Everything you enter stays in your browser until you download it — nothing is saved to a database or shared with anyone.

Step 1 of 5: Vulnerability Information

Step 1: Vulnerability Information

Looking it up prefills the fields below, including the affected component. You can still edit anything afterward.
Severity is derived automatically from the score.
Affected Component

The specific vulnerable dependency (usually a library), as identified by the CVE. Prefilled from NVD's data when available — enter it manually if not.