MCP 서버

nist-nvd-mcp-server

io.github.cyanheads/nist-nvd-mcp-server
보안 공개 · 연결 가능 MCP 2025-11-25

이 MCP로 할 수 있는 일

Searches the NIST vulnerability database, retrieves CVE details and history, resolves CPEs, and audits products for affected vulnerabilities.

nvd_audit_cpe
Audit CPE for Vulnerabilities
Find all CVEs affecting a specific product and version using CPE (Common Platform Enumeration). Requires either an exact CPE name (cpeName) or a partial match string (virtualMatchString) with optional version range bounds. With cpeName, NVD scopes results to configurations where the product is directly vulnerable, not merely referenced as a dependency. Use nvd_search_cpes first to resolve the correct CPE string for a product. Returns full CVE records.
읽기 전용 멱등성
입력 스키마
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'default': 20, 'maximum': 2000, 'minimum': 1, 'description': 'Maximum number of CVEs to return (default 20, max 2000).'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Zero-based page offset for pagination. Page through totalCount with a modest limit rather than raising limit â\x80\x94 this tool returns full CVE records, so a large limit is a large response.'}, 'cpeName': {'type': 'string', 'description': 'Full CPEv2.3 name (e.g., "cpe:2.3:a:apache:http_server:2.4.51:*:*:*:*:*:*:*"). NVD adds isVulnerable automatically. Mutually exclusive with virtualMatchString.'}, 'versionEnd': {'type': 'string', 'description': 'Upper version bound. Requires virtualMatchString.'}, 'severityMin': {'enum': ['LOW', 'MEDIUM', 'HIGH', 'CRITICAL'], 'type': 'string', 'description': 'Filter out CVEs below this severity level. Applied after NVD returns the page, so it can only drop CVEs within limit â\x80\x94 raise limit to widen what it sees.'}, 'allLanguages': {'type': 'boolean', 'default': False, 'description': 'When true, keeps every localized description NVD supplies on each record. Default keeps English only.'}, 'versionStart': {'type': 'string', 'description': 'Lower version bound. Requires virtualMatchString.'}, 'versionEndType': {'enum': ['including', 'excluding'], 'type': 'string', 'default': 'including', 'description': 'Whether the upper version bound is inclusive or exclusive.'}, 'versionStartType': {'enum': ['including', 'excluding'], 'type': 'string', 'default': 'including', 'description': 'Whether the lower version bound is inclusive or exclusive.'}, 'virtualMatchString': {'type': 'string', 'description': 'Partial CPE match pattern (e.g., "cpe:2.3:a:apache:http_server:*"). Use with versionStart/versionEnd for version range audits. Mutually exclusive with cpeName.'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['cves', 'totalCount', 'returned', 'offset', 'auditTarget']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'cves': {'type': 'array', 'items': {'type': 'object', 'required': ['cveId', 'vulnStatus', 'published', 'lastModified', 'descriptions', 'cvssScores', 'weaknesses', 'configurationNodes'], 'properties': {'cveId': {'type': 'string', 'description': 'CVE identifier (e.g., "CVE-2021-44228").'}, 'cisaKev': {'type': 'object', 'required': ['exploitAddDate', 'actionDueDate', 'requiredAction', 'vulnerabilityName'], 'properties': {'actionDueDate': {'type': 'string', 'description': 'Federal agency remediation deadline.'}, 'exploitAddDate': {'type': 'string', 'description': 'Date added to CISA KEV catalog.'}, 'requiredAction': {'type': 'string', 'description': 'Required remediation steps.'}, 'vulnerabilityName': {'type': 'string', 'description': "CISA's vulnerability name."}}, 'description': 'CISA KEV fields. Present only when CVE is in the KEV catalog.', 'additionalProperties': False}, 'severity': {'type': 'object', 'required': ['label', 'score', 'fromVersion'], 'properties': {'label': {'type': 'string', 'description': 'Highest severity label across all CVSS versions.'}, 'score': {'type': 'number', 'description': 'Highest base score (0.0â\x80\x9310.0).'}, 'fromVersion': {'type': 'string', 'description': 'Which CVSS version this top score came from.'}}, 'description': 'Top severity. Absent if no CVSS scores present.', 'additionalProperties': False}, 'published': {'type': 'string', 'description': 'ISO 8601 publication datetime.'}, 'cvssScores': {'type': 'array', 'items': {'type': 'object', 'required': ['version', 'sourceType', 'baseScore', 'severity'], 'properties': {'version': {'type': 'string', 'description': 'CVSS version (e.g., "2.0", "3.1", "4.0").'}, 'severity': {'type': 'string', 'description': 'Severity label: CRITICAL, HIGH, MEDIUM, or LOW.'}, 'baseScore': {'type': 'number', 'description': 'Base score (0.0â\x80\x9310.0).'}, 'sourceType': {'type': 'string', 'description': 'Score source: "Primary" = NVD, "Secondary" = CNA.'}, 'vectorString': {'type': 'string', 'description': 'CVSS vector string.'}}, 'description': 'One CVSS score entry.', 'additionalProperties': False}, 'description': 'All available CVSS scores across versions.'