Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
nmap-vulners — Nmap NSE script that queries the Vulners API to identify known vulnerabilities (CVEs) for detected network services, enhancing standard port scanning with automated CVE lookup and CVSS scoring. | Kitploit
Tools/GitHubGitHub/vulnerscom/nmap-vulners
Vulnerability ScannersVulnerability AnalysisInformation GatheringNetwork Security
GitHubvulnerscom/nmap-vulners

nmap-vulners

Nmap NSE script that queries the Vulners API to identify known vulnerabilities (CVEs) for detected network services, enhancing standard port scanning with automated CVE lookup and CVSS scoring.

View Repository
3.4k559201 day agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

nmap-vulners

Turn an nmap service scan into a ranked list of CVEs, exploits and what is being attacked in the wild.

One NSE script that takes the software nmap already identified, asks the Vulners database what is known about it, and prints the answer inside the scan report - worst first, by what is actually exploitable.

tests license nmap data stars

Three scans: an SSH port with no API key, the same port with one, and a web port where the sweep names the Tomcat behind a Coyote banner

Real scans of hosts published for scanning. No key, then a key, then a web port: nmap's -sV reports a Coyote banner and the sweep names the Tomcat and the jQuery behind it.


What it does

For every open port it looks up the software nmap identified - the CPEs that -sV produced - and prints what Vulners knows about it: worst first by what is being exploited rather than by score alone, and each row a link to the page behind it.

On an HTTP port it also fingerprints the web stack itself, which names software -sV cannot see - an application framework, a CMS, the PHP version behind a reverse proxy. 721 rules read the parts of a response that carry a version: the Server header, X-Powered-By, cookies, the page title, <meta> tags, <script src> filenames and the body. Those identities are looked up too, and published onto the port so the rest of the scan can use them.

Two things it does beyond the sweep:

  • it reads nmap's own service banner. When -sV could not name a service, the raw banner is matched against rules for FTP, SMTP, SSH, MySQL, DNS, NTP, LDAP and more. That costs no extra request, and it is the case where a port would otherwise report nothing at all.
  • it asks a product that will not say. A CMS that names itself and hides its version is common, and no amount of pattern matching extracts a number that is not on the page. When the product is recognised and the version is not, one request goes to the place that answers - /CHANGELOG.txt for Drupal, /administrator/manifests/files/joomla.xml for Joomla. A host running none of the six probed products is sent nothing extra.
nmap -sV --script vulners <target>

That is the whole interface. It works without an API key; with one it tells you more. There is no mode switch.

PORT      STATE SERVICE VERSION
80/tcp    open  http    Apache httpd 2.4.7 ((Ubuntu))
| vulners: cpe:/a:apache:http_server:2.4.7  272 findings, 56 exploitable
|   SEVERITY  CVSS    AI  FLAGS    LINK
|   ========  ====  ====  =======  ==============================================================
|   CRITICAL  10.0   8.8  EXP      https://vulners.com/gitee/3E6BA608-776F-5B1F-9BA5-589CD2A5A351
|   CRITICAL   9.8   9.9  EXP      https://vulners.com/zdt/1337DAY-ID-39214
|   CRITICAL   9.8   9.6  EXP      https://vulners.com/packetstorm/PACKETSTORM:171631
|   CRITICAL   9.8   9.9           https://vulners.com/cve/CVE-2021-44790
|   CRITICAL   9.8   9.8           https://vulners.com/cve/CVE-2023-25690
|_  262 more not shown; -v shows all, -vv adds where each was found

With a key, the same scan of the same host answers differently - KEV means CISA has recorded the vulnerability as exploited in the wild, and EPSS is the published probability that it will be:

| vulners: cpe:/a:apache:http_server:2.4.7  272 findings, 78 exploitable
|   SEVERITY  CVSS  EPSS  FLAGS    LINK
|   ========  ====  ====  =======  ==============================================================
|   CRITICAL   9.1  >99%  KEV EXP  https://vulners.com/cve/CVE-2024-38475
|   CRITICAL   9.0  >99%  KEV EXP  https://vulners.com/cve/CVE-2021-40438
|   CRITICAL   9.1  >99%  KEV      https://vulners.com/cnvd/CNVD-2024-36387
|   CRITICAL  10.0   71%  EXP      https://vulners.com/gitee/3E6BA608-776F-5B1F-9BA5-589CD2A5A351
|   CRITICAL   9.8   97%  EXP      https://vulners.com/cve/CVE-2021-44790
|_  262 more not shown; -v shows all, -vv adds where each was found

Same 272 findings, a different order, a different top row - and 22 more of them known to be exploitable, because a key links each exploit to the CVEs it exploits. Both of these are real answers from vulners.com, captured against a local server presenting that banner.

Ranking

Facts outrank predictions. Findings are ordered:

  1. CISA KEV - recorded as exploited in the wild
  2. SSVC active - a coordinator's judgement that exploitation is happening
  3. an exploit exists - the code is published, for this or for a CVE it names
  4. high EPSS - a model expects exploitation
  5. everything else

CVSS breaks ties inside a band, not across them: an exploited 7.5 is a worse problem than an unexploited 9.8, and this is the order that says so.

Columns follow the data. A signal the answer did not carry loses its column rather than showing an empty cell, because a blank EPSS reads as "quiet", and that is a claim an absent field cannot support.

What an API key adds

Without a keyEvery CPE nmap found is looked up on the free endpoint. Findings, scores, exploit flags and Vulners' own AI score. No credits, no account
A key, no creditsEach finding gains what the id endpoint knows: titles, dates, the upstream advisory or exploit page, the exploit-to-CVE linkage, CISA KEV, and - depending on the licence - EPSS and SSVC
A key, one creditSoftware the free path could not name at all is identified from its raw banner. This is the only thing here that costs anything, and only for a service with no CPE

A port that already carries a CPE never costs a credit: measured across four products, the free lookup returns the same CVEs as the paid one for a CPE. What a credit buys is identification, not more vulnerabilities.

Free keys are at vulners.com/userinfo.

Install

macOS, Linux, Kali, WSL - one line, no arguments:

curl -fsSL https://raw.githubusercontent.com/vulnersCom/nmap-vulners/master/install.sh | sh

Windows - PowerShell as Administrator:

irm https://raw.githubusercontent.com/vulnersCom/nmap-vulners/master/install.ps1 | iex

The installer asks nmap where it keeps its data, copies the scripts and their data files there, rebuilds the script database, and then checks that --script vulners really resolves to what it just installed - nmap ships a vulners.nse of its own, and this replaces it.

Without root, and other options
# into ~/.nmap, no sudo; the installer prints the NMAPDIR line to add to your profile
curl -fsSL https://raw.githubusercontent.com/vulnersCom/nmap-vulners/master/install.sh | sh -s -- --user

# a specific directory
./install.sh --prefix /usr/local/share/nmap

# a specific release
./install.sh --ref v2.0

# remove everything it installed
./install.sh --uninstall

PowerShell takes the same options: -User, -Prefix, -Ref, -Uninstall.

From a checkout
git clone https://github.com/vulnersCom/nmap-vulners
cd nmap-vulners
./install.sh
Download Tool