# Search

POST /discovery/vulnerability-search: Searches Deepinfo's CVE database with filters.

Source: https://docs.deepinfo.com/reference/vulnerability/search/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/discovery/vulnerability-search`

Searches Deepinfo's CVE database with filters.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `page_size` | Optional | Min `25`, max `100`. Default `100`. | `25` |
| `export` | Optional | Default `false`. |  |
| `export_format` | Optional | One of: `json`, `csv`. |  |
| `export_scope` | Optional | One of: `basic`, `default`, `extended`. |  |
| `page` | Optional | Min `1`, max `400`. Default `1`. | `1` |

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | array | Optional | List of `{field, order}` |

```json
{}
```

## Filtering

Example body:

```json
{
  "filters": {
    "must": [
      {
        "name": "id",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "id",
      "order": "desc"
    }
  ]
}
```

See [Getting Started → Search & Filters](/getting-started/search-and-filters/) for the operators.

The Request Template example holds this body with some of the filters of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value; Searchable Fields lists them all. Copy it, keep the filters you need and set their values.

### Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400). Example: a worked example that filters by the field, with the request and the response it returns.

Operators: `eq`, `startswith`, `wildcard`, `exists`

| Field | Description | Example |
|---|---|---|
| `source_identifier` | The CVE's assigner, shown as Assigner in the platform: the organization that submitted the CVE record, identified by an email address or a UUID. | [Example](/reference/vulnerability/search/examples/source-identifier/) |
| `status` | Analysis status of the CVE record. Values seen: `Received`, `Awaiting Analysis`, `Undergoing Analysis`, `Analyzed`, `Modified`, `Deferred`, `Rejected`. | [Example 1](/reference/vulnerability/search/examples/status/)<br>[Example 2](/reference/vulnerability/search/examples/sort-last-modified/) |
| `descriptions.lang` | Language of one of the CVE's descriptions, as a two-letter code (`en` and `es` seen). | [Example](/reference/vulnerability/search/examples/descriptions-lang/) |
| `references.url` | URL of one of the CVE's references, such as a vendor advisory, a patch or an exploit. | [Example](/reference/vulnerability/search/examples/references-url/) |
| `references.source` | Who added the reference to the CVE record, identified by an email address or a UUID. | [Example](/reference/vulnerability/search/examples/references-source/) |
| `metrics.cvss_metric_v2.source` | Who provided a CVSS 2.0 assessment of the CVE, identified by an email address or a UUID. A CVE can carry one CVSS 2.0 assessment per source. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-source/) |
| `metrics.cvss_metric_v2.type` | Role of a CVSS 2.0 assessment of the CVE. Values: `Primary`, `Secondary`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-type/) |
| `metrics.cvss_metric_v2.cvss_data.version` | CVSS version of the assessment; always `2.0` here. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-cvss-data-version/) |
| `metrics.cvss_metric_v2.cvss_data.vector_string` | The full CVSS 2.0 vector of the assessment, for example `AV:N/AC:L/Au:N/C:C/I:C/A:C`; it encodes the individual metrics of the assessment. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-cvss-data-vector-string/) |
| `metrics.cvss_metric_v2.cvss_data.access_vector` | CVSS 2.0 Access Vector (AV): how an attacker reaches the vulnerable system. Values: `NETWORK`, `ADJACENT_NETWORK`, `LOCAL`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-cvss-data-access-vector/) |
| `metrics.cvss_metric_v2.cvss_data.access_complexity` | CVSS 2.0 Access Complexity (AC): how difficult the attack is once the attacker has access to the target. Values: `HIGH`, `MEDIUM`, `LOW`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-cvss-data-access-complexity/) |
| `metrics.cvss_metric_v2.cvss_data.authentication` | CVSS 2.0 Authentication (Au): how many times an attacker must authenticate to exploit the vulnerability. Values: `MULTIPLE`, `SINGLE`, `NONE`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-cvss-data-authentication/) |
| `metrics.cvss_metric_v2.cvss_data.confidentiality_impact` | CVSS 2.0 Confidentiality Impact (C): how much a successful attack affects the confidentiality of data. Values: `NONE`, `PARTIAL`, `COMPLETE`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-cvss-data-confidentiality-impact/) |
| `metrics.cvss_metric_v2.cvss_data.integrity_impact` | CVSS 2.0 Integrity Impact (I): how much a successful attack affects the integrity of data. Values: `NONE`, `PARTIAL`, `COMPLETE`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-cvss-data-integrity-impact/) |
| `metrics.cvss_metric_v2.cvss_data.availability_impact` | CVSS 2.0 Availability Impact (A): how much a successful attack affects the availability of the affected system. Values: `NONE`, `PARTIAL`, `COMPLETE`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-cvss-data-availability-impact/) |
| `metrics.cvss_metric_v2.cvss_data.exploitability` | CVSS 2.0 Exploitability (E), a temporal metric: how mature the exploit code or technique is. Values: `UNPROVEN`, `PROOF_OF_CONCEPT`, `FUNCTIONAL`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v2.cvss_data.remediation_level` | CVSS 2.0 Remediation Level (RL), a temporal metric: what kind of fix is available. Values: `OFFICIAL_FIX`, `TEMPORARY_FIX`, `WORKAROUND`, `UNAVAILABLE`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v2.cvss_data.report_confidence` | CVSS 2.0 Report Confidence (RC), a temporal metric: how far the existence of the vulnerability is confirmed. Values: `UNCONFIRMED`, `UNCORROBORATED`, `CONFIRMED`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v2.cvss_data.collateral_damage_potential` | CVSS 2.0 Collateral Damage Potential (CDP), an environmental metric: the potential for loss of life, physical assets or revenue. Values: `NONE`, `LOW`, `LOW_MEDIUM`, `MEDIUM_HIGH`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v2.cvss_data.target_distribution` | CVSS 2.0 Target Distribution (TD), an environmental metric: the share of systems in an environment that are vulnerable. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v2.cvss_data.confidentiality_requirement` | CVSS 2.0 Confidentiality Requirement (CR), an environmental metric: how important confidentiality of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v2.cvss_data.integrity_requirement` | CVSS 2.0 Integrity Requirement (IR), an environmental metric: how important integrity of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v2.cvss_data.availability_requirement` | CVSS 2.0 Availability Requirement (AR), an environmental metric: how important availability of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v2.base_severity` | Severity band of the CVSS 2.0 base score. Values: `LOW`, `MEDIUM`, `HIGH`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-base-severity/) |
| `metrics.cvss_metric_v30.source` | Who provided a CVSS 3.0 assessment of the CVE, identified by an email address or a UUID. A CVE can carry one CVSS 3.0 assessment per source. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-source/) |
| `metrics.cvss_metric_v30.type` | Role of a CVSS 3.0 assessment of the CVE. Values: `Primary`, `Secondary`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-type/) |
| `metrics.cvss_metric_v30.cvss_data.version` | CVSS version of the assessment; always `3.0` here. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-cvss-data-version/) |
| `metrics.cvss_metric_v30.cvss_data.vector_string` | The full CVSS 3.0 vector of the assessment, for example `CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`; it encodes the individual metrics of the assessment. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-cvss-data-vector-string/) |
| `metrics.cvss_metric_v30.cvss_data.attack_vector` | CVSS 3.0 Attack Vector (AV): how an attacker reaches the vulnerable component. Values: `NETWORK`, `ADJACENT_NETWORK`, `LOCAL`, `PHYSICAL`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-cvss-data-attack-vector/) |
| `metrics.cvss_metric_v30.cvss_data.attack_complexity` | CVSS 3.0 Attack Complexity (AC): how difficult the attack is to carry out. Values: `LOW`, `HIGH`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-cvss-data-attack-complexity/) |
| `metrics.cvss_metric_v30.cvss_data.privileges_required` | CVSS 3.0 Privileges Required (PR): the level of privileges an attacker needs before the attack. Values: `NONE`, `LOW`, `HIGH`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-cvss-data-privileges-required/) |
| `metrics.cvss_metric_v30.cvss_data.user_interaction` | CVSS 3.0 User Interaction (UI): whether a user other than the attacker must take part in the attack. Values: `NONE`, `REQUIRED`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-cvss-data-user-interaction/) |
| `metrics.cvss_metric_v30.cvss_data.scope` | CVSS 3.0 Scope (S): whether a successful attack can affect components beyond the vulnerable one. Values: `UNCHANGED`, `CHANGED`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-cvss-data-scope/) |
| `metrics.cvss_metric_v30.cvss_data.confidentiality_impact` | CVSS 3.0 Confidentiality Impact (C): how much a successful attack affects the confidentiality of data. Values: `NONE`, `LOW`, `HIGH`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-cvss-data-confidentiality-impact/) |
| `metrics.cvss_metric_v30.cvss_data.integrity_impact` | CVSS 3.0 Integrity Impact (I): how much a successful attack affects the integrity of data. Values: `NONE`, `LOW`, `HIGH`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-cvss-data-integrity-impact/) |
| `metrics.cvss_metric_v30.cvss_data.availability_impact` | CVSS 3.0 Availability Impact (A): how much a successful attack affects the availability of the affected system. Values: `NONE`, `LOW`, `HIGH`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-cvss-data-availability-impact/) |
| `metrics.cvss_metric_v30.cvss_data.base_severity` | Severity band of the CVSS 3.0 base score. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-cvss-data-base-severity/) |
| `metrics.cvss_metric_v30.cvss_data.exploit_code_maturity` | CVSS 3.0 Exploit Code Maturity (E), a temporal metric: how mature the exploit code or technique is. Values: `UNPROVEN`, `PROOF_OF_CONCEPT`, `FUNCTIONAL`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.remediation_level` | CVSS 3.0 Remediation Level (RL), a temporal metric: what kind of fix is available. Values: `OFFICIAL_FIX`, `TEMPORARY_FIX`, `WORKAROUND`, `UNAVAILABLE`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.report_confidence` | CVSS 3.0 Report Confidence (RC), a temporal metric: how far the existence of the vulnerability is confirmed. Values: `UNKNOWN`, `REASONABLE`, `CONFIRMED`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.temporal_severity` | Severity band of the CVSS 3.0 temporal score. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.confidentiality_requirement` | CVSS 3.0 Confidentiality Requirement (CR), an environmental metric: how important confidentiality of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.integrity_requirement` | CVSS 3.0 Integrity Requirement (IR), an environmental metric: how important integrity of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.availability_requirement` | CVSS 3.0 Availability Requirement (AR), an environmental metric: how important availability of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.modified_attack_vector` | CVSS 3.0 Modified Attack Vector (MAV), an environmental metric that overrides Attack Vector for a specific environment. Values: `NETWORK`, `ADJACENT_NETWORK`, `LOCAL`, `PHYSICAL`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.modified_attack_complexity` | CVSS 3.0 Modified Attack Complexity (MAC), an environmental metric that overrides Attack Complexity for a specific environment. Values: `HIGH`, `LOW`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.modified_privileges_required` | CVSS 3.0 Modified Privileges Required (MPR), an environmental metric that overrides Privileges Required for a specific environment. Values: `HIGH`, `LOW`, `NONE`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.modified_user_interaction` | CVSS 3.0 Modified User Interaction (MUI), an environmental metric that overrides User Interaction for a specific environment. Values: `NONE`, `REQUIRED`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.modified_scope` | CVSS 3.0 Modified Scope (MS), an environmental metric that overrides Scope for a specific environment. Values: `UNCHANGED`, `CHANGED`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.modified_confidentiality_impact` | CVSS 3.0 Modified Confidentiality Impact (MC), an environmental metric that overrides Confidentiality Impact for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.modified_integrity_impact` | CVSS 3.0 Modified Integrity Impact (MI), an environmental metric that overrides Integrity Impact for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.modified_availability_impact` | CVSS 3.0 Modified Availability Impact (MA), an environmental metric that overrides Availability Impact for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.environmental_severity` | Severity band of the CVSS 3.0 environmental score. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.source` | Who provided a CVSS 3.1 assessment of the CVE, identified by an email address or a UUID. A CVE can carry one CVSS 3.1 assessment per source. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-source/) |