}, 'references': {'type': 'array', 'items': {'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'Reference URL.'}, 'tags': {'type': 'array', 'items': {'type': 'string', 'description': 'One classification tag.'}, 'description': 'Classification tags.'}, 'source': {'type': 'string', 'description': 'Who contributed the reference, as the contributor name NVD publishes for it (e.g. "CVE", "CISA-ADP"). Contributors NVD identifies by email address keep that address (e.g. "security@apache.org"); an identifier absent from NVD\'s contributor dictionary passes through as its raw value.'}}, 'description': 'One external reference.', 'additionalProperties': False}, 'description': 'External references.'}, 'vulnStatus': {'type': 'string', 'description': 'NVD analysis status.'}, 'weaknesses': {'type': 'array', 'items': {'type': 'object', 'required': ['source', 'cweIds'], 'properties': {'cweIds': {'type': 'array', 'items': {'type': 'string', 'description': 'One CWE identifier.'}, 'description': 'CWE identifiers for this source.'}, 'source': {'type': 'string', 'description': 'Who classified the weakness, as the contributor name NVD publishes for it (e.g. "CVE", "CISA-ADP"). Contributors NVD identifies by email address keep that address (e.g. "nvd@nist.gov"); an identifier absent from NVD\'s contributor dictionary passes through as its raw value.'}}, 'description': 'One weakness classification entry.', 'additionalProperties': False}, 'description': 'CWE weakness classifications.'}, 'descriptions': {'type': 'array', 'items': {'type': 'object', 'required': ['lang', 'value'], 'properties': {'lang': {'type': 'string', 'description': 'Language code.'}, 'value': {'type': 'string', 'description': 'CVE description.'}}, 'description': 'One localized CVE description.', 'additionalProperties': False}, 'description': 'CVE descriptions by language.'}, 'lastModified': {'type': 'string', 'description': 'ISO 8601 last-modified datetime.'}, 'configurationNodes': {'type': 'array', 'items': {'type': 'object', 'required': ['groupIndex', 'cpeMatch'], 'properties': {'cpeMatch': {'type': 'array', 'items': {'type': 'object', 'required': ['vulnerable', 'criteria'], 'properties': {'criteria': {'type': 'string', 'description': 'CPEv2.3 match criteria string.'}, 'vulnerable': {'type': 'boolean', 'description': 'Whether this CPE is the vulnerable component or only the context it runs in.'}, 'versionEndExcluding': {'type': 'string', 'description': 'Exclusive upper version bound.'}, 'versionEndIncluding': {'type': 'string', 'description': 'Inclusive upper version bound.'}, 'versionStartExcluding': {'type': 'string', 'description': 'Exclusive lower version bound.'}, 'versionStartIncluding': {'type': 'string', 'description': 'Inclusive lower version bound.'}}, 'description': 'One CPE match criterion.', 'additionalProperties': False}, 'description': "This node's CPE match criteria, in the order NVD lists them."}, 'groupIndex': {'type': 'number', 'description': 'Zero-based index of the NVD configuration group this node belongs to. Nodes sharing a groupIndex were siblings in one group, combined by groupOperator.'}, 'nodeOperator': {'type': 'string', 'description': "Logical operator (AND/OR) combining this node's own criteria below. Absent when the node has nothing to combine."}, 'groupOperator': {'type': 'string', 'description': 'Logical operator (AND/OR) combining this node with its sibling nodes in the same group. An "AND" means every node in the group must match for the CVE to apply â\x80\x94 e.g. a firmware node and the hardware it runs on. Absent when the group has nothing to combine.'}}, 'description': 'One affected product configuration node, tagged with the group it came from.', 'additionalProperties': False}, 'description': "Affected product configuration nodes. NVD nests these under configuration groups; the groups are represented by groupIndex so each node's own criteria stay together."}}, 'description': 'Full CVE record for one vulnerability affecting the product.', 'additionalProperties': False}, 'description': 'Full CVE records for CVEs affecting the specified product.'}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['missing_cpe_input', 'conflicting_cpe_inputs', 'version_range_without_match_string', 'invalid_cpe_format', 'rate_limited'], 'description': 'Machine-readable failure mode. Declared by this tool: `missing_cpe_input`: Neither cpeName nor virtualMatchString was provided. `conflicting_cpe_inputs`: Both cpeName and virtualMatchString were provided simultaneously. `version_range_without_match_string`: versionStart or versionEnd was provided without virtualMatchString. `invalid_cpe_format`: cpeName or virtualMatchString does not start with "cpe:2.3:", or NVD rejected it as a malformed CPE parameter â\x80\x94 cpeName rejects anything short of a complete CPEv2.3 name, virtualMatchString only genuinely malformed characters. `rate_limited`: NVD returned HTTP 403 indicating the rate limit was exceeded. