# vulnersCom/nmap-vulners

Nmap NSE scripts that turn a service scan into CVEs, CVSS scores and known exploits — fingerprints software from HTTP responses and checks every detected CPE against the Vulners database.

Repository: https://github.com/vulnersCom/nmap-vulners
Canonical: https://ross.abutalabs.com/products/nmap-vulners
Homepage: https://vulners.com
Language: Lua
License: NOASSERTION
License Family: other
Topics: cpe, cve, cvss, exploit-database, fingerprinting, infosec, lua, network-scanner, nmap, nmap-scripts, nse, nse-scripts, pentesting, security, security-tools, vulnerability-detection, vulnerability-scanner, vulners
Last push: 2026-08-21T12:21:24+00:00

## Health v2 (maintenance only)
Score: 98/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 98, release rhythm 98, longevity 100
- inputs: {"age_days": 3179, "days_push": 12, "days_rel": 13, "gap_med": 0, "n_releases_24m": 4}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3415, forks 559 (observed 2026-08-28T04:08:03.668550+00:00)

## What it is
A collection of Nmap NSE scripts that enrich service scans with CVEs, CVSS scores and known exploits from the Vulners database. It fingerprints software from scan results and HTTP banners, matches detected CPEs against Vulners, and prints ranked vulnerability results directly in the nmap report.

## Use cases
- find cves for services detected by nmap
- check open ports for known exploits
- vulnerability scan during pentest
- identify software versions from http banners and match to cves
- rank scan findings by exploitability
- audit network hosts for vulnerable software

## When to choose
- you already use nmap and want CVE context in the same scan
- you want exploit-aware ranking rather than raw CVSS scores
- you need a lightweight script-based tool with no separate scanner install

## When to avoid
- you need authenticated or agent-based host scanning rather than network service detection
- you want a standalone vulnerability scanner with its own scanning engine
- you cannot send scan data to the external vulners.com service

## Facets
- artifact type: plugin
- maturity: active
- function: vulnerability-scanning, security, search-engine
- domain: security, penetration-testing, networking, developer-tools
- platform: windows, cli
- tags: nmap, nse-scripts, cve, cvss, cpe, exploit-database, vulners, pentesting, lua, network-scanning, linux, macos

## Member repositories
- vulnersCom/nmap-vulners (main) score 98

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:03.668550+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:38:29.082962+00:00, confidence not recorded.
  - readme: https://github.com/vulnersCom/nmap-vulners (fetched 2026-08-28T04:08:03.668550+00:00, sha bc028b24f442)
  - homepage: https://vulners.com (fetched 2026-08-29T09:32:28.026404+00:00, sha 9771bb4ed7c5)
  - site_page: https://docs.vulners.com (fetched 2026-08-29T09:32:28.033235+00:00, sha 195f127736d1)
  - site_page: https://docs.vulners.com/docs/api (fetched 2026-08-29T09:32:28.034840+00:00, sha 8ce3854405a4)
  - site_page: https://docs.vulners.com/changelog (fetched 2026-08-29T09:32:28.036561+00:00, sha 289a35f94918)
  - site_page: https://vulners.com/company/about-us (fetched 2026-08-29T09:32:28.039847+00:00, sha d254cf84b0e2)
  - site_page: https://vulners.com/static/docs/privacy_policy.html (fetched 2026-08-29T09:32:28.041573+00:00, sha b340a85eca2a)
  - site_page: https://vulners.com/blog/audit_library_api (fetched 2026-08-29T09:32:28.031421+00:00, sha 55a62e1d2fd6)
  - site_page: https://vulners.com/pricing (fetched 2026-08-29T09:32:28.029454+00:00, sha abc6504136c7)
- Data as of 2026-08-30T08:39:29.467469+00:00.
