Cve Intelligence
by cve-security.com in Security & trust
CVE intelligence: exploitation (KEV/EPSS), detection coverage, fixed versions, CPE configurations.
https://cve-security.com/api/mcp
Last 30 days
- Uptime
- 100%
- Response time
- 171 ms typical, 171 ms slowest 5%
- Last check
- 2 h ago
- Next check
- in 4 h
How to call it
Add it to any MCP client that supports remote servers.
{
"mcpServers": {
"cve-intelligence": {
"type": "http",
"url": "https://cve-security.com/api/mcp"
}
}
}9 tools
- get_cve
Full intelligence record for one CVE: per-scorer CVSS, EPSS, CISA KEV/ransomware/SSVC, four remote-detection modalities (the checks that work over the network) plus a host-check tier (self-contained Nuclei templates and Metasploit local modules that run on the system itself) and
- search_cves
Search the catalog. Free text (q) and/or structured filters: vendor (slug), cwe (CWE-nnn), technique (ATT&CK id, such as T1190), year ("2024,2025"), sev ("critical,high"), kev (0|1), kev_from / kev_to (ISO days, half-open CISA listing window; imply kev=1), kev_vendor (the CISA ve
- query_package
CVEs affecting one open-source package, by purl (pkg:npm/lodash) or ecosystem + name (Maven names are group:artifact). Returns the CVE list KEV-first with each OSV version range VERBATIM: `events` plus one render-safe projection: `fixed` (the upgrade targets) or `affected_through
- get_updates
The publication change stream: what this site published, stamped with OUR publish time (first_published, kev_added, detection_added, remediation_added, first_sighted, chain_added, and the BOD 26-04 Table 1 input changes ssvc_changed, kev_due_changed, kev_triage_flag_changed, kev_
- get_scoreboard
The Defender Scoreboard report (CC BY 4.0): exploited vs detectable vs patchable, every figure with its method, caveat and denominator, plus the corpus block and any method-change notes. Cite as "CVE Security Defender Scoreboard, cve-security.com/scoreboard".
- get_sightings
Field sightings: CVEs a named sensor network recorded in the last 7 or 30 days, most sighting days first. A field sighting is a day on which Shadowserver honeypots (cited by VulnCheck KEV and published as daily lists by CIRCL Vulnerability-Lookup) or VulnCheck canary sensors reco
- get_chains
Known Chained Vulnerabilities™: pairs of CVEs that a cited source reports were used together in one exploit chain (VulnCheck KEV entry text, Metasploit modules, SigmaHQ rules, press, research or academic sentences, community text judged by a local model). Each row carries both CV
- get_epss_movers
CVEs whose EPSS exploitation probability rose the most recently. window is "7d" (default) or "30d". Each rise is measured between same-EPSS-model-version scores, so a model release (which shifts the whole distribution) never appears as a mover. A rise raises the priority of a CVE
- table1_read
BOD 26-04 Table 1 read for up to 50 CVEs at a stated asset exposure. Per CVE this dataset supplies CISA KEV status and due date, CISA's SSVC Automatable and Technical impact (Vulnrichment) and CISA's forensic triage flag on the KEV entry; you supply exposure for the asset (yes, n
Security scan
- No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.
Recent checks
| When | Result | HTTP | Time |
|---|---|---|---|
| 2 h ago | Passed | 200 | 171 ms |