Knowing you have vulnerable packages is one thing. Finding them across GitLab repos, spreadsheets, and one-off NVD lookups is another. CVE Scanner brings software inventory, vulnerability matching, and dependency sync into a single admin workspace so critical and high issues are hard to miss.
It is built for security and operations teams who need a clear picture of what they run — and which known CVEs apply — without hopping between tools.
What the app does.
CVE Scanner starts with a dashboard: how much software you track, how many CVEs are linked, and how many of those are critical or high, alongside the status of the latest NVD scan.
From there you work through focused tabs. On Software, you build an inventory by hand or from GitLab, attach CPE identifiers, search and filter, and scan one package or the whole list against NVD. On CVEs, you browse matched vulnerabilities and filter by severity, with links to official NVD detail pages. Tags let you label packages and optionally exclude entries from scanning. GitLab sync imports .csproj and package.json dependencies as software entries tagged by repository. Settings shows whether NVD and GitLab are configured.
Together, those views turn scattered dependency data into a repeatable scan-and-review loop for critical and high risk.
Core problem it solves.
Modern apps pull packages from many repos and ecosystems. Risk lives in NuGet and npm manifests, in old versions nobody remembers installing, and in CVEs published long after a dependency was added. Teams often discover issues late — or not at all — because inventory, CPE matching, and NVD checks never sit in one workflow.
Spreadsheets go stale. Manual NVD searches do not scale. GitLab alone does not tell you which imported packages are critical. CVE Scanner removes that fragmentation: one inventory, one scan path, severity-filtered results, and a GitLab import so the software you actually ship is the software you review for known vulnerabilities.
Target users.
CVE Scanner is for system admins, security teams, and technical operations staff who need a clear view of critical and high CVEs across the software they run and the GitLab projects that introduced it.
Tech stack.
- Frontend: Angular 19, PrimeNG
- Backend: .NET 8, ASP.NET Core
- Database: PostgreSQL
- Integrations: NIST NVD API, GitLab API
- Platform: BBWT3-Lite
Key features.
- Dashboard with software, CVE, critical, and high counts
- Software inventory with CPE matching and NVD scans
- CVE list filtered by severity
- Tag management (including exclude-from-scan)
- GitLab sync for .csproj and package.json dependencies
- Settings view for NVD API and GitLab configuration