Search
https://api.deepinfo.com/v1/discovery/vulnerability-searchSearches Deepinfo's CVE database with filters.
Authentication
Send your API key in the apikey request header.
Query Parameters
| Parameter | Required | Description |
|---|---|---|
page_ | Optional | Min 25, max 100. Default 100.Example 25 |
export | Optional | Default false. |
export_ | Optional | One of: json, csv. |
export_ | Optional | One of: basic, default, extended. |
page | Optional | Min 1, max 400. Default 1.Example 1 |
Request Body
| Parameter | Type | Required | Description |
|---|---|---|---|
filters | object | Optional | See Filtering below |
sort | array | Optional | List of {field, order} |
{}
Filtering
Example body:
{
"filters": {
"must": [
{
"name": "id",
"type": "eq",
"value": "<value>"
}
]
},
"sort": [
{
"field": "id",
"order": "desc"
}
]
}
See Getting Started → Search & Filters for the operators.
The Request Template example holds this body with some of the filters of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value; Searchable Fields lists them all. Copy it, keep the filters you need and set their values.
Searchable Fields
Grouped by the operators they accept (measured against the API; sending another operator returns 400). Example: a worked example that filters by the field, with the request and the response it returns.
Operators eq startswith wildcard exists
| Field | Description | Example |
|---|---|---|
source_ | The CVE's assigner, shown as Assigner in the platform: the organization that submitted the CVE record, identified by an email address or a UUID. | CVEs Published by the Apache Software Foundation |
status | Analysis status of the CVE record. Values seen: Received, Awaiting Analysis, Undergoing Analysis, Analyzed, Modified, Deferred, Rejected. | |
descriptions. | Language of one of the CVE's descriptions, as a two-letter code (en and es seen). | CVEs With a Spanish Description |
references. | URL of one of the CVE's references, such as a vendor advisory, a patch or an exploit. | CVEs With a Palo Alto Networks Advisory |
references. | Who added the reference to the CVE record, identified by an email address or a UUID. | References Added by Red Hat |
metrics. | Who provided a CVSS 2.0 assessment of the CVE, identified by an email address or a UUID. A CVE can carry one CVSS 2.0 assessment per source. | CVSS v2: Scored by the NVD |
metrics. | Role of a CVSS 2.0 assessment of the CVE. Values: Primary, Secondary. | CVSS v2: Secondary Scores |
metrics. | CVSS version of the assessment; always 2.0 here. | CVSS v2: Any Score |
metrics. | The full CVSS 2.0 vector of the assessment, for example AV:N/AC:L/Au:N/C:C/I:C/A:C; it encodes the individual metrics of the assessment. | CVSS v2: Remote, No Authentication, Complete Impact |
metrics. | CVSS 2.0 Access Vector (AV): how an attacker reaches the vulnerable system. Values: NETWORK, ADJACENT_NETWORK, LOCAL. | CVSS v2: Local Access Vector |
metrics. | CVSS 2.0 Access Complexity (AC): how difficult the attack is once the attacker has access to the target. Values: HIGH, MEDIUM, LOW. | CVSS v2: Medium Access Complexity |
metrics. | CVSS 2.0 Authentication (Au): how many times an attacker must authenticate to exploit the vulnerability. Values: MULTIPLE, SINGLE, NONE. | CVSS v2: Single Authentication |
metrics. | CVSS 2.0 Confidentiality Impact (C): how much a successful attack affects the confidentiality of data. Values: NONE, PARTIAL, COMPLETE. | CVSS v2: Complete Confidentiality Impact |
metrics. | CVSS 2.0 Integrity Impact (I): how much a successful attack affects the integrity of data. Values: NONE, PARTIAL, COMPLETE. | CVSS v2: Partial Integrity Impact |
metrics. | CVSS 2.0 Availability Impact (A): how much a successful attack affects the availability of the affected system. Values: NONE, PARTIAL, COMPLETE. | CVSS v2: No Availability Impact |
metrics. | CVSS 2.0 Exploitability (E), a temporal metric: how mature the exploit code or technique is. Values: UNPROVEN, PROOF_OF_CONCEPT, FUNCTIONAL, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 2.0 Remediation Level (RL), a temporal metric: what kind of fix is available. Values: OFFICIAL_FIX, TEMPORARY_FIX, WORKAROUND, UNAVAILABLE, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 2.0 Report Confidence (RC), a temporal metric: how far the existence of the vulnerability is confirmed. Values: UNCONFIRMED, UNCORROBORATED, CONFIRMED, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 2.0 Collateral Damage Potential (CDP), an environmental metric: the potential for loss of life, physical assets or revenue. Values: NONE, LOW, LOW_MEDIUM, MEDIUM_HIGH, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 2.0 Target Distribution (TD), an environmental metric: the share of systems in an environment that are vulnerable. Values: NONE, LOW, MEDIUM, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 2.0 Confidentiality Requirement (CR), an environmental metric: how important confidentiality of the affected asset is to the organization. Values: LOW, MEDIUM, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 2.0 Integrity Requirement (IR), an environmental metric: how important integrity of the affected asset is to the organization. Values: LOW, MEDIUM, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 2.0 Availability Requirement (AR), an environmental metric: how important availability of the affected asset is to the organization. Values: LOW, MEDIUM, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | Severity band of the CVSS 2.0 base score. Values: LOW, MEDIUM, HIGH. | CVSS v2: Medium Severity |
metrics. | Who provided a CVSS 3.0 assessment of the CVE, identified by an email address or a UUID. A CVE can carry one CVSS 3.0 assessment per source. | CVSS v3.0: Scored by HackerOne |
metrics. | Role of a CVSS 3.0 assessment of the CVE. Values: Primary, Secondary. | CVSS v3.0: Primary Scores |
metrics. | CVSS version of the assessment; always 3.0 here. | CVSS v3.0: Any Score |
metrics. | The full CVSS 3.0 vector of the assessment, for example CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; it encodes the individual metrics of the assessment. | CVSS v3.0: Remote Without Privileges or Interaction |
metrics. | CVSS 3.0 Attack Vector (AV): how an attacker reaches the vulnerable component. Values: NETWORK, ADJACENT_NETWORK, LOCAL, PHYSICAL. | CVSS v3.0: Local Attack Vector |
metrics. | CVSS 3.0 Attack Complexity (AC): how difficult the attack is to carry out. Values: LOW, HIGH. | CVSS v3.0: High Attack Complexity |
metrics. | CVSS 3.0 Privileges Required (PR): the level of privileges an attacker needs before the attack. Values: NONE, LOW, HIGH. | CVSS v3.0: High Privileges Required |
metrics. | CVSS 3.0 User Interaction (UI): whether a user other than the attacker must take part in the attack. Values: NONE, REQUIRED. | CVSS v3.0: User Interaction Required |