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'notice': {'type': 'string', 'description': 'Guidance on the shape of this page. When no CVEs came back it distinguishes a target NVD holds no CVEs for from a severityMin filter that dropped everything on the page, from an offset past the result set, from an empty page NVD returned inside a range it says has matches. On a partial page it names the offset that reaches the next one.'}, 'offset': {'type': 'number', 'description': 'Page offset used in this query.'}, 'returned': {'type': 'number', 'description': 'Number of CVE records returned.'}, 'totalCount': {'type': 'number', 'description': 'Total CVEs matched before pagination.'}, 'auditTarget': {'type': 'string', 'description': 'The CPE name or virtual match string used for this audit.'}, 'severityMin': {'type': 'string', 'description': 'The client-side minimum severity filter applied. Absent when none was set.'}, 'filteredCount': {'type': 'number', 'description': 'CVEs dropped by the severityMin filter from the page NVD returned. Present whenever severityMin is set; 0 means the filter dropped nothing, so a narrow result reflects totalCount and limit instead. This is not totalCount minus returned â\x80\x94 CVEs beyond limit were never fetched and so were never evaluated against the filter.'}}, 'additionalProperties': False}
nvd_get_cve
Get CVE Details
Fetch one or more CVEs by ID from the NIST National Vulnerability Database. Returns CVSS scores across all available versions (v2.0, v3.0, v3.1, v4.0), CWE weakness classifications, affected CPE configurations, CISA KEV fields, and references. Up to 100 CVE IDs per call. For bulk lookups of more than 10 IDs, use brief: true — full records for 100 CVEs can exceed 1MB and exhaust context budgets.
읽기 전용 멱등성
입력 스키마
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['cveIds'], 'properties': {'brief': {'type': 'boolean', 'default': False, 'description': 'When true, returns trimmed records (ID, status, top CVSS score, KEV name, published date, and a truncated description) instead of full detail. Recommended for batches of more than 10 IDs.'}, 'cveIds': {'anyOf': [{'type': 'string', 'description': 'A single CVE ID (e.g., "CVE-2021-44228").'}, {'type': 'array', 'items': {'type': 'string'}, 'maxItems': 100, 'minItems': 1, 'description': 'An array of CVE IDs â\x80\x94 at least 1, up to 100 per call.'}], 'description': 'One CVE ID or an array of up to 100 CVE IDs to fetch.'}, 'allLanguages': {'type': 'boolean', 'default': False, 'description': 'When true, keeps every localized description NVD supplies on each record, and full records render all of them. Default keeps English only, falling back to whatever exists if a record has no English entry. Brief records always carry a single truncated description.'}, 'includeReferences': {'type': 'boolean', 'default': True, 'description': 'When false, omits the references array to reduce response size.'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['brief', 'cves', 'requested', 'returned']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'cves': {'type': 'array', 'items': {'type': 'object', 'required': ['cveId', 'vulnStatus', 'published'], 'properties': {'cveId': {'type': 'string', 'description': 'CVE identifier (e.g., "CVE-2021-44228").'}, 'cisaKev': {'type': 'object', 'required': ['exploitAddDate', 'actionDueDate', 'requiredAction', 'vulnerabilityName'], 'properties': {'actionDueDate': {'type': 'string', 'description': 'Federal agency remediation deadline.'}, 'exploitAddDate': {'type': 'string', 'description': 'Date added to CISA KEV catalog.'}, 'requiredAction': {'type': 'string', 'description': 'Required remediation steps.'}, 'vulnerabilityName': {'type': 'string', 'description': "CISA's vulnerability name."}}, 'description': 'CISA KEV fields. Present only when CVE is in the KEV catalog.', 'additionalProperties': False}, 'severity': {'type': 'object', 'required': ['label', 'score', 'fromVersion'], 'properties': {'label': {'type': 'string', 'description': 'Highest severity label across all CVSS versions.'}, 'score': {'type': 'number', 'description': 'Highest base score (0.0â\x80\x9310.0).'}, 'fromVersion': {'type': 'string', 'description': 'Which CVSS version this top score came from.'}}, 'description': 'Top severity. Absent if no CVSS scores present.', 'additionalProperties': False}, 'published': {'type': 'string', 'description': 'ISO 8601 publication datetime.'}, 'cvssScores': {'type': 'array', 'items': {'type': 'object', 'required': ['version', 'sourceType', 'baseScore', 'severity'], 'properties': {'version': {'type': 'string', 'description': 'CVSS version (e.g., "2.0", "3.1", "4.0").'}, 'severity': {'type': 'string', 'description': 'Severity label: CRITICAL, HIGH, MEDIUM, or LOW.'