| `metrics.cvss_metric_v31.type` | Role of a CVSS 3.1 assessment of the CVE. Values: `Primary`, `Secondary`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-type/) |
| `metrics.cvss_metric_v31.cvss_data.version` | CVSS version of the assessment; always `3.1` here. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-cvss-data-version/) |
| `metrics.cvss_metric_v31.cvss_data.vector_string` | The full CVSS 3.1 vector of the assessment, for example `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`; it encodes the individual metrics of the assessment. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-cvss-data-vector-string/) |
| `metrics.cvss_metric_v31.cvss_data.attack_vector` | CVSS 3.1 Attack Vector (AV): how an attacker reaches the vulnerable component. Values: `NETWORK`, `ADJACENT_NETWORK`, `LOCAL`, `PHYSICAL`. | [Example 1](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-cvss-data-attack-vector/)<br>[Example 2](/reference/vulnerability/search/examples/remote-unauthenticated-no-interaction/) |
| `metrics.cvss_metric_v31.cvss_data.attack_complexity` | CVSS 3.1 Attack Complexity (AC): how difficult the attack is to carry out. Values: `LOW`, `HIGH`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-cvss-data-attack-complexity/) |
| `metrics.cvss_metric_v31.cvss_data.privileges_required` | CVSS 3.1 Privileges Required (PR): the level of privileges an attacker needs before the attack. Values: `NONE`, `LOW`, `HIGH`. | [Example 1](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-cvss-data-privileges-required/)<br>[Example 2](/reference/vulnerability/search/examples/remote-unauthenticated-no-interaction/) |
| `metrics.cvss_metric_v31.cvss_data.user_interaction` | CVSS 3.1 User Interaction (UI): whether a user other than the attacker must take part in the attack. Values: `NONE`, `REQUIRED`. | [Example 1](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-cvss-data-user-interaction/)<br>[Example 2](/reference/vulnerability/search/examples/remote-unauthenticated-no-interaction/) |
| `metrics.cvss_metric_v31.cvss_data.scope` | CVSS 3.1 Scope (S): whether a successful attack can affect components beyond the vulnerable one. Values: `UNCHANGED`, `CHANGED`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-cvss-data-scope/) |
| `metrics.cvss_metric_v31.cvss_data.confidentiality_impact` | CVSS 3.1 Confidentiality Impact (C): how much a successful attack affects the confidentiality of data. Values: `NONE`, `LOW`, `HIGH`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-cvss-data-confidentiality-impact/) |
| `metrics.cvss_metric_v31.cvss_data.integrity_impact` | CVSS 3.1 Integrity Impact (I): how much a successful attack affects the integrity of data. Values: `NONE`, `LOW`, `HIGH`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-cvss-data-integrity-impact/) |
| `metrics.cvss_metric_v31.cvss_data.availability_impact` | CVSS 3.1 Availability Impact (A): how much a successful attack affects the availability of the affected system. Values: `NONE`, `LOW`, `HIGH`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-cvss-data-availability-impact/) |
| `metrics.cvss_metric_v31.cvss_data.base_severity` | Severity band of the CVSS 3.1 base score. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-cvss-data-base-severity/) |
| `metrics.cvss_metric_v31.cvss_data.exploit_code_maturity` | CVSS 3.1 Exploit Code Maturity (E), a temporal metric: how mature the exploit code or technique is. Values: `UNPROVEN`, `PROOF_OF_CONCEPT`, `FUNCTIONAL`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.remediation_level` | CVSS 3.1 Remediation Level (RL), a temporal metric: what kind of fix is available. Values: `OFFICIAL_FIX`, `TEMPORARY_FIX`, `WORKAROUND`, `UNAVAILABLE`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.report_confidence` | CVSS 3.1 Report Confidence (RC), a temporal metric: how far the existence of the vulnerability is confirmed. Values: `UNKNOWN`, `REASONABLE`, `CONFIRMED`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.temporal_severity` | Severity band of the CVSS 3.1 temporal score. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.confidentiality_requirement` | CVSS 3.1 Confidentiality Requirement (CR), an environmental metric: how important confidentiality of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.integrity_requirement` | CVSS 3.1 Integrity Requirement (IR), an environmental metric: how important integrity of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.availability_requirement` | CVSS 3.1 Availability Requirement (AR), an environmental metric: how important availability of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.modified_attack_vector` | CVSS 3.1 Modified Attack Vector (MAV), an environmental metric that overrides Attack Vector for a specific environment. Values: `NETWORK`, `ADJACENT_NETWORK`, `LOCAL`, `PHYSICAL`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.modified_attack_complexity` | CVSS 3.1 Modified Attack Complexity (MAC), an environmental metric that overrides Attack Complexity for a specific environment. Values: `HIGH`, `LOW`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.modified_privileges_required` | CVSS 3.1 Modified Privileges Required (MPR), an environmental metric that overrides Privileges Required for a specific environment. Values: `HIGH`, `LOW`, `NONE`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.modified_user_interaction` | CVSS 3.1 Modified User Interaction (MUI), an environmental metric that overrides User Interaction for a specific environment. Values: `NONE`, `REQUIRED`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.modified_scope` | CVSS 3.1 Modified Scope (MS), an environmental metric that overrides Scope for a specific environment. Values: `UNCHANGED`, `CHANGED`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.modified_confidentiality_impact` | CVSS 3.1 Modified Confidentiality Impact (MC), an environmental metric that overrides Confidentiality Impact for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.modified_integrity_impact` | CVSS 3.1 Modified Integrity Impact (MI), an environmental metric that overrides Integrity Impact for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.modified_availability_impact` | CVSS 3.1 Modified Availability Impact (MA), an environmental metric that overrides Availability Impact for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.environmental_severity` | Severity band of the CVSS 3.1 environmental score. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`; not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v40.source` | Who provided a CVSS 4.0 assessment of the CVE, identified by an email address or a UUID. A CVE can carry one CVSS 4.0 assessment per source. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-source/) |
| `metrics.cvss_metric_v40.type` | Role of a CVSS 4.0 assessment of the CVE. Values: `Primary`, `Secondary`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-type/) |
| `metrics.cvss_metric_v40.cvss_data.version` | CVSS version of the assessment; always `4.0` here. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-version/) |
| `metrics.cvss_metric_v40.cvss_data.vector_string` | The full CVSS 4.0 vector of the assessment, for example `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H` followed by the threat, environmental and supplemental metrics (`X` when not defined). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-vector-string/) |
| `metrics.cvss_metric_v40.cvss_data.base_severity` | Severity band of the CVSS 4.0 base score. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-base-severity/) |
| `metrics.cvss_metric_v40.cvss_data.attack_vector` | CVSS 4.0 Attack Vector (AV): how an attacker reaches the vulnerable system. Values: `NETWORK`, `ADJACENT`, `LOCAL`, `PHYSICAL`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-attack-vector/) |
| `metrics.cvss_metric_v40.cvss_data.attack_complexity` | CVSS 4.0 Attack Complexity (AC): how difficult the attack is to carry out. Values: `LOW`, `HIGH`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-attack-complexity/) |
| `metrics.cvss_metric_v40.cvss_data.attack_requirements` | CVSS 4.0 Attack Requirements (AT): whether the attack depends on conditions of the vulnerable system that the attacker does not control. Values: `NONE`, `PRESENT`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-attack-requirements/) |
| `metrics.cvss_metric_v40.cvss_data.privileges_required` | CVSS 4.0 Privileges Required (PR): the level of privileges an attacker needs before the attack. Values: `NONE`, `LOW`, `HIGH`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-privileges-required/) |
| `metrics.cvss_metric_v40.cvss_data.user_interaction` | CVSS 4.0 User Interaction (UI): whether and how a user other than the attacker must take part in the attack. Values: `NONE`, `PASSIVE`, `ACTIVE`. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-user-interaction/) |
| `metrics.cvss_metric_v40.cvss_data.vulnerable_system_confidentiality` | CVSS 4.0 Vulnerable System Confidentiality (VC): impact of a successful attack on the confidentiality of the vulnerable system. Values: `NONE`, `LOW`, `HIGH`; rarely filled, and for most CVSS 4.0 assessments the value appears only in `vector_string` (as `VC`). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-impact/) |
| `metrics.cvss_metric_v40.cvss_data.vulnerable_system_integrity` | CVSS 4.0 Vulnerable System Integrity (VI): impact of a successful attack on the integrity of the vulnerable system. Values: `NONE`, `LOW`, `HIGH`; rarely filled, and for most CVSS 4.0 assessments the value appears only in `vector_string` (as `VI`). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-impact/) |
| `metrics.cvss_metric_v40.cvss_data.vulnerable_system_availability` | CVSS 4.0 Vulnerable System Availability (VA): impact of a successful attack on the availability of the vulnerable system. Values: `NONE`, `LOW`, `HIGH`; rarely filled, and for most CVSS 4.0 assessments the value appears only in `vector_string` (as `VA`). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-impact/) |
| `metrics.cvss_metric_v40.cvss_data.subsequent_system_confidentiality` | CVSS 4.0 Subsequent System Confidentiality (SC): impact of a successful attack on the confidentiality of other systems beyond the vulnerable one. Values: `NONE`, `LOW`, `HIGH`; rarely filled, and for most CVSS 4.0 assessments the value appears only in `vector_string` (as `SC`). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-impact/) |
| `metrics.cvss_metric_v40.cvss_data.subsequent_system_integrity` | CVSS 4.0 Subsequent System Integrity (SI): impact of a successful attack on the integrity of other systems beyond the vulnerable one. Values: `NONE`, `LOW`, `HIGH`; rarely filled, and for most CVSS 4.0 assessments the value appears only in `vector_string` (as `SI`). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-impact/) |
