SBOM Exposure Snapshot
Upload or paste a CycloneDX, SPDX JSON document or dependency manifest to scan all declared components against the OSV.dev open vulnerability database. The scanner identifies known CVEs and security advisories with precise version matching, returning an immediate severity breakdown across Critical, High, Medium, and Low vulnerabilities alongside top exposed components. The live interactive scanner is available at /sbom-exposure with no registration required. The tool operates in-request and does not store your SBOM data on our servers. For continuous vulnerability monitoring and full CRA Annex I Part II(1) due diligence, CVD Portal integrates SBOM ingestion with automated alerting and CSAF 2.0 advisory generation.
Last updated 25 August 2026
Accepts CycloneDX or SPDX JSON, or a dependency manifest (package.json, requirements.txt, go.mod, Cargo.toml, Gemfile.lock).
Analysed in-request. Your SBOM is never stored on our servers.
Frequently asked
Where can I run the SBOM exposure snapshot tool?
What formats does the SBOM exposure snapshot support?
How are vulnerabilities matched against components?
Does this tool upload or store my SBOM?
How does SBOM exposure scanning help with CRA compliance?
Ready to automate your CVD programme?
CVD Portal integrates all these tools and handles your Article 13 and 14 obligations automatically.
Start your free portal →