metrics. | CVSS 3.0 Scope (S): whether a successful attack can affect components beyond the vulnerable one. Values: UNCHANGED, CHANGED. | CVSS v3.0: Changed Scope |
metrics. | CVSS 3.0 Confidentiality Impact (C): how much a successful attack affects the confidentiality of data. Values: NONE, LOW, HIGH. | CVSS v3.0: Low Confidentiality Impact |
metrics. | CVSS 3.0 Integrity Impact (I): how much a successful attack affects the integrity of data. Values: NONE, LOW, HIGH. | CVSS v3.0: No Integrity Impact |
metrics. | CVSS 3.0 Availability Impact (A): how much a successful attack affects the availability of the affected system. Values: NONE, LOW, HIGH. | CVSS v3.0: High Availability Impact |
metrics. | Severity band of the CVSS 3.0 base score. Values: NONE, LOW, MEDIUM, HIGH, CRITICAL. | CVSS v3.0: Medium Severity |
metrics. | CVSS 3.0 Exploit Code Maturity (E), a temporal metric: how mature the exploit code or technique is. Values: UNPROVEN, PROOF_OF_CONCEPT, FUNCTIONAL, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.0 Remediation Level (RL), a temporal metric: what kind of fix is available. Values: OFFICIAL_FIX, TEMPORARY_FIX, WORKAROUND, UNAVAILABLE, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.0 Report Confidence (RC), a temporal metric: how far the existence of the vulnerability is confirmed. Values: UNKNOWN, REASONABLE, CONFIRMED, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | Severity band of the CVSS 3.0 temporal score. Values: NONE, LOW, MEDIUM, HIGH, CRITICAL; not filled for any CVE in the current data. | |
metrics. | CVSS 3.0 Confidentiality Requirement (CR), an environmental metric: how important confidentiality of the affected asset is to the organization. Values: LOW, MEDIUM, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.0 Integrity Requirement (IR), an environmental metric: how important integrity of the affected asset is to the organization. Values: LOW, MEDIUM, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.0 Availability Requirement (AR), an environmental metric: how important availability of the affected asset is to the organization. Values: LOW, MEDIUM, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.0 Modified Attack Vector (MAV), an environmental metric that overrides Attack Vector for a specific environment. Values: NETWORK, ADJACENT_NETWORK, LOCAL, PHYSICAL, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.0 Modified Attack Complexity (MAC), an environmental metric that overrides Attack Complexity for a specific environment. Values: HIGH, LOW, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.0 Modified Privileges Required (MPR), an environmental metric that overrides Privileges Required for a specific environment. Values: HIGH, LOW, NONE, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.0 Modified User Interaction (MUI), an environmental metric that overrides User Interaction for a specific environment. Values: NONE, REQUIRED, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.0 Modified Scope (MS), an environmental metric that overrides Scope for a specific environment. Values: UNCHANGED, CHANGED, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.0 Modified Confidentiality Impact (MC), an environmental metric that overrides Confidentiality Impact for a specific environment. Values: NONE, LOW, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.0 Modified Integrity Impact (MI), an environmental metric that overrides Integrity Impact for a specific environment. Values: NONE, LOW, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.0 Modified Availability Impact (MA), an environmental metric that overrides Availability Impact for a specific environment. Values: NONE, LOW, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | Severity band of the CVSS 3.0 environmental score. Values: NONE, LOW, MEDIUM, HIGH, CRITICAL; not filled for any CVE in the current data. | |
metrics. | Who provided a CVSS 3.1 assessment of the CVE, identified by an email address or a UUID. A CVE can carry one CVSS 3.1 assessment per source. | CVSS v3.1: Scored by Microsoft |
metrics. | Role of a CVSS 3.1 assessment of the CVE. Values: Primary, Secondary. | CVSS v3.1: Primary Scores |
metrics. | CVSS version of the assessment; always 3.1 here. | CVSS v3.1: Any Score |
metrics. | The full CVSS 3.1 vector of the assessment, for example CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; it encodes the individual metrics of the assessment. | CVSS v3.1: The Log4Shell Vector |
metrics. | CVSS 3.1 Attack Vector (AV): how an attacker reaches the vulnerable component. Values: NETWORK, ADJACENT_NETWORK, LOCAL, PHYSICAL. | |
metrics. | CVSS 3.1 Attack Complexity (AC): how difficult the attack is to carry out. Values: LOW, HIGH. | CVSS v3.1: High Attack Complexity |
metrics. | CVSS 3.1 Privileges Required (PR): the level of privileges an attacker needs before the attack. Values: NONE, LOW, HIGH. | |
metrics. | CVSS 3.1 User Interaction (UI): whether a user other than the attacker must take part in the attack. Values: NONE, REQUIRED. | |
metrics. | CVSS 3.1 Scope (S): whether a successful attack can affect components beyond the vulnerable one. Values: UNCHANGED, CHANGED. | CVSS v3.1: Unchanged Scope |
metrics. | CVSS 3.1 Confidentiality Impact (C): how much a successful attack affects the confidentiality of data. Values: NONE, LOW, HIGH. | CVSS v3.1: High Confidentiality Impact |
metrics. | CVSS 3.1 Integrity Impact (I): how much a successful attack affects the integrity of data. Values: NONE, LOW, HIGH. | CVSS v3.1: Low Integrity Impact |
metrics. | CVSS 3.1 Availability Impact (A): how much a successful attack affects the availability of the affected system. Values: NONE, LOW, HIGH. | CVSS v3.1: No Availability Impact |
metrics. | Severity band of the CVSS 3.1 base score. Values: NONE, LOW, MEDIUM, HIGH, CRITICAL. | CVSS v3.1: Critical Severity |
metrics. | CVSS 3.1 Exploit Code Maturity (E), a temporal metric: how mature the exploit code or technique is. Values: UNPROVEN, PROOF_OF_CONCEPT, FUNCTIONAL, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.1 Remediation Level (RL), a temporal metric: what kind of fix is available. Values: OFFICIAL_FIX, TEMPORARY_FIX, WORKAROUND, UNAVAILABLE, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.1 Report Confidence (RC), a temporal metric: how far the existence of the vulnerability is confirmed. Values: UNKNOWN, REASONABLE, CONFIRMED, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | Severity band of the CVSS 3.1 temporal score. Values: NONE, LOW, MEDIUM, HIGH, CRITICAL; not filled for any CVE in the current data. | |