| `metrics.cvss_metric_v40.cvss_data.subsequent_system_availability` | CVSS 4.0 Subsequent System Availability (SA): impact of a successful attack on the availability of other systems beyond the vulnerable one. Values: `NONE`, `LOW`, `HIGH`; rarely filled, and for most CVSS 4.0 assessments the value appears only in `vector_string` (as `SA`). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-impact/) |
| `metrics.cvss_metric_v40.cvss_data.exploit_maturity` | CVSS 4.0 Exploit Maturity (E), a threat metric: how likely the vulnerability is to be attacked, based on known exploits and attacks. Values: `UNREPORTED`, `PROOF_OF_CONCEPT`, `ATTACKED`, `NOT_DEFINED` (stored when the vector has `E:X`). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-exploit-maturity/) |
| `metrics.cvss_metric_v40.cvss_data.confidentiality_requirements` | CVSS 4.0 Confidentiality Requirement (CR), an environmental metric: how important confidentiality of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; rarely filled. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-supplemental/) |
| `metrics.cvss_metric_v40.cvss_data.integrity_requirements` | CVSS 4.0 Integrity Requirement (IR), an environmental metric: how important integrity of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; rarely filled. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-supplemental/) |
| `metrics.cvss_metric_v40.cvss_data.availability_requirements` | CVSS 4.0 Availability Requirement (AR), an environmental metric: how important availability of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; rarely filled. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-supplemental/) |
| `metrics.cvss_metric_v40.cvss_data.modified_attack_vector` | CVSS 4.0 Modified Attack Vector (MAV), an environmental metric that overrides Attack Vector for a specific environment. Values: `NETWORK`, `ADJACENT`, `LOCAL`, `PHYSICAL`, `NOT_DEFINED`; usually `NOT_DEFINED` (`MAV:X` in the vector). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-modified/) |
| `metrics.cvss_metric_v40.cvss_data.modified_attack_complexity` | CVSS 4.0 Modified Attack Complexity (MAC), an environmental metric that overrides Attack Complexity for a specific environment. Values: `HIGH`, `LOW`, `NOT_DEFINED`; usually `NOT_DEFINED` (`MAC:X` in the vector). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-modified/) |
| `metrics.cvss_metric_v40.cvss_data.modified_attack_requirements` | CVSS 4.0 Modified Attack Requirements (MAT), an environmental metric that overrides Attack Requirements for a specific environment. Values: `NONE`, `PRESENT`, `NOT_DEFINED`; usually `NOT_DEFINED` (`MAT:X` in the vector). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-modified/) |
| `metrics.cvss_metric_v40.cvss_data.modified_privileges_required` | CVSS 4.0 Modified Privileges Required (MPR), an environmental metric that overrides Privileges Required for a specific environment. Values: `HIGH`, `LOW`, `NONE`, `NOT_DEFINED`; usually `NOT_DEFINED` (`MPR:X` in the vector). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-modified/) |
| `metrics.cvss_metric_v40.cvss_data.modified_user_interaction` | CVSS 4.0 Modified User Interaction (MUI), an environmental metric that overrides User Interaction for a specific environment. Values: `NONE`, `PASSIVE`, `ACTIVE`, `NOT_DEFINED`; usually `NOT_DEFINED` (`MUI:X` in the vector). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-modified/) |
| `metrics.cvss_metric_v40.cvss_data.modified_vulnerable_system_confidentiality` | CVSS 4.0 Modified Vulnerable System Confidentiality (MVC), an environmental metric that overrides Vulnerable System Confidentiality for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; rarely filled. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-supplemental/) |
| `metrics.cvss_metric_v40.cvss_data.modified_vulnerable_system_integrity` | CVSS 4.0 Modified Vulnerable System Integrity (MVI), an environmental metric that overrides Vulnerable System Integrity for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; rarely filled. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-supplemental/) |
| `metrics.cvss_metric_v40.cvss_data.modified_vulnerable_system_availability` | CVSS 4.0 Modified Vulnerable System Availability (MVA), an environmental metric that overrides Vulnerable System Availability for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; rarely filled. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-supplemental/) |
| `metrics.cvss_metric_v40.cvss_data.modified_subsequent_system_confidentiality` | CVSS 4.0 Modified Subsequent System Confidentiality (MSC), an environmental metric that overrides Subsequent System Confidentiality for a specific environment. Values: `NEGLIGIBLE`, `LOW`, `HIGH`, `NOT_DEFINED`; rarely filled. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-supplemental/) |
| `metrics.cvss_metric_v40.cvss_data.modified_subsequent_system_integrity` | CVSS 4.0 Modified Subsequent System Integrity (MSI), an environmental metric that overrides Subsequent System Integrity for a specific environment. Values: `NEGLIGIBLE`, `LOW`, `HIGH`, `SAFETY`, `NOT_DEFINED`; rarely filled. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-supplemental/) |
| `metrics.cvss_metric_v40.cvss_data.modified_subsequent_system_availability` | CVSS 4.0 Modified Subsequent System Availability (MSA), an environmental metric that overrides Subsequent System Availability for a specific environment. Values: `NEGLIGIBLE`, `LOW`, `HIGH`, `SAFETY`, `NOT_DEFINED`; rarely filled. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-supplemental/) |
| `metrics.cvss_metric_v40.cvss_data.safety` | CVSS 4.0 Safety (S), a supplemental metric: whether exploitation can affect human safety. Values: `NEGLIGIBLE`, `PRESENT`, `NOT_DEFINED`; rarely filled, and `vector_string` usually has `S:X` (not defined). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-supplemental/) |
| `metrics.cvss_metric_v40.cvss_data.automatable` | CVSS 4.0 Automatable (AU), a supplemental metric: whether an attacker can automate exploitation across many targets. Values: `NO`, `YES`, `NOT_DEFINED`; rarely filled, and `vector_string` usually has `AU:X` (not defined). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-supplemental/) |
| `metrics.cvss_metric_v40.cvss_data.recovery` | CVSS 4.0 Recovery (R), a supplemental metric: how the system recovers after an attack. Values: `AUTOMATIC`, `USER`, `IRRECOVERABLE`, `NOT_DEFINED`; rarely filled, and `vector_string` usually has `R:X` (not defined). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-supplemental/) |
| `metrics.cvss_metric_v40.cvss_data.value_density` | CVSS 4.0 Value Density (V), a supplemental metric: whether the resources an attacker gains control of are diffuse or concentrated. Values: `DIFFUSE`, `CONCENTRATED`, `NOT_DEFINED`; usually `NOT_DEFINED` (`V:X` in the vector). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-value-density/) |
| `metrics.cvss_metric_v40.cvss_data.vulnerability_response_effort` | CVSS 4.0 Vulnerability Response Effort (RE), a supplemental metric: how much effort it takes to respond to the vulnerability. Values: `LOW`, `MODERATE`, `HIGH`, `NOT_DEFINED`; usually `NOT_DEFINED` (`RE:X` in the vector). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-vulnerability-response-effort/) |
| `metrics.cvss_metric_v40.cvss_data.provider_urgency` | CVSS 4.0 Provider Urgency (U), a supplemental metric: the urgency the provider assigns to the vulnerability. Values: `CLEAR`, `GREEN`, `AMBER`, `RED`, `NOT_DEFINED`; usually `NOT_DEFINED` (`U:X` in the vector). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-provider-urgency/) |
| `weaknesses.source` | Who assigned a weakness (CWE) to the CVE, identified by an email address or a UUID. | [Example](/reference/vulnerability/search/examples/weaknesses-source/) |
| `weaknesses.type` | Role of a weakness entry of the CVE. Values: `Primary`, `Secondary`. | [Example](/reference/vulnerability/search/examples/weaknesses-type/) |
| `weaknesses.description.lang` | Language code of a weakness entry; `en` in all data seen. | [Example](/reference/vulnerability/search/examples/weaknesses-description-lang/) |
| `weaknesses.description.value` | The weakness itself: a CWE ID such as `CWE-94`, or `NVD-CWE-noinfo` (not enough information) or `NVD-CWE-Other` (no specific CWE fits). | [Example](/reference/vulnerability/search/examples/weaknesses-description-value/) |
| `configurations.operator` | Operator that joins the nodes of one applicability configuration (a product combination the CVE applies to): `AND` or `OR`. Set only when the configuration has more than one node; `AND` in all data seen. | [Example](/reference/vulnerability/search/examples/configurations-operator/) |
| `configurations.nodes.operator` | Operator that joins the CPE matches inside a configuration node: `AND` or `OR`; `OR` in all data seen. | [Example](/reference/vulnerability/search/examples/configurations-nodes-operator/) |
| `configurations.nodes.cpe_match.criteria` | CPE 2.3 match string of a product in the configuration, for example `cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*`. | [Example](/reference/vulnerability/search/examples/configurations-nodes-cpe-match-criteria/) |
| `configurations.nodes.cpe_match.match_criteria_id` | Unique identifier (UUID) of the CPE match criterion. | [Example](/reference/vulnerability/search/examples/configurations-nodes-cpe-match-match-criteria-id/) |
| `configurations.nodes.cpe_match.version_start_including` | Start of the affected version range of the CPE match, inclusive: this version and later ones are affected. | [Example](/reference/vulnerability/search/examples/configurations-nodes-cpe-match-version-start-including/) |
| `configurations.nodes.cpe_match.version_start_excluding` | Start of the affected version range of the CPE match, exclusive: versions after this one are affected. | [Example](/reference/vulnerability/search/examples/configurations-nodes-cpe-match-version-start-excluding/) |
| `configurations.nodes.cpe_match.version_end_including` | End of the affected version range of the CPE match, inclusive: this version and earlier ones are affected. | [Example](/reference/vulnerability/search/examples/configurations-nodes-cpe-match-version-end-including/) |
| `configurations.nodes.cpe_match.version_end_excluding` | End of the affected version range of the CPE match, exclusive: versions before this one are affected. | [Example](/reference/vulnerability/search/examples/configurations-nodes-cpe-match-version-end-excluding/) |
| `enrichment.cpe.criteria` | CPE 2.3 match string of a product the CVE applies to, in Deepinfo's product list for the CVE (built from the CPE matches in `configurations`). | [Example](/reference/vulnerability/search/examples/enrichment-cpe-criteria/) |
| `enrichment.cpe.vendor` | Vendor of a product the CVE applies to, as written in its CPE (lower case, for example `adobe` or `cisco`). | [Example 1](/reference/vulnerability/search/examples/enrichment-cpe-vendor/)<br>[Example 2](/reference/vulnerability/search/examples/moveit-except-cve-2023-34362/)<br>[Example 3](/reference/vulnerability/search/examples/microsoft-2024-high-epss/)<br>[Example 4](/reference/vulnerability/search/examples/sort-base-score/)<br>[Example 5](/reference/vulnerability/search/examples/sort-base-severity/) |
| `enrichment.cpe.product` | Product the CVE applies to, as written in its CPE (lower case with underscores, for example `linux_kernel`). | [Example 1](/reference/vulnerability/search/examples/enrichment-cpe-product/)<br>[Example 2](/reference/vulnerability/search/examples/moveit-except-cve-2023-34362/)<br>[Example 3](/reference/vulnerability/search/examples/sort-id/)<br>[Example 4](/reference/vulnerability/search/examples/sort-base-score/)<br>[Example 5](/reference/vulnerability/search/examples/sort-base-severity/) |
| `enrichment.cpe.product_type` | Kind of product, from the CPE part. Values: `a` (application), `h` (hardware), `o` (operating system). | [Example](/reference/vulnerability/search/examples/enrichment-cpe-product-type/) |
| `enrichment.cpe.version_start_including` | Start of the product's affected version range, inclusive: this version and later ones are affected. | [Example](/reference/vulnerability/search/examples/enrichment-cpe-version-start-including/) |
