Catalogue search
- When to use it
- Use this when you have one identifier, a vendor name, a product name or a few descriptive words and want to find the relevant vulnerability report.
- How it works
- Enter a complete CVE, EUVD or BSI WID-SEC identifier to search every available catalogue year. Exact identifier searches ignore the selected year and other filters so an older record is not hidden accidentally. A word search, such as a vendor or product name, stays within the filters you selected.
- What the result means
- The page shows matching records with a short description, severity, exploitation indicators and remediation state. Open a record to see the complete evidence, affected products, versions, fixes and source links.
- What it cannot tell you
- A search result does not prove that the product is installed in your environment or that the vulnerability applies to your configuration. A reserved or newly published identifier may also be absent until it reaches a configured source.
Filters and sorting
- When to use it
- Use filters when the search results are too broad or when you want to review a defined group, such as confirmed exploited CVEs, critical records or vulnerabilities with a patch reference.
- How it works
- Choose a publication year and one or more evidence filters. The page combines the selected conditions, so every additional filter can reduce the result set. Sorting changes the order of the same result set; it does not change the underlying evidence.
- What the result means
- The matching count and record list update to reflect the current selection. Clear individual filters or use the clear action when a combination becomes too narrow.
- What it cannot tell you
- Filters can only use information that a source supplied and BlackTree retained. An empty result can mean that no record matches, but it can also mean that a field is missing. For example, not being listed in KEV is not proof that exploitation has never occurred.
Full CVE report
- When to use it
- Open the full report when you need to understand one vulnerability before deciding whether to investigate, escalate or schedule remediation.
- How it works
- The report brings together the CVE description, CVSS severity, exploitation evidence, EPSS forecast, BlackTree assessment, product-specific affected ranges, fixed versions, vendor guidance, national guidance, source links and material change history.
- What the result means
- Each conclusion remains attached to its source. Product names stay beside their own affected and fixed versions so version ranges from different products are not combined into one instruction.
- What it cannot tell you
- The report does not scan your assets, confirm that an affected feature is enabled, measure internet exposure or approve a production change. Validate the product, version and vendor instruction against your own inventory and change process.
Country reports
- When to use it
- Use a country tab when you want to read guidance from a national cyber-security authority or compare that guidance with the main CVE record.
- How it works
- BlackTree matches national advisories to the CVE and displays every retained source field. Interface labels and BlackTree fallback text use the local language. Wording supplied by the authority remains as published, including any English vendor text quoted inside a local-language bulletin.
- What the result means
- You can review the authority’s summary, impact, affected systems, remediation, exploitation statements, references and official bulletin link without losing the connection to the main CVE report.
- What it cannot tell you
- No country advisory means only that BlackTree has not matched one from that authority. It does not mean the vulnerability is irrelevant, unexploited or safe in that country.
Known Exploited
- When to use it
- Use this page to start with vulnerabilities for which CISA has confirmed evidence of exploitation in the wild.
- How it works
- The page lists current CISA Known Exploited Vulnerabilities, normally with the newest catalogue additions first. Each item links to the full BlackTree report and shows the vendor, product, severity and remediation deadline when available.
- What the result means
- A KEV listing is strong evidence that defenders should evaluate exposure and remediation promptly. Use the linked report to identify the affected product branch and the correct fix.
- What it cannot tell you
- This is not a complete list of every vulnerability used by every attacker. Absence from CISA KEV does not prove that exploitation has not happened, and a KEV listing does not prove that your environment contains the affected product.
Patch Intelligence
- When to use it
- Use Patch Intelligence to review monthly Patch Tuesday releases and other supported vendor bulletin information as an operational release cycle.
- How it works
- The page groups advisories by release cycle, vendor, product and linked CVE. It keeps source availability, validation state and editorial readiness visible so delayed or incomplete source data is not presented as complete.
- What the result means
- You can move from a monthly overview to an individual advisory, see which CVEs and products it covers, and follow the authoritative vendor source before planning deployment.
- What it cannot tell you
- The page cannot determine whether a patch is compatible with your systems, whether a restart is acceptable or whether an entitled vendor note contains extra instructions. Those checks remain part of your testing and change process.
Recent Changes
- When to use it
- Use this page when you want to know what materially changed after a CVE was first published, instead of rereading complete reports manually.
- How it works
- Choose the last 24 hours or last seven days. BlackTree shows meaningful changes to severity, exploitation, remediation, affected products, versions, national guidance and evidence coverage while excluding routine refreshes and cosmetic differences.
- What the result means
- Each item identifies the CVE and the type of change, then links to the report’s change history so you can review the current evidence in context.
