Vulnerability Search Examples · Example 12 of 18 in Filters › CVSS v4.0

CVEs whose CVSS 4.0 threat metric says attacks have been reported.

Operator
eq

metrics.cvss_metric_v40.cvss_data.exploit_maturity is the threat metric: how far exploitation has gone (ATTACKED means attacks have been reported, NOT_DEFINED that the scorer left it unset), in the CVSS 4.0 metric (metrics.cvss_metric_v40, one entry per scoring source).

eq matches the exact value ATTACKED.

In the response, look at results[].metrics.cvss_metric_v40[].cvss_data.exploit_maturity.

Request

What this example sends. Every parameter is documented on Search; the exact request is in the code panel.

ParameterValue
page_sizequery25
filters.must[0].namebodymetrics.cvss_metric_v40.cvss_data.exploit_maturity
filters.must[0].typebodyeq
filters.must[0].valuebodyATTACKED

Reference updated