| `enrichment.cpe.version_start_excluding` | Start of the product's affected version range, exclusive: versions after this one are affected. | [Example](/reference/vulnerability/search/examples/enrichment-cpe-version-start-excluding/) |
| `enrichment.cpe.version_end_including` | End of the product's affected version range, inclusive: this version and earlier ones are affected. | [Example](/reference/vulnerability/search/examples/enrichment-cpe-version-end-including/) |
| `enrichment.cpe.version_end_excluding` | End of the product's affected version range, exclusive: versions before this one are affected. | [Example](/reference/vulnerability/search/examples/enrichment-cpe-version-end-excluding/) |
| `enrichment.cpe.affected_versions_first` | First affected version of the product; together with `affected_versions_last` it gives the version range the platform shows (for example v1.5.0 - v1.7.0). | [Example](/reference/vulnerability/search/examples/enrichment-cpe-affected-versions-first/) |
| `enrichment.cpe.affected_versions_last` | Last affected version of the product; together with `affected_versions_first` it gives the version range the platform shows (for example v1.5.0 - v1.7.0). | [Example](/reference/vulnerability/search/examples/enrichment-cpe-affected-versions-last/) |
| `enrichment.cpe.cpe_names.cpe_name` | A concrete CPE 2.3 name covered by the product's match string. You can filter on it, but only GET /discovery/vulnerability-detail returns it; search results leave it out. | [Example](/reference/vulnerability/search/examples/enrichment-cpe-cpe-names-cpe-name/) |
| `enrichment.cwe.owasptop10_2021` | OWASP Top 10 (2021) category of the weakness. Values: `A01 Broken Access Control`, `A02 Cryptographic Failures`, `A03 Injection`, `A04 Insecure Design`, `A05 Security Misconfiguration`, `A06 Vulnerable and Outdated Components`, `A07 Identification and Authentication Failures`, `A08 Software and Data Integrity Failures`, `A09 Security Logging and Monitoring Failures`, `A10 Server-Side Request Forgery (SSRF)`. | [Example](/reference/vulnerability/search/examples/enrichment-cwe-owasptop10-2021/) |
| `enrichment.cisa_kev.vendor_project` | Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example `Microsoft`. | [Example 1](/reference/vulnerability/search/examples/enrichment-cisa-kev-vendor-project/)<br>[Example 2](/reference/vulnerability/search/examples/sort-enrichment-cpe-product/) |
| `enrichment.cisa_kev.product` | Product named in the CVE's CISA KEV entry, for example `Kernel` or `Multiple Products`. | [Example](/reference/vulnerability/search/examples/enrichment-cisa-kev-product/) |
| `enrichment.cisa_kev.known_ransomware_campaign_use` | Whether the CVE is known to be used in ransomware campaigns, according to CISA KEV. Values: `Known`, `Unknown`. | [Example 1](/reference/vulnerability/search/examples/enrichment-cisa-kev-known-ransomware-campaign-use/)<br>[Example 2](/reference/vulnerability/search/examples/ransomware-kev-2026/) |
| `enrichment.vdeep_metric.source` | Source of the CVE's main CVSS assessment (copied from the highest CVSS version available), as an email address or a UUID; the platform shows it as CVE ORIGIN. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-source/) |
| `enrichment.vdeep_metric.type` | Role of the CVE's main CVSS assessment: `Primary` or `Secondary`. When the highest CVSS version has both, the Primary one is used. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-type/) |
| `enrichment.vdeep_metric.cvss_data.version` | CVSS version of the CVE's main CVSS assessment, the highest version available. Values: `2.0`, `3.0`, `3.1`, `4.0`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-version/) |
| `enrichment.vdeep_metric.cvss_data.vector_string` | CVSS vector of the CVE's main CVSS assessment, in the format of its version (for example `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`). | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-vector-string/) |
| `enrichment.vdeep_metric.cvss_data.attack_vector` | Attack vector of the CVE's main CVSS assessment (Access Vector for CVSS 2.0). Values: `NETWORK`, `ADJACENT_NETWORK`, `ADJACENT`, `LOCAL`, `PHYSICAL`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-attack-vector/) |
| `enrichment.vdeep_metric.cvss_data.attack_complexity` | Attack complexity of the CVE's main CVSS assessment (Access Complexity for CVSS 2.0). Values: `LOW`, `MEDIUM`, `HIGH`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-attack-complexity/) |
| `enrichment.vdeep_metric.cvss_data.attack_requirements` | Attack Requirements (AT) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0. Values: `NONE`, `PRESENT`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-attack-requirements/) |
| `enrichment.vdeep_metric.cvss_data.privileges_required` | Privileges required by the CVE's main CVSS assessment; empty when it is CVSS 2.0. Values: `NONE`, `LOW`, `HIGH`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-privileges-required/) |
| `enrichment.vdeep_metric.cvss_data.user_interaction` | User interaction of the CVE's main CVSS assessment; empty when it is CVSS 2.0. Values: `NONE`, `REQUIRED` (CVSS 3.x) or `NONE`, `PASSIVE`, `ACTIVE` (CVSS 4.0). | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-user-interaction/) |
| `enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality` | Confidentiality impact of the CVE's main CVSS assessment: the Confidentiality Impact of a CVSS 2.0 or 3.x assessment (`NONE`, `PARTIAL`, `COMPLETE` or `NONE`, `LOW`, `HIGH`), or VC of a CVSS 4.0 one, which is rarely filled. The platform shows it in the C/I/A classification. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-vulnerable-system-confidentiality/) |
| `enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity` | Integrity impact of the CVE's main CVSS assessment: the Integrity Impact of a CVSS 2.0 or 3.x assessment (`NONE`, `PARTIAL`, `COMPLETE` or `NONE`, `LOW`, `HIGH`), or VI of a CVSS 4.0 one, which is rarely filled. The platform shows it in the C/I/A classification. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-vulnerable-system-integrity/) |
| `enrichment.vdeep_metric.cvss_data.vulnerable_system_availability` | Availability impact of the CVE's main CVSS assessment: the Availability Impact of a CVSS 2.0 or 3.x assessment (`NONE`, `PARTIAL`, `COMPLETE` or `NONE`, `LOW`, `HIGH`), or VA of a CVSS 4.0 one, which is rarely filled. The platform shows it in the C/I/A classification. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-vulnerable-system-availability/) |
| `enrichment.vdeep_metric.cvss_data.subsequent_system_confidentiality` | Subsequent System Confidentiality (SC) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NONE`, `LOW`, `HIGH`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-subsequent-system/) |
| `enrichment.vdeep_metric.cvss_data.subsequent_system_integrity` | Subsequent System Integrity (SI) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NONE`, `LOW`, `HIGH`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-subsequent-system/) |
| `enrichment.vdeep_metric.cvss_data.subsequent_system_availability` | Subsequent System Availability (SA) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NONE`, `LOW`, `HIGH`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-subsequent-system/) |
| `enrichment.vdeep_metric.cvss_data.exploit_maturity` | Exploit Maturity (E) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0. Values: `UNREPORTED`, `PROOF_OF_CONCEPT`, `ATTACKED`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-exploit-maturity/) |
| `enrichment.vdeep_metric.cvss_data.confidentiality_requirements` | Confidentiality Requirement (CR) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-supplemental/) |
| `enrichment.vdeep_metric.cvss_data.integrity_requirements` | Integrity Requirement (IR) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-supplemental/) |
| `enrichment.vdeep_metric.cvss_data.availability_requirements` | Availability Requirement (AR) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-supplemental/) |
| `enrichment.vdeep_metric.cvss_data.modified_attack_vector` | Modified Attack Vector (MAV) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `NETWORK`, `ADJACENT`, `LOCAL`, `PHYSICAL`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-modified/) |
| `enrichment.vdeep_metric.cvss_data.modified_attack_complexity` | Modified Attack Complexity (MAC) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `HIGH`, `LOW`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-modified/) |
| `enrichment.vdeep_metric.cvss_data.modified_attack_requirements` | Modified Attack Requirements (MAT) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `NONE`, `PRESENT`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-modified/) |
| `enrichment.vdeep_metric.cvss_data.modified_privileges_required` | Modified Privileges Required (MPR) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `HIGH`, `LOW`, `NONE`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-modified/) |
| `enrichment.vdeep_metric.cvss_data.modified_user_interaction` | Modified User Interaction (MUI) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `NONE`, `PASSIVE`, `ACTIVE`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-modified/) |
| `enrichment.vdeep_metric.cvss_data.modified_vulnerable_system_confidentiality` | Modified Vulnerable System Confidentiality (MVC) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-supplemental/) |
| `enrichment.vdeep_metric.cvss_data.modified_vulnerable_system_integrity` | Modified Vulnerable System Integrity (MVI) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-supplemental/) |
| `enrichment.vdeep_metric.cvss_data.modified_vulnerable_system_availability` | Modified Vulnerable System Availability (MVA) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-supplemental/) |
| `enrichment.vdeep_metric.cvss_data.modified_subsequent_system_confidentiality` | Modified Subsequent System Confidentiality (MSC) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NEGLIGIBLE`, `LOW`, `HIGH`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-supplemental/) |
| `enrichment.vdeep_metric.cvss_data.modified_subsequent_system_integrity` | Modified Subsequent System Integrity (MSI) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NEGLIGIBLE`, `LOW`, `HIGH`, `SAFETY`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-supplemental/) |
| `enrichment.vdeep_metric.cvss_data.modified_subsequent_system_availability` | Modified Subsequent System Availability (MSA) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NEGLIGIBLE`, `LOW`, `HIGH`, `SAFETY`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-supplemental/) |
| `enrichment.vdeep_metric.cvss_data.safety` | Safety (S) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NEGLIGIBLE`, `PRESENT`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-supplemental/) |
| `enrichment.vdeep_metric.cvss_data.automatable` | Automatable (AU) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NO`, `YES`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-supplemental/) |
| `enrichment.vdeep_metric.cvss_data.recovery` | Recovery (R) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `AUTOMATIC`, `USER`, `IRRECOVERABLE`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-supplemental/) |
| `enrichment.vdeep_metric.cvss_data.value_density` | Value Density (V) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `DIFFUSE`, `CONCENTRATED`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-value-density/) |
| `enrichment.vdeep_metric.cvss_data.vulnerability_response_effort` | Vulnerability Response Effort (RE) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `LOW`, `MODERATE`, `HIGH`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-vulnerability-response-effort/) |
| `enrichment.vdeep_metric.cvss_data.provider_urgency` | Provider Urgency (U) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `CLEAR`, `GREEN`, `AMBER`, `RED`, `NOT_DEFINED`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-provider-urgency/) |
| `enrichment.vdeep_metric.cvss_data.base_severity` | Severity of the CVE's main CVSS assessment. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL` (`LOW`, `MEDIUM`, `HIGH` for CVSS 2.0); the platform shows it as the CVE's severity. | [Example 1](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-base-severity/)<br>[Example 2](/reference/vulnerability/search/examples/kev-critical-high-epss/) |