metrics. | CVSS 3.1 Confidentiality Requirement (CR), an environmental metric: how important confidentiality of the affected asset is to the organization. Values: LOW, MEDIUM, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.1 Integrity Requirement (IR), an environmental metric: how important integrity of the affected asset is to the organization. Values: LOW, MEDIUM, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.1 Availability Requirement (AR), an environmental metric: how important availability of the affected asset is to the organization. Values: LOW, MEDIUM, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.1 Modified Attack Vector (MAV), an environmental metric that overrides Attack Vector for a specific environment. Values: NETWORK, ADJACENT_NETWORK, LOCAL, PHYSICAL, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.1 Modified Attack Complexity (MAC), an environmental metric that overrides Attack Complexity for a specific environment. Values: HIGH, LOW, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.1 Modified Privileges Required (MPR), an environmental metric that overrides Privileges Required for a specific environment. Values: HIGH, LOW, NONE, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.1 Modified User Interaction (MUI), an environmental metric that overrides User Interaction for a specific environment. Values: NONE, REQUIRED, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.1 Modified Scope (MS), an environmental metric that overrides Scope for a specific environment. Values: UNCHANGED, CHANGED, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.1 Modified Confidentiality Impact (MC), an environmental metric that overrides Confidentiality Impact for a specific environment. Values: NONE, LOW, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.1 Modified Integrity Impact (MI), an environmental metric that overrides Integrity Impact for a specific environment. Values: NONE, LOW, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | CVSS 3.1 Modified Availability Impact (MA), an environmental metric that overrides Availability Impact for a specific environment. Values: NONE, LOW, HIGH, NOT_DEFINED; not filled for any CVE in the current data. | |
metrics. | Severity band of the CVSS 3.1 environmental score. Values: NONE, LOW, MEDIUM, HIGH, CRITICAL; not filled for any CVE in the current data. | |
metrics. | Who provided a CVSS 4.0 assessment of the CVE, identified by an email address or a UUID. A CVE can carry one CVSS 4.0 assessment per source. | CVSS 4.0: Scored by VulnCheck |
metrics. | Role of a CVSS 4.0 assessment of the CVE. Values: Primary, Secondary. | CVSS 4.0: Secondary Scores |
metrics. | CVSS version of the assessment; always 4.0 here. | CVSS 4.0: Any Score |
metrics. | The full CVSS 4.0 vector of the assessment, for example CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H followed by the threat, environmental and supplemental metrics (X when not defined). | CVSS 4.0: Remote With High Impact |
metrics. | Severity band of the CVSS 4.0 base score. Values: NONE, LOW, MEDIUM, HIGH, CRITICAL. | CVSS 4.0: Medium Severity |
metrics. | CVSS 4.0 Attack Vector (AV): how an attacker reaches the vulnerable system. Values: NETWORK, ADJACENT, LOCAL, PHYSICAL. | CVSS 4.0: Local Attack Vector |
metrics. | CVSS 4.0 Attack Complexity (AC): how difficult the attack is to carry out. Values: LOW, HIGH. | CVSS 4.0: High Attack Complexity |
metrics. | CVSS 4.0 Attack Requirements (AT): whether the attack depends on conditions of the vulnerable system that the attacker does not control. Values: NONE, PRESENT. | CVSS 4.0: Attack Requirements Present |
metrics. | CVSS 4.0 Privileges Required (PR): the level of privileges an attacker needs before the attack. Values: NONE, LOW, HIGH. | CVSS 4.0: High Privileges Required |
metrics. | CVSS 4.0 User Interaction (UI): whether and how a user other than the attacker must take part in the attack. Values: NONE, PASSIVE, ACTIVE. | CVSS 4.0: Passive User Interaction |
metrics. | CVSS 4.0 Vulnerable System Confidentiality (VC): impact of a successful attack on the confidentiality of the vulnerable system. Values: NONE, LOW, HIGH; rarely filled, and for most CVSS 4.0 assessments the value appears only in vector_string (as VC). | CVSS 4.0: Impact on the Vulnerable and Subsequent Systems |
metrics. | CVSS 4.0 Vulnerable System Integrity (VI): impact of a successful attack on the integrity of the vulnerable system. Values: NONE, LOW, HIGH; rarely filled, and for most CVSS 4.0 assessments the value appears only in vector_string (as VI). | CVSS 4.0: Impact on the Vulnerable and Subsequent Systems |
metrics. | CVSS 4.0 Vulnerable System Availability (VA): impact of a successful attack on the availability of the vulnerable system. Values: NONE, LOW, HIGH; rarely filled, and for most CVSS 4.0 assessments the value appears only in vector_string (as VA). | CVSS 4.0: Impact on the Vulnerable and Subsequent Systems |
metrics. | CVSS 4.0 Subsequent System Confidentiality (SC): impact of a successful attack on the confidentiality of other systems beyond the vulnerable one. Values: NONE, LOW, HIGH; rarely filled, and for most CVSS 4.0 assessments the value appears only in vector_string (as SC). | CVSS 4.0: Impact on the Vulnerable and Subsequent Systems |
metrics. | CVSS 4.0 Subsequent System Integrity (SI): impact of a successful attack on the integrity of other systems beyond the vulnerable one. Values: NONE, LOW, HIGH; rarely filled, and for most CVSS 4.0 assessments the value appears only in vector_string (as SI). | CVSS 4.0: Impact on the Vulnerable and Subsequent Systems |
metrics. | CVSS 4.0 Subsequent System Availability (SA): impact of a successful attack on the availability of other systems beyond the vulnerable one. Values: NONE, LOW, HIGH; rarely filled, and for most CVSS 4.0 assessments the value appears only in vector_string (as SA). | CVSS 4.0: Impact on the Vulnerable and Subsequent Systems |
metrics. | CVSS 4.0 Exploit Maturity (E), a threat metric: how likely the vulnerability is to be attacked, based on known exploits and attacks. Values: UNREPORTED, PROOF_OF_CONCEPT, ATTACKED, NOT_DEFINED (stored when the vector has E:X). | CVSS 4.0: Exploit Maturity Attacked |
metrics. | CVSS 4.0 Confidentiality Requirement (CR), an environmental metric: how important confidentiality of the affected asset is to the organization. Values: LOW, MEDIUM, HIGH, NOT_DEFINED; rarely filled. | CVSS 4.0: Security Requirements and Supplemental Metrics |
metrics. | CVSS 4.0 Integrity Requirement (IR), an environmental metric: how important integrity of the affected asset is to the organization. Values: LOW, MEDIUM, HIGH, NOT_DEFINED; rarely filled. | CVSS 4.0: Security Requirements and Supplemental Metrics |
metrics. | CVSS 4.0 Availability Requirement (AR), an environmental metric: how important availability of the affected asset is to the organization. Values: LOW, MEDIUM, HIGH, NOT_DEFINED; rarely filled. | CVSS 4.0: Security Requirements and Supplemental Metrics |
