POSThttps://api.deepinfo.com/v1/easm/vulnerabilities/asset-search:export

Exports every record matching filters (no pagination). format=csv returns CSV text; format=json returns a JSON array. Large exports can time out: narrow them with filters.

Authentication

Send your API key in the apikey request header.

Query Parameters

ParameterRequiredDescription
formatOptional
One of: json, csv.
Examplecsv

Request Body

ParameterTypeRequiredDescription
filtersobjectOptional
See Filtering below
sortarrayOptional
List of {field, order}
application/json
{
  "filters": {
    "must": [
      {
        "name": "asset",
        "type": "eq",
        "value": "acme.example"
      }
    ]
  }
}

Filtering

Example body:

JSON
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "asset.name",
      "order": "desc"
    }
  ]
}

See Getting Started → Search & Filters for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators eq in startswith endswith wildcard fuzzy contains_any contains_all exists

FieldDescription
assetThe affected asset's name, for filtering: a domain, subdomain or IP address, or for a website asset host:port. Filter with eq and the exact name to get one asset's CVEs; responses carry it in asset.name.
domain_assetThe name of the domain asset the affected asset belongs to, for filtering (for a domain, its own name); responses carry it in asset.domain_asset.name.
asset_tagsYour own tags on the affected asset, for filtering; responses carry them in asset.tags.
technologies.vendorVendor of a technology detected on the affected asset, as a lower-case identifier such as apache, php or jquery. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.
technologies.productProduct name of a technology detected on the affected asset, as a lower-case identifier such as http_server, php or bootstrap.
technologies.versionDetected version of that technology on the affected asset, such as 1.0.0; empty when no version was detected.
cve.idThe CVE identifier, such as CVE-2021-44228; filter on it to list the assets the CVE affects.
cve.enrichment.vdeep_metric.cvss_versionCVSS version of the CVE's main CVSS assessment, the one the cvss_data fields come from, for example 3.1, 3.0 or 2.0.
cve.enrichment.cwe.owasptop10_2021OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example A03 Injection or A01 Broken Access Control; empty when the CWE has none. The platform shows it as the OWASP chip.
cve.enrichment.cwe.nameName of a CWE weakness linked to the CVE, for example Out-of-bounds Write or Improper Input Validation.
cve.enrichment.cwe.descriptionThe CWE catalog's description of a weakness linked to the CVE.
cve.enrichment.cwe.scopeSecurity areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: Confidentiality, Integrity, Availability, Access Control, Authentication, Authorization, Accountability, Non-Repudiation, Other.
cve.enrichment.cwe.impactTechnical impacts a CWE weakness of the CVE can have, from the CWE entry, for example Execute Unauthorized Code or Commands, Read Memory or DoS: Crash, Exit, or Restart.
cve.enrichment.cwe.detection_methodMethods that can detect a CWE weakness of the CVE, from the CWE entry, for example Automated Static Analysis, Fuzzing or Manual Analysis; the platform shows them as DETECTION METHOD.
cve.enrichment.cisa_kev.vendor_projectVendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example Apache or Microsoft; empty for CVEs not in the catalog.
cve.enrichment.cisa_kev.productProduct named in the CVE's CISA KEV entry, for example Log4j2 or Multiple Products.
cve.enrichment.cisa_kev.vulnerability_nameName of the vulnerability in the CVE's CISA KEV entry, for example Apache Log4j2 Remote Code Execution Vulnerability.
cve.enrichment.cisa_kev.short_descriptionCISA's short description of the vulnerability in the CVE's KEV entry.
cve.enrichment.cisa_kev.required_actionAction CISA requires in the CVE's KEV entry, for example Apply updates per vendor instructions.
cve.enrichment.cisa_kev.known_ransomware_campaign_useWhether the CVE's CISA KEV entry reports use in ransomware campaigns: Known or Unknown; the platform adds a RANSOMWARE badge for Known.
cve.enrichment.cisa_kev.notesNotes in the CVE's CISA KEV entry, often reference URLs.