Operators: `eq`, `gt`, `gte`, `lt`, `lte`, `exists`

| Field | Description | Example |
|---|---|---|
| `published` | Date and time the CVE was first published, in ISO 8601 UTC (for example `2026-06-30T16:16:54Z`). | [Example 1](/reference/vulnerability/search/examples/published/)<br>[Example 2](/reference/vulnerability/search/examples/operator-lt/)<br>[Example 3](/reference/vulnerability/search/examples/microsoft-2024-high-epss/)<br>[Example 4](/reference/vulnerability/search/examples/sqli-or-command-injection-recent/)<br>[Example 5](/reference/vulnerability/search/examples/sort-enrichment-cpe-vendor/)<br>[Example 6](/reference/vulnerability/search/examples/sort-epss/)<br>[Example 7](/reference/vulnerability/search/examples/page-400/) |
| `last_modified` | Date and time the CVE record was last changed, in ISO 8601 UTC (for example `2026-08-26T16:35:20Z`). | [Example](/reference/vulnerability/search/examples/last-modified/) |
| `cisa_exploit_add` | Date the CVE was added to the CISA Known Exploited Vulnerabilities (KEV) catalog (YYYY-MM-DD), as given in the CVE record. `enrichment.cisa_kev.date_added` holds the same date and is filled for a few more CVEs. | [Example](/reference/vulnerability/search/examples/cisa-exploit-add/) |
| `cisa_action_due` | Remediation due date from the CISA KEV catalog (YYYY-MM-DD), as given in the CVE record. `enrichment.cisa_kev.due_date` holds the same date and is filled for a few more CVEs. | [Example](/reference/vulnerability/search/examples/cisa-action-due/) |
| `metrics.cvss_metric_v2.cvss_data.base_score` | CVSS 2.0 base score of the assessment, from 0 to 10. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-cvss-data-base-score/) |
| `metrics.cvss_metric_v2.cvss_data.temporal_score` | CVSS 2.0 temporal score, from 0 to 10: the base score adjusted by the temporal metrics. Not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v2.cvss_data.environmental_score` | CVSS 2.0 environmental score, from 0 to 10: the score adjusted for a specific environment. Not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v2.exploitability_score` | CVSS 2.0 exploitability subscore, from 0 to 10: the part of the base score that comes from access vector, access complexity and authentication. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-exploitability-score/) |
| `metrics.cvss_metric_v2.impact_score` | CVSS 2.0 impact subscore, from 0 to 10: the part of the base score that comes from the confidentiality, integrity and availability impacts. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-impact-score/) |
| `metrics.cvss_metric_v30.cvss_data.base_score` | CVSS 3.0 base score of the assessment, from 0 to 10. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-cvss-data-base-score/) |
| `metrics.cvss_metric_v30.cvss_data.temporal_score` | CVSS 3.0 temporal score, from 0 to 10: the base score adjusted by the temporal metrics. Not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.cvss_data.environmental_score` | CVSS 3.0 environmental score, from 0 to 10: the score adjusted for a specific environment. Not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v30.exploitability_score` | CVSS 3.0 exploitability subscore: the part of the base score that comes from attack vector, attack complexity, privileges required and user interaction (for example `3.9`). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-exploitability-score/) |
| `metrics.cvss_metric_v30.impact_score` | CVSS 3.0 impact subscore: the part of the base score that comes from the confidentiality, integrity and availability impacts (for example `5.9`). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-impact-score/) |
| `metrics.cvss_metric_v31.cvss_data.base_score` | CVSS 3.1 base score of the assessment, from 0 to 10. | [Example 1](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-cvss-data-base-score/)<br>[Example 2](/reference/vulnerability/search/examples/remote-unauthenticated-no-interaction/) |
| `metrics.cvss_metric_v31.cvss_data.temporal_score` | CVSS 3.1 temporal score, from 0 to 10: the base score adjusted by the temporal metrics. Not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.cvss_data.environmental_score` | CVSS 3.1 environmental score, from 0 to 10: the score adjusted for a specific environment. Not filled for any CVE in the current data. |  |
| `metrics.cvss_metric_v31.exploitability_score` | CVSS 3.1 exploitability subscore: the part of the base score that comes from attack vector, attack complexity, privileges required and user interaction (for example `3.9`). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-exploitability-score/) |
| `metrics.cvss_metric_v31.impact_score` | CVSS 3.1 impact subscore: the part of the base score that comes from the confidentiality, integrity and availability impacts (for example `5.9`). | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-impact-score/) |
| `metrics.cvss_metric_v40.cvss_data.base_score` | CVSS 4.0 base score of the assessment, from 0 to 10. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-base-score/) |
| `vendor_comments.last_modified` | Date and time the vendor comment was last changed, in ISO 8601 UTC. | [Example](/reference/vulnerability/search/examples/vendor-comments-last-modified/) |
| `enrichment.cwe.id` | Number of a CWE weakness linked to the CVE (for example `94` for CWE-94). `enrichment.cwe` adds CWE catalog details for each CWE listed in `weaknesses`. | [Example 1](/reference/vulnerability/search/examples/enrichment-cwe-id/)<br>[Example 2](/reference/vulnerability/search/examples/sqli-or-command-injection-recent/)<br>[Example 3](/reference/vulnerability/search/examples/sort-enrichment-cpe-vendor/) |
| `enrichment.epss_score.epss` | EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage. | [Example 1](/reference/vulnerability/search/examples/enrichment-epss-score-epss/)<br>[Example 2](/reference/vulnerability/search/examples/kev-critical-high-epss/)<br>[Example 3](/reference/vulnerability/search/examples/microsoft-2024-high-epss/) |
| `enrichment.epss_score.percentile` | Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (`0.95` means 95% of them have the same or a lower score). | [Example](/reference/vulnerability/search/examples/enrichment-epss-score-percentile/) |
| `enrichment.epss_score.date` | Date of the EPSS score (YYYY-MM-DD); the platform shows it as ANALYSIS DATE. | [Example](/reference/vulnerability/search/examples/enrichment-epss-score-date/) |
| `enrichment.cisa_kev.date_added` | Date the CVE was added to the CISA KEV catalog (YYYY-MM-DD); empty for CVEs not in the catalog. The platform shows CISA KEV: YES when it is set. | [Example 1](/reference/vulnerability/search/examples/enrichment-cisa-kev-date-added/)<br>[Example 2](/reference/vulnerability/search/examples/operator-exists/)<br>[Example 3](/reference/vulnerability/search/examples/kev-critical-high-epss/)<br>[Example 4](/reference/vulnerability/search/examples/ransomware-kev-2026/)<br>[Example 5](/reference/vulnerability/search/examples/sort-published/)<br>[Example 6](/reference/vulnerability/search/examples/sort-cisa-kev-date-added/)<br>[Example 7](/reference/vulnerability/search/examples/page-2/)<br>[Example 8](/reference/vulnerability/search/examples/page-size-100/) |
| `enrichment.cisa_kev.due_date` | Remediation due date in the CVE's CISA KEV entry (YYYY-MM-DD), shown as REMEDIATION DUE; the results table marks CVEs that have it as EXPLOITABLE. | [Example](/reference/vulnerability/search/examples/enrichment-cisa-kev-due-date/) |
| `enrichment.vdeep_metric.cvss_data.base_score` | Base score, from 0 to 10, of the CVE's main CVSS assessment: the assessment of the highest CVSS version the CVE has. The platform shows it as the CVE's score. | [Example 1](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-base-score/)<br>[Example 2](/reference/vulnerability/search/examples/operator-gt/) |

Operators: `eq`, `startswith`, `wildcard`, `contains_any`, `contains_all`, `exists`

| Field | Description | Example |
|---|---|---|
| `evaluator_comment` | Free-text comment from the CVE's evaluator, such as a link to the matching CWE entry or a note on how the score applies to particular platforms or versions. Filled for few CVEs. | [Example](/reference/vulnerability/search/examples/evaluator-comment/) |
| `evaluator_solution` | Free-text note from the CVE's evaluator about the fix, often a link or a quote from an advisory. Filled for few CVEs. | [Example](/reference/vulnerability/search/examples/evaluator-solution/) |
| `evaluator_impact` | Free-text note from the CVE's evaluator about the impact or the affected products, often quoting an advisory. Filled for few CVEs. | [Example](/reference/vulnerability/search/examples/evaluator-impact/) |
| `cisa_required_action` | Action CISA requires for the CVE in the KEV catalog, as given in the CVE record, for example to apply updates per vendor instructions. Same text as `enrichment.cisa_kev.required_action`. | [Example](/reference/vulnerability/search/examples/cisa-required-action/) |
| `cisa_vulnerability_name` | Name of the vulnerability in the CISA KEV catalog, as given in the CVE record. Same text as `enrichment.cisa_kev.vulnerability_name`. | [Example](/reference/vulnerability/search/examples/cisa-vulnerability-name/) |
| `vendor_comments.organization` | Name of a vendor that commented on the CVE, for example `Red Hat` or `Oracle`. | [Example](/reference/vulnerability/search/examples/vendor-comments-organization/) |
| `vendor_comments.comment` | Text of the vendor's statement about the CVE. | [Example](/reference/vulnerability/search/examples/vendor-comments-comment/) |
| `enrichment.cwe.name` | Name of the CWE weakness, for example `Improper Access Control`. | [Example](/reference/vulnerability/search/examples/enrichment-cwe-name/) |
| `enrichment.cisa_kev.vulnerability_name` | Name of the vulnerability in the CVE's CISA KEV entry. | [Example](/reference/vulnerability/search/examples/enrichment-cisa-kev-vulnerability-name/) |
| `enrichment.cisa_kev.short_description` | CISA's short description of the vulnerability in the KEV entry. | [Example](/reference/vulnerability/search/examples/enrichment-cisa-kev-short-description/) |
| `enrichment.cisa_kev.required_action` | Action CISA requires in the KEV entry, for example to apply updates per vendor instructions. | [Example](/reference/vulnerability/search/examples/enrichment-cisa-kev-required-action/) |
| `enrichment.cisa_kev.notes` | Notes in the CVE's CISA KEV entry, usually reference URLs separated by `;`. | [Example](/reference/vulnerability/search/examples/enrichment-cisa-kev-notes/) |

