Skip to content
Noroxi
CVE Database
CVE list
1729 actively exploited
Analysis, action score, detection and remediation
My stack
Only the technologies you use
SBOM scanner
Vulnerabilities in your dependency list and the version to upgrade to
Weakness classes
Root causes and fixed code
API and MCP
JSON endpoints, connect Claude and Cursor
Open data
Daily CSV and Parquet snapshots, citation
Researchers
Leaderboard of people and teams credited with CVEs
Methodology
How we calculate the action score
All CVEs
Contribute to an analysis
Services
Web and API penetration testing
Hands-on manual testing focused on the OWASP Top 10 and business logic flaws.
Mobile application testing
iOS and Android apps, tested together with the APIs behind them.
Infrastructure and network penetration testing
Internal and external networks, Active Directory, VPN and endpoints.
Cloud security assessment
Configuration and permissions review across AWS, Azure and GCP.
Red team
An objective-driven exercise that measures how well you detect and respond.
Source code review
Static analysis plus manual review, with every finding tied to a line number.
KVKK and ISO 27001 compliance
With you from gap analysis all the way to the certification audit.
All services
Not sure where to start? Free assessment
Pentest Tools
Security headers test
HSTS, CSP and cookie settings
SSL/TLS check
Certificate chain, protocols, ciphers
Email security
SPF, DKIM and DMARC
External surface discovery
Subdomains in public records
All tools and how they work
Blog
About
Sign in
Free assessment
Sign in
Access your account, manage your watchlist and requests.
Continue with Google
Continue with GitHub
or
Email
Password
Sign in
No account?
Sign up
Forgot password?
EN