# Vulnerability Asset Search

POST /easm/vulnerabilities/asset-search: Searches vulnerabilities per asset (one record per asset + CVE), with state.

Source: https://docs.deepinfo.com/reference/easm/vulnerability-asset-search/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/easm/vulnerabilities/asset-search`

Searches vulnerabilities per asset (one record per asset + CVE), with state.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `page_size` | Optional | Min `25`, max `100`. Default `100`. | `25` |
| `page` | Optional | Min `1`, max `800`. Default `1`. | `1` |

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | array | Optional | List of `{field, order}` |

```json
{}
```

## Filtering

Example body:

```json
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "asset.name",
      "order": "desc"
    }
  ]
}
```

See [Getting Started → Search & Filters](/getting-started/search-and-filters/) for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

### Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators: `eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`

| Field | Description |
|---|---|
| `asset` | The affected asset's name, for filtering: a domain, subdomain or IP address, or for a website asset `host:port`. Filter with `eq` and the exact name to get one asset's CVEs; responses carry it in `asset.name`. |
| `domain_asset` | The name of the domain asset the affected asset belongs to, for filtering (for a domain, its own name); responses carry it in `asset.domain_asset.name`. |
| `asset_tags` | Your own tags on the affected asset, for filtering; responses carry them in `asset.tags`. |
| `technologies.vendor` | Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE. |
| `technologies.product` | Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`. |
| `technologies.version` | Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected. |
| `cve.id` | The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects. |
| `cve.enrichment.vdeep_metric.cvss_version` | CVSS version of the CVE's main CVSS assessment, the one the `cvss_data` fields come from, for example `3.1`, `3.0` or `2.0`. |
| `cve.enrichment.cwe.owasptop10_2021` | OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example `A03 Injection` or `A01 Broken Access Control`; empty when the CWE has none. The platform shows it as the OWASP chip. |
| `cve.enrichment.cwe.name` | Name of a CWE weakness linked to the CVE, for example `Out-of-bounds Write` or `Improper Input Validation`. |
| `cve.enrichment.cwe.description` | The CWE catalog's description of a weakness linked to the CVE. |
| `cve.enrichment.cwe.scope` | Security areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: `Confidentiality`, `Integrity`, `Availability`, `Access Control`, `Authentication`, `Authorization`, `Accountability`, `Non-Repudiation`, `Other`. |
| `cve.enrichment.cwe.impact` | Technical impacts a CWE weakness of the CVE can have, from the CWE entry, for example `Execute Unauthorized Code or Commands`, `Read Memory` or `DoS: Crash, Exit, or Restart`. |
| `cve.enrichment.cwe.detection_method` | Methods that can detect a CWE weakness of the CVE, from the CWE entry, for example `Automated Static Analysis`, `Fuzzing` or `Manual Analysis`; the platform shows them as DETECTION METHOD. |
| `cve.enrichment.cisa_kev.vendor_project` | Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example `Apache` or `Microsoft`; empty for CVEs not in the catalog. |
| `cve.enrichment.cisa_kev.product` | Product named in the CVE's CISA KEV entry, for example `Log4j2` or `Multiple Products`. |
| `cve.enrichment.cisa_kev.vulnerability_name` | Name of the vulnerability in the CVE's CISA KEV entry, for example `Apache Log4j2 Remote Code Execution Vulnerability`. |
| `cve.enrichment.cisa_kev.short_description` | CISA's short description of the vulnerability in the CVE's KEV entry. |
| `cve.enrichment.cisa_kev.required_action` | Action CISA requires in the CVE's KEV entry, for example `Apply updates per vendor instructions.` |
| `cve.enrichment.cisa_kev.known_ransomware_campaign_use` | Whether the CVE's CISA KEV entry reports use in ransomware campaigns: `Known` or `Unknown`; the platform adds a RANSOMWARE badge for `Known`. |
| `cve.enrichment.cisa_kev.notes` | Notes in the CVE's CISA KEV entry, often reference URLs. |

