Vulnerability Search
https://api.deepinfo.com/v1/easm/vulnerabilities/searchSearches vulnerabilities (CVEs) affecting your assets, one record per CVE.
Authentication
Send your API key in the apikey request header.
Query Parameters
| Parameter | Required | Description |
|---|---|---|
page_ | Optional | Min 25, max 100. Default 100.Example 25 |
page | Optional | Min 1, max 800. Default 1.Example 1 |
Request Body
| Parameter | Type | Required | Description |
|---|---|---|---|
filters | object | Optional | See Filtering below |
sort | array | Optional | List of {field, order} |
{}
Filtering
Example body:
{
"filters": {
"must": [
{
"name": "state",
"type": "eq",
"value": "<value>"
}
]
},
"sort": [
{
"field": "cve.id",
"order": "desc"
}
]
}
See Getting Started → Search & Filters for the operators.
The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.
Searchable Fields
Grouped by the operators they accept (measured against the API; sending another operator returns 400).
Operators eq in gte lte exists
| Field | Description |
|---|---|
cve. | When the CVE was first published, in ISO 8601 UTC (for example 2025-06-01T08:00:00Z). |
cve. | When the CVE record was last changed, in ISO 8601 UTC. |
cve. | CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY. |
cve. | Number of a CWE weakness linked to the CVE, for example 787 for CWE-787; a CVE can have several CWEs or none. The platform shows it as CWE-<id> after the CWE name. |
cve. | IDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as CAPEC-<id> under ATTACK STAGES. |
cve. | EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage. |
cve. | Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (0.95 means 95% of them have the same or a lower score). |
cve. | Date of the CVE's EPSS score, as a UTC date-time at midnight (for example 2026-09-23T00:00:00Z); the platform shows it as ANALYSIS DATE. |
cve. | Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog. |
cve. | Remediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill. |
affected_ | Number of your assets the CVE is active on (state newly_detected, unresolved or reappeared); the Vulnerability List shows it as ASSETS. |
affected_ | Number of domain assets the CVE is active on; part of affected_asset_count.total. |
affected_ | Number of subdomain assets the CVE is active on; part of affected_asset_count.total. |
affected_ | Number of IP address assets the CVE is active on; part of affected_asset_count.total. |
affected_ | Number of website assets the CVE is active on; part of affected_asset_count.total. |
affected_ | Number of domain assets the CVE is active on; in the samples it always equals affected_asset_count.domain. |
first_ | When the CVE was first detected on any of your assets, in ISO 8601 UTC: the earliest first_seen_date of its per-asset records. The platform marks a CVE first seen in the last 7 days as NEW. |
last_ | When the CVE was most recently detected on any of your assets, in ISO 8601 UTC: the latest last_seen_date of its per-asset records. |
last_ | When your assets were last checked for the CVE, in ISO 8601 UTC: the latest last_check_date of its per-asset records. |
certainly_ | Number of your assets on which the CVE is certain (verified through testing and confirmed as valid), whatever the per-asset state, active or inactive. |
certainly_ | Number of domain assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total. |
certainly_ | Number of subdomain assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total. |
certainly_ | Number of IP address assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total. |
certainly_ | Number of website assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total. |
potentially_ | Number of your assets on which the CVE is potential (identified through testing but not yet confirmed), whatever the per-asset state, active or inactive. |
potentially_ | Number of domain assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total. |
potentially_ | Number of subdomain assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total. |
potentially_ | Number of IP address assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total. |
potentially_ | Number of website assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total. |
Operators eq in startswith endswith wildcard fuzzy contains_ contains_ exists
| Field | Description |
|---|---|
cve. | The CVE identifier, such as CVE-2021-44228; the Vulnerability List's SEARCH box matches it. |
cve. | CVSS version of the CVE's main CVSS assessment, the one the cvss_data fields come from, for example 3.1, 3.0 or 2.0. |
