NEWWindows patch check — build + KBs → unpatched CVEs

Know what's actually
vulnerable.

Vulnerability scanners want cpe:2.3:a:7-zip:7-zip. Your fleet reports “7-Zip 24.08 (x64 edition)”. Evil-DB closes that gap — then tells you exactly which version fixes it.

Try:
—
CVEs tracked
—
Known exploited (KEV)
daily
EPSS scores
hourly
NVD sync

Three problems, solved server-side

Every fleet scanner reimplements these badly. We do them once, in the API, so your client stays thin.

01

Resolve the name

A hand-maintained regex CPE map is wrong in a different way in every client. Post a DisplayName and publisher, get ranked cpe candidates with confidence scores.

POST /api/v1/cve/resolve
{ "displayName": "7-Zip 24.08",
  "publisher": "Igor Pavlov" }

→ 7-zip:7-zip  (1.00)
02

Match honestly

An empty result means one of two very different things. We tell you which — so a typo'd product name is never silently reported as clean.

GET /cve/match?vendor=openssl
    &product=openssl&version=1.0.1

→ productKnown: true
  matches: 75
03

Return the fix

A finding is a report. A finding with a target version is a work order. We surface the version that closes the range, straight from the CPE config.

CVE-2014-0160  critical 7.5
  fixedVersion → 1.0.1g

CVE-2014-0224  high
  fixedVersion → 1.0.1h

Not every CVE is worth a ticket

A raw CVSS list is noise. Evil-DB ships the three signals that actually decide what you patch first — on every match, no extra call.

  • CISA KEV

    Synced daily from the authoritative catalog, not derived second-hand. If it's being exploited in the wild, you know on the same response.

  • EPSS

    FIRST.org's exploit-probability score, refreshed daily, so you can rank by likelihood instead of theoretical severity.

  • Public exploit available

    Whether a weaponised exploit or detection template exists in the open — sourced from nuclei-templates. A medium-CVSS bug with a public exploit outranks a critical without one.

GET /api/v1/cve/match
{
  "productKnown": true,
  "versionParsed": true,
  "matches": [
    {
      "cveId": "CVE-2021-44228",
      "severity": "critical",
      "cvssScore": 10.0,
      "isKev": true,
      "epssScore": 0.944,
      "fixedVersion": "2.15.0",
      "exploit": {
        "source": "nuclei-templates",
        "url": "https://github.com/..."
      }
    }
  ]
}

Built to be automated

Bulk endpoints for fleet-wide scans, server-side severity filters so you aren't shipping megabytes of noise, and a plain-text API reference an LLM can read in one request.

# the whole API, as plain text
curl https://evil-db.io/llms.txt

# 100 products, critical-only, one call
curl -X POST https://evil-db.io/api/v1/cve/match \
  -H 'x-api-key: ...' \
  -d '{"items":[...],"minCvss":9,"kev":true}'               

Free tier: 1,000 lookups/day. No card required.