POSThttps://api.deepinfo.com/v1/easm/vulnerabilities/search

Searches vulnerabilities (CVEs) affecting your assets, one record per CVE.

Authentication

Send your API key in the apikey request header.

Query Parameters

ParameterRequiredDescription
page_sizeOptional
Min 25, max 100. Default 100.
Example25
pageOptional
Min 1, max 800. Default 1.
Example1

Request Body

ParameterTypeRequiredDescription
filtersobjectOptional
See Filtering below
sortarrayOptional
List of {field, order}
application/json
{}

Filtering

Example body:

JSON
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "cve.id",
      "order": "desc"
    }
  ]
}

See Getting Started → Search & Filters for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators eq in gte lte exists

FieldDescription
cve.publishedWhen the CVE was first published, in ISO 8601 UTC (for example 2025-06-01T08:00:00Z).
cve.last_modifiedWhen the CVE record was last changed, in ISO 8601 UTC.
cve.enrichment.vdeep_metric.cvss_data.base_scoreCVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.
cve.enrichment.cwe.idNumber of a CWE weakness linked to the CVE, for example 787 for CWE-787; a CVE can have several CWEs or none. The platform shows it as CWE-<id> after the CWE name.
cve.enrichment.cwe.capec_idIDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as CAPEC-<id> under ATTACK STAGES.
cve.enrichment.epss_score.epssEPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.
cve.enrichment.epss_score.percentilePercentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (0.95 means 95% of them have the same or a lower score).
cve.enrichment.epss_score.dateDate of the CVE's EPSS score, as a UTC date-time at midnight (for example 2026-09-23T00:00:00Z); the platform shows it as ANALYSIS DATE.
cve.enrichment.cisa_kev.date_addedDate the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.
cve.enrichment.cisa_kev.due_dateRemediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill.
affected_asset_count.totalNumber of your assets the CVE is active on (state newly_detected, unresolved or reappeared); the Vulnerability List shows it as ASSETS.
affected_asset_count.domainNumber of domain assets the CVE is active on; part of affected_asset_count.total.
affected_asset_count.subdomainNumber of subdomain assets the CVE is active on; part of affected_asset_count.total.
affected_asset_count.ipNumber of IP address assets the CVE is active on; part of affected_asset_count.total.
affected_asset_count.websiteNumber of website assets the CVE is active on; part of affected_asset_count.total.
affected_domain_asset_countNumber of domain assets the CVE is active on; in the samples it always equals affected_asset_count.domain.
first_seen_dateWhen the CVE was first detected on any of your assets, in ISO 8601 UTC: the earliest first_seen_date of its per-asset records. The platform marks a CVE first seen in the last 7 days as NEW.
last_seen_dateWhen the CVE was most recently detected on any of your assets, in ISO 8601 UTC: the latest last_seen_date of its per-asset records.
last_check_dateWhen your assets were last checked for the CVE, in ISO 8601 UTC: the latest last_check_date of its per-asset records.
certainly_affected_asset_count.totalNumber of your assets on which the CVE is certain (verified through testing and confirmed as valid), whatever the per-asset state, active or inactive.
certainly_affected_asset_count.domainNumber of domain assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total.
certainly_affected_asset_count.subdomainNumber of subdomain assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total.
certainly_affected_asset_count.ipNumber of IP address assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total.
certainly_affected_asset_count.websiteNumber of website assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total.
potentially_affected_asset_count.totalNumber of your assets on which the CVE is potential (identified through testing but not yet confirmed), whatever the per-asset state, active or inactive.
potentially_affected_asset_count.domainNumber of domain assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total.
potentially_affected_asset_count.subdomainNumber of subdomain assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total.
potentially_affected_asset_count.ipNumber of IP address assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total.
potentially_affected_asset_count.websiteNumber of website assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total.

Operators eq in startswith endswith wildcard fuzzy contains_any contains_all exists

