Reference · Advisory Database

A CVE id means nothing.
This translates it.

Look up any vulnerability and get a plain answer, free and public.

01 · Look anything up

Type a CVE. Get a straight answer.

Paste the id and get the flaw, its severity, the fix, and whether it is being exploited. Here is Log4Shell.

advisory.moole.ai · vulnerability database live lookup
CVE-2021-44228 Log4Shell Critical · CVSS 10.0

A remote attacker can run their own code on your server by sending a crafted string that Apache Log4j logs. Log4j sees a special ${jndi:...} pattern in the text it is logging, follows it out to an attacker-controlled server over JNDI, and loads whatever it is told to. Anything that logged untrusted input was exposed.

Exploited in the wild
Actively exploited
Mass scanning and real attacks began within days of disclosure. On CISA's Known Exploited Vulnerabilities list.
Type of flaw
Remote code execution via JNDI lookup injection in the logging library.
Affected package & versions
org.apache.logging.log4j : log4j-core
2.0-beta9 through 2.14.1
The fix
Upgrade log4j-core to 2.17.1 or later. (2.15.0 and 2.16.0 fixed the main flaw but had follow-up issues, so go to 2.17.1+.)

A CVE id is a barcode.
This is the label you can actually read.

02 · Inside an entry

Four things, on every entry.

The questions you actually have, in the order you have them.

01

Plain description

What the flaw is, in one sentence a person can read.

02

Real-world exploit context

Whether attackers are using it right now, not just a score.

03

Metrics done right

Severity and exploitability, side by side.

04

The fix

The exact version to upgrade to, or the mitigation to apply.

03 · The Zero Day Dictionary

Security terms, in plain English.

The Zero Day Dictionary: around 100 terms, each in one clear sentence. A few examples.

SSRF · Server-Side Request Forgery
A flaw where an attacker tricks your server into making requests to places it should not, like internal systems that are not exposed to the outside.
IDOR · Insecure Direct Object Reference
When changing an id in a request lets you read or edit someone else's data, because the app trusts the id without checking you are allowed to touch it.
Supply-chain attack
An attack that reaches you through software you trust, by compromising a dependency, a build tool, or an update instead of hitting you directly.
SBOM · Software Bill of Materials
A complete list of every component and dependency inside a piece of software, so you know exactly what is in it and can check it against known flaws.
04 · Same brain as the platform

Not a separate silo.

This is the same intelligence Moolé uses to rank real risk across your code, dependencies, and containers.

Open the vulnerability database →