# CVSS Score Stats

GET /explore/vulnerability-insight/vulnerability-stats-by-cvss-scores: Distribution of CVEs by CVSS score.

Source: https://docs.deepinfo.com/reference/vulnerability/cvss-score-stats/

Last updated: 2026-09-27

---
`GET https://api.deepinfo.com/v1/explore/vulnerability-insight/vulnerability-stats-by-cvss-scores`

Distribution of CVEs by CVSS score.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `vendor` | Optional |  |  |
| `product` | Optional |  |  |
| `version` | Optional |  |  |
| `version__startswith` | Optional |  |  |

## Response Fields

| Field | Type |
|---|---|
| `vendor` | string |
| `product` | string |
| `version` | string |
| `cve_count` | integer |
| `cve_count_by_score` | array of object |

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `vendor` | string |
| `product` | string |
| `version` | string |
| `cve_count` | number |
| `cve_count_by_score` | array<object> |
| `cve_count_by_score[].score` | number |
| `cve_count_by_score[].cve_count` | number |

## Examples

### 200 · OK

```bash
curl 'https://api.deepinfo.com/v1/explore/vulnerability-insight/vulnerability-stats-by-cvss-scores' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "vendor": "",
  "product": "",
  "version": "",
  "cve_count": 395222,
  "cve_count_by_score": [
    {
      "score": 7.5,
      "cve_count": 41878
    },
    {
      "score": 7.8,
      "cve_count": 28190
    }
  ]
}
```

## Worked Examples

Worked examples of this endpoint, each on its own page with the exact request and its response: [CVSS Score Stats Examples](/reference/vulnerability/cvss-score-stats/examples/).

- [Every CVE by CVSS Score](/reference/vulnerability/cvss-score-stats/examples/default/): Without parameters, the number of CVEs for every CVSS base score across the whole database.
- [Apache Log4j CVEs by CVSS Score](/reference/vulnerability/cvss-score-stats/examples/vendor-product/): The CVSS score distribution of Apache Log4j's CVEs.