FieldDescription
cve.idThe CVE identifier, such as CVE-2021-44228; the Vulnerability List's SEARCH box matches it.
cve.enrichment.vdeep_metric.cvss_versionCVSS version of the CVE's main CVSS assessment, the one the cvss_data fields come from, for example 3.1, 3.0 or 2.0.
cve.enrichment.cwe.owasptop10_2021OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example A03 Injection or A01 Broken Access Control; empty when the CWE has none. The platform shows it as the OWASP chip.
cve.enrichment.cwe.nameName of a CWE weakness linked to the CVE, for example Out-of-bounds Write or Improper Input Validation.
cve.enrichment.cwe.descriptionThe CWE catalog's description of a weakness linked to the CVE.
cve.enrichment.cwe.scopeSecurity areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: Confidentiality, Integrity, Availability, Access Control, Authentication, Authorization, Accountability, Non-Repudiation, Other.
cve.enrichment.cwe.impactTechnical impacts a CWE weakness of the CVE can have, from the CWE entry, for example Execute Unauthorized Code or Commands, Read Memory or DoS: Crash, Exit, or Restart.
cve.enrichment.cwe.detection_methodMethods that can detect a CWE weakness of the CVE, from the CWE entry, for example Automated Static Analysis, Fuzzing or Manual Analysis; the platform shows them as DETECTION METHOD.
cve.enrichment.cisa_kev.vendor_projectVendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example Apache or Microsoft; empty for CVEs not in the catalog.
cve.enrichment.cisa_kev.productProduct named in the CVE's CISA KEV entry, for example Log4j2 or Multiple Products.
cve.enrichment.cisa_kev.vulnerability_nameName of the vulnerability in the CVE's CISA KEV entry, for example Apache Log4j2 Remote Code Execution Vulnerability.
cve.enrichment.cisa_kev.short_descriptionCISA's short description of the vulnerability in the CVE's KEV entry.
cve.enrichment.cisa_kev.required_actionAction CISA requires in the CVE's KEV entry, for example Apply updates per vendor instructions.
cve.enrichment.cisa_kev.known_ransomware_campaign_useWhether the CVE's CISA KEV entry reports use in ransomware campaigns: Known or Unknown; the platform adds a RANSOMWARE badge for Known.
cve.enrichment.cisa_kev.notesNotes in the CVE's CISA KEV entry, often reference URLs.
affected_asset_tagsYour own tags on the assets the CVE affects, as a list of strings; filter on it to find CVEs on assets with a given tag.

Operators eq in exists

FieldDescription
cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentialityConfidentiality impact of the CVE's main CVSS assessment: NONE, PARTIAL or COMPLETE for CVSS 2.0, NONE, LOW or HIGH for CVSS 3.x. The platform shows it as the C of the C/I/A chip.
cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrityIntegrity impact of the CVE's main CVSS assessment: NONE, PARTIAL or COMPLETE for CVSS 2.0, NONE, LOW or HIGH for CVSS 3.x. The platform shows it as the I of the C/I/A chip.
cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availabilityAvailability impact of the CVE's main CVSS assessment: NONE, PARTIAL or COMPLETE for CVSS 2.0, NONE, LOW or HIGH for CVSS 3.x. The platform shows it as the A of the C/I/A chip.
cve.enrichment.vdeep_metric.cvss_data.base_severitySeverity of the CVE's main CVSS assessment: critical, high, medium, low, none or unknown; CVSS 2.0 has no critical, so a 2.0 score of 10 is high. The Vulnerability List severity tabs filter on it.
stateWhether the CVE is still active on at least one of your assets: active or inactive. The per-asset states are in Vulnerability Asset Search, and the Vulnerability List shows active CVEs only.

Operators eq exists

FieldDescription
is_certaintrue when the CVE is certain on at least one of your assets, that is, verified through testing and confirmed as valid; see certainly_affected_asset_count.
is_potentialtrue when the CVE is potential on at least one of your assets, that is, identified through testing but not yet confirmed; see potentially_affected_asset_count.

Sortable Fields

FieldDescription
cve.idThe CVE identifier, such as CVE-2021-44228; the Vulnerability List's SEARCH box matches it.
cve.publishedWhen the CVE was first published, in ISO 8601 UTC (for example 2025-06-01T08:00:00Z).
cve.last_modifiedWhen the CVE record was last changed, in ISO 8601 UTC.
cve.enrichment.vdeep_metric.cvss_data.base_scoreCVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.
cve.enrichment.vdeep_metric.cvss_data.base_severitySeverity of the CVE's main CVSS assessment: critical, high, medium, low, none or unknown; CVSS 2.0 has no critical, so a 2.0 score of 10 is high. The Vulnerability List severity tabs filter on it.
cve.enrichment.cwe.idNumber of a CWE weakness linked to the CVE, for example 787 for CWE-787; a CVE can have several CWEs or none. The platform shows it as CWE-<id> after the CWE name.
cve.enrichment.epss_score.epssEPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.
cve.enrichment.cisa_kev.date_addedDate the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.
affected_asset_count.totalNumber of your assets the CVE is active on (state newly_detected, unresolved or reappeared); the Vulnerability List shows it as ASSETS.
affected_asset_count.domainNumber of domain assets the CVE is active on; part of affected_asset_count.total.
affected_asset_count.subdomainNumber of subdomain assets the CVE is active on; part of affected_asset_count.total.
affected_asset_count.ipNumber of IP address assets the CVE is active on; part of affected_asset_count.total.
affected_asset_count.websiteNumber of website assets the CVE is active on; part of affected_asset_count.total.
affected_domain_asset_countNumber of domain assets the CVE is active on; in the samples it always equals affected_asset_count.domain.
first_seen_dateWhen the CVE was first detected on any of your assets, in ISO 8601 UTC: the earliest first_seen_date of its per-asset records. The platform marks a CVE first seen in the last 7 days as NEW.
last_seen_dateWhen the CVE was most recently detected on any of your assets, in ISO 8601 UTC: the latest last_seen_date of its per-asset records.
stateWhether the CVE is still active on at least one of your assets: active or inactive. The per-asset states are in Vulnerability Asset Search, and the Vulnerability List shows active CVEs only.
is_certaintrue when the CVE is certain on at least one of your assets, that is, verified through testing and confirmed as valid; see certainly_affected_asset_count.
is_potentialtrue when the CVE is potential on at least one of your assets, that is, identified through testing but not yet confirmed; see potentially_affected_asset_count.
certainly_affected_asset_count.totalNumber of your assets on which the CVE is certain (verified through testing and confirmed as valid), whatever the per-asset state, active or inactive.
certainly_affected_asset_count.domainNumber of domain assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total.
certainly_affected_asset_count.subdomainNumber of subdomain assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total.
certainly_affected_asset_count.ipNumber of IP address assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total.
certainly_affected_asset_count.websiteNumber of website assets on which the CVE is certain, active or inactive; part of certainly_affected_asset_count.total.
potentially_affected_asset_count.totalNumber of your assets on which the CVE is potential (identified through testing but not yet confirmed), whatever the per-asset state, active or inactive.
potentially_affected_asset_count.domainNumber of domain assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total.
potentially_affected_asset_count.subdomainNumber of subdomain assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total.
potentially_affected_asset_count.ipNumber of IP address assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total.
potentially_affected_asset_count.websiteNumber of website assets on which the CVE is potential, active or inactive; part of potentially_affected_asset_count.total.

