Tenable Exports (Vulnerabilities) API is one of 107 APIs that Tenable publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
Tagged areas include Exports (Vulnerabilities). The published artifact set on APIs.io includes an OpenAPI specification.
This API exposes
5 operations
across 5 paths,
and defines 21 schemas.
It is described by OpenAPI 3.2.0, at version 1.0.0.
Requests are made against a single base URL, https://www.tenable.com/downloads/api/v2.
5 operations5 paths21 schemas3 GET2 POST
Metadata
The identity and technical contract details declared by the specification.
Specification
OpenAPI 3.2.0
API Version
1.0.0
Base URL
https://cloud.tenable.com
Authentication
API Key
Resource Areas
1
Authentication & Security 1
Tenable Exports (Vulnerabilities) API declares
1 security scheme
for authenticating requests.
An API key is passed in the header as Authorization (Bearer).
By default, every request must be authenticated.
Bearer — Example: Bearer {{token}}
Paths & Operations 5
Across 5 paths, the API surfaces 5 operations — 3 GET, 2 POST. Each is listed below with its method, path, parameters, and response codes.
The contract defines 21 schemas that model the data the API accepts and returns. The most detailed are Export_Vulnerabilities_plugin (60 properties), Export_Vulnerabilities_response-vulns-chunk (21 properties), Export_Vulnerabilities_response-vulns-export-chunk-asset (17 properties), Export_Vulnerabilities_response-vulns-export-status (13 properties). Each schema is shown below with its type and property counts.
Export_Vulnerabilities_ErrorResponse
object
3 properties
Export_Vulnerabilities_software-vuln-item
object
Software package attribution data for a vulnerability finding.
12 properties
Export_Vulnerabilities_software-vuln-fix
object
Fix information for a vulnerable software package.
2 properties
Export_Vulnerabilities_cvss_vector
object
Additional CVSSv2 metrics for the vulnerability.
7 properties
Export_Vulnerabilities_port
object
Information about the port the scanner used to connect to the asset.
Information about the asset where the scan detected the vulnerability.
17 properties
Export_Vulnerabilities_epss_filter
object
Filters vulnerabilities by their Exploit Prediction Scoring System (EPSS) score, expressed as a percentage from 0 to 100. You can combine properties to define…
6 properties
Export_Vulnerabilities_cvss3_vector
object
Additional CVSSv3 metrics for the vulnerability.
7 properties
Export_Vulnerabilities_time_taken_to_fix_filter
object
Returns vulnerabilities based on how long (in seconds) that it took your organization to fix. Your export results will only include vulnerabilities in the fixe…
2 properties
Export_Vulnerabilities_cvss_temporal_vector
object
CVSSv2 temporal metrics for the vulnerability.
4 properties
Export_Vulnerabilities_vpr_filter
object
Filters vulnerabilities based on their Vulnerability Priority Rating (VPR) version 1 score. You can define score ranges using properties such as gte (greater t…
6 properties
Export_Vulnerabilities_cvss4_vector
object
An object representing the full set of CVSS v4.0 base metrics for the vulnerability. These metrics define the intrinsic characteristics of the vulnerability, i…
12 properties
Export_Vulnerabilities_response-vulns-export-jobs
object
10 properties
Export_Vulnerabilities_cvss4_threat_vector
object
An object representing the CVSS v4.0 Threat metrics for the vulnerability. These metrics provide context on current, observed threat activity in the wild, such…
Information about the specified vulnerabilities export job.
13 properties
Export_Vulnerabilities_cvss4_filter
object
Filters vulnerabilities based on their CVSS version 4 (CVSSv4) base score. You can specify score ranges using the provided comparison properties. For example,…
6 properties
Export_Vulnerabilities_scan-information
object
Information about the latest scan that detected the vulnerability.
4 properties
Export_Vulnerabilities_vpr_v2_filter
object
Filters vulnerabilities based on their Vulnerability Priority Rating (VPR) version 2 score. This enhanced version is labeled VPR (Beta) in the user interface.…
6 properties
Export_Vulnerabilities_plugin
object
Information about the plugin that detected the vulnerability.
60 properties
Export_Vulnerabilities_cvss3_temporal_vector
object
CVSSv3 temporal metrics for the vulnerability.
4 properties
Specification
The full machine-readable OpenAPI contract behind this narrative.
Every API here is available over the API and to AI agents over MCP. APIs is not yet its own endpoint on the v1 API. Reach this content through network search and the tag graph, or the MCP server below.
Installs https://mcp.apievangelist.com/mcp in Claude, Cursor, VS Code and the rest — one button, every client.
MCP tools for apis
4 tools reach this content
search_api_evangelistSearch every content type across the network at once.
find_relatedThe shared-tag relevance graph — what else covers this.
get_tagEverything one tag labels, across all content types.
guide_topicPRO — a curated bundle for a topic: area, guidance, rules, papers, stories, services.
A second provider on the same verified email joins the account you already have.
Your account
ⓘWhere this information came from
This is an independent, third-party profile of Tenable Exports (Vulnerabilities) API, published by
API Evangelist. We do not operate, host, resell, or
support these APIs, and we are not affiliated with or endorsed by the company unless stated above.
Everything here is built from publicly available information — the company's own site,
developer portal, documentation, public repositories, and the specifications it publishes for public use.
Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's
public API artifacts, scored against a published rubric. They are not certifications,
endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and
you do not need to justify the request. A removed company is recorded as unrated, never scored
zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy → On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.