}, 'baseScore': {'type': 'number', 'description': 'Base score (0.0â\x80\x9310.0).'}, 'sourceType': {'type': 'string', 'description': 'Score source: "Primary" = NVD, "Secondary" = CNA.'}, 'vectorString': {'type': 'string', 'description': 'CVSS vector string.'}}, 'description': 'One CVSS score entry.', 'additionalProperties': False}, 'description': 'All available CVSS scores across versions.'}, 'references': {'type': 'array', 'items': {'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'Reference URL.'}, 'tags': {'type': 'array', 'items': {'type': 'string', 'description': 'One classification tag.'}, 'description': 'Classification tags.'}, 'source': {'type': 'string', 'description': 'Who contributed the reference, as the contributor name NVD publishes for it (e.g. "CVE", "CISA-ADP"). Contributors NVD identifies by email address keep that address (e.g. "security@apache.org"); an identifier absent from NVD\'s contributor dictionary passes through as its raw value.'}}, 'description': 'One external reference.', 'additionalProperties': False}, 'description': 'External references.'}, 'vulnStatus': {'type': 'string', 'description': 'NVD analysis status.'}, 'weaknesses': {'type': 'array', 'items': {'type': 'object', 'required': ['source', 'cweIds'], 'properties': {'cweIds': {'type': 'array', 'items': {'type': 'string', 'description': 'One CWE identifier.'}, 'description': 'CWE identifiers for this source.'}, 'source': {'type': 'string', 'description': 'Who classified the weakness, as the contributor name NVD publishes for it (e.g. "CVE", "CISA-ADP"). Contributors NVD identifies by email address keep that address (e.g. "nvd@nist.gov"); an identifier absent from NVD\'s contributor dictionary passes through as its raw value.'}}, 'description': 'One weakness classification entry.', 'additionalProperties': False}, 'description': 'CWE weakness classifications.'}, 'description': {'type': 'string', 'description': 'Opening 200 characters of the English CVE description, truncated with an ellipsis when longer. Enough to tell one result from another; call nvd_get_cve for the full text. Absent when NVD carries no description for the record.'}, 'descriptions': {'type': 'array', 'items': {'type': 'object', 'required': ['lang', 'value'], 'properties': {'lang': {'type': 'string', 'description': 'Language code.'}, 'value': {'type': 'string', 'description': 'CVE description.'}}, 'description': 'One localized CVE description.', 'additionalProperties': False}, 'description': 'CVE descriptions by language.'}, 'lastModified': {'type': 'string', 'description': 'ISO 8601 last-modified datetime.'}, 'configurationNodes': {'type': 'array', 'items': {'type': 'object', 'required': ['groupIndex', 'cpeMatch'], 'properties': {'cpeMatch': {'type': 'array', 'items': {'type': 'object', 'required': ['vulnerable', 'criteria'], 'properties': {'criteria': {'type': 'string', 'description': 'CPEv2.3 match criteria string.'}, 'vulnerable': {'type': 'boolean', 'description': 'Whether this CPE is the vulnerable component or only the context it runs in.'}, 'versionEndExcluding': {'type': 'string', 'description': 'Exclusive upper version bound.'}, 'versionEndIncluding': {'type': 'string', 'description': 'Inclusive upper version bound.'}, 'versionStartExcluding': {'type': 'string', 'description': 'Exclusive lower version bound.'}, 'versionStartIncluding': {'type': 'string', 'description': 'Inclusive lower version bound.'}}, 'description': 'One CPE match criterion.', 'additionalProperties': False}, 'description': "This node's CPE match criteria, in the order NVD lists them."}, 'groupIndex': {'type': 'number', 'description': 'Zero-based index of the NVD configuration group this node belongs to. Nodes sharing a groupIndex were siblings in one group, combined by groupOperator.'}, 'nodeOperator': {'type': 'string', 'description': "Logical operator (AND/OR) combining this node's own criteria below. Absent when the node has nothing to combine."}, 'groupOperator': {'type': 'string', 'description': 'Logical operator (AND/OR) combining this node with its sibling nodes in the same group. An "AND" means every node in the group must match for the CVE to apply â\x80\x94 e.g. a firmware node and the hardware it runs on. Absent when the group has nothing to combine.'}}, 'description': 'One affected product configuration node, tagged with the group it came from.', 'additionalProperties': False}, 'description': "Affected product configuration nodes. NVD nests these under configuration groups; the groups are represented by groupIndex so each node's own criteria stay together."}, 'cisaVulnerabilityName': {'type': 'string', 'description': 'CISA KEV vulnerability name. Present only when in the KEV catalog.'