Vulnerability Asset Export
https://api.deepinfo.com/v1/easm/vulnerabilities/asset-search:exportExports every record matching filters (no pagination). format=csv returns CSV text; format=json returns a JSON array. Large exports can time out: narrow them with filters.
Authentication
Send your API key in the apikey request header.
Query Parameters
| Parameter | Required | Description |
|---|---|---|
format | Optional | One of: json, csv.Example csv |
Request Body
| Parameter | Type | Required | Description |
|---|---|---|---|
filters | object | Optional | See Filtering below |
sort | array | Optional | List of {field, order} |
{
"filters": {
"must": [
{
"name": "asset",
"type": "eq",
"value": "acme.example"
}
]
}
}
Filtering
Example body:
{
"filters": {
"must": [
{
"name": "state",
"type": "eq",
"value": "<value>"
}
]
},
"sort": [
{
"field": "asset.name",
"order": "desc"
}
]
}
See Getting Started → Search & Filters for the operators.
The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.
Searchable Fields
Grouped by the operators they accept (measured against the API; sending another operator returns 400).
Operators eq in startswith endswith wildcard fuzzy contains_ contains_ exists
| Field | Description |
|---|---|
asset | The affected asset's name, for filtering: a domain, subdomain or IP address, or for a website asset host:port. Filter with eq and the exact name to get one asset's CVEs; responses carry it in asset.name. |
domain_ | The name of the domain asset the affected asset belongs to, for filtering (for a domain, its own name); responses carry it in asset.domain_asset.name. |
asset_ | Your own tags on the affected asset, for filtering; responses carry them in asset.tags. |
technologies. | Vendor of a technology detected on the affected asset, as a lower-case identifier such as apache, php or jquery. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE. |
technologies. | Product name of a technology detected on the affected asset, as a lower-case identifier such as http_server, php or bootstrap. |
technologies. | Detected version of that technology on the affected asset, such as 1.0.0; empty when no version was detected. |
cve. | The CVE identifier, such as CVE-2021-44228; filter on it to list the assets the CVE affects. |
cve. | CVSS version of the CVE's main CVSS assessment, the one the cvss_data fields come from, for example 3.1, 3.0 or 2.0. |
cve. | OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example A03 Injection or A01 Broken Access Control; empty when the CWE has none. The platform shows it as the OWASP chip. |
cve. | Name of a CWE weakness linked to the CVE, for example Out-of-bounds Write or Improper Input Validation. |
cve. | The CWE catalog's description of a weakness linked to the CVE. |
cve. | Security areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: Confidentiality, Integrity, Availability, Access Control, Authentication, Authorization, Accountability, Non-Repudiation, Other. |
cve. | Technical impacts a CWE weakness of the CVE can have, from the CWE entry, for example Execute Unauthorized Code or Commands, Read Memory or DoS: Crash, Exit, or Restart. |
cve. | Methods that can detect a CWE weakness of the CVE, from the CWE entry, for example Automated Static Analysis, Fuzzing or Manual Analysis; the platform shows them as DETECTION METHOD. |
cve. | Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example Apache or Microsoft; empty for CVEs not in the catalog. |
cve. | Product named in the CVE's CISA KEV entry, for example Log4j2 or Multiple Products. |
cve. | Name of the vulnerability in the CVE's CISA KEV entry, for example Apache Log4j2 Remote Code Execution Vulnerability. |
cve. | CISA's short description of the vulnerability in the CVE's KEV entry. |
cve. | Action CISA requires in the CVE's KEV entry, for example Apply updates per vendor instructions. |
cve. | Whether the CVE's CISA KEV entry reports use in ransomware campaigns: Known or Unknown; the platform adds a RANSOMWARE badge for Known. |
cve. | Notes in the CVE's CISA KEV entry, often reference URLs. |
Operators eq in gte lte exists
| Field | Description |
|---|---|
cve. | When the CVE was first published, in ISO 8601 UTC (for example 2025-06-01T08:00:00Z). |
cve. | When the CVE record was last changed, in ISO 8601 UTC. |
cve. | CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY. |
cve. | Number of a CWE weakness linked to the CVE, for example 787 for CWE-787; a CVE can have several CWEs or none. The platform shows it as CWE-<id> after the CWE name. |
cve. | IDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as CAPEC-<id> under ATTACK STAGES. |
cve. | EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage. |
