Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

NVD CVE API

Common Vulnerabilities and Exposures records

NVD CVE API is one of 6 APIs that NVD publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 1 JSON Schema definition.

Tagged areas include CVE. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, a getting-started guide, authentication docs, rate-limit docs, and 1 JSON Schema.

This API exposes 1 operation across 1 path, and defines 6 schemas. It is described by OpenAPI 3.1.0, at version 2.0.0.

Requests are made against a single base URL, https://services.nvd.nist.gov/rest/json.

1 operations 1 paths 6 schemas 1 GET

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.1.0
API Version
2.0.0
Server
https://services.nvd.nist.gov/rest/json
Authentication
API Key
Resource Areas
1

Authentication & Security 1

NVD CVE API declares 1 security scheme for authenticating requests. An API key is passed in the header as apiKey (APIKey). By default, every request must be authenticated, though some operations may also be called without credentials.

  • APIKey — NVD API key (optional but recommended). Without a key: 5 requests/30s. With a key: 50 requests/30s. Request at https://nvd.nist.gov/developers/request-an-api-k…

Paths & Operations 1

Across 1 path, the API surfaces 1 operation — 1 GET. Each is listed below with its method, path, parameters, and response codes.

CVE 1

Common Vulnerabilities and Exposures records

GET
/cves/2.0
Get CVE records
getCVEs 22 params → 200400403429

Schemas 6

The contract defines 6 schemas that model the data the API accepts and returns. The most detailed are CVE (14 properties), CVEResponse (7 properties), CVSSMetricV3 (5 properties), CVSSMetricV2 (4 properties). Each schema is shown below with its type and property counts.

CVE
object
A CVE vulnerability record
14 properties
CVEResponse
object
7 properties
ErrorResponse
object
1 property
CVSSMetricV3
object
5 properties
CVEConfiguration
object
1 property
CVSSMetricV2
object
4 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

nvd-cve-api-openapi.yml Raw ↑

Other APIs NVD publishes across the network.

National Vulnerability Database API
NVD CPE API
NVD CPE Match API
NVD CVE Change History API
NVD Sources API