← All tools
Free Tool

SBOM Exposure Snapshot

Upload or paste a CycloneDX, SPDX JSON document or dependency manifest to scan all declared components against the OSV.dev open vulnerability database. The scanner identifies known CVEs and security advisories with precise version matching, returning an immediate severity breakdown across Critical, High, Medium, and Low vulnerabilities alongside top exposed components. The live interactive scanner is available at /sbom-exposure with no registration required. The tool operates in-request and does not store your SBOM data on our servers. For continuous vulnerability monitoring and full CRA Annex I Part II(1) due diligence, CVD Portal integrates SBOM ingestion with automated alerting and CSAF 2.0 advisory generation.

Last updated 25 August 2026

.json, .txt, .mod, .lock, .xml

Accepts CycloneDX or SPDX JSON, or a dependency manifest (package.json, requirements.txt, go.mod, Cargo.toml, Gemfile.lock).

Analysed in-request. Your SBOM is never stored on our servers.

Frequently asked

Where can I run the SBOM exposure snapshot tool?
The live tool is available at /sbom-exposure. You can upload a CycloneDX or SPDX JSON document, or a package dependency manifest, to run an immediate vulnerability exposure scan.
What formats does the SBOM exposure snapshot support?
The tool accepts CycloneDX JSON, SPDX 2.3 and 3.0 JSON, as well as package dependency manifests including package.json, requirements.txt, go.mod, Cargo.toml, and Gemfile.lock.
How are vulnerabilities matched against components?
Components and their exact version strings are matched against OSV.dev, an open vulnerability database aggregating GitHub Security Advisories, RustSec, PyPA, Go vulnerability database, and distribution security feeds.
Does this tool upload or store my SBOM?
No. The document is analysed in-request and is never stored on our servers or in any database. The scan results are returned directly to your browser.
How does SBOM exposure scanning help with CRA compliance?
CRA Annex I Part II(1) requires manufacturers to identify and document vulnerabilities in components throughout the product lifecycle. Article 13(5) obligates manufacturers to exercise due diligence on third-party components. Regular SBOM vulnerability scanning provides the evidence needed to demonstrate component due diligence.

Ready to automate your CVD programme?

CVD Portal integrates all these tools and handles your Article 13 and 14 obligations automatically.

Start your free portal →