Operators: `eq`, `exists`

| Field | Description | Example |
|---|---|---|
| `metrics.cvss_metric_v2.ac_insuf_info` | Flag on a CVSS 2.0 assessment: `true` when there was not enough information to rate Access Complexity. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-ac-insuf-info/) |
| `metrics.cvss_metric_v2.obtain_all_privilege` | Flag on a CVSS 2.0 assessment: `true` when a successful attack gives the attacker all privileges on the affected system. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-obtain-all-privilege/) |
| `metrics.cvss_metric_v2.obtain_user_privilege` | Flag on a CVSS 2.0 assessment: `true` when a successful attack gives the attacker user-level privileges on the affected system. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-obtain-user-privilege/) |
| `metrics.cvss_metric_v2.obtain_other_privilege` | Flag on a CVSS 2.0 assessment: `true` when a successful attack gives the attacker other privileges on the affected system. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-obtain-other-privilege/) |
| `metrics.cvss_metric_v2.user_interaction_required` | Flag on a CVSS 2.0 assessment: `true` when exploitation needs a user to take some action. | [Example](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-user-interaction-required/) |
| `configurations.negate` | When `true`, the configuration's condition is negated. Not filled for any CVE in the current data. |  |
| `configurations.nodes.negate` | When `true`, the node matches products that do not meet its CPE matches; `false` in all data seen. | [Example](/reference/vulnerability/search/examples/configurations-nodes-negate/) |
| `configurations.nodes.cpe_match.vulnerable` | `true` when the product in this CPE match is vulnerable; `false` when it is only part of the configuration, such as the hardware a vulnerable firmware runs on. | [Example](/reference/vulnerability/search/examples/configurations-nodes-cpe-match-vulnerable/) |
| `enrichment.cpe.vulnerable` | `true` when the product is vulnerable; `false` when it is only part of an affected configuration, such as the hardware a vulnerable firmware runs on. | [Example](/reference/vulnerability/search/examples/enrichment-cpe-vulnerable/) |
| `enrichment.cpe.cpe_names.deprecated` | `true` when that CPE name is deprecated in the CPE dictionary. You can filter on it, but only GET /discovery/vulnerability-detail returns it; search results leave it out. | [Example](/reference/vulnerability/search/examples/enrichment-cpe-cpe-names-deprecated/) |

Operators: `eq`, `in`, `startswith`, `wildcard`, `exists`

| Field | Description | Example |
|---|---|---|
| `references.tags` | Tags that classify a reference. Values: `Vendor Advisory`, `Third Party Advisory`, `Patch`, `Exploit`, `VDB Entry`, `Mailing List`, `US Government Resource`, `Issue Tracking`, `Release Notes`, `Broken Link`, `Permissions Required`, `Product`, `Mitigation`, `Technical Description`, `Not Applicable`, `Press/Media Coverage`, `Tool Signature`, `URL Repurposed`. | [Example 1](/reference/vulnerability/search/examples/references-tags/)<br>[Example 2](/reference/vulnerability/search/examples/operator-in/) |
| `enrichment.cpe.affected_versions` | All affected versions of the product. You can filter on it, but only GET /discovery/vulnerability-detail returns it; search results leave it out. | [Example](/reference/vulnerability/search/examples/enrichment-cpe-affected-versions/) |
| `enrichment.cwe.scope` | Security areas the weakness can affect, from the CWE entry. Values: `Confidentiality`, `Integrity`, `Availability`, `Access Control`, `Accountability`, `Authentication`, `Authorization`, `Non-Repudiation`, `Other`. | [Example](/reference/vulnerability/search/examples/enrichment-cwe-scope/) |
| `enrichment.cwe.impact` | Technical impacts the weakness can have, from the CWE entry, for example `Execute Unauthorized Code or Commands`, `Read Application Data` or `DoS: Crash, Exit, or Restart`. | [Example](/reference/vulnerability/search/examples/enrichment-cwe-impact/) |
| `enrichment.cwe.detection_method` | Methods that can detect the weakness, from the CWE entry, for example `Automated Static Analysis`, `Fuzzing` or `Manual Analysis`. | [Example](/reference/vulnerability/search/examples/enrichment-cwe-detection-method/) |
| `enrichment.vdeep_metric.available_versions` | CVSS versions the CVE has assessments for, highest first. Values: `2.0`, `3.0`, `3.1`, `4.0`. | [Example](/reference/vulnerability/search/examples/enrichment-vdeep-metric-available-versions/) |

Operators: `wildcard`, `contains_any`, `contains_all`, `exists`

| Field | Description | Example |
|---|---|---|
| `descriptions.value` | Text of one of the CVE's descriptions, in the language given by `descriptions.lang`. For a rejected CVE it holds the rejection reason. | [Example 1](/reference/vulnerability/search/examples/descriptions-value/)<br>[Example 2](/reference/vulnerability/search/examples/operator-contains-any/)<br>[Example 3](/reference/vulnerability/search/examples/operator-contains-all/) |
| `enrichment.cwe.description` | The CWE catalog's description of the weakness. | [Example](/reference/vulnerability/search/examples/enrichment-cwe-description/) |

Operators: `eq`, `in`, `gt`, `gte`, `lt`, `lte`, `exists`

| Field | Description | Example |
|---|---|---|
| `enrichment.cwe.capec_id` | IDs of CAPEC attack patterns related to the weakness, as numbers; the platform shows them as `CAPEC-<id>` under ATTACK STAGES. | [Example](/reference/vulnerability/search/examples/enrichment-cwe-capec-id/) |

Operators: `eq`, `startswith`, `wildcard`, `gt`, `lt`, `exists`

| Field | Description | Example |
|---|---|---|
| `id` | The CVE identifier, in the form CVE-YYYY-NNNN with four to seven digits after the year (for example `CVE-2021-44228`). | [Example 1](/reference/vulnerability/search/examples/id/)<br>[Example 2](/reference/vulnerability/search/examples/operator-wildcard/)<br>[Example 3](/reference/vulnerability/search/examples/operator-startswith/)<br>[Example 4](/reference/vulnerability/search/examples/moveit-except-cve-2023-34362/) |

### Sortable Fields

Example: a worked example that sorts by the field, with the request and the response it returns.

| Field | Description | Example |
|---|---|---|
| `id` | The CVE identifier, in the form CVE-YYYY-NNNN with four to seven digits after the year (for example `CVE-2021-44228`). | [Example](/reference/vulnerability/search/examples/sort-id/) |
| `enrichment.cpe.vendor` | Vendor of a product the CVE applies to, as written in its CPE (lower case, for example `adobe` or `cisco`). | [Example](/reference/vulnerability/search/examples/sort-enrichment-cpe-vendor/) |
| `enrichment.cpe.product` | Product the CVE applies to, as written in its CPE (lower case with underscores, for example `linux_kernel`). | [Example](/reference/vulnerability/search/examples/sort-enrichment-cpe-product/) |
| `published` | Date and time the CVE was first published, in ISO 8601 UTC (for example `2026-06-30T16:16:54Z`). | [Example 1](/reference/vulnerability/search/examples/metrics-cvss-metric-v2-obtain-other-privilege/)<br>[Example 2](/reference/vulnerability/search/examples/sort-published/) |
| `last_modified` | Date and time the CVE record was last changed, in ISO 8601 UTC (for example `2026-08-26T16:35:20Z`). | [Example](/reference/vulnerability/search/examples/sort-last-modified/) |
| `enrichment.vdeep_metric.cvss_data.base_score` | Base score, from 0 to 10, of the CVE's main CVSS assessment: the assessment of the highest CVSS version the CVE has. The platform shows it as the CVE's score. | [Example](/reference/vulnerability/search/examples/sort-base-score/) |
| `enrichment.vdeep_metric.cvss_data.base_severity` | Severity of the CVE's main CVSS assessment. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL` (`LOW`, `MEDIUM`, `HIGH` for CVSS 2.0); the platform shows it as the CVE's severity. | [Example](/reference/vulnerability/search/examples/sort-base-severity/) |
| `enrichment.epss_score.epss` | EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage. | [Example](/reference/vulnerability/search/examples/sort-epss/) |
| `enrichment.cisa_kev.date_added` | Date the CVE was added to the CISA KEV catalog (YYYY-MM-DD); empty for CVEs not in the catalog. The platform shows CISA KEV: YES when it is set. | [Example](/reference/vulnerability/search/examples/sort-cisa-kev-date-added/) |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `page` | integer |  |
| `page_size` | integer |  |
| `result_count` | integer |  |
| `results` | array of object |  |
| `results[].id` | string |  |
| `results[].source_identifier` | string |  |
| `results[].published` | string | date-time |
| `results[].last_modified` | string | date-time |
| `results[].status` | string |  |
| `results[].evaluator_comment` | string |  |
| `results[].evaluator_solution` | string |  |
| `results[].evaluator_impact` | string |  |
| `results[].cisa_exploit_add` | string | date |
| `results[].cisa_action_due` | string | date |
| `results[].cisa_required_action` | string |  |
| `results[].cisa_vulnerability_name` | string |  |
| `results[].descriptions` | array of object |  |
| `results[].references` | array of object |  |
| `results[].metrics` | object |  |
| `results[].weaknesses` | array of object |  |
| `results[].configurations` | array of object |  |
| `results[].vendor_comments` | array of object |  |
| `results[].enrichment` | object |  |

Paginated. See [Getting Started → Pagination](/getting-started/pagination/).