Operators: `eq`, `in`, `gte`, `lte`, `exists`

| Field | Description |
|---|---|
| `cve.published` | When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). |
| `cve.last_modified` | When the CVE record was last changed, in ISO 8601 UTC. |
| `cve.enrichment.vdeep_metric.cvss_data.base_score` | CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY. |
| `cve.enrichment.cwe.id` | Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name. |
| `cve.enrichment.cwe.capec_id` | IDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as `CAPEC-<id>` under ATTACK STAGES. |
| `cve.enrichment.epss_score.epss` | EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage. |
| `cve.enrichment.epss_score.percentile` | Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (`0.95` means 95% of them have the same or a lower score). |
| `cve.enrichment.epss_score.date` | Date of the CVE's EPSS score, as a UTC date-time at midnight (for example `2026-09-23T00:00:00Z`); the platform shows it as ANALYSIS DATE. |
| `cve.enrichment.cisa_kev.date_added` | Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog. |
| `cve.enrichment.cisa_kev.due_date` | Remediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill. |
| `first_seen_date` | When the CVE was first detected on this asset, in ISO 8601 UTC. |
| `last_seen_date` | When the CVE was most recently detected on this asset, in ISO 8601 UTC. |
| `last_check_date` | When the asset was last checked for this CVE, in ISO 8601 UTC; it equals `last_seen_date` while the CVE is still found and is later once the CVE is `verified_resolved`. |

Operators: `eq`, `in`, `exists`

| Field | Description |
|---|---|
| `asset_type` | The affected asset's type, for filtering: `domain`, `subdomain`, `ip` or `website`; responses carry it in `asset.type`. |
| `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality` | Confidentiality impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the C of the C/I/A chip. |
| `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity` | Integrity impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the I of the C/I/A chip. |
| `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability` | Availability impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the A of the C/I/A chip. |
| `cve.enrichment.vdeep_metric.cvss_data.base_severity` | Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it. |
| `state` | The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set. |

Operators: `eq`, `exists`

| Field | Description |
|---|---|
| `is_certain` | `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both. |
| `is_potential` | `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential). |

### Sortable Fields

| Field | Description |
|---|---|
| `asset.name` | The affected asset's name: a domain, subdomain or IP address, or for a website asset `host:port`. Sort only; filter with `asset`. |
| `asset.type` | The affected asset's type: `domain`, `subdomain`, `ip` or `website`. Sort only; filter with `asset_type`. |
| `asset.domain_asset.name` | The name of the domain asset the affected asset belongs to (for a domain, its own name); null when the asset's domain is not one of your assets. Sort only; filter with `domain_asset`. |
| `technologies.vendor` | Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE. |
| `technologies.product` | Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`. |
| `technologies.version` | Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected. |
| `cve.id` | The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects. |
| `cve.published` | When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). |
| `cve.last_modified` | When the CVE record was last changed, in ISO 8601 UTC. |
| `cve.enrichment.vdeep_metric.cvss_data.base_score` | CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY. |
| `cve.enrichment.vdeep_metric.cvss_data.base_severity` | Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it. |
| `cve.enrichment.cwe.id` | Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name. |
| `cve.enrichment.epss_score.epss` | EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage. |
| `cve.enrichment.cisa_kev.date_added` | Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog. |
| `first_seen_date` | When the CVE was first detected on this asset, in ISO 8601 UTC. |
| `last_seen_date` | When the CVE was most recently detected on this asset, in ISO 8601 UTC. |
| `state` | The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set. |
| `is_certain` | `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both. |
| `is_potential` | `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential). |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `page` | integer |  |
| `page_size` | integer |  |
| `result_count` | integer |  |
| `results` | array of object |  |
| `results[].id` | string |  |
| `results[].asset` | object |  |
| `results[].technologies` | array of object |  |
| `results[].cve` | object |  |
| `results[].first_seen_date` | string | date-time |
| `results[].last_seen_date` | string | date-time |
| `results[].last_check_date` | string | date-time |
| `results[].state` | string | One of `newly_detected`, `reappeared`, `unresolved`, `marked_as_resolved`, `risk_accepted`, `ignored`, `marked_as_false_positive`, `not_applicable`, `verified_resolved` |
| `results[].is_certain` | boolean |  |
| `results[].is_potential` | boolean |  |

Paginated. See [Getting Started → Pagination](/getting-started/pagination/).

