# Vulnerability Export

POST /easm/vulnerabilities/search:export: Exports every record matching filters (no pagination). format=csv returns CSV text; format=json returns a JSON array.

Source: https://docs.deepinfo.com/reference/easm/vulnerability-export/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/easm/vulnerabilities/search:export`

Exports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `format` | Optional | One of: `json`, `csv`. | `csv` |

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | array | Optional | List of `{field, order}` |

```json
{}
```

## Filtering

Example body:

```json
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "cve.id",
      "order": "desc"
    }
  ]
}
```

See [Getting Started → Search & Filters](/getting-started/search-and-filters/) for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

### Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators: `eq`, `in`, `gte`, `lte`, `exists`

| Field | Description |
|---|---|
| `cve.published` | When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). |
| `cve.last_modified` | When the CVE record was last changed, in ISO 8601 UTC. |
| `cve.enrichment.vdeep_metric.cvss_data.base_score` | CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY. |
| `cve.enrichment.cwe.id` | Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name. |
| `cve.enrichment.cwe.capec_id` | IDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as `CAPEC-<id>` under ATTACK STAGES. |
| `cve.enrichment.epss_score.epss` | EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage. |
| `cve.enrichment.epss_score.percentile` | Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (`0.95` means 95% of them have the same or a lower score). |
| `cve.enrichment.epss_score.date` | Date of the CVE's EPSS score, as a UTC date-time at midnight (for example `2026-09-23T00:00:00Z`); the platform shows it as ANALYSIS DATE. |
| `cve.enrichment.cisa_kev.date_added` | Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog. |
| `cve.enrichment.cisa_kev.due_date` | Remediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill. |
| `affected_asset_count.total` | Number of your assets the CVE is active on (state `newly_detected`, `unresolved` or `reappeared`); the Vulnerability List shows it as ASSETS. |
| `affected_asset_count.domain` | Number of domain assets the CVE is active on; part of `affected_asset_count.total`. |
| `affected_asset_count.subdomain` | Number of subdomain assets the CVE is active on; part of `affected_asset_count.total`. |
| `affected_asset_count.ip` | Number of IP address assets the CVE is active on; part of `affected_asset_count.total`. |
| `affected_asset_count.website` | Number of website assets the CVE is active on; part of `affected_asset_count.total`. |
| `affected_domain_asset_count` | Number of domain assets the CVE is active on; in the samples it always equals `affected_asset_count.domain`. |
| `first_seen_date` | When the CVE was first detected on any of your assets, in ISO 8601 UTC: the earliest `first_seen_date` of its per-asset records. The platform marks a CVE first seen in the last 7 days as NEW. |
| `last_seen_date` | When the CVE was most recently detected on any of your assets, in ISO 8601 UTC: the latest `last_seen_date` of its per-asset records. |
| `last_check_date` | When your assets were last checked for the CVE, in ISO 8601 UTC: the latest `last_check_date` of its per-asset records. |
| `certainly_affected_asset_count.total` | Number of your assets on which the CVE is certain (verified through testing and confirmed as valid), whatever the per-asset state, active or inactive. |
| `certainly_affected_asset_count.domain` | Number of domain assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`. |
| `certainly_affected_asset_count.subdomain` | Number of subdomain assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`. |
| `certainly_affected_asset_count.ip` | Number of IP address assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`. |
| `certainly_affected_asset_count.website` | Number of website assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`. |
| `potentially_affected_asset_count.total` | Number of your assets on which the CVE is potential (identified through testing but not yet confirmed), whatever the per-asset state, active or inactive. |
| `potentially_affected_asset_count.domain` | Number of domain assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`. |
| `potentially_affected_asset_count.subdomain` | Number of subdomain assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`. |
| `potentially_affected_asset_count.ip` | Number of IP address assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`. |
| `potentially_affected_asset_count.website` | Number of website assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`. |

