Am I affected?

Enter the version you run. This lists the tracked CVEs whose vendor data covers it, known exploited first, and the lowest release on your branch that clears them. It runs entirely in your browser.

Read this before relying on an answer

  • Answers come from the vendor's CVE records, the affected-version ranges Fortinet and Palo Alto publish to the CVE Program. Vendors sometimes add fixes to their advisory without updating the record. Every result links the advisory; it is the final word.
  • "Could not determine" is never counted as safe. When the record's ranges are missing, unreadable, or truncated here, the CVE is listed separately so you can check it by hand.
  • Affected is not the same as exploitable. Many CVEs need a specific feature enabled or an interface exposed. The advisory says which.
  • Cisco works differently. Cisco's CVE records list the releases that are affected, one by one, and say nothing about the rest. So for ASA, FTD, FMC and ISE this page can tell you a release is listed as affected, but a release that is not listed has not been declared safe, and there is no fixed release to recommend. Use Cisco's Software Checker for fixed releases.
  • Only CVEs tracked on this site are checked. GlobalProtect is not covered yet: its version numbers cannot be ordered reliably enough to answer this question.