metrics. | CVSS 4.0 Modified Attack Vector (MAV), an environmental metric that overrides Attack Vector for a specific environment. Values: NETWORK, ADJACENT, LOCAL, PHYSICAL, NOT_DEFINED; usually NOT_DEFINED (MAV:X in the vector). | CVSS 4.0: Environmental Metrics Left Unset |
metrics. | CVSS 4.0 Modified Attack Complexity (MAC), an environmental metric that overrides Attack Complexity for a specific environment. Values: HIGH, LOW, NOT_DEFINED; usually NOT_DEFINED (MAC:X in the vector). | CVSS 4.0: Environmental Metrics Left Unset |
metrics. | CVSS 4.0 Modified Attack Requirements (MAT), an environmental metric that overrides Attack Requirements for a specific environment. Values: NONE, PRESENT, NOT_DEFINED; usually NOT_DEFINED (MAT:X in the vector). | CVSS 4.0: Environmental Metrics Left Unset |
metrics. | CVSS 4.0 Modified Privileges Required (MPR), an environmental metric that overrides Privileges Required for a specific environment. Values: HIGH, LOW, NONE, NOT_DEFINED; usually NOT_DEFINED (MPR:X in the vector). | CVSS 4.0: Environmental Metrics Left Unset |
metrics. | CVSS 4.0 Modified User Interaction (MUI), an environmental metric that overrides User Interaction for a specific environment. Values: NONE, PASSIVE, ACTIVE, NOT_DEFINED; usually NOT_DEFINED (MUI:X in the vector). | CVSS 4.0: Environmental Metrics Left Unset |
metrics. | CVSS 4.0 Modified Vulnerable System Confidentiality (MVC), an environmental metric that overrides Vulnerable System Confidentiality for a specific environment. Values: NONE, LOW, HIGH, NOT_DEFINED; rarely filled. | CVSS 4.0: Security Requirements and Supplemental Metrics |
metrics. | CVSS 4.0 Modified Vulnerable System Integrity (MVI), an environmental metric that overrides Vulnerable System Integrity for a specific environment. Values: NONE, LOW, HIGH, NOT_DEFINED; rarely filled. | CVSS 4.0: Security Requirements and Supplemental Metrics |
metrics. | CVSS 4.0 Modified Vulnerable System Availability (MVA), an environmental metric that overrides Vulnerable System Availability for a specific environment. Values: NONE, LOW, HIGH, NOT_DEFINED; rarely filled. | CVSS 4.0: Security Requirements and Supplemental Metrics |
metrics. | CVSS 4.0 Modified Subsequent System Confidentiality (MSC), an environmental metric that overrides Subsequent System Confidentiality for a specific environment. Values: NEGLIGIBLE, LOW, HIGH, NOT_DEFINED; rarely filled. | CVSS 4.0: Security Requirements and Supplemental Metrics |
metrics. | CVSS 4.0 Modified Subsequent System Integrity (MSI), an environmental metric that overrides Subsequent System Integrity for a specific environment. Values: NEGLIGIBLE, LOW, HIGH, SAFETY, NOT_DEFINED; rarely filled. | CVSS 4.0: Security Requirements and Supplemental Metrics |
metrics. | CVSS 4.0 Modified Subsequent System Availability (MSA), an environmental metric that overrides Subsequent System Availability for a specific environment. Values: NEGLIGIBLE, LOW, HIGH, SAFETY, NOT_DEFINED; rarely filled. | CVSS 4.0: Security Requirements and Supplemental Metrics |
metrics. | CVSS 4.0 Safety (S), a supplemental metric: whether exploitation can affect human safety. Values: NEGLIGIBLE, PRESENT, NOT_DEFINED; rarely filled, and vector_string usually has S:X (not defined). | CVSS 4.0: Security Requirements and Supplemental Metrics |
metrics. | CVSS 4.0 Automatable (AU), a supplemental metric: whether an attacker can automate exploitation across many targets. Values: NO, YES, NOT_DEFINED; rarely filled, and vector_string usually has AU:X (not defined). | CVSS 4.0: Security Requirements and Supplemental Metrics |
metrics. | CVSS 4.0 Recovery (R), a supplemental metric: how the system recovers after an attack. Values: AUTOMATIC, USER, IRRECOVERABLE, NOT_DEFINED; rarely filled, and vector_string usually has R:X (not defined). | CVSS 4.0: Security Requirements and Supplemental Metrics |
metrics. | CVSS 4.0 Value Density (V), a supplemental metric: whether the resources an attacker gains control of are diffuse or concentrated. Values: DIFFUSE, CONCENTRATED, NOT_DEFINED; usually NOT_DEFINED (V:X in the vector). | CVSS 4.0: Concentrated Value Density |
metrics. | CVSS 4.0 Vulnerability Response Effort (RE), a supplemental metric: how much effort it takes to respond to the vulnerability. Values: LOW, MODERATE, HIGH, NOT_DEFINED; usually NOT_DEFINED (RE:X in the vector). | CVSS 4.0: Moderate Response Effort |
metrics. | CVSS 4.0 Provider Urgency (U), a supplemental metric: the urgency the provider assigns to the vulnerability. Values: CLEAR, GREEN, AMBER, RED, NOT_DEFINED; usually NOT_DEFINED (U:X in the vector). | CVSS 4.0: Red Provider Urgency |
weaknesses. | Who assigned a weakness (CWE) to the CVE, identified by an email address or a UUID. | Weaknesses Assigned by a Source With a UUID |
weaknesses. | Role of a weakness entry of the CVE. Values: Primary, Secondary. | Secondary Weakness Entries |
weaknesses. | Language code of a weakness entry; en in all data seen. | Weakness Entries in English |
weaknesses. | The weakness itself: a CWE ID such as CWE-94, or NVD-CWE-noinfo (not enough information) or NVD-CWE-Other (no specific CWE fits). | Weakness CWE-502 (Deserialization) |
configurations. | Operator that joins the nodes of one applicability configuration (a product combination the CVE applies to): AND or OR. Set only when the configuration has more than one node; AND in all data seen. | Configurations That Need Two Products |
configurations. | Operator that joins the CPE matches inside a configuration node: AND or OR; OR in all data seen. | Nodes Joined With AND |
configurations. | CPE 2.3 match string of a product in the configuration, for example cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*. | Configurations Matching MOVEit Transfer |
configurations. | Unique identifier (UUID) of the CPE match criterion. | One CPE Match Criterion by Id |
configurations. | Start of the affected version range of the CPE match, inclusive: this version and later ones are affected. | Configurations Starting at Version 2.13.0 |
configurations. | Start of the affected version range of the CPE match, exclusive: versions after this one are affected. | Configurations Starting After Version 1.8.5 |
configurations. | End of the affected version range of the CPE match, inclusive: this version and earlier ones are affected. | Configurations Ending at Version 7.4.3 |
configurations. | End of the affected version range of the CPE match, exclusive: versions before this one are affected. | Configurations Fixed in Version 2.5.12 |
enrichment. | CPE 2.3 match string of a product the CVE applies to, in Deepinfo's product list for the CVE (built from the CPE matches in configurations). | Affected Product: XZ Utils 5.6.0 |