Operators: `eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`

| Field | Description |
|---|---|
| `cve.id` | The CVE identifier, such as `CVE-2021-44228`; the Vulnerability List's SEARCH box matches it. |
| `cve.enrichment.vdeep_metric.cvss_version` | CVSS version of the CVE's main CVSS assessment, the one the `cvss_data` fields come from, for example `3.1`, `3.0` or `2.0`. |
| `cve.enrichment.cwe.owasptop10_2021` | OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example `A03 Injection` or `A01 Broken Access Control`; empty when the CWE has none. The platform shows it as the OWASP chip. |
| `cve.enrichment.cwe.name` | Name of a CWE weakness linked to the CVE, for example `Out-of-bounds Write` or `Improper Input Validation`. |
| `cve.enrichment.cwe.description` | The CWE catalog's description of a weakness linked to the CVE. |
| `cve.enrichment.cwe.scope` | Security areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: `Confidentiality`, `Integrity`, `Availability`, `Access Control`, `Authentication`, `Authorization`, `Accountability`, `Non-Repudiation`, `Other`. |
| `cve.enrichment.cwe.impact` | Technical impacts a CWE weakness of the CVE can have, from the CWE entry, for example `Execute Unauthorized Code or Commands`, `Read Memory` or `DoS: Crash, Exit, or Restart`. |
| `cve.enrichment.cwe.detection_method` | Methods that can detect a CWE weakness of the CVE, from the CWE entry, for example `Automated Static Analysis`, `Fuzzing` or `Manual Analysis`; the platform shows them as DETECTION METHOD. |
| `cve.enrichment.cisa_kev.vendor_project` | Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example `Apache` or `Microsoft`; empty for CVEs not in the catalog. |
| `cve.enrichment.cisa_kev.product` | Product named in the CVE's CISA KEV entry, for example `Log4j2` or `Multiple Products`. |
| `cve.enrichment.cisa_kev.vulnerability_name` | Name of the vulnerability in the CVE's CISA KEV entry, for example `Apache Log4j2 Remote Code Execution Vulnerability`. |
| `cve.enrichment.cisa_kev.short_description` | CISA's short description of the vulnerability in the CVE's KEV entry. |
| `cve.enrichment.cisa_kev.required_action` | Action CISA requires in the CVE's KEV entry, for example `Apply updates per vendor instructions.` |
| `cve.enrichment.cisa_kev.known_ransomware_campaign_use` | Whether the CVE's CISA KEV entry reports use in ransomware campaigns: `Known` or `Unknown`; the platform adds a RANSOMWARE badge for `Known`. |
| `cve.enrichment.cisa_kev.notes` | Notes in the CVE's CISA KEV entry, often reference URLs. |
| `affected_asset_tags` | Your own tags on the assets the CVE affects, as a list of strings; filter on it to find CVEs on assets with a given tag. |

Operators: `eq`, `in`, `exists`

| Field | Description |
|---|---|
| `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality` | Confidentiality impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the C of the C/I/A chip. |
| `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity` | Integrity impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the I of the C/I/A chip. |
| `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability` | Availability impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the A of the C/I/A chip. |
| `cve.enrichment.vdeep_metric.cvss_data.base_severity` | Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it. |
| `state` | Whether the CVE is still active on at least one of your assets: `active` or `inactive`. The per-asset states are in Vulnerability Asset Search, and the Vulnerability List shows `active` CVEs only. |

Operators: `eq`, `exists`

| Field | Description |
|---|---|
| `is_certain` | `true` when the CVE is certain on at least one of your assets, that is, verified through testing and confirmed as valid; see `certainly_affected_asset_count`. |
| `is_potential` | `true` when the CVE is potential on at least one of your assets, that is, identified through testing but not yet confirmed; see `potentially_affected_asset_count`. |