}}, 'description': 'One CVE record. Every field beyond cveId, vulnStatus, and published depends on the mode: full mode (the default) carries all of them except description and cisaVulnerabilityName, which are the brief-mode substitutes for descriptions and cisaKev.', 'additionalProperties': {}}, 'description': 'CVE records â\x80\x94 full detail by default, trimmed rows when brief is true.'}, 'brief': {'type': 'boolean', 'description': 'Whether brief or full records were returned.'}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['invalid_cve_id_format', 'cve_not_found', 'rate_limited'], 'description': 'Machine-readable failure mode. Declared by this tool: `invalid_cve_id_format`: One or more CVE IDs fail format validation (NVD returns HTTP 404 for malformed IDs). `cve_not_found`: A valid-format CVE ID returns no results â\x80\x94 the ID is well-formed but does not exist in NVD. `rate_limited`: NVD returned HTTP 403 indicating the rate limit was exceeded. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'returned': {'type': 'number', 'description': 'Number of CVE records returned.'}, 'requested': {'type': 'number', 'description': 'Number of CVE IDs requested.'}, 'missingIds': {'type': 'array', 'items': {'type': 'string', 'description': 'A CVE ID not found in NVD.'}, 'description': 'CVE IDs requested but not found in NVD. Absent when all IDs matched.'}}, 'additionalProperties': False}
nvd_get_cve_history
Get CVE Change History
Retrieve the change history for a single CVE — CVSS score revisions, reference additions, status transitions (e.g., "Received" → "Analyzed"), and CPE configuration updates. Use when tracking a CVE's escalation or investigating when a score changed. Events are returned newest-first by default; pass order="oldest" for the CVE's earliest events. For the current record, call nvd_get_cve instead. The NVD history endpoint is significantly slower than other NVD endpoints, especially without an API key — set NVD_API_KEY for reliable operation.
읽기 전용 멱등성
입력 스키마
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['cveId'], 'properties': {'cveId': {'type': 'string', 'description': 'CVE identifier to retrieve history for (e.g., "CVE-2021-44228").'}, 'limit': {'type': 'integer', 'default': 20, 'maximum': 2000, 'minimum': 1, 'description': 'Maximum number of change events to return (default 20, max 2000).'}, 'order': {'enum': ['oldest', 'newest'], 'type': 'string', 'default': 'newest', 'description': 'Which end of the history to page from. Default "newest" returns the most recent events first, which is what escalation and re-score questions need. "oldest" returns NVD\'s native order (the CVE\'s first events first) and costs one upstream request, or two when the offset overruns the history; "newest" costs up to two on any history longer than limit.'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Zero-based offset for paginating through change events, counted from whichever end order anchors to: offset 0 is the newest event under the default order="newest", and the oldest event under order="oldest".'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['cveId', 'changes', 'totalCount', 'returned', 'offset', 'order']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'cveId': {'type': 'string', 'description': 'The CVE ID for which history was retrieved.'}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['invalid_cve_id_format', 'rate_limited'], 'description': 'Machine-readable failure mode. Declared by this tool: `invalid_cve_id_format`: The CVE ID fails format validation (NVD returns HTTP 404 for malformed IDs). `rate_limited`: NVD returned HTTP 403 indicating the rate limit was exceeded. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'order': {'enum': ['oldest', 'newest'], 'type': 'string', 'description': 'Which end of the history this page was anchored to.'}, 'notice': {'type': 'string', 'description': 'Guidance on the shape of this page. When no events came back it distinguishes an offset past the end of the history, from an empty page NVD returned inside a range it says has events, from a CVE NVD holds no history for â\x80\x94 the last of which covers both a record it has never revised and a CVE ID it does not hold. On a partial page it names the offset that reaches the next one, counted from the same end order anchors to.'}, 'offset': {'type': 'number', 'description': 'Page offset used in this query.'}, 'changes': {'type': 'array', 'items': {'type': 'object', 'required': ['changeDate', 'details'], 'properties': {'details': {'type': 'array', 'items': {'type': 'object', 'properties': {'type': {'type': 'string', 'description': 'The type of data changed (e.g., "CVSS V3.1", "CWE", "Reference").'}, 'action': {'type': 'string', 'description': 'The action taken (e.g., "Added", "Changed", "Removed").'}, 'newValue': {'type': 'string', 'description': 'The value after the change. Structured upstream values (e.g. "Affected", "SSVC" details) arrive as a JSON string â\x80\x94 parse it to read the fields.'