enrichment. | Vendor of a product the CVE applies to, as written in its CPE (lower case, for example adobe or cisco). | |
enrichment. | Product the CVE applies to, as written in its CPE (lower case with underscores, for example linux_kernel). | |
enrichment. | Kind of product, from the CPE part. Values: a (application), h (hardware), o (operating system). | Affected Hardware |
enrichment. | Start of the product's affected version range, inclusive: this version and later ones are affected. | Affected Range Starting at 12.5.0 |
enrichment. | Start of the product's affected version range, exclusive: versions after this one are affected. | Affected Range Starting After 6.3 |
enrichment. | End of the product's affected version range, inclusive: this version and earlier ones are affected. | Affected Range Ending at 2.4.2 |
enrichment. | End of the product's affected version range, exclusive: versions before this one are affected. | Affected Range Fixed in 19.1.8 |
enrichment. | First affected version of the product; together with affected_versions_last it gives the version range the platform shows (for example v1.5.0 - v1.7.0). | First Affected Release 2023.4 |
enrichment. | Last affected version of the product; together with affected_versions_first it gives the version range the platform shows (for example v1.5.0 - v1.7.0). | Last Affected Release 2026.2 |
enrichment. | A concrete CPE 2.3 name covered by the product's match string. You can filter on it, but only GET /discovery/vulnerability-detail returns it; search results leave it out. | One Concrete CPE Name |
enrichment. | OWASP Top 10 (2021) category of the weakness. Values: A01 Broken Access Control, A02 Cryptographic Failures, A03 Injection, A04 Insecure Design, A05 Security Misconfiguration, A06 Vulnerable and Outdated Components, A07 Identification and Authentication Failures, A08 Software and Data Integrity Failures, A09 Security Logging and Monitoring Failures, A10 Server-Side Request Forgery (SSRF). | OWASP Top 10: Server-Side Request Forgery |
enrichment. | Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example Microsoft. | |
enrichment. | Product named in the CVE's CISA KEV entry, for example Kernel or Multiple Products. | KEV Product: Exchange Server |
enrichment. | Whether the CVE is known to be used in ransomware campaigns, according to CISA KEV. Values: Known, Unknown. | |
enrichment. | Source of the CVE's main CVSS assessment (copied from the highest CVSS version available), as an email address or a UUID; the platform shows it as CVE ORIGIN. | Deepinfo Score From GitHub |
enrichment. | Role of the CVE's main CVSS assessment: Primary or Secondary. When the highest CVSS version has both, the Primary one is used. | Deepinfo Score From the NVD |
enrichment. | CVSS version of the CVE's main CVSS assessment, the highest version available. Values: 2.0, 3.0, 3.1, 4.0. | Deepinfo Score From CVSS v2 |
enrichment. | CVSS vector of the CVE's main CVSS assessment, in the format of its version (for example CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). | Deepinfo Score Vector: Classic 9.8 |
enrichment. | Attack vector of the CVE's main CVSS assessment (Access Vector for CVSS 2.0). Values: NETWORK, ADJACENT_NETWORK, ADJACENT, LOCAL, PHYSICAL. | Deepinfo Score: Physical Attack Vector |
enrichment. | Attack complexity of the CVE's main CVSS assessment (Access Complexity for CVSS 2.0). Values: LOW, MEDIUM, HIGH. | Deepinfo Score: High Attack Complexity |
enrichment. | Attack Requirements (AT) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0. Values: NONE, PRESENT. | Deepinfo Score: Attack Requirements Present |
enrichment. | Privileges required by the CVE's main CVSS assessment; empty when it is CVSS 2.0. Values: NONE, LOW, HIGH. | Deepinfo Score: High Privileges Required |
enrichment. | User interaction of the CVE's main CVSS assessment; empty when it is CVSS 2.0. Values: NONE, REQUIRED (CVSS 3.x) or NONE, PASSIVE, ACTIVE (CVSS 4.0). | Deepinfo Score: User Interaction Required |
enrichment. | Confidentiality impact of the CVE's main CVSS assessment: the Confidentiality Impact of a CVSS 2.0 or 3.x assessment (NONE, PARTIAL, COMPLETE or NONE, LOW, HIGH), or VC of a CVSS 4.0 one, which is rarely filled. The platform shows it in the C/I/A classification. | Deepinfo Score: Complete Confidentiality Impact |
enrichment. | Integrity impact of the CVE's main CVSS assessment: the Integrity Impact of a CVSS 2.0 or 3.x assessment (NONE, PARTIAL, COMPLETE or NONE, LOW, HIGH), or VI of a CVSS 4.0 one, which is rarely filled. The platform shows it in the C/I/A classification. | Deepinfo Score: Low Integrity Impact |
enrichment. | Availability impact of the CVE's main CVSS assessment: the Availability Impact of a CVSS 2.0 or 3.x assessment (NONE, PARTIAL, COMPLETE or NONE, LOW, HIGH), or VA of a CVSS 4.0 one, which is rarely filled. The platform shows it in the C/I/A classification. | Deepinfo Score: Low Availability Impact |
enrichment. | Subsequent System Confidentiality (SC) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: NONE, LOW, HIGH. | Deepinfo Score: No Impact on Subsequent Systems |
enrichment. | Subsequent System Integrity (SI) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: NONE, LOW, HIGH. | Deepinfo Score: No Impact on Subsequent Systems |
enrichment. | Subsequent System Availability (SA) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: NONE, LOW, HIGH. | Deepinfo Score: No Impact on Subsequent Systems |
enrichment. | Exploit Maturity (E) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0. Values: UNREPORTED, PROOF_OF_CONCEPT, ATTACKED, NOT_DEFINED. | Deepinfo Score: Exploit Maturity Attacked |
enrichment. | Confidentiality Requirement (CR) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: LOW, MEDIUM, HIGH, NOT_DEFINED. | Deepinfo Score: Security Requirements and Supplemental Metrics |
enrichment. | Integrity Requirement (IR) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: LOW, MEDIUM, HIGH, NOT_DEFINED. | Deepinfo Score: Security Requirements and Supplemental Metrics |
enrichment. | Availability Requirement (AR) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: LOW, MEDIUM, HIGH, NOT_DEFINED. | Deepinfo Score: Security Requirements and Supplemental Metrics |
enrichment. | Modified Attack Vector (MAV) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually NOT_DEFINED. Values: NETWORK, ADJACENT, LOCAL, PHYSICAL, NOT_DEFINED. | Deepinfo Score: Environmental Metrics Left Unset |
enrichment. | Modified Attack Complexity (MAC) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually NOT_DEFINED. Values: HIGH, LOW, NOT_DEFINED. | Deepinfo Score: Environmental Metrics Left Unset |
enrichment. | Modified Attack Requirements (MAT) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually NOT_DEFINED. Values: NONE, PRESENT, NOT_DEFINED. | Deepinfo Score: Environmental Metrics Left Unset |