cve. | Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (0.95 means 95% of them have the same or a lower score). |
cve. | Date of the CVE's EPSS score, as a UTC date-time at midnight (for example 2026-09-23T00:00:00Z); the platform shows it as ANALYSIS DATE. |
cve. | Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog. |
cve. | Remediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill. |
first_ | When the CVE was first detected on this asset, in ISO 8601 UTC. |
last_ | When the CVE was most recently detected on this asset, in ISO 8601 UTC. |
last_ | When the asset was last checked for this CVE, in ISO 8601 UTC; it equals last_seen_date while the CVE is still found and is later once the CVE is verified_resolved. |
Operators eq in exists
| Field | Description |
|---|---|
asset_ | The affected asset's type, for filtering: domain, subdomain, ip or website; responses carry it in asset.type. |
cve. | Confidentiality impact of the CVE's main CVSS assessment: NONE, PARTIAL or COMPLETE for CVSS 2.0, NONE, LOW or HIGH for CVSS 3.x. The platform shows it as the C of the C/I/A chip. |
cve. | Integrity impact of the CVE's main CVSS assessment: NONE, PARTIAL or COMPLETE for CVSS 2.0, NONE, LOW or HIGH for CVSS 3.x. The platform shows it as the I of the C/I/A chip. |
cve. | Availability impact of the CVE's main CVSS assessment: NONE, PARTIAL or COMPLETE for CVSS 2.0, NONE, LOW or HIGH for CVSS 3.x. The platform shows it as the A of the C/I/A chip. |
cve. | Severity of the CVE's main CVSS assessment: critical, high, medium, low, none or unknown; CVSS 2.0 has no critical, so a 2.0 score of 10 is high. The Vulnerability List severity tabs filter on it. |
state | The CVE's state on this asset: newly_detected, unresolved and reappeared are active states set by the platform; not_applicable and verified_resolved are inactive states set by the platform, and ignored, risk_accepted, marked_as_resolved and marked_as_false_positive are inactive states you set. |
Operators eq exists
| Field | Description |
|---|---|
is_ | true when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both. |
is_ | true when the CVE on this asset has been identified through testing but not yet confirmed (Potential). |
Sortable Fields
| Field | Description |
|---|---|
asset. | The affected asset's name: a domain, subdomain or IP address, or for a website asset host:port. Sort only; filter with asset. |
asset. | The affected asset's type: domain, subdomain, ip or website. Sort only; filter with asset_type. |
asset. | The name of the domain asset the affected asset belongs to (for a domain, its own name); null when the asset's domain is not one of your assets. Sort only; filter with domain_asset. |
technologies. | Vendor of a technology detected on the affected asset, as a lower-case identifier such as apache, php or jquery. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE. |
technologies. | Product name of a technology detected on the affected asset, as a lower-case identifier such as http_server, php or bootstrap. |
technologies. | Detected version of that technology on the affected asset, such as 1.0.0; empty when no version was detected. |
cve. | The CVE identifier, such as CVE-2021-44228; filter on it to list the assets the CVE affects. |
cve. | When the CVE was first published, in ISO 8601 UTC (for example 2025-06-01T08:00:00Z). |
cve. | When the CVE record was last changed, in ISO 8601 UTC. |
cve. | CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY. |
cve. | Severity of the CVE's main CVSS assessment: critical, high, medium, low, none or unknown; CVSS 2.0 has no critical, so a 2.0 score of 10 is high. The Vulnerability List severity tabs filter on it. |
cve. | Number of a CWE weakness linked to the CVE, for example 787 for CWE-787; a CVE can have several CWEs or none. The platform shows it as CWE-<id> after the CWE name. |
cve. | EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage. |
cve. | Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog. |
first_ | When the CVE was first detected on this asset, in ISO 8601 UTC. |
last_ | When the CVE was most recently detected on this asset, in ISO 8601 UTC. |
state | The CVE's state on this asset: newly_detected, unresolved and reappeared are active states set by the platform; not_applicable and verified_resolved are inactive states set by the platform, and ignored, risk_accepted, marked_as_resolved and marked_as_false_positive are inactive states you set. |
is_ | true when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both. |
is_ | true when the CVE on this asset has been identified through testing but not yet confirmed (Potential). |
Examples
Selecting one loads it into the request and response panels.