}, 'oldValue': {'type': 'string', 'description': 'The value before the change. Structured upstream values (e.g. "Affected", "SSVC" details) arrive as a JSON string â\x80\x94 parse it to read the fields.'}}, 'description': 'One field-level change within this event.', 'additionalProperties': False}, 'description': 'Individual change detail entries within this event.'}, 'eventName': {'type': 'string', 'description': 'Name of the change event (e.g., "CVE Modified", "Initial Analysis").'}, 'changeDate': {'type': 'string', 'description': 'ISO 8601 datetime when this change occurred.'}}, 'description': 'One CVE change event with its field-level details.', 'additionalProperties': False}, 'description': 'CVE change events ordered to match the requested order â\x80\x94 newest first by default, oldest first when order="oldest".'}, 'returned': {'type': 'number', 'description': 'Number of change events returned in this response.'}, 'totalCount': {'type': 'number', 'description': 'Total change events on record for this CVE.'}}, 'additionalProperties': False}
nvd_search_cpes
Search CPE Dictionary
Search the NVD CPE (Common Platform Enumeration) dictionary by product keyword or partial match string. Returns CPE names, human-readable titles, and deprecation status. Use before nvd_audit_cpe to resolve the correct CPE name for a product — CPE strings are precise identifiers (e.g., cpe:2.3:a:apache:http_server:2.4.51:*:*:*:*:*:*:*) and must match exactly to audit the right product.
읽기 전용
입력 스키마
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'default': 20, 'maximum': 10000, 'minimum': 1, 'description': 'Maximum number of CPE entries to return (default 20, max 10000).'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Zero-based page offset for pagination. When totalCount exceeds offset + returned, raise offset to reach the rest â\x80\x94 a vendor-level keyword has nothing left to narrow toward.'}, 'keyword': {'type': 'string', 'description': 'Product name or vendor keyword (e.g., "apache http server", "openssl", "nginx"). At least one of keyword or cpeMatchString is required.'}, 'cpeMatchString': {'type': 'string', 'description': 'Partial CPEv2.3 pattern (e.g., "cpe:2.3:a:apache:http_server"). At least one of keyword or cpeMatchString is required.'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['cpes', 'totalCount', 'returned', 'offset']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'cpes': {'type': 'array', 'items': {'type': 'object', 'required': ['cpeName', 'deprecated'], 'properties': {'title': {'type': 'string', 'description': 'Human-readable product title. Absent when NVD has no English title.'}, 'cpeName': {'type': 'string', 'description': 'Full CPEv2.3 name (use this as the cpeName in nvd_audit_cpe).'}, 'deprecated': {'type': 'boolean', 'description': 'Whether this CPE has been deprecated in the NVD dictionary.'}, 'deprecatedBy': {'type': 'array', 'items': {'type': 'string', 'description': 'Superseding CPE name.'}, 'description': 'CPE names that supersede this deprecated entry.'}, 'lastModified': {'type': 'string', 'description': 'ISO 8601 datetime when this CPE was last modified.'}}, 'description': 'One CPE dictionary entry.', 'additionalProperties': False}, 'description': 'Matching CPE dictionary entries.'}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['missing_search_input', 'invalid_cpe_format', 'rate_limited'], 'description': 'Machine-readable failure mode. Declared by this tool: `missing_search_input`: Neither keyword nor cpeMatchString was provided. `invalid_cpe_format`: The cpeMatchString does not start with "cpe:2.3:", or NVD rejected it as a malformed CPE parameter. A merely truncated prefix is a legitimate partial match and returns an empty page instead. `rate_limited`: NVD returned HTTP 403 indicating the rate limit was exceeded. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'notice': {'type': 'string', 'description': 'Guidance when no CPEs matched, the offset ran past the result set, NVD returned an empty page inside a range it says has matches, or entries remain beyond this page.'}, 'offset': {'type': 'number', 'description': 'Page offset used in this query.'}, 'returned': {'type': 'number', 'description': 'Number of entries returned in this response.'}, 'totalCount': {'type': 'number', 'description': 'Total matching CPE entries before the limit was applied.'}}, 'additionalProperties': False}
nvd_search_cves
Search CVEs
Search CVEs by keyword, severity, CWE, date range, or CISA KEV status. The primary discovery tool for vulnerability surveillance and triage workflows. pubDays and lastModDays are convenience shorthands that expand to date pairs; values over 120 days are clamped to the NVD maximum and reported in the response enrichment. Returns brief summaries — call nvd_get_cve for full detail on specific IDs. At least one filter is recommended; omitting all filters returns CVEs in default NVD index order (oldest first by CVE ID).