- What it cannot tell you
- The history begins when BlackTree observed and stored the field. It may not reproduce every earlier upstream revision, and a quiet period does not mean that vendors have stopped publishing information elsewhere.
Multi-CVE lookup
- When to use it
- Use this when you have a list of CVE identifiers and need one comparison table for an email, spreadsheet or working file.
- How it works
- Paste identifiers or load a TXT or CSV file containing up to 250 unique CVEs. The browser extracts valid identifiers, removes duplicates and reports malformed or unavailable values. The original file stays in the browser; only the normalized CVE identifiers are sent for the lookup.
- What the result means
- The output uses the same columns and values for email, spreadsheet copy and CSV download. Every matched CVE links to its full report. Review affected products, affected versions and fixed versions together before reusing the table.
- What it cannot tell you
- This is not an asset or inventory upload. It cannot decide whether the listed CVEs apply to your systems, and it should never receive hostnames, IP addresses, credentials or incident information.
Inventory applicability
- When to use it
- Use this when you have a supported software bill of materials, usually called an SBOM, and want a first comparison between its components and the CVE catalogue. Optional VEX data can add a vendor or supplier statement about whether a vulnerability affects a component.
- How it works
- Select CycloneDX or SPDX JSON files and, if available, a supported VEX JSON file. The browser reads the original files locally, extracts normalized component identifiers and sends only the information needed for matching. The matcher compares package identifiers, suppliers, products, versions and aliases.
- What the result means
- Matched means that a sufficiently strong relationship was found. Review match means that one or more relationships are plausible but need human checking. Unmatched means no reliable relationship was found. Candidate CVEs link to their full reports.
- What it cannot tell you
- A match does not prove that vulnerable code is installed, enabled, reachable or exploitable. An unmatched result does not mean unaffected. Follow the alias and version checks in the how-to guide and keep uncertain components in manual review.
PDF report
- When to use it
- Use the PDF option when you need a readable point-in-time copy of one CVE report for a meeting, case file or internal review.
- How it works
- The site prepares a print-friendly version of the current report. Choose Save as PDF in the browser print window. The document includes the report identity, generation date, evidence, product-aware remediation and source context available at that moment.
- What the result means
- The saved file can be shared or archived according to your organisation’s rules. Its generation date tells the reader when the evidence was captured.
- What it cannot tell you
- A PDF does not update itself. Reopen the live report and authoritative vendor advisory before acting, especially when the saved copy is more than a few days old or the source is changing quickly.
API access
- When to use it
- Use the API when an approved application needs to read BlackTree catalogue, report, change or applicability information automatically rather than through the website.
- How it works
- The application sends a documented web request and receives structured data that software can process. Protected routes require an access key and apply limits so one client cannot overload the service.
- What the result means
- Responses use stable fields described in the API documentation. Integrators should handle unavailable data, request limits and source-state warnings explicitly rather than treating them as empty or safe results.
- What it cannot tell you
- API access does not grant permission to bypass authentication, collect the entire service without agreement or turn evidence into an automatic patch decision. The calling system remains responsible for credentials, retries, validation and human approval.
What the main report sections mean
- Recommended action
- A BlackTree prioritisation statement derived from the currently stored evidence. It is operational guidance, not an automatic change approval.
- Exploit reality
- Keeps confirmed exploitation, referenced public exploit material, EPSS probability and technical attack conditions separate.
- Affected
- Product-aware affected ranges assembled from the strongest available structured source. Each product stays attached to its own versions.
- Fixed
- Product-aware fixed versions or the strongest available vendor remediation statement. A source link is provided when the structured version field is incomplete.
- Evidence and provenance
- Shows which authority supplied each class of evidence, what is missing, the material change history and links to upstream sources.
- Country tabs
- Show every retained field from the matched national advisory, including published notes, product states, scores, remediation, threats, references and source metadata.
How to interpret labels
A positive label means that an explicit source statement was found. A neutral or unavailable label normally means that the source did not supply enough evidence. It must not be silently converted into a negative conclusion.
- Confirmed exploited: backed by a known-exploited catalogue or explicit authority statement.
- Public exploit referenced: a source points to public material, but BlackTree does not promise that it is safe, functional or weaponised.
- Patch available: an authoritative update, fixed product state or remediation statement exists. Product applicability still needs validation.
- Awaiting fix: no verified fix was found in the currently retained structured evidence.
- Matched inventory: a sufficiently strong component relationship was found.
- Review match: the relationship is plausible but not precise enough for an automatic applicability conclusion.
- Unmatched inventory: no reliable relationship was found. This is not an unaffected result.