enrichment. | Modified Privileges Required (MPR) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually NOT_DEFINED. Values: HIGH, LOW, NONE, NOT_DEFINED. | Deepinfo Score: Environmental Metrics Left Unset |
enrichment. | Modified User Interaction (MUI) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually NOT_DEFINED. Values: NONE, PASSIVE, ACTIVE, NOT_DEFINED. | Deepinfo Score: Environmental Metrics Left Unset |
enrichment. | Modified Vulnerable System Confidentiality (MVC) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: NONE, LOW, HIGH, NOT_DEFINED. | Deepinfo Score: Security Requirements and Supplemental Metrics |
enrichment. | Modified Vulnerable System Integrity (MVI) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: NONE, LOW, HIGH, NOT_DEFINED. | Deepinfo Score: Security Requirements and Supplemental Metrics |
enrichment. | Modified Vulnerable System Availability (MVA) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: NONE, LOW, HIGH, NOT_DEFINED. | Deepinfo Score: Security Requirements and Supplemental Metrics |
enrichment. | Modified Subsequent System Confidentiality (MSC) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: NEGLIGIBLE, LOW, HIGH, NOT_DEFINED. | Deepinfo Score: Security Requirements and Supplemental Metrics |
enrichment. | Modified Subsequent System Integrity (MSI) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: NEGLIGIBLE, LOW, HIGH, SAFETY, NOT_DEFINED. | Deepinfo Score: Security Requirements and Supplemental Metrics |
enrichment. | Modified Subsequent System Availability (MSA) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: NEGLIGIBLE, LOW, HIGH, SAFETY, NOT_DEFINED. | Deepinfo Score: Security Requirements and Supplemental Metrics |
enrichment. | Safety (S) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: NEGLIGIBLE, PRESENT, NOT_DEFINED. | Deepinfo Score: Security Requirements and Supplemental Metrics |
enrichment. | Automatable (AU) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: NO, YES, NOT_DEFINED. | Deepinfo Score: Security Requirements and Supplemental Metrics |
enrichment. | Recovery (R) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: AUTOMATIC, USER, IRRECOVERABLE, NOT_DEFINED. | Deepinfo Score: Security Requirements and Supplemental Metrics |
enrichment. | Value Density (V) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually NOT_DEFINED. Values: DIFFUSE, CONCENTRATED, NOT_DEFINED. | Deepinfo Score: Diffuse Value Density |
enrichment. | Vulnerability Response Effort (RE) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually NOT_DEFINED. Values: LOW, MODERATE, HIGH, NOT_DEFINED. | Deepinfo Score: Low Response Effort |
enrichment. | Provider Urgency (U) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually NOT_DEFINED. Values: CLEAR, GREEN, AMBER, RED, NOT_DEFINED. | Deepinfo Score: Amber Provider Urgency |
enrichment. | Severity of the CVE's main CVSS assessment. Values: NONE, LOW, MEDIUM, HIGH, CRITICAL (LOW, MEDIUM, HIGH for CVSS 2.0); the platform shows it as the CVE's severity. |
Operators eq gt gte lt lte exists
| Field | Description | Example |
|---|---|---|
published | Date and time the CVE was first published, in ISO 8601 UTC (for example 2026-06-30T16:16:54Z). | |
last_ | Date and time the CVE record was last changed, in ISO 8601 UTC (for example 2026-08-26T16:35:20Z). | CVEs Modified Since 20 September 2026 |
cisa_ | Date the CVE was added to the CISA Known Exploited Vulnerabilities (KEV) catalog (YYYY-MM-DD), as given in the CVE record. enrichment.cisa_kev.date_added holds the same date and is filled for a few more CVEs. | Added to CISA KEV Since 1 September 2026 |
cisa_ | Remediation due date from the CISA KEV catalog (YYYY-MM-DD), as given in the CVE record. enrichment.cisa_kev.due_date holds the same date and is filled for a few more CVEs. | KEV Remediation Due in November 2021 |
metrics. | CVSS 2.0 base score of the assessment, from 0 to 10. | CVSS v2: Base Score of 10 |
metrics. | CVSS 2.0 temporal score, from 0 to 10: the base score adjusted by the temporal metrics. Not filled for any CVE in the current data. | |
metrics. | CVSS 2.0 environmental score, from 0 to 10: the score adjusted for a specific environment. Not filled for any CVE in the current data. | |
metrics. | CVSS 2.0 exploitability subscore, from 0 to 10: the part of the base score that comes from access vector, access complexity and authentication. | CVSS v2: Low Exploitability Score |
metrics. | CVSS 2.0 impact subscore, from 0 to 10: the part of the base score that comes from the confidentiality, integrity and availability impacts. | CVSS v2: Low Impact Score |
metrics. | CVSS 3.0 base score of the assessment, from 0 to 10. | CVSS v3.0: Base Score 9 and Up |
metrics. | CVSS 3.0 temporal score, from 0 to 10: the base score adjusted by the temporal metrics. Not filled for any CVE in the current data. | |
metrics. | CVSS 3.0 environmental score, from 0 to 10: the score adjusted for a specific environment. Not filled for any CVE in the current data. | |
metrics. | CVSS 3.0 exploitability subscore: the part of the base score that comes from attack vector, attack complexity, privileges required and user interaction (for example 3.9). | CVSS v3.0: Highest Exploitability Score |
metrics. | CVSS 3.0 impact subscore: the part of the base score that comes from the confidentiality, integrity and availability impacts (for example 5.9). | CVSS v3.0: Low Impact Score |
metrics. | CVSS 3.1 base score of the assessment, from 0 to 10. | |
metrics. | CVSS 3.1 temporal score, from 0 to 10: the base score adjusted by the temporal metrics. Not filled for any CVE in the current data. | |
metrics. | CVSS 3.1 environmental score, from 0 to 10: the score adjusted for a specific environment. Not filled for any CVE in the current data. | |
metrics. | CVSS 3.1 exploitability subscore: the part of the base score that comes from attack vector, attack complexity, privileges required and user interaction (for example 3.9). | CVSS v3.1: Hard to Exploit |
metrics. | CVSS 3.1 impact subscore: the part of the base score that comes from the confidentiality, integrity and availability impacts (for example 5.9). | CVSS v3.1: Impact Score 5.9 and Up |
metrics. | CVSS 4.0 base score of the assessment, from 0 to 10. | CVSS 4.0: Base Score 9.0 to 9.9 |
vendor_ | Date and time the vendor comment was last changed, in ISO 8601 UTC. | Vendor Comments Since 2012 |
enrichment. | Number of a CWE weakness linked to the CVE (for example 94 for CWE-94). enrichment.cwe adds CWE catalog details for each CWE listed in weaknesses. | |
enrichment. | EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage. | |
enrichment. | Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (0.95 means 95% of them have the same or a lower score). | Top 0.1% by EPSS |
