Any Nmap export
XML (-oX), normal (-oN), grepable (-oG) or a raw paste — the format is detected automatically.
Paste or upload an Nmap export — XML, normal or grepable — and get every host and service, a network map, and matched vulnerabilities and misconfigurations. Parsed entirely in your browser.
XML (-oX), normal (-oN) and grepable (-oG) output are all auto-detected.
XML · Normal · Grepable
What it does
Point it at any Nmap export and get a readable map of the network, every open service, and what's worth fixing first.
XML (-oX), normal (-oN), grepable (-oG) or a raw paste — the format is detected automatically.
Detected product/version strings are checked against a curated set of known CVEs, and Nmap's own vuln/vulners script output is parsed directly.
Anonymous FTP, SMBv1, open Redis/MongoDB/Elasticsearch, exposed Docker/etcd APIs, weak TLS and more — flagged by service and script output.
Every host grouped by subnet, sized by open ports and colored by its worst finding, so you can scan a whole scan at a glance.
How it works
nmap -sV -O --script vuln -oX scan.xml <target> (or -oN / -oG, or just the default terminal output).
Paste the text or drop the file — the format is detected automatically.
Browse hosts, the network map, and vulnerabilities/misconfigurations ranked by severity.
Privacy
Parsing, vulnerability matching and misconfiguration checks all run locally in WebAssembly. Nothing is uploaded to a server.
FAQ
XML (-oX), normal (-oN) and grepable (-oG), plus pasting any of those directly. XML carries the most detail (service versions, CPEs, full script output), so it gives the most accurate findings.
No — it combines a small, hand-curated set of well-known CVEs matched by product/version with direct parsing of Nmap's own vulners/vulscan and *-vuln-* script output when you ran those scripts. It is not a live feed from the NVD. Treat matches as leads to verify, not a complete vulnerability scan.
No. It's a fast way to triage an Nmap scan you already ran. For authoritative results, run a dedicated scanner (e.g. Nessus, OpenVAS) against the same hosts.
No. Parsing, matching and the network map all run in your browser via WebAssembly. The scan data never leaves your machine.