cve. | OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example A03 Injection or A01 Broken Access Control; empty when the CWE has none. The platform shows it as the OWASP chip. |
cve. | Name of a CWE weakness linked to the CVE, for example Out-of-bounds Write or Improper Input Validation. |
cve. | The CWE catalog's description of a weakness linked to the CVE. |
cve. | Security areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: Confidentiality, Integrity, Availability, Access Control, Authentication, Authorization, Accountability, Non-Repudiation, Other. |
cve. | Technical impacts a CWE weakness of the CVE can have, from the CWE entry, for example Execute Unauthorized Code or Commands, Read Memory or DoS: Crash, Exit, or Restart. |
cve. | Methods that can detect a CWE weakness of the CVE, from the CWE entry, for example Automated Static Analysis, Fuzzing or Manual Analysis; the platform shows them as DETECTION METHOD. |
cve. | Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example Apache or Microsoft; empty for CVEs not in the catalog. |
cve. | Product named in the CVE's CISA KEV entry, for example Log4j2 or Multiple Products. |
cve. | Name of the vulnerability in the CVE's CISA KEV entry, for example Apache Log4j2 Remote Code Execution Vulnerability. |
cve. | CISA's short description of the vulnerability in the CVE's KEV entry. |
cve. | Action CISA requires in the CVE's KEV entry, for example Apply updates per vendor instructions. |
cve. | Whether the CVE's CISA KEV entry reports use in ransomware campaigns: Known or Unknown; the platform adds a RANSOMWARE badge for Known. |
cve. | Notes in the CVE's CISA KEV entry, often reference URLs. |
affected_ | Your own tags on the assets the CVE affects, as a list of strings; filter on it to find CVEs on assets with a given tag. |
Operators eq in exists
| Field | Description |
|---|---|
cve. | Confidentiality impact of the CVE's main CVSS assessment: NONE, PARTIAL or COMPLETE for CVSS 2.0, NONE, LOW or HIGH for CVSS 3.x. The platform shows it as the C of the C/I/A chip. |
cve. | Integrity impact of the CVE's main CVSS assessment: NONE, PARTIAL or COMPLETE for CVSS 2.0, NONE, LOW or HIGH for CVSS 3.x. The platform shows it as the I of the C/I/A chip. |
cve. | Availability impact of the CVE's main CVSS assessment: NONE, PARTIAL or COMPLETE for CVSS 2.0, NONE, LOW or HIGH for CVSS 3.x. The platform shows it as the A of the C/I/A chip. |
cve. | Severity of the CVE's main CVSS assessment: critical, high, medium, low, none or unknown; CVSS 2.0 has no critical, so a 2.0 score of 10 is high. The Vulnerability List severity tabs filter on it. |
state | Whether the CVE is still active on at least one of your assets: active or inactive. The per-asset states are in Vulnerability Asset Search, and the Vulnerability List shows active CVEs only. |
Operators eq exists
| Field | Description |
|---|---|
is_ | true when the CVE is certain on at least one of your assets, that is, verified through testing and confirmed as valid; see certainly_affected_asset_count. |
is_ | true when the CVE is potential on at least one of your assets, that is, identified through testing but not yet confirmed; see potentially_affected_asset_count. |
Sortable Fields
| Field | Description |
|---|---|
cve. | The CVE identifier, such as CVE-2021-44228; the Vulnerability List's SEARCH box matches it. |
cve. | When the CVE was first published, in ISO 8601 UTC (for example 2025-06-01T08:00:00Z). |
cve. | When the CVE record was last changed, in ISO 8601 UTC. |
cve. | CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY. |
cve. | Severity of the CVE's main CVSS assessment: critical, high, medium, low, none or unknown; CVSS 2.0 has no critical, so a 2.0 score of 10 is high. The Vulnerability List severity tabs filter on it. |
cve. | Number of a CWE weakness linked to the CVE, for example 787 for CWE-787; a CVE can have several CWEs or none. The platform shows it as CWE-<id> after the CWE name. |
cve. | EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage. |
cve. | Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog. |
affected_ | Number of your assets the CVE is active on (state newly_detected, unresolved or reappeared); the Vulnerability List shows it as ASSETS. |
affected_ | Number of domain assets the CVE is active on; part of affected_asset_count.total. |
affected_ | Number of subdomain assets the CVE is active on; part of affected_asset_count.total. |
affected_ | Number of IP address assets the CVE is active on; part of affected_asset_count.total. |
affected_ | Number of website assets the CVE is active on; part of affected_asset_count.total. |
affected_ | Number of domain assets the CVE is active on; in the samples it always equals affected_asset_count.domain. |
