All checks

Vulnerabilities

CVEs Shodan links to the services running on the host

What it is

Lists the CVEs associated with the services running on this host (matched from the product and version each service advertises). Indicates known exploited CVEs (CISA KEV) and the EPSS exploit likelihood and CVSS severity and linking each to it's record in the National Vulnerability Database.

Why it matters

A starting point rather than a verdict. Matching is done on banner versions, so expect false positives from backported patches, and do not read an empty list as proof that the host is clean.

Related checks