읽기 전용
입력 스키마
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'cweId': {'type': 'string', 'description': 'Filter by CWE weakness ID (e.g., "CWE-79", "NVD-CWE-Other").'}, 'limit': {'type': 'integer', 'default': 20, 'maximum': 2000, 'minimum': 1, 'description': 'Maximum number of results to return (default 20, max 2000).'}, 'offset': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Zero-based page offset for pagination.'}, 'kevOnly': {'type': 'boolean', 'default': False, 'description': 'When true, filters results to CVEs in the CISA Known Exploited Vulnerabilities catalog.'}, 'keyword': {'type': 'string', 'description': 'Full-text search across CVE descriptions (AND-semantics across words).'}, 'pubDays': {'type': 'integer', 'maximum': 9007199254740991, 'description': 'CVEs published in the last N days (max 120; values over 120 are clamped). Mutually exclusive with pubStartDate/pubEndDate.', 'exclusiveMinimum': 0}, 'severity': {'enum': ['LOW', 'MEDIUM', 'HIGH', 'CRITICAL'], 'type': 'string', 'description': 'Filter to CVEs in exactly this CVSS severity band â\x80\x94 NVD matches the one band, not a floor. Covering several bands (e.g. HIGH and CRITICAL) takes one call per band.'}, 'noRejected': {'type': 'boolean', 'default': True, 'description': 'When true (default), excludes CVEs with REJECT/Rejected status.'}, 'pubEndDate': {'type': 'string', 'description': 'ISO 8601 datetime for publication range end. Both pubStartDate and pubEndDate required together.'}, 'exactPhrase': {'type': 'boolean', 'default': False, 'description': 'When true, keyword matches as an exact phrase rather than ANDing its words independently. Requires keyword.'}, 'lastModDays': {'type': 'integer', 'maximum': 9007199254740991, 'description': 'CVEs last modified in the last N days (max 120; values over 120 are clamped). Mutually exclusive with lastModStartDate/lastModEndDate.', 'exclusiveMinimum': 0}, 'pubStartDate': {'type': 'string', 'description': 'ISO 8601 datetime for publication range start. Both pubStartDate and pubEndDate required together. Mutually exclusive with pubDays.'}, 'lastModEndDate': {'type': 'string', 'description': 'ISO 8601 datetime for last-modified range end. Both required together.'}, 'severityVersion': {'enum': ['v2', 'v3', 'v4'], 'type': 'string', 'default': 'v3', 'description': 'CVSS version to use for the severity filter. Default: v3 (maps to cvssV3Severity).'}, 'lastModStartDate': {'type': 'string', 'description': 'ISO 8601 datetime for last-modified range start. Both required together. Mutually exclusive with lastModDays.'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['cves', 'totalCount', 'returned', 'offset']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'cves': {'type': 'array', 'items': {'type': 'object', 'required': ['cveId', 'vulnStatus', 'published'], 'properties': {'cveId': {'type': 'string', 'description': 'CVE identifier (e.g., "CVE-2021-44228").'}, 'severity': {'type': 'object', 'required': ['label', 'score', 'fromVersion'], 'properties': {'label': {'type': 'string', 'description': 'Highest severity label across all CVSS versions.'}, 'score': {'type': 'number', 'description': 'Highest base score (0.0â\x80\x9310.0).'}, 'fromVersion': {'type': 'string', 'description': 'CVSS version this score came from.'}}, 'description': 'Top severity. Absent if no CVSS scores are present.', 'additionalProperties': False}, 'published': {'type': 'string', 'description': 'ISO 8601 publication datetime.'}, 'vulnStatus': {'type': 'string', 'description': 'NVD analysis status.'}, 'description': {'type': 'string', 'description': 'Opening 200 characters of the English CVE description, truncated with an ellipsis when longer. Enough to tell one result from another; call nvd_get_cve for the full text. Absent when NVD carries no description for the record.'}, 'filteredSeverity': {'type': 'object', 'required': ['label', 'score', 'fromVersion'], 'properties': {'label': {'type': 'string', 'description': 'Severity label at the CVSS version the severity filter used.'}, 'score': {'type': 'number', 'description': 'Base score at that CVSS version (0.0â\x80\x9310.0).'}, 'fromVersion': {'type': 'string', 'description': 'The CVSS version the severity filter matched on.'