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `page` | number |
| `page_size` | number |
| `result_count` | number |
| `results` | array<object> |
| `results[].id` | string |
| `results[].asset` | object |
| `results[].asset.id` | string |
| `results[].asset.name` | string |
| `results[].asset.name_unicode` | string |
| `results[].asset.type` | string |
| `results[].asset.domain_asset` | object |
| `results[].asset.domain_asset.id` | string |
| `results[].asset.domain_asset.name` | string |
| `results[].asset.domain_asset.name_unicode` | string |
| `results[].asset.tags` | array |
| `results[].technologies` | array<object> |
| `results[].technologies[].vendor` | string |
| `results[].technologies[].product` | string |
| `results[].technologies[].version` | string \| null |
| `results[].cve` | object |
| `results[].cve.id` | string |
| `results[].cve.published` | string |
| `results[].cve.last_modified` | string |
| `results[].cve.enrichment` | object |
| `results[].cve.enrichment.cwe` | array<object> |
| `results[].cve.enrichment.cwe[].id` | number |
| `results[].cve.enrichment.cwe[].owasptop10_2021` | string |
| `results[].cve.enrichment.cwe[].name` | string |
| `results[].cve.enrichment.cwe[].description` | string |
| `results[].cve.enrichment.cwe[].capec_id` | array<number> |
| `results[].cve.enrichment.cwe[].scope` | array<string> |
| `results[].cve.enrichment.cwe[].impact` | array<string> |
| `results[].cve.enrichment.cwe[].detection_method` | array |
| `results[].cve.enrichment.epss_score` | object |
| `results[].cve.enrichment.epss_score.epss` | number |
| `results[].cve.enrichment.epss_score.percentile` | number |
| `results[].cve.enrichment.epss_score.date` | string |
| `results[].cve.enrichment.cisa_kev` | null |
| `results[].cve.enrichment.vdeep_metric` | object |
| `results[].cve.enrichment.vdeep_metric.cvss_version` | string |
| `results[].cve.enrichment.vdeep_metric.cvss_data` | object |
| `results[].cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality` | string |
| `results[].cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity` | string |
| `results[].cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability` | string |
| `results[].cve.enrichment.vdeep_metric.cvss_data.base_score` | number |
| `results[].cve.enrichment.vdeep_metric.cvss_data.base_severity` | string |
| `results[].first_seen_date` | string |
| `results[].last_seen_date` | string |
| `results[].last_check_date` | string |
| `results[].state` | string |
| `results[].is_certain` | boolean |
| `results[].is_potential` | boolean |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/easm/vulnerabilities/asset-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 21,
  "results": [
    {
      "id": "00000000000000000000000e0c9d0001",
      "asset": {
        "id": "000000000000000ea4f90001",
        "name": "acme.example",
        "name_unicode": "acme.example",
        "type": "domain",
        "domain_asset": {
          "id": "000000000000000e915c0001",
          "name": "acme.example",
          "name_unicode": "acme.example"
        },
        "tags": []
      },
      "technologies": [
        {
          "vendor": "acme",
          "product": "acme.js",
          "version": null
        },
        {
          "vendor": "acme-2",
          "product": "acme-portal-2",
          "version": "1.0.0"
        }
      ],
      "cve": {
        "id": "CVE-0000-0001",
        "published": "2025-06-01T08:00:00Z",
        "last_modified": "2025-07-01T08:00:00Z",
        "enrichment": {
          "cwe": [
            {
              "id": 79,
              "owasptop10_2021": "A03 Injection",
              "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
              "description": "Web page output includes user input without neutralizing it.",
              "capec_id": [
                100,
                101
              ],
              "scope": [
                "Other"
              ],
              "impact": [
                "Varies by Context"
              ],
              "detection_method": []
            }
          ],
          "epss_score": {
            "epss": 0.05,
            "percentile": 0.5,
            "date": "2025-07-16T08:00:00Z"
          },
          "cisa_kev": null,
          "vdeep_metric": {
            "cvss_version": "3.1",
            "cvss_data": {
              "vulnerable_system_confidentiality": "HIGH",
              "vulnerable_system_integrity": "HIGH",
              "vulnerable_system_availability": "HIGH",
              "base_score": 9.8,
              "base_severity": "critical"
            }
          }
        }
      },
      "first_seen_date": "2025-06-01T08:00:00Z",
      "last_seen_date": "2025-07-31T08:00:00Z",
      "last_check_date": "2025-07-31T08:00:00Z",
      "state": "verified_resolved",
      "is_certain": true,
      "is_potential": false
    },
    {
      "id": "00000000000000000000000e0c9d0002",
      "asset": {
        "id": "000000000000000ea4f90002",
        "name": "fernhill.example",
        "name_unicode": "fernhill.example",
        "type": "domain",
        "domain_asset": {
          "id": "000000000000000e915c0002",
          "name": "fernhill.example",
          "name_unicode": "fernhill.example"
        },
        "tags": []
      },
      "technologies": [
        {
          "vendor": "acme-4",
          "product": "acme-portal-4",
          "version": null
        },
        {
          "vendor": "acme-5",
          "product": "acme-portal-5",
          "version": null
        }
      ],
      "cve": {
        "id": "CVE-0000-0002",
        "published": "2025-05-25T08:00:00Z",
        "last_modified": "2025-06-24T08:00:00Z",
        "enrichment": {
          "cwe": [
            {
              "id": 200,
              "owasptop10_2021": "A01 Broken Access Control",
              "name": "Exposure of Sensitive Information to an Unauthorized Actor",
              "description": "Sensitive information reaches someone who should not see it.",
              "capec_id": [
                109,
                110
              ],
              "scope": [
                "Other"
              ],
              "impact": [
                "Varies by Context"
              ],
              "detection_method": []
            }
          ],
          "epss_score": {
            "epss": 0.05,
            "percentile": 0.5,
            "date": "2025-07-09T08:00:00Z"
          },
          "cisa_kev": null,
          "vdeep_metric": {
            "cvss_version": "3.1",
            "cvss_data": {
              "vulnerable_system_confidentiality": "HIGH",
              "vulnerable_system_integrity": "HIGH",
              "vulnerable_system_availability": "HIGH",
              "base_score": 9.8,
              "base_severity": "critical"
            }
          }
        }
      },
      "first_seen_date": "2025-05-25T08:00:00Z",
      "last_seen_date": "2025-07-24T08:00:00Z",
      "last_check_date": "2025-07-24T08:00:00Z",
      "state": "verified_resolved",
      "is_certain": true,
      "is_potential": false
    }
  ]
}
```

### 400 · Invalid Parameter (invalid page=0)

