
Eleven vulnerability intelligence sources correlated into one decision.
Do I need to stop what I’m doing, right now? That’s the only question that matters when a CVE lands on your desk. CVEHawk answers it in about a second — with no API key, no subscription, and no cloud.
Windows 10/11 · v3.1.0 · free · no API key, no account
Roughly 250 new CVEs are published every day. Most scanners hand you a severity number and a queue sorted by it — so you patch a 9.8 that nobody has ever exploited while a 7.5 with a working Metasploit module and confirmed in-the-wild activity sits three pages down.
Severity is not risk. Risk needs exploit availability, exploitation probability, confirmed attacker use, and how reachable the thing actually is. That data exists, in public, spread across eleven services that don’t talk to each other.
CVEHawk reads all eleven and gives you one answer you can defend in a meeting.
No black box, no proprietary magic number. Ask CVEHawk why, and it tells you.
Verbatim output from cvehawk lookup CVE-2021-44228 --explain. The factors total 109 and the score is capped at 100. The SSVC verdict comes from CISA’s own published decision tree — not a number we invented.
A desktop app with a terminal built in. Point and click, or type — same engine either way.

Overview — feed freshness and cache state up top, newly published CVEs below, already scored and triaged.

Lookup — every risk point attributed, then the exploit inventory itself: weaponized Metasploit modules with the command to run them.

Search — query NVD by keyword, product, CWE or KEV status, ranked by real-world risk rather than raw severity.

CISA KEV — the catalogue of confirmed in-the-wild exploitation, filterable by vendor, with ransomware use flagged.

Monitoring — watch a product, a vendor or a single CVE, and get a Discord message the moment something changes.
Not “an exploit may exist” — the actual artifacts, ranked by confidence. Exploit-DB entries, Metasploit modules with the command to run them, Nuclei templates you can scan your own estate with this afternoon, and curated proof-of-concepts. Log4Shell resolves to 174 of them.
CISA Coordinator v2.0.3, the full 36-row decision table transcribed from CERT/CC. Act, Attend, Track* or Track — the same framework CISA uses.
Bulk corpora are cached locally in a compressed index. Once warm, lookups keep working on a plane, in a SCIF, or behind an air gap.
Point it at CycloneDX or SPDX and it resolves every dependency against OSV, then ranks findings by what's genuinely dangerous — not by how many it can produce.
Fail a build on KEV-listed dependencies or a risk threshold. Emits SARIF, so findings land natively in GitHub code scanning.
Discord and webhook alerts that fire on transitions — a new KEV listing, a first public exploit, an EPSS spike. Never the same CVE twice.
Every one of these is a free public service. No paid tier, no waitlist, no key to manage or rotate. An optional free NVD key raises a rate limit; nothing breaks without it.
| Surface | For |
|---|---|
| Desktop app | Windows installer with a built-in terminal. Point and click, or type. |
| CLI | cvehawk lookup CVE-2021-44228 --explain — scriptable, pipeable, colour-aware. |
| REST API + dashboard | FastAPI with OpenAPI docs. Drop it behind your own auth. |
| MCP server | Give Claude, or any MCP client, live vulnerability intelligence. |
| Discord bot | /lookup, /watch, and an automatic feed of newly published CVEs. |
Start menu entry, desktop shortcut, and cvehawk added to your PATH. Installs per-user — no admin rights needed.
The Discord is where releases get announced, questions get answered, and the CVE feed bot posts newly published vulnerabilities as they land.
Linux and macOS builds of the desktop app are planned.
Yes. Every intelligence source it reads is a free public service, and there is no paid tier. We ask for an email so we can send you the download link and let you know about releases — there is no account to create and no card involved.
No. CVEHawk sends CVE identifiers and package names to public APIs to look them up. There is no telemetry, no account, and no CVEHawk server — the desktop app talks to a local process bound to loopback.
NVD publishes in roughly hourly batches and CVEHawk reads the live API, so lookups are as current as NVD. KEV and EPSS refresh daily; the exploit corpora daily.
Yes. Enterprise support and integration work are available through Devora.