enrichment. | Date of the EPSS score (YYYY-MM-DD); the platform shows it as ANALYSIS DATE. | EPSS Scores Dated 22 September 2026 or Earlier |
enrichment. | Date the CVE was added to the CISA KEV catalog (YYYY-MM-DD); empty for CVEs not in the catalog. The platform shows CISA KEV: YES when it is set. | |
enrichment. | Remediation due date in the CVE's CISA KEV entry (YYYY-MM-DD), shown as REMEDIATION DUE; the results table marks CVEs that have it as EXPLOITABLE. | KEV Remediation Due From 24 September 2026 |
enrichment. | Base score, from 0 to 10, of the CVE's main CVSS assessment: the assessment of the highest CVSS version the CVE has. The platform shows it as the CVE's score. |
Operators eq startswith wildcard contains_ contains_ exists
| Field | Description | Example |
|---|---|---|
evaluator_ | Free-text comment from the CVE's evaluator, such as a link to the matching CWE entry or a note on how the score applies to particular platforms or versions. Filled for few CVEs. | NVD Comments That Quote Oracle |
evaluator_ | Free-text note from the CVE's evaluator about the fix, often a link or a quote from an advisory. Filled for few CVEs. | CVEs With an NVD Solution Note |
evaluator_ | Free-text note from the CVE's evaluator about the impact or the affected products, often quoting an advisory. Filled for few CVEs. | NVD Impact Notes on CVSS v2 Scoring |
cisa_ | Action CISA requires for the CVE in the KEV catalog, as given in the CVE record, for example to apply updates per vendor instructions. Same text as enrichment.cisa_kev.required_action. | KEV Entries That Require Vendor Updates |
cisa_ | Name of the vulnerability in the CISA KEV catalog, as given in the CVE record. Same text as enrichment.cisa_kev.vulnerability_name. | KEV Names With Remote Code Execution |
vendor_ | Name of a vendor that commented on the CVE, for example Red Hat or Oracle. | CVEs With a Red Hat Comment |
vendor_ | Text of the vendor's statement about the CVE. | CVEs With Vendor Comment Text |
enrichment. | Name of the CWE weakness, for example Improper Access Control. | CWE Name: Deserialization of Untrusted Data |
enrichment. | Name of the vulnerability in the CVE's CISA KEV entry. | KEV Names That Mention Log4j2 |
enrichment. | CISA's short description of the vulnerability in the KEV entry. | KEV Descriptions That Mention JNDI |
enrichment. | Action CISA requires in the KEV entry, for example to apply updates per vendor instructions. | KEV Entries That Require Mitigations |
enrichment. | Notes in the CVE's CISA KEV entry, usually reference URLs separated by ;. | KEV Notes That Cite a CISA Directive |
Operators eq exists
| Field | Description | Example |
|---|---|---|
metrics. | Flag on a CVSS 2.0 assessment: true when there was not enough information to rate Access Complexity. | CVSS v2: Insufficient Information |
metrics. | Flag on a CVSS 2.0 assessment: true when a successful attack gives the attacker all privileges on the affected system. | CVSS v2: Attack Gains All Privileges |
metrics. | Flag on a CVSS 2.0 assessment: true when a successful attack gives the attacker user-level privileges on the affected system. | CVSS v2: Attack Gains User Privileges |
metrics. | Flag on a CVSS 2.0 assessment: true when a successful attack gives the attacker other privileges on the affected system. | CVSS v2: Attack Gains Other Privileges |
metrics. | Flag on a CVSS 2.0 assessment: true when exploitation needs a user to take some action. | CVSS v2: User Interaction Required |
configurations. | When true, the configuration's condition is negated. Not filled for any CVE in the current data. | |
configurations. | When true, the node matches products that do not meet its CPE matches; false in all data seen. | Configuration Nodes That Are Not Negated |
configurations. | true when the product in this CPE match is vulnerable; false when it is only part of the configuration, such as the hardware a vulnerable firmware runs on. | Configurations Listing a Platform |
enrichment. | true when the product is vulnerable; false when it is only part of an affected configuration, such as the hardware a vulnerable firmware runs on. | Affected Products That Are Platforms |
enrichment. | true when that CPE name is deprecated in the CPE dictionary. You can filter on it, but only GET /discovery/vulnerability-detail returns it; search results leave it out. | Affected CPE Names That Are Deprecated |
Operators eq in startswith wildcard exists
| Field | Description | Example |
|---|---|---|
references. | Tags that classify a reference. Values: Vendor Advisory, Third Party Advisory, Patch, Exploit, VDB Entry, Mailing List, US Government Resource, Issue Tracking, Release Notes, Broken Link, Permissions Required, Product, Mitigation, Technical Description, Not Applicable, Press/Media Coverage, Tool Signature, URL Repurposed. | |
enrichment. | All affected versions of the product. You can filter on it, but only GET /discovery/vulnerability-detail returns it; search results leave it out. | One Release Inside the Affected Range |
enrichment. | Security areas the weakness can affect, from the CWE entry. Values: Confidentiality, Integrity, Availability, Access Control, Accountability, Authentication, Authorization, Non-Repudiation, Other. | CWE Scope: Non-Repudiation |
enrichment. | Technical impacts the weakness can have, from the CWE entry, for example Execute Unauthorized Code or Commands, Read Application Data or DoS: Crash, Exit, or Restart. | CWE Impact: Hide Activities |
enrichment. | Methods that can detect the weakness, from the CWE entry, for example Automated Static Analysis, Fuzzing or Manual Analysis. | CWE Detectable by Fuzzing |
enrichment. | CVSS versions the CVE has assessments for, highest first. Values: 2.0, 3.0, 3.1, 4.0. | CVEs With a CVSS v3.0 Score |
Operators wildcard contains_ contains_ exists
| Field | Description | Example |
|---|---|---|
descriptions. | Text of one of the CVE's descriptions, in the language given by descriptions.lang. For a rejected CVE it holds the rejection reason. | |
enrichment. | The CWE catalog's description of the weakness. | CWE Descriptions That Mention a Shortcut |
Operators eq in gt gte lt lte exists
| Field | Description | Example |
|---|---|---|
enrichment. | IDs of CAPEC attack patterns related to the weakness, as numbers; the platform shows them as CAPEC-<id> under ATTACK STAGES. | CAPEC 66 or 7 (SQL Injection Patterns) |
Operators eq startswith wildcard gt lt exists
| Field | Description | Example |
|---|---|---|
id | The CVE identifier, in the form CVE-YYYY-NNNN with four to seven digits after the year (for example CVE-2021-44228). |
Sortable Fields
Example: a worked example that sorts by the field, with the request and the response it returns.