Operators eq in gte lte exists

FieldDescription
cve.publishedWhen the CVE was first published, in ISO 8601 UTC (for example 2025-06-01T08:00:00Z).
cve.last_modifiedWhen the CVE record was last changed, in ISO 8601 UTC.
cve.enrichment.vdeep_metric.cvss_data.base_scoreCVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.
cve.enrichment.cwe.idNumber of a CWE weakness linked to the CVE, for example 787 for CWE-787; a CVE can have several CWEs or none. The platform shows it as CWE-<id> after the CWE name.
cve.enrichment.cwe.capec_idIDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as CAPEC-<id> under ATTACK STAGES.
cve.enrichment.epss_score.epssEPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.
cve.enrichment.epss_score.percentilePercentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (0.95 means 95% of them have the same or a lower score).
cve.enrichment.epss_score.dateDate of the CVE's EPSS score, as a UTC date-time at midnight (for example 2026-09-23T00:00:00Z); the platform shows it as ANALYSIS DATE.
cve.enrichment.cisa_kev.date_addedDate the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.
cve.enrichment.cisa_kev.due_dateRemediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill.
first_seen_dateWhen the CVE was first detected on this asset, in ISO 8601 UTC.
last_seen_dateWhen the CVE was most recently detected on this asset, in ISO 8601 UTC.
last_check_dateWhen the asset was last checked for this CVE, in ISO 8601 UTC; it equals last_seen_date while the CVE is still found and is later once the CVE is verified_resolved.

Operators eq in exists

FieldDescription
asset_typeThe affected asset's type, for filtering: domain, subdomain, ip or website; responses carry it in asset.type.
cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentialityConfidentiality impact of the CVE's main CVSS assessment: NONE, PARTIAL or COMPLETE for CVSS 2.0, NONE, LOW or HIGH for CVSS 3.x. The platform shows it as the C of the C/I/A chip.
cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrityIntegrity impact of the CVE's main CVSS assessment: NONE, PARTIAL or COMPLETE for CVSS 2.0, NONE, LOW or HIGH for CVSS 3.x. The platform shows it as the I of the C/I/A chip.
cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availabilityAvailability impact of the CVE's main CVSS assessment: NONE, PARTIAL or COMPLETE for CVSS 2.0, NONE, LOW or HIGH for CVSS 3.x. The platform shows it as the A of the C/I/A chip.
cve.enrichment.vdeep_metric.cvss_data.base_severitySeverity of the CVE's main CVSS assessment: critical, high, medium, low, none or unknown; CVSS 2.0 has no critical, so a 2.0 score of 10 is high. The Vulnerability List severity tabs filter on it.
stateThe CVE's state on this asset: newly_detected, unresolved and reappeared are active states set by the platform; not_applicable and verified_resolved are inactive states set by the platform, and ignored, risk_accepted, marked_as_resolved and marked_as_false_positive are inactive states you set.

Operators eq exists

FieldDescription
is_certaintrue when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.
is_potentialtrue when the CVE on this asset has been identified through testing but not yet confirmed (Potential).

Sortable Fields

FieldDescription
asset.nameThe affected asset's name: a domain, subdomain or IP address, or for a website asset host:port. Sort only; filter with asset.
asset.typeThe affected asset's type: domain, subdomain, ip or website. Sort only; filter with asset_type.
asset.domain_asset.nameThe name of the domain asset the affected asset belongs to (for a domain, its own name); null when the asset's domain is not one of your assets. Sort only; filter with domain_asset.
technologies.vendorVendor of a technology detected on the affected asset, as a lower-case identifier such as apache, php or jquery. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.
technologies.productProduct name of a technology detected on the affected asset, as a lower-case identifier such as http_server, php or bootstrap.
technologies.versionDetected version of that technology on the affected asset, such as 1.0.0; empty when no version was detected.
cve.idThe CVE identifier, such as CVE-2021-44228; filter on it to list the assets the CVE affects.
cve.publishedWhen the CVE was first published, in ISO 8601 UTC (for example 2025-06-01T08:00:00Z).
cve.last_modifiedWhen the CVE record was last changed, in ISO 8601 UTC.
cve.enrichment.vdeep_metric.cvss_data.base_scoreCVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.
cve.enrichment.vdeep_metric.cvss_data.base_severitySeverity of the CVE's main CVSS assessment: critical, high, medium, low, none or unknown; CVSS 2.0 has no critical, so a 2.0 score of 10 is high. The Vulnerability List severity tabs filter on it.
cve.enrichment.cwe.idNumber of a CWE weakness linked to the CVE, for example 787 for CWE-787; a CVE can have several CWEs or none. The platform shows it as CWE-<id> after the CWE name.
cve.enrichment.epss_score.epssEPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.
cve.enrichment.cisa_kev.date_addedDate the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.
first_seen_dateWhen the CVE was first detected on this asset, in ISO 8601 UTC.
last_seen_dateWhen the CVE was most recently detected on this asset, in ISO 8601 UTC.
stateThe CVE's state on this asset: newly_detected, unresolved and reappeared are active states set by the platform; not_applicable and verified_resolved are inactive states set by the platform, and ignored, risk_accepted, marked_as_resolved and marked_as_false_positive are inactive states you set.
is_certaintrue when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.
is_potentialtrue when the CVE on this asset has been identified through testing but not yet confirmed (Potential).

Examples

Selecting one loads it into the request and response panels.

Reference updated