesn’t mean drop everything

Roughly 250 new CVEs are published every day. Most scanners hand you a severity number and a queue sorted by it — so you patch a 9.8 that nobody has ever exploited while a 7.5 with a working Metasploit module and confirmed in-the-wild activity sits three pages down.

Severity is not risk. Risk needs exploit availability, exploitation probability, confirmed attacker use, and how reachable the thing actually is. That data exists, in public, spread across eleven services that don’t talk to each other.

CVEHawk reads all eleven and gives you one answer you can defend in a meeting.

Explainable by design

Every point is attributable

No black box, no proprietary magic number. Ask CVEHawk why, and it tells you.

100 CRITICALCVE-2021-44228CISA KEVRANSOMWARESSVC: Act
+32.0CISA KEVlisted in CISA KEV on 2021-12-10; remediation overdue
+22.0EPSS100.0% probability of exploitation within 30 days
+20.0CVSSbase score 10.0 (CRITICAL) v3.1
+18.0Exploit maturityweaponized module available (Metasploit-class)
+8.0Ransomwareknown use in ransomware campaigns
+5.0Attack vectornetwork reachable, no privileges required, no user interaction
+4.0Exploit corroboration151 independent high-confidence exploit artifacts

Verbatim output from cvehawk lookup CVE-2021-44228 --explain. The factors total 109 and the score is capped at 100. The SSVC verdict comes from CISA’s own published decision tree — not a number we invented.

The application

Built for how you actually work

A desktop app with a terminal built in. Point and click, or type — same engine either way.

CVEHawk v3.1.0
CVEHawk overview: feed freshness, indexed CVEs, cache size and the latest published CVEs

Overview — feed freshness and cache state up top, newly published CVEs below, already scored and triaged.

CVEHawk v3.1.0
CVEHawk lookup for CVE-2021-44228 with risk composition and weaponized exploit modules

Lookup — every risk point attributed, then the exploit inventory itself: weaponized Metasploit modules with the command to run them.

CVEHawk v3.1.0
CVEHawk search across NVD, ranked by real-world risk

Search — query NVD by keyword, product, CWE or KEV status, ranked by real-world risk rather than raw severity.

CVEHawk v3.1.0
CISA Known Exploited Vulnerabilities catalogue filtered by vendor, with ransomware flags

CISA KEV — the catalogue of confirmed in-the-wild exploitation, filterable by vendor, with ransomware use flagged.

CVEHawk v3.1.0
CVEHawk monitoring: Discord bot commands, webhook alerts and the product watchlist

Monitoring — watch a product, a vendor or a single CVE, and get a Discord message the moment something changes.

What you get

Everything, without a single API key

Exploit inventory, not rumour

Not “an exploit may exist” — the actual artifacts, ranked by confidence. Exploit-DB entries, Metasploit modules with the command to run them, Nuclei templates you can scan your own estate with this afternoon, and curated proof-of-concepts. Log4Shell resolves to 174 of them.

SSVC decisions

CISA Coordinator v2.0.3, the full 36-row decision table transcribed from CERT/CC. Act, Attend, Track* or Track — the same framework CISA uses.

Works offline

Bulk corpora are cached locally in a compressed index. Once warm, lookups keep working on a plane, in a SCIF, or behind an air gap.

SBOM scanning

Point it at CycloneDX or SPDX and it resolves every dependency against OSV, then ranks findings by what's genuinely dangerous — not by how many it can produce.

CI policy gate

Fail a build on KEV-listed dependencies or a risk threshold. Emits SARIF, so findings land natively in GitHub code scanning.

Change-driven alerts

Discord and webhook alerts that fire on transitions — a new KEV listing, a first public exploit, an EPSS spike. Never the same CVE twice.

Under the hood

Eleven sources, zero credentials

Every one of these is a free public service. No paid tier, no waitlist, no key to manage or rotate. An optional free NVD key raises a rate limit; nothing breaks without it.

NVD 2.0CVE ProgramCISA KEVFIRST EPSSOSVGitHub AdvisoriesExploit-DBMetasploitNucleiPoC-in-GitHubGitHub Search
NVD 2.0CVE ProgramCISA KEVFIRST EPSSOSVGitHub AdvisoriesExploit-DBMetasploitNucleiPoC-in-GitHubGitHub SearchNVD 2.0CVE ProgramCISA KEVFIRST EPSSOSVGitHub AdvisoriesExploit-DBMetasploitNucleiPoC-in-GitHubGitHub Search
Five ways in

Meet your workflow where it is

SurfaceFor
Desktop appWindows installer with a built-in terminal. Point and click, or type.
CLIcvehawk lookup CVE-2021-44228 --explain — scriptable, pipeable, colour-aware.
REST API + dashboardFastAPI with OpenAPI docs. Drop it behind your own auth.
MCP serverGive Claude, or any MCP client, live vulnerability intelligence.
Discord bot/lookup, /watch, and an automatic feed of newly published CVEs.
Get it

Download

Windows installer

Start menu entry, desktop shortcut, and cvehawk added to your PATH. Installs per-user — no admin rights needed.

We’ll email you a confirmation link. One address, one click — no account, and we don’t pass it on to anyone.

Version
3.1.0
Size
42 MB
SHA-256
8e74d1ec2065b2eb5b7d6256442d7d44f0d12d252e56ff6ca33bef7864e34340

Community & support

The Discord is where releases get announced, questions get answered, and the CVE feed bot posts newly published vulnerabilities as they land.

  • Release announcements
  • Direct support from the team
  • Live feed of new CVEs
  • Feature requests and roadmap
discord.gg/XMXKnxJmRZ

Linux and macOS builds of the desktop app are planned.

Questions

The obvious ones

Is it really free?

Yes. Every intelligence source it reads is a free public service, and there is no paid tier. We ask for an email so we can send you the download link and let you know about releases — there is no account to create and no card involved.

Does my data leave the machine?

No. CVEHawk sends CVE identifiers and package names to public APIs to look them up. There is no telemetry, no account, and no CVEHawk server — the desktop app talks to a local process bound to loopback.

How current is it?

NVD publishes in roughly hourly batches and CVEHawk reads the live API, so lookups are as current as NVD. KEV and EPSS refresh daily; the exploit corpora daily.

Can I use it commercially?

Yes. Enterprise support and integration work are available through Devora.