| Field | Description | Example |
|---|---|---|
id | The CVE identifier, in the form CVE-YYYY-NNNN with four to seven digits after the year (for example CVE-2021-44228). | Sort by Id: Newest Log4j CVEs First |
enrichment. | Vendor of a product the CVE applies to, as written in its CPE (lower case, for example adobe or cisco). | Sort by Vendor |
enrichment. | Product the CVE applies to, as written in its CPE (lower case with underscores, for example linux_kernel). | Sort by Product |
published | Date and time the CVE was first published, in ISO 8601 UTC (for example 2026-06-30T16:16:54Z). | |
last_ | Date and time the CVE record was last changed, in ISO 8601 UTC (for example 2026-08-26T16:35:20Z). | Sort by Last Modified: Recently Changed Analysed CVEs |
enrichment. | Base score, from 0 to 10, of the CVE's main CVSS assessment: the assessment of the highest CVSS version the CVE has. The platform shows it as the CVE's score. | Sort by Deepinfo Score: Lowest First |
enrichment. | Severity of the CVE's main CVSS assessment. Values: NONE, LOW, MEDIUM, HIGH, CRITICAL (LOW, MEDIUM, HIGH for CVSS 2.0); the platform shows it as the CVE's severity. | Sort by Deepinfo Severity |
enrichment. | EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage. | Sort by EPSS: Most Likely to Be Exploited First |
enrichment. | Date the CVE was added to the CISA KEV catalog (YYYY-MM-DD); empty for CVEs not in the catalog. The platform shows CISA KEV: YES when it is set. | Sort by KEV Date: Latest Additions First |
Response Fields
| Field | Type | Description |
|---|---|---|
page | integer | |
page_ | integer | |
result_ | integer | |
results | array of object | |
results[]. | string | |
results[]. | string | |
results[]. | string | date-time |
results[]. | string | date-time |
results[]. | string | |
results[]. | string | |
results[]. | string | |
results[]. | string | |
results[]. | string | date |
results[]. | string | date |
results[]. | string | |
results[]. | string | |
results[]. | array of object | |
results[]. | array of object | |
results[]. | object | |
results[]. | array of object | |
results[]. | array of object | |
results[]. | array of object | |
results[]. | object |
Paginated. See Getting Started → Pagination.
Response Schema
Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.
| Field | Type | Example |
|---|---|---|
page | number | 1 |
page_size | number | 25 |
result_count | number | 395222 |
results | array< | |
results[]. | string | "CVE-2026-9508" |
results[]. | string | |
results[]. | string | "2026-05-29T13:16:23Z" |
results[]. | string | "2026-07-21T12:10:00Z" |
results[]. | string | "Deferred" |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | array< | |
results[]. | string | "en" |
results[]. | string | "Incorrect permission settings on a…" |
results[]. | array< | |
results[]. | string | "https://www.incibe.es/en/incibe-cer…" |
results[]. | string | |
results[]. | null | |
results[]. | object | |
results[]. | array< | |
results[]. | string | |
results[]. | string | "Secondary" |
results[]. | object | |
results[]. | string | "4.0" |
results[]. | string | "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/V…" |
results[]. | string | "NETWORK" |
results[]. | string | "LOW" |
results[]. | string | "NONE" |
results[]. | string | "NONE" |
results[]. | string | "NONE" |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | string | "NOT_DEFINED" |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | string | "NOT_DEFINED" |
results[]. | string | "NOT_DEFINED" |
results[]. | string | "NOT_DEFINED" |
results[]. | string | "NOT_DEFINED" |
results[]. | string | "NOT_DEFINED" |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | string | "NOT_DEFINED" |
results[]. | string | "NOT_DEFINED" |
results[]. | string | "NOT_DEFINED" |
results[]. | number | 10 |
results[]. | string | "CRITICAL" |
results[]. | array< | |
results[]. | string | |
results[]. | string | "Secondary" |
results[]. | object | |
results[]. | string | "3.1" |
results[]. | string | "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:…" |
results[]. | string | "NETWORK" |
results[]. | string | "LOW" |
results[]. | string | "NONE" |
results[]. | string | "NONE" |
results[]. | string | "CHANGED" |
results[]. | string | "HIGH" |
results[]. | string | "HIGH" |
results[]. | string | "HIGH" |
results[]. | number | 10 |
results[]. | string | "CRITICAL" |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | number | 3.9 |
results[]. | number | 6 |
results[]. | null | |
results[]. | null | |
results[]. | array< | |
results[]. | string | |
results[]. | string | "Secondary" |
results[]. | array< | |
results[]. | string | "en" |
results[]. | string | "CWE-732" |
results[]. | null | |
results[]. | null | |
results[]. | object | |
results[]. | null | |
results[]. | array< | |
results[]. | number | 732 |
results[]. | null | |
results[]. | string | "Incorrect Permission Assignment for…" |
results[]. | string | "The product specifies permissions f…" |
results[]. | array< | 1 |
results[]. | array< | "Access Control" |
results[]. | array< | "Gain Privileges or Assume Identity" |
results[]. | array< | "Architecture or Design Review" |
results[]. | object | |
results[]. | number | 0.00341 |
results[]. | number | 0.27608 |
results[]. | string | "2026-09-21" |
results[]. | null | |
results[]. | object | |
results[]. | array< | "4.0" |
results[]. | string | |
results[]. | string | "Secondary" |
results[]. | object | |
results[]. | string | "4.0" |
results[]. | string | "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/V…" |
results[]. | string | "NETWORK" |
results[]. | string | "LOW" |
results[]. | string | "NONE" |
results[]. | string | "NONE" |
results[]. | string | "NONE" |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | string | "NOT_DEFINED" |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | string | "NOT_DEFINED" |
results[]. | string | "NOT_DEFINED" |
results[]. | string | "NOT_DEFINED" |
results[]. | string | "NOT_DEFINED" |
results[]. | string | "NOT_DEFINED" |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | null | |
results[]. | string | "NOT_DEFINED" |
results[]. | string | "NOT_DEFINED" |
results[]. | string | "NOT_DEFINED" |
results[]. | number | 10 |
results[]. | string | "CRITICAL" |
Examples
Saved examples from the Deepinfo API and a request template. Selecting one loads it into the request and response panels.
Worked Examples
Worked examples of this endpoint, each on its own page with the exact request and the response it returns.
- One CVE by IdThe record of one CVE, Log4Shell, by its id.
- CVSS v3.1: Base Score 9.8 and UpCVEs whose CVSS v3.1 base score is 9.8 or higher.
- EPSS 0.9 and UpCVEs whose EPSS score, the chance of exploitation in the next 30 days, is 0.9 or higher.
- KEV CVEs Used by RansomwareCVEs that CISA knows are used in ransomware campaigns.
- Exploited, Critical and Likely to Be Exploited AgainCVEs in CISA KEV with a critical Deepinfo score and an EPSS score of 0.9 or more.
- Sort by EPSS: Most Likely to Be Exploited FirstCVEs published in 2026, highest EPSS score first.