### Sortable Fields

| Field | Description |
|---|---|
| `cve.id` | The CVE identifier, such as `CVE-2021-44228`; the Vulnerability List's SEARCH box matches it. |
| `cve.published` | When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). |
| `cve.last_modified` | When the CVE record was last changed, in ISO 8601 UTC. |
| `cve.enrichment.vdeep_metric.cvss_data.base_score` | CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY. |
| `cve.enrichment.vdeep_metric.cvss_data.base_severity` | Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it. |
| `cve.enrichment.cwe.id` | Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name. |
| `cve.enrichment.epss_score.epss` | EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage. |
| `cve.enrichment.cisa_kev.date_added` | Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog. |
| `affected_asset_count.total` | Number of your assets the CVE is active on (state `newly_detected`, `unresolved` or `reappeared`); the Vulnerability List shows it as ASSETS. |
| `affected_asset_count.domain` | Number of domain assets the CVE is active on; part of `affected_asset_count.total`. |
| `affected_asset_count.subdomain` | Number of subdomain assets the CVE is active on; part of `affected_asset_count.total`. |
| `affected_asset_count.ip` | Number of IP address assets the CVE is active on; part of `affected_asset_count.total`. |
| `affected_asset_count.website` | Number of website assets the CVE is active on; part of `affected_asset_count.total`. |
| `affected_domain_asset_count` | Number of domain assets the CVE is active on; in the samples it always equals `affected_asset_count.domain`. |
| `first_seen_date` | When the CVE was first detected on any of your assets, in ISO 8601 UTC: the earliest `first_seen_date` of its per-asset records. The platform marks a CVE first seen in the last 7 days as NEW. |
| `last_seen_date` | When the CVE was most recently detected on any of your assets, in ISO 8601 UTC: the latest `last_seen_date` of its per-asset records. |
| `state` | Whether the CVE is still active on at least one of your assets: `active` or `inactive`. The per-asset states are in Vulnerability Asset Search, and the Vulnerability List shows `active` CVEs only. |
| `is_certain` | `true` when the CVE is certain on at least one of your assets, that is, verified through testing and confirmed as valid; see `certainly_affected_asset_count`. |
| `is_potential` | `true` when the CVE is potential on at least one of your assets, that is, identified through testing but not yet confirmed; see `potentially_affected_asset_count`. |
| `certainly_affected_asset_count.total` | Number of your assets on which the CVE is certain (verified through testing and confirmed as valid), whatever the per-asset state, active or inactive. |
| `certainly_affected_asset_count.domain` | Number of domain assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`. |
| `certainly_affected_asset_count.subdomain` | Number of subdomain assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`. |
| `certainly_affected_asset_count.ip` | Number of IP address assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`. |
| `certainly_affected_asset_count.website` | Number of website assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`. |
| `potentially_affected_asset_count.total` | Number of your assets on which the CVE is potential (identified through testing but not yet confirmed), whatever the per-asset state, active or inactive. |
| `potentially_affected_asset_count.domain` | Number of domain assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`. |
| `potentially_affected_asset_count.subdomain` | Number of subdomain assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`. |
| `potentially_affected_asset_count.ip` | Number of IP address assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`. |
| `potentially_affected_asset_count.website` | Number of website assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`. |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/easm/vulnerabilities/search:export?format=csv' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: text/csv; charset=utf-8` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```
id,cve.id,cve.published,cve.last_modified,cve.enrichment.cwe.id,cve.enrichment.cwe.owasptop10_2021,cve.enrichment.cwe.name,cve.enrichment.cwe.description,cve.enrichment.cwe.capec_id,cve.enrichment.cwe.scope,cve.enrichment.cwe.impact,cve.enrichment.cwe.detection_method,cve.enrichment.epss_score.epss,cve.enrichment.epss_score.percentile,cve.enrichment.epss_score.date,cve.enrichment.cisa_kev.vendor_project,cve.enrichment.cisa_kev.product,cve.enrichment.cisa_kev.vulnerability_name,cve.enrichment.cisa_kev.date_added,cve.enrichment.cisa_kev.short_description,cve.enrichment.cisa_kev.required_action,cve.enrichment.cisa_kev.due_date,cve.enrichment.cisa_kev.known_ransomware_campaign_use,cve.enrichment.cisa_kev.notes,cve.enrichment.vdeep_metric.cvss_version,cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality,cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity,cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability,cve.enrichment.vdeep_metric.cvss_data.base_score,cve.enrichment.vdeep_metric.cvss_data.base_severity,affected_asset_count.total,affected_asset_count.domain,affected_asset_count.subdomain,affected_asset_count.ip,affected_asset_count.website,affected_domain_asset_count,affected_asset_tags,first_seen_date,last_seen_date,last_check_date,state,is_certain,is_potential,certainly_affected_asset_count.total,certainly_affected_asset_count.domain,certainly_affected_asset_count.subdomain,certainly_affected_asset_count.ip,certainly_affected_asset_count.website,potentially_affected_asset_count.total,potentially_affected_asset_count.domain,potentially_affected_asset_count.subdomain,potentially_affected_asset_count.ip,potentially_affected_asset_count.website
00000000000000000000000e0c9d0001,CVE-0000-0001,2025-06-01T08:00:00Z,2025-07-01T08:00:00Z,,,,,,,,,0.05,0.5,2025-07-16T08:00:00Z,,,,,,,,,,2.0,COMPLETE,COMPLETE,COMPLETE,10,high,79,36,3,17,23,0,,2025-06-01T08:00:00Z,2025-07-31T08:00:00Z,2025-07-31T08:00:00Z,active,True,False,54,14,25,4,11,70,26,17,21,6
00000000000000000000000e0c9d0002,CVE-0000-0002,2025-05-25T08:00:00Z,2025-06-24T08:00:00Z,89,,Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'),An SQL query is built from user input without neutralizing it.,103;104;105,Availability;Confidentiality;Integrity,"DoS: Crash, Exit, or Restart;DoS: Resource Consumption (CPU);DoS: Resource Consumption (Memory)",Architecture or Design Review;Automated Dynamic Analysis;Automated Static Analysis,0.05,0.5,2025-07-09T08:00:00Z,,,,,,,,,,2.0,COMPLETE,COMPLETE,COMPLETE,10,high,83,37,4,18,24,1,,2025-05-25T08:00:00Z,2025-07-24T08:00:00Z,2025-07-24T08:00:00Z,active,True,False,58,15,26,5,12,74,27,18,22,7
00000000000000000000000e0c9d0003,CVE-0000-0003,2025-05-18T08:00:00Z,2025-06-17T08:00:00Z,20,,Improper Input Validation,Input is used without checking that it has the properties the product needs.,106;107;108,Availability;Confidentiality;Integrity,"DoS: Crash, Exit, or Restart;DoS: Resource Consumption (CPU);DoS: Resource Consumption (Memory)",Architecture or Design Review;Automated Dynamic Analysis;Automated Static Analysis,0.05,0.5,2025-07-02T08:00:00Z,,,,,,,,,,2.0,COMPLETE,COMPLETE,COMPLETE,10,high,87,38,5,19,25,2,,2025-05-18T08:00:00Z,2025-07-17T08:00:00Z,2025-07-17T08:00:00Z,active,True,False,62,16,27,6,13,78,28,19,23,8
```

### 400 · Invalid Parameter (invalid format=invalid_value)

