Google & OpenSSF OSV Database · Vulnerability Intelligence
Open-Source
OSV Vulnerability Scanner
Real-time dependency auditing across npm, PyPI, Go, Maven, Cargo, & Composer. Detect CVEs, CVSS scores, and patch recommendations instantly.
Single Package Scan
Query vulnerability records for a specific library name and version.
Project Manifest Batch Scan
Supports package.json, requirements.txt, go.mod, pom.xml, Cargo.toml, composer.json
Click here or drag & drop a manifest file
Extracts package dependencies and batch scans vulnerabilities simultaneously
CVE & OSV Vulnerability Intelligence Lookup
Enter a vulnerability identifier such as CVE-2023-30861, GHSA-36p3-wjmg-865f, or OSV-2020-111 to view CVSS score, affected versions, and remediation guidance.
File Hash Version & Risk Detector
Determine package versions and security risk from repository source file hashes.