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `page` | number |
| `page_size` | number |
| `result_count` | number |
| `results` | array<object> |
| `results[].id` | string |
| `results[].source_identifier` | string |
| `results[].published` | string |
| `results[].last_modified` | string |
| `results[].status` | string |
| `results[].evaluator_comment` | null |
| `results[].evaluator_solution` | null |
| `results[].evaluator_impact` | null |
| `results[].cisa_exploit_add` | null |
| `results[].cisa_action_due` | null |
| `results[].cisa_required_action` | null |
| `results[].cisa_vulnerability_name` | null |
| `results[].descriptions` | array<object> |
| `results[].descriptions[].lang` | string |
| `results[].descriptions[].value` | string |
| `results[].references` | array<object> |
| `results[].references[].url` | string |
| `results[].references[].source` | string |
| `results[].references[].tags` | null |
| `results[].metrics` | object |
| `results[].metrics.cvss_metric_v40` | array<object> |
| `results[].metrics.cvss_metric_v40[].source` | string |
| `results[].metrics.cvss_metric_v40[].type` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data` | object |
| `results[].metrics.cvss_metric_v40[].cvss_data.version` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.vector_string` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.attack_vector` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.attack_complexity` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.attack_requirements` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.privileges_required` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.user_interaction` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.vulnerable_system_confidentiality` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.vulnerable_system_integrity` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.vulnerable_system_availability` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.subsequent_system_confidentiality` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.subsequent_system_integrity` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.subsequent_system_availability` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.exploit_maturity` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.confidentiality_requirements` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.integrity_requirements` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.availability_requirements` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.modified_attack_vector` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.modified_attack_complexity` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.modified_attack_requirements` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.modified_privileges_required` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.modified_user_interaction` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.modified_vulnerable_system_confidentiality` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.modified_vulnerable_system_integrity` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.modified_vulnerable_system_availability` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.modified_subsequent_system_confidentiality` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.modified_subsequent_system_integrity` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.modified_subsequent_system_availability` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.safety` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.automatable` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.recovery` | null |
| `results[].metrics.cvss_metric_v40[].cvss_data.value_density` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.vulnerability_response_effort` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.provider_urgency` | string |
| `results[].metrics.cvss_metric_v40[].cvss_data.base_score` | number |
| `results[].metrics.cvss_metric_v40[].cvss_data.base_severity` | string |
| `results[].metrics.cvss_metric_v31` | array<object> \| null |
| `results[].metrics.cvss_metric_v31[].source` | string |
| `results[].metrics.cvss_metric_v31[].type` | string |
| `results[].metrics.cvss_metric_v31[].cvss_data` | object |
| `results[].metrics.cvss_metric_v31[].cvss_data.version` | string |
| `results[].metrics.cvss_metric_v31[].cvss_data.vector_string` | string |
| `results[].metrics.cvss_metric_v31[].cvss_data.attack_vector` | string |
| `results[].metrics.cvss_metric_v31[].cvss_data.attack_complexity` | string |
| `results[].metrics.cvss_metric_v31[].cvss_data.privileges_required` | string |
| `results[].metrics.cvss_metric_v31[].cvss_data.user_interaction` | string |
| `results[].metrics.cvss_metric_v31[].cvss_data.scope` | string |
| `results[].metrics.cvss_metric_v31[].cvss_data.confidentiality_impact` | string |
| `results[].metrics.cvss_metric_v31[].cvss_data.integrity_impact` | string |
| `results[].metrics.cvss_metric_v31[].cvss_data.availability_impact` | string |
| `results[].metrics.cvss_metric_v31[].cvss_data.base_score` | number |
| `results[].metrics.cvss_metric_v31[].cvss_data.base_severity` | string |
| `results[].metrics.cvss_metric_v31[].cvss_data.exploit_code_maturity` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.remediation_level` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.report_confidence` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.temporal_score` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.temporal_severity` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.confidentiality_requirement` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.integrity_requirement` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.availability_requirement` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.modified_attack_vector` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.modified_attack_complexity` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.modified_privileges_required` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.modified_user_interaction` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.modified_scope` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.modified_confidentiality_impact` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.modified_integrity_impact` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.modified_availability_impact` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.environmental_score` | null |
| `results[].metrics.cvss_metric_v31[].cvss_data.environmental_severity` | null |
| `results[].metrics.cvss_metric_v31[].exploitability_score` | number |
| `results[].metrics.cvss_metric_v31[].impact_score` | number |
| `results[].metrics.cvss_metric_v30` | null |
| `results[].metrics.cvss_metric_v2` | null |
| `results[].weaknesses` | array<object> |
| `results[].weaknesses[].source` | string |
| `results[].weaknesses[].type` | string |
| `results[].weaknesses[].description` | array<object> |
| `results[].weaknesses[].description[].lang` | string |
| `results[].weaknesses[].description[].value` | string |
| `results[].configurations` | null |
| `results[].vendor_comments` | null |
| `results[].enrichment` | object |
| `results[].enrichment.cpe` | null |
| `results[].enrichment.cwe` | array<object> |
| `results[].enrichment.cwe[].id` | number |
| `results[].enrichment.cwe[].owasptop10_2021` | null |
| `results[].enrichment.cwe[].name` | string |
| `results[].enrichment.cwe[].description` | string |
| `results[].enrichment.cwe[].capec_id` | array<number> |
| `results[].enrichment.cwe[].scope` | array<string> |
| `results[].enrichment.cwe[].impact` | array<string> |
| `results[].enrichment.cwe[].detection_method` | array<string> \| null |
| `results[].enrichment.epss_score` | object |
| `results[].enrichment.epss_score.epss` | number |
| `results[].enrichment.epss_score.percentile` | number |
| `results[].enrichment.epss_score.date` | string |
| `results[].enrichment.cisa_kev` | null |
| `results[].enrichment.vdeep_metric` | object |
| `results[].enrichment.vdeep_metric.available_versions` | array<string> |
| `results[].enrichment.vdeep_metric.source` | string |
| `results[].enrichment.vdeep_metric.type` | string |
| `results[].enrichment.vdeep_metric.cvss_data` | object |
| `results[].enrichment.vdeep_metric.cvss_data.version` | string |
| `results[].enrichment.vdeep_metric.cvss_data.vector_string` | string |
| `results[].enrichment.vdeep_metric.cvss_data.attack_vector` | string |
| `results[].enrichment.vdeep_metric.cvss_data.attack_complexity` | string |
| `results[].enrichment.vdeep_metric.cvss_data.attack_requirements` | string |
| `results[].enrichment.vdeep_metric.cvss_data.privileges_required` | string |
| `results[].enrichment.vdeep_metric.cvss_data.user_interaction` | string |
| `results[].enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality` | null |
| `results[].enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity` | null |
| `results[].enrichment.vdeep_metric.cvss_data.vulnerable_system_availability` | null |
| `results[].enrichment.vdeep_metric.cvss_data.subsequent_system_confidentiality` | null |
| `results[].enrichment.vdeep_metric.cvss_data.subsequent_system_integrity` | null |
| `results[].enrichment.vdeep_metric.cvss_data.subsequent_system_availability` | null |
| `results[].enrichment.vdeep_metric.cvss_data.exploit_maturity` | string |
| `results[].enrichment.vdeep_metric.cvss_data.confidentiality_requirements` | null |
| `results[].enrichment.vdeep_metric.cvss_data.integrity_requirements` | null |
| `results[].enrichment.vdeep_metric.cvss_data.availability_requirements` | null |
| `results[].enrichment.vdeep_metric.cvss_data.modified_attack_vector` | string |
| `results[].enrichment.vdeep_metric.cvss_data.modified_attack_complexity` | string |
| `results[].enrichment.vdeep_metric.cvss_data.modified_attack_requirements` | string |
| `results[].enrichment.vdeep_metric.cvss_data.modified_privileges_required` | string |
| `results[].enrichment.vdeep_metric.cvss_data.modified_user_interaction` | string |
| `results[].enrichment.vdeep_metric.cvss_data.modified_vulnerable_system_confidentiality` | null |
| `results[].enrichment.vdeep_metric.cvss_data.modified_vulnerable_system_integrity` | null |
| `results[].enrichment.vdeep_metric.cvss_data.modified_vulnerable_system_availability` | null |
| `results[].enrichment.vdeep_metric.cvss_data.modified_subsequent_system_confidentiality` | null |
| `results[].enrichment.vdeep_metric.cvss_data.modified_subsequent_system_integrity` | null |
| `results[].enrichment.vdeep_metric.cvss_data.modified_subsequent_system_availability` | null |
| `results[].enrichment.vdeep_metric.cvss_data.safety` | null |
| `results[].enrichment.vdeep_metric.cvss_data.automatable` | null |
| `results[].enrichment.vdeep_metric.cvss_data.recovery` | null |
| `results[].enrichment.vdeep_metric.cvss_data.value_density` | string |
| `results[].enrichment.vdeep_metric.cvss_data.vulnerability_response_effort` | string |
| `results[].enrichment.vdeep_metric.cvss_data.provider_urgency` | string |
| `results[].enrichment.vdeep_metric.cvss_data.base_score` | number |
| `results[].enrichment.vdeep_metric.cvss_data.base_severity` | string |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 395222,
  "results": [
    {
      "id": "CVE-2026-9508",
      "source_identifier": "user@incibe.es",
      "published": "2026-05-29T13:16:23Z",
      "last_modified": "2026-07-21T12:10:00Z",
      "status": "Deferred",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path within the NGINX webroot. This vulnerability allows an attacker with network access to directly download backup ZIP files via ‘http(s)://[server]/download/…’ without requiring authentication. This expos…"
        },
        {
          "lang": "es",
          "value": "Configuración de permisos incorrecta en un recurso crítico en Suprema BioStar 2 (versiones 2.9.3 a 2.9.11) que permite que los archivos de copia de seguridad queden expuestos públicamente cuando el administrador configura su ruta dentro del directorio raíz web de NGINX. Esta vulnerabilidad permite a un atacante con acceso a la red descargar directamente archivos ZIP de copia de seguridad a través …"
        }
      ],
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-supremas-biostar",
          "source": "user@incibe.es",
          "tags": null
        }
      ],
      "metrics": {
        "cvss_metric_v40": [
          {
            "source": "user@incibe.es",
            "type": "Secondary",
            "cvss_data": {
              "version": "4.0",
              "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "attack_requirements": "NONE",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "vulnerable_system_confidentiality": null,
              "vulnerable_system_integrity": null,
              "vulnerable_system_availability": null,
              "subsequent_system_confidentiality": null,
              "subsequent_system_integrity": null,
              "subsequent_system_availability": null,
              "exploit_maturity": "NOT_DEFINED",
              "confidentiality_requirements": null,
              "integrity_requirements": null,
              "availability_requirements": null,
              "modified_attack_vector": "NOT_DEFINED",
              "modified_attack_complexity": "NOT_DEFINED",
              "modified_attack_requirements": "NOT_DEFINED",
              "modified_privileges_required": "NOT_DEFINED",
              "modified_user_interaction": "NOT_DEFINED",
              "modified_vulnerable_system_confidentiality": null,
              "modified_vulnerable_system_integrity": null,
              "modified_vulnerable_system_availability": null,
              "modified_subsequent_system_confidentiality": null,
              "modified_subsequent_system_integrity": null,
              "modified_subsequent_system_availability": null,