Response Fields

FieldTypeDescription
pageinteger
page_sizeinteger
result_countinteger
resultsarray of object
results[].idstring
results[].cveobject
results[].affected_asset_countobject
results[].affected_domain_asset_countinteger
results[].affected_asset_tagsarray of string
results[].first_seen_datestring
date-time
results[].last_seen_datestring
date-time
results[].last_check_datestring
date-time
results[].statestring
One of active, inactive
results[].is_certainboolean
results[].is_potentialboolean
results[].certainly_affected_asset_countobject
results[].potentially_affected_asset_countobject

Paginated. See Getting Started → Pagination.

Response Schema

Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

FieldTypeExample
pagenumber1
page_sizenumber25
result_countnumber21
resultsarray<object>
results[].idstring"00000000000000000000000e0c9d0001"
results[].cveobject
results[].cve.idstring"CVE-0000-0001"
results[].cve.publishedstring"2025-06-01T08:00:00Z"
results[].cve.last_modifiedstring"2025-07-01T08:00:00Z"
results[].cve.enrichmentobject
results[].cve.enrichment.cwearray<object>
results[].cve.enrichment.cwe[].idnumber200
results[].cve.enrichment.cwe[].owasptop10_2021null
results[].cve.enrichment.cwe[].namestring"Exposure of Sensitive Information t…"
results[].cve.enrichment.cwe[].descriptionstring"Sensitive information reaches someo…"
results[].cve.enrichment.cwe[].capec_idarray<number>109
results[].cve.enrichment.cwe[].scopearray<string>"Availability"
results[].cve.enrichment.cwe[].impactarray<string>"DoS: Crash, Exit, or Restart"
results[].cve.enrichment.cwe[].detection_methodarray<string>"Architecture or Design Review"
results[].cve.enrichment.epss_scoreobject
results[].cve.enrichment.epss_score.epssnumber0.05
results[].cve.enrichment.epss_score.percentilenumber0.5
results[].cve.enrichment.epss_score.datestring"2025-07-16T08:00:00Z"
results[].cve.enrichment.cisa_kevnull
results[].cve.enrichment.vdeep_metricobject
results[].cve.enrichment.vdeep_metric.cvss_versionstring"2.0"
results[].cve.enrichment.vdeep_metric.cvss_dataobject
results[].cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentialitystring"COMPLETE"
results[].cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integritystring"COMPLETE"
results[].cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availabilitystring"COMPLETE"
results[].cve.enrichment.vdeep_metric.cvss_data.base_scorenumber10
results[].cve.enrichment.vdeep_metric.cvss_data.base_severitystring"high"
results[].affected_asset_countobject
results[].affected_asset_count.totalnumber85
results[].affected_asset_count.domainnumber12
results[].affected_asset_count.subdomainnumber36
results[].affected_asset_count.ipnumber25
results[].affected_asset_count.websitenumber12
results[].affected_domain_asset_countnumber30
results[].affected_asset_tagsarray
results[].first_seen_datestring"2025-06-01T08:00:00Z"
results[].last_seen_datestring"2025-07-31T08:00:00Z"
results[].last_check_datestring"2025-07-31T08:00:00Z"
results[].statestring"active"
results[].is_certainbooleantrue
results[].is_potentialbooleanfalse
results[].certainly_affected_asset_countobject
results[].certainly_affected_asset_count.totalnumber11
results[].certainly_affected_asset_count.domainnumber0
results[].certainly_affected_asset_count.subdomainnumber6
results[].certainly_affected_asset_count.ipnumber4
results[].certainly_affected_asset_count.websitenumber1
results[].potentially_affected_asset_countobject
results[].potentially_affected_asset_count.totalnumber83
results[].potentially_affected_asset_count.domainnumber22
results[].potentially_affected_asset_count.subdomainnumber13
results[].potentially_affected_asset_count.ipnumber18
results[].potentially_affected_asset_count.websitenumber30

Examples

Selecting one loads it into the request and response panels.

Reference updated