Google & OpenSSF OSV Database · Vulnerability Intelligence

Open-Source
OSV Vulnerability Scanner

Real-time dependency auditing across npm, PyPI, Go, Maven, Cargo, & Composer. Detect CVEs, CVSS scores, and patch recommendations instantly.

Single Package Scan

Query vulnerability records for a specific library name and version.

Project Manifest Batch Scan

Supports package.json, requirements.txt, go.mod, pom.xml, Cargo.toml, composer.json

Click here or drag & drop a manifest file

Extracts package dependencies and batch scans vulnerabilities simultaneously

CVE & OSV Vulnerability Intelligence Lookup

Enter a vulnerability identifier such as CVE-2023-30861, GHSA-36p3-wjmg-865f, or OSV-2020-111 to view CVSS score, affected versions, and remediation guidance.

File Hash Version & Risk Detector

Determine package versions and security risk from repository source file hashes.

Notice