              "safety": null,
              "automatable": null,
              "recovery": null,
              "value_density": "NOT_DEFINED",
              "vulnerability_response_effort": "NOT_DEFINED",
              "provider_urgency": "NOT_DEFINED",
              "base_score": 10.0,
              "base_severity": "CRITICAL"
            }
          }
        ],
        "cvss_metric_v31": null,
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "user@incibe.es",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-732"
            }
          ]
        }
      ],
      "configurations": null,
      "vendor_comments": null,
      "enrichment": {
        "cpe": null,
        "cwe": [
          {
            "id": 732,
            "owasptop10_2021": null,
            "name": "Incorrect Permission Assignment for Critical Resource",
            "description": "The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.",
            "capec_id": [
              1,
              17
            ],
            "scope": [
              "Access Control",
              "Confidentiality"
            ],
            "impact": [
              "Gain Privileges or Assume Identity",
              "Modify Application Data"
            ],
            "detection_method": [
              "Architecture or Design Review",
              "Automated Dynamic Analysis"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.00341,
          "percentile": 0.27608,
          "date": "2026-09-21"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "4.0"
          ],
          "source": "user@incibe.es",
          "type": "Secondary",
          "cvss_data": {
            "version": "4.0",
            "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": "NONE",
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": null,
            "vulnerable_system_integrity": null,
            "vulnerable_system_availability": null,
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": "NOT_DEFINED",
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": "NOT_DEFINED",
            "modified_attack_complexity": "NOT_DEFINED",
            "modified_attack_requirements": "NOT_DEFINED",
            "modified_privileges_required": "NOT_DEFINED",
            "modified_user_interaction": "NOT_DEFINED",
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": "NOT_DEFINED",
            "vulnerability_response_effort": "NOT_DEFINED",
            "provider_urgency": "NOT_DEFINED",
            "base_score": 10.0,
            "base_severity": "CRITICAL"
          }
        }
      }
    },
    {
      "id": "CVE-2026-93606",
      "source_identifier": "user@vulncheck.com",
      "published": "2026-09-18T14:19:12Z",
      "last_modified": "2026-09-18T18:18:31Z",
      "status": "Deferred",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks in lib/bridge.js) only wraps `then`/`catch` rejection slots that hold a function, and the sandbox-side `Symbol.species`/`…"
        }
      ],
      "references": [
        {
          "url": "https://github.com/patriksimek/vm2/security/advisories/GHSA-6454-5x88-m6jw",
          "source": "user@vulncheck.com",
          "tags": null
        },
        {
          "url": "https://www.vulncheck.com/advisories/vm2-before-3.12.1-sandbox-escape-via-promise-symbol-species",
          "source": "user@vulncheck.com",
          "tags": null
        }
      ],
      "metrics": {
        "cvss_metric_v40": [
          {
            "source": "user@vulncheck.com",
            "type": "Secondary",
            "cvss_data": {
              "version": "4.0",
              "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "attack_requirements": "NONE",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "vulnerable_system_confidentiality": null,
              "vulnerable_system_integrity": null,
              "vulnerable_system_availability": null,
              "subsequent_system_confidentiality": null,
              "subsequent_system_integrity": null,
              "subsequent_system_availability": null,
              "exploit_maturity": "NOT_DEFINED",
              "confidentiality_requirements": null,
              "integrity_requirements": null,
              "availability_requirements": null,
              "modified_attack_vector": "NOT_DEFINED",
              "modified_attack_complexity": "NOT_DEFINED",
              "modified_attack_requirements": "NOT_DEFINED",
              "modified_privileges_required": "NOT_DEFINED",
              "modified_user_interaction": "NOT_DEFINED",
              "modified_vulnerable_system_confidentiality": null,
              "modified_vulnerable_system_integrity": null,
              "modified_vulnerable_system_availability": null,
              "modified_subsequent_system_confidentiality": null,
              "modified_subsequent_system_integrity": null,
              "modified_subsequent_system_availability": null,
              "safety": null,
              "automatable": null,
              "recovery": null,
              "value_density": "NOT_DEFINED",
              "vulnerability_response_effort": "NOT_DEFINED",
              "provider_urgency": "NOT_DEFINED",
              "base_score": 10.0,
              "base_severity": "CRITICAL"
            }
          }
        ],
        "cvss_metric_v31": [
          {
            "source": "user@vulncheck.com",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 10.0,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 6.0
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "user@vulncheck.com",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-693"
            }
          ]
        }
      ],
      "configurations": null,
      "vendor_comments": null,
      "enrichment": {
        "cpe": null,
        "cwe": [
          {
            "id": 693,
            "owasptop10_2021": null,
            "name": "Protection Mechanism Failure",
            "description": "The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.",
            "capec_id": [
              1,
              17
            ],
            "scope": [
              "Access Control"
            ],
            "impact": [
              "Bypass Protection Mechanism"
            ],
            "detection_method": null
          }
        ],
        "epss_score": {
          "epss": 0.00518,
          "percentile": 0.42896,
          "date": "2026-09-21"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "4.0",
            "3.1"
          ],
          "source": "user@vulncheck.com",
          "type": "Secondary",
          "cvss_data": {
            "version": "4.0",
            "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": "NONE",
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": null,
            "vulnerable_system_integrity": null,
            "vulnerable_system_availability": null,
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": "NOT_DEFINED",
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": "NOT_DEFINED",
            "modified_attack_complexity": "NOT_DEFINED",
            "modified_attack_requirements": "NOT_DEFINED",
            "modified_privileges_required": "NOT_DEFINED",
            "modified_user_interaction": "NOT_DEFINED",
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": "NOT_DEFINED",
            "vulnerability_response_effort": "NOT_DEFINED",
            "provider_urgency": "NOT_DEFINED",
            "base_score": 10.0,
            "base_severity": "CRITICAL"
          }
        }
      }
    }
  ]
}
```

### 400 · Invalid Parameter (invalid export=notabool)

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/vulnerability-search?export=notabool' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "code": 10400,
  "parameters": [
    {
      "param": "export",
      "details": [
        "Must be a valid boolean."
      ]
    }
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```

### Request Template

The request only: a request template has no response.

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "source_identifier",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "status",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "descriptions.lang",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "references.url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "references.source",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "metrics.cvss_metric_v2.source",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "metrics.cvss_metric_v2.type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "metrics.cvss_metric_v2.cvss_data.version",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "metrics.cvss_metric_v2.cvss_data.vector_string",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "metrics.cvss_metric_v2.cvss_data.access_vector",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "published",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "last_modified",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "cisa_exploit_add",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "cisa_action_due",
        "type": "eq",
        "value": "2026-01-01T00:00:00Z"
      },
      {
        "name": "metrics.cvss_metric_v2.cvss_data.base_score",
        "type": "eq",
        "value": 0
      },
      {
        "name": "metrics.cvss_metric_v2.cvss_data.temporal_score",
        "type": "eq",
        "value": 0
      },
      {
        "name": "metrics.cvss_metric_v2.cvss_data.environmental_score",
        "type": "eq",
        "value": 0
      },
      {
        "name": "metrics.cvss_metric_v2.exploitability_score",
        "type": "eq",
        "value": 0
      },
      {
        "name": "metrics.cvss_metric_v2.impact_score",
        "type": "eq",
        "value": 0
      },
      {
        "name": "metrics.cvss_metric_v30.cvss_data.base_score",
        "type": "eq",
        "value": 0
      },
      {
        "name": "evaluator_comment",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "evaluator_solution",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "evaluator_impact",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cisa_required_action",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cisa_vulnerability_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "vendor_comments.organization",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "vendor_comments.comment",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "enrichment.cwe.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "enrichment.cisa_kev.vulnerability_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "enrichment.cisa_kev.short_description",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "metrics.cvss_metric_v2.ac_insuf_info",
        "type": "eq",
        "value": true
      },
      {
        "name": "metrics.cvss_metric_v2.obtain_all_privilege",
        "type": "eq",
        "value": true
      },
      {
        "name": "metrics.cvss_metric_v2.obtain_user_privilege",
        "type": "eq",
        "value": true
      },
      {
        "name": "metrics.cvss_metric_v2.obtain_other_privilege",
        "type": "eq",
        "value": true
      },
      {
        "name": "metrics.cvss_metric_v2.user_interaction_required",
        "type": "eq",
        "value": true
      },
      {
        "name": "configurations.negate",
        "type": "eq",
        "value": true
      },
      {
        "name": "configurations.nodes.negate",
        "type": "eq",
        "value": true
      },
      {
        "name": "configurations.nodes.cpe_match.vulnerable",
        "type": "eq",
        "value": true
      },
      {
        "name": "enrichment.cpe.vulnerable",
        "type": "eq",
        "value": true
      },
      {
        "name": "enrichment.cpe.cpe_names.deprecated",
        "type": "eq",
        "value": true
      },
      {
        "name": "references.tags",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "enrichment.cpe.affected_versions",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "enrichment.cwe.scope",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "enrichment.cwe.impact",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "enrichment.cwe.detection_method",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "enrichment.vdeep_metric.available_versions",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "descriptions.value",
        "type": "wildcard",
        "value": "<value>"
      },
      {
        "name": "enrichment.cwe.description",
        "type": "wildcard",
        "value": "<value>"
      },
      {
        "name": "enrichment.cwe.capec_id",
        "type": "eq",
        "value": 0
      },
      {
        "name": "id",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "id",
      "order": "desc"
    }
  ]
}'
```

## Worked Examples

Worked examples of this endpoint, each on its own page with the exact request and its response: [Vulnerability Search Examples](/reference/vulnerability/search/examples/).

- [One CVE by Id](/reference/vulnerability/search/examples/id/): The record of one CVE, Log4Shell, by its id.
- [CVSS v3.1: Base Score 9.8 and Up](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-cvss-data-base-score/): CVEs whose CVSS v3.1 base score is 9.8 or higher.
- [EPSS 0.9 and Up](/reference/vulnerability/search/examples/enrichment-epss-score-epss/): CVEs whose EPSS score, the chance of exploitation in the next 30 days, is 0.9 or higher.
- [KEV CVEs Used by Ransomware](/reference/vulnerability/search/examples/enrichment-cisa-kev-known-ransomware-campaign-use/): CVEs that CISA knows are used in ransomware campaigns.
- [Exploited, Critical and Likely to Be Exploited Again](/reference/vulnerability/search/examples/kev-critical-high-epss/): CVEs in CISA KEV with a critical Deepinfo score and an EPSS score of 0.9 or more.
- [Sort by EPSS: Most Likely to Be Exploited First](/reference/vulnerability/search/examples/sort-epss/): CVEs published in 2026, highest EPSS score first.