```bash
curl -X POST 'https://api.deepinfo.com/v1/easm/vulnerabilities/asset-search?page=0' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "parameters": [
    {
      "param": "page",
      "details": [
        "Ensure this value is greater than or equal to 1."
      ]
    }
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```

### Request Template

The request only: a request template has no response.

```bash
curl -X POST 'https://api.deepinfo.com/v1/easm/vulnerabilities/asset-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "asset",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain_asset",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "asset_tags",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "technologies.vendor",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "technologies.product",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "technologies.version",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_version",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.owasptop10_2021",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.description",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.scope",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.impact",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.detection_method",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.vendor_project",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.product",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.vulnerability_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.short_description",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.required_action",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.known_ransomware_campaign_use",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.notes",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.published",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "cve.last_modified",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_data.base_score",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.enrichment.cwe.id",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.enrichment.cwe.capec_id",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.enrichment.epss_score.epss",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.enrichment.epss_score.percentile",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.enrichment.epss_score.date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "cve.enrichment.cisa_kev.date_added",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "cve.enrichment.cisa_kev.due_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "first_seen_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "last_seen_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "last_check_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "asset_type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_data.base_severity",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "is_certain",
        "type": "eq",
        "value": true
      },
      {
        "name": "is_potential",
        "type": "eq",
        "value": true
      }
    ]
  },
  "sort": [
    {
      "field": "asset.name",
      "order": "desc"
    }
  ]
}'
```
