Abstract
Abstract The escalating frequency and sophistication of cyberattacks, coupled with the accelerating pace of vulnerability disclosure, have rendered manual network vulnerability assessment operationally infeasible for organisations of all sizes. Commercial vulnerability scanners such as Nessus Professional and Qualys remain financially prohibitive for small and medium-sized enterprises and 108IDEAS: Uniuyo Journal of Philosophy and Multi-Disciplinary Studies Vol. 2, No. 1, SEPTEMBER 2026 educational institutions, while existing open-source alternatives typically depend on static, periodically refreshed vulnerability databases and demand considerable technical expertise to deploy. This paper presents the design and implementation of a lightweight, open-source network vulnerability scanner that unifies concurrent network scanning, banner-based service detection, realtime Common Vulnerabilities and Exposures (CVE) intelligence retrieval from the National Vulnerability Database (NVD) Application Programming Interface (API) v2.0, and Common Vulnerability Scoring System (CVSS) v3.1-based severity ranking within a single accessible pipeline. The system further incorporates IP geolocation, Internet Service Provider (ISP) and Autonomous System Number (ASN) identification, and a graphical user interface with real-time severity visualisation. The tool was implemented in Python 3.x using a thread-pool-based concurrent scanning engine and evaluated against the authorised host scanme.nmap.org. All twelve defined functional test cases passed, and the system produced ten CVE findings across six High- and four Mediumseverity categories from two detected services, generating structured JSON and HTML reports. The results demonstrate that real-time, severity-ranked vulnerability intelligence can be delivered without licensing costs or extensive configuration overhead, addressing an accessibility gap identified across the reviewed literature. Limitations relating to evaluation scope and keyword-based CVE matching are discussed alongside directions for future enhancement.
Keywords: Network Vulnerability Assessment; CVE; CVSS; NIST NVD API; Automated Security Scanning; Vulnerability Prioritisa
Author(s):
Isaac Isoji Motajo
Department of Cyber Security, Faculty of Computing, Air Force Institute of
Technology, Kaduna, Nigeria
Corresponding Author Email: isojimotajo@gmail.com
ORCID: https://orcid.org/0009-0004-0941-0994
Muhammad Mashkur Tajuddeen
Department of Cyber Security, Faculty of Computing, Air Force Institute of
Technology, Kaduna, Nigeria
Email: muhdtaju@gmail.com
ORCID: https://orcid.org/0009-0002-1920-0224
Samson Adeyinka
Department of Cyber Security, Faculty of Computing, Air Force Institute of
Technology, Kaduna, Nigeria
Email: samson.adeyinka@afit.edu.ng
ORCID: https://orcid.org/0009-0005-9361-7337