}}, 'description': 'Severity at the CVSS version the severity filter matched this CVE on. Present only when a severity filter was supplied and that version disagrees with the cross-version top severity above â\x80\x94 e.g. a CVE scored v2 10.0 (HIGH) and v3.1 9.8 (CRITICAL) headlines as HIGH but matched a CRITICAL v3 query on the 9.8.', 'additionalProperties': False}, 'cisaVulnerabilityName': {'type': 'string', 'description': 'CISA KEV vulnerability name. Present only when in the KEV catalog.'}}, 'description': 'Brief summary for one matching CVE.', 'additionalProperties': False}, 'description': 'Matching CVE summaries. Call nvd_get_cve for full detail on specific IDs.'}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['exact_phrase_without_keyword', 'mutually_exclusive_params', 'missing_date_pair', 'date_range_inverted', 'date_range_exceeds_max', 'invalid_date_format', 'invalid_severity_for_version', 'rate_limited'], 'description': 'Machine-readable failure mode. Declared by this tool: `exact_phrase_without_keyword`: exactPhrase was set without a keyword. It selects how keyword matches and has nothing to modify on its own; NVD rejects the underlying flag on the same grounds. `mutually_exclusive_params`: Both pubDays and pubStartDate/pubEndDate provided, or both lastModDays and lastModStartDate/lastModEndDate. `missing_date_pair`: Only one of pubStartDate/pubEndDate (or lastModStartDate/lastModEndDate) was provided â\x80\x94 NVD requires both. `date_range_inverted`: The end date is before the start date. `date_range_exceeds_max`: Explicit pubStartDate/pubEndDate or lastModStartDate/lastModEndDate span more than 120 days. `invalid_date_format`: A date string provided for pubStartDate, pubEndDate, lastModStartDate, or lastModEndDate is not a valid ISO 8601 datetime. `invalid_severity_for_version`: severity="CRITICAL" was specified with severityVersion="v2" â\x80\x94 CVSS v2 has no CRITICAL tier. `rate_limited`: NVD returned HTTP 403 indicating the rate limit was exceeded. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'notice': {'type': 'string', 'description': 'Guidance when no CVEs were returned â\x80\x94 distinguishes a query nothing matched from an offset past the result set from an empty page NVD returned inside a range it says has matches â\x80\x94 or, on a partial page, the offset that reaches the next one.'}, 'offset': {'type': 'number', 'description': 'Page offset used in this query.'}, 'returned': {'type': 'number', 'description': 'Number of CVEs returned in this response.'}, 'totalCount': {'type': 'number', 'description': 'Total matching CVEs in NVD before pagination.'}, 'datesClamped': {'type': 'array', 'items': {'type': 'object', 'required': ['param', 'original', 'clamped'], 'properties': {'param': {'type': 'string', 'description': 'The parameter that was clamped (pubDays or lastModDays).'}, 'clamped': {'type': 'number', 'description': 'The clamped value used (max 120).'}, 'original': {'type': 'number', 'description': 'The original value supplied.'}}, 'description': 'A single clamping event for one convenience date parameter.', 'additionalProperties': False}, 'description': 'Entries for any pubDays/lastModDays values that exceeded 120 and were auto-clamped. Absent when no clamping occurred.'}, 'filtersApplied': {'type': 'object', 'properties': {'cweId': {'type': 'string', 'description': 'The CWE weakness filter that was applied.'}, 'kevOnly': {'type': 'boolean', 'description': 'Present as true when results were limited to the CISA KEV catalog.'}, 'keyword': {'type': 'string', 'description': 'The keyword filter that was applied.'}, 'severity': {'type': 'string', 'description': 'The exact CVSS severity band that was applied â\x80\x94 results are limited to this band alone, so higher bands are not included.'}, 'noRejected': {'type': 'boolean', 'description': 'Present as false when rejected CVEs were left in the results.'}, 'exactPhrase': {'type': 'boolean', 'description': 'Present as true when the keyword was matched as an exact phrase rather than word-by-word.'}, 'severityVersion': {'type': 'string', 'description': 'The CVSS version the severity filter matched on. Present only alongside severity.'}}, 'description': 'The non-default filters this query actually applied â\x80\x94 the ones that can account for an empty or unexpectedly narrow result set. Absent when the query ran unfiltered, which is itself the answer when a result set is unexpectedly broad.', 'additionalProperties': False}}, 'additionalProperties': False}
추가됨
nvd_get_cve_history
2026년 9월 22일 2:40 AM
추가됨
nvd_search_cpes
2026년 9월 22일 2:40 AM
추가됨
nvd_audit_cpe
2026년 9월 22일 2:40 AM
추가됨
nvd_search_cves
2026년 9월 22일 2:40 AM
추가됨
nvd_get_cve
2026년 9월 22일 2:40 AM