first_ | When the CVE was first detected on any of your assets, in ISO 8601 UTC: the earliest first_seen_date of its per-asset records. The platform marks a CVE first seen in the last 7 days as NEW. |
last_ | When the CVE was most recently detected on any of your assets, in ISO 8601 UTC: the latest last_seen_date of its per-asset records. |
state | Whether the CVE is still active on at least one of your assets: active or inactive. The per-asset states are in Vulnerability Asset Search, and the Vulnerability List shows active CVEs only. |
is_ | true when the CVE is certain on at least one of your assets, that is, verified through testing and confirmed as valid; see certainly_affected_asset_count. |
is_ | true when the CVE is potential on at least one of your assets, that is, identified through testing but not yet confirmed; see potentially_affected_asset_count. |
certainly_ | Number of your assets on which the CVE is certain (verified through testing and confirmed as valid), whatever the per-asset state, active or inactive. |
certainly_ | Number of domain assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total. |
certainly_ | Number of subdomain assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total. |
certainly_ | Number of IP address assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total. |
certainly_ | Number of website assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total. |
potentially_ | Number of your assets on which the CVE is potential (identified through testing but not yet confirmed), whatever the per-asset state, active or inactive. |
potentially_ | Number of domain assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total. |
potentially_ | Number of subdomain assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total. |
potentially_ | Number of IP address assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total. |
potentially_ | Number of website assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total. |
Response Fields
| Field | Type | Description |
|---|---|---|
page | integer | |
page_ | integer | |
result_ | integer | |
results | array of object | |
results[]. | string | |
results[]. | object | |
results[]. | object | |
results[]. | integer | |
results[]. | array of string | |
results[]. | string | date-time |
results[]. | string | date-time |
results[]. | string | date-time |
results[]. | string | One of active, inactive |
results[]. | boolean | |
results[]. | boolean | |
results[]. | object | |
results[]. | object |
Paginated. See Getting Started → Pagination.
Response Schema
Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.
| Field | Type | Example |
|---|---|---|
page | number | 1 |
page_size | number | 25 |
result_count | number | 21 |
results | array< | |
results[]. | string | "00000000000000000000000e0c9d0001" |
results[]. | object | |
results[]. | string | "CVE-0000-0001" |
results[]. | string | "2025-06-01T08:00:00Z" |
results[]. | string | "2025-07-01T08:00:00Z" |
results[]. | object | |
results[]. | array< | |
results[]. | number | 200 |
results[]. | null | |
results[]. | string | "Exposure of Sensitive Information t…" |
results[]. | string | "Sensitive information reaches someo…" |
results[]. | array< | 109 |
results[]. | array< | "Availability" |
results[]. | array< | "DoS: Crash, Exit, or Restart" |
results[]. | array< | "Architecture or Design Review" |
results[]. | object | |
results[]. | number | 0.05 |
results[]. | number | 0.5 |
results[]. | string | "2025-07-16T08:00:00Z" |
results[]. | null | |
results[]. | object | |
results[]. | string | "2.0" |
results[]. | object | |
results[]. | string | "COMPLETE" |
results[]. | string | "COMPLETE" |
results[]. | string | "COMPLETE" |
results[]. | number | 10 |
results[]. | string | "high" |
results[]. | object | |
results[]. | number | 85 |
results[]. | number | 12 |
results[]. | number | 36 |
results[]. | number | 25 |
results[]. | number | 12 |
results[]. | number | 30 |
results[]. | array | |
results[]. | string | "2025-06-01T08:00:00Z" |
results[]. | string | "2025-07-31T08:00:00Z" |
results[]. | string | "2025-07-31T08:00:00Z" |
results[]. | string | "active" |
results[]. | boolean | true |
results[]. | boolean | false |
results[]. | object | |
results[]. | number | 11 |
results[]. | number | 0 |
results[]. | number | 6 |
results[]. | number | 4 |
results[]. | number | 1 |
results[]. | object | |
results[]. | number | 83 |
results[]. | number | 22 |
results[]. | number | 13 |
results[]. | number | 18 |
results[]. | number | 30 |
Examples
Selecting one loads it into the request and response panels.