Skip to main content
POST
/nvd/cves/search

Authorizations

access-token
string
header
required

API token from the dashboard

Headers

access-token
string
required

Body

application/json
count
integer
required
Required range: x >= 1
timeout
integer
default:300
Required range: 20 <= x <= 1500
keyword
string | null
keyword_exact_match
boolean
default:false
cvss_v2_severity
enum<string> | null
Available options:
LOW,
MEDIUM,
HIGH
cvss_v3_severity
enum<string> | null
Available options:
LOW,
MEDIUM,
HIGH,
CRITICAL
cvss_v4_severity
enum<string> | null
Available options:
LOW,
MEDIUM,
HIGH,
CRITICAL
cvss_v2_metrics
string | null
cvss_v3_metrics
string | null
cvss_v4_metrics
string | null
cwe_id
string | null
cpe_name
string | null
is_vulnerable
boolean
default:false
virtual_match_string
string | null
version_start
string | null
version_start_type
enum<string> | null
Available options:
including,
excluding
version_end
string | null
version_end_type
enum<string> | null
Available options:
including,
excluding
pub_start_date
string | null
pub_end_date
string | null
last_mod_start_date
string | null
last_mod_end_date
string | null
has_kev
boolean
default:false
has_cert_alerts
boolean
default:false
has_cert_notes
boolean
default:false
has_oval
boolean
default:false
cve_tag
enum<string> | null
Available options:
disputed,
unsupported-when-assigned,
exclusively-hosted-service
source_identifier
string | null
no_rejected
boolean
default:false

Response

Successful Response

id
string
required
@type
string
default:NvdCve
source_identifier
string | null
published_at
string | null
last_modified_at
string | null
vuln_status
string | null
cve_tags
string[]
evaluator_comment
string | null
evaluator_solution
string | null
evaluator_impact
string | null
cwe_ids
string[]
weaknesses
object[]
cvss_metrics
object[]
ssvc
object[]
configurations
object[]
references
object[]
affected
object[]
vendor_comments
object[]
is_kev
boolean
default:false
cisa_exploit_add
string | null
cisa_action_due
string | null
cisa_required_action
string | null
cisa_vulnerability_name
string | null
web_url
string
default:""