```bash
curl -X POST 'https://api.deepinfo.com/v1/easm/vulnerabilities/search:export?format=invalid_value' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "parameters": [
    {
      "param": "format",
      "details": [
        "Select a valid choice."
      ]
    }
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```

### Request Template

The request only: a request template has no response.

```bash
curl -X POST 'https://api.deepinfo.com/v1/easm/vulnerabilities/search:export?format=csv' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "cve.published",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "cve.last_modified",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_data.base_score",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.enrichment.cwe.id",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.enrichment.cwe.capec_id",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.enrichment.epss_score.epss",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.enrichment.epss_score.percentile",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.enrichment.epss_score.date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "cve.enrichment.cisa_kev.date_added",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "cve.enrichment.cisa_kev.due_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "affected_asset_count.total",
        "type": "eq",
        "value": 0
      },
      {
        "name": "affected_asset_count.domain",
        "type": "eq",
        "value": 0
      },
      {
        "name": "affected_asset_count.subdomain",
        "type": "eq",
        "value": 0
      },
      {
        "name": "affected_asset_count.ip",
        "type": "eq",
        "value": 0
      },
      {
        "name": "affected_asset_count.website",
        "type": "eq",
        "value": 0
      },
      {
        "name": "affected_domain_asset_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "first_seen_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "last_seen_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "last_check_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "certainly_affected_asset_count.total",
        "type": "eq",
        "value": 0
      },
      {
        "name": "certainly_affected_asset_count.domain",
        "type": "eq",
        "value": 0
      },
      {
        "name": "certainly_affected_asset_count.subdomain",
        "type": "eq",
        "value": 0
      },
      {
        "name": "certainly_affected_asset_count.ip",
        "type": "eq",
        "value": 0
      },
      {
        "name": "certainly_affected_asset_count.website",
        "type": "eq",
        "value": 0
      },
      {
        "name": "potentially_affected_asset_count.total",
        "type": "eq",
        "value": 0
      },
      {
        "name": "potentially_affected_asset_count.domain",
        "type": "eq",
        "value": 0
      },
      {
        "name": "potentially_affected_asset_count.subdomain",
        "type": "eq",
        "value": 0
      },
      {
        "name": "potentially_affected_asset_count.ip",
        "type": "eq",
        "value": 0
      },
      {
        "name": "potentially_affected_asset_count.website",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_version",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.owasptop10_2021",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.description",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.scope",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.impact",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.detection_method",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.vendor_project",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.product",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.vulnerability_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.short_description",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.required_action",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.known_ransomware_campaign_use",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.notes",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "affected_asset_tags",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_data.base_severity",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "is_certain",
        "type": "eq",
        "value": true
      },
      {
        "name": "is_potential",
        "type": "eq",
        "value": true
      }
    ]
  },
  "sort": [
    {
      "field": "cve.id",
      "order": "desc"
    }
  ]
}'
```
