81trust / 100
Cve Lookup
by CVE lookup in Security & trust
x402 APIPassing, checked 40 min ago
Look up a CVE by id, or search CVEs by keyword or product: the NVD description, CVSS severity and vector (v4.0, v3.1, v2), CWE weaknesses, affected products and versions (CPE), and reference links, joined with the EPSS exploitation probability (next 30 days) and whether CISA lists it as a known exploited vulnerability (date added, due date, ransomware use). This product uses the NVD API but is not endorsed or certified by the NVD.
POST https://agent402.tools/api/cve-lookup
Last 30 days
All checks passedSome failedAll failedNot checked
- Uptime
- 100%
- Response time
- 197 ms typical, 197 ms slowest 5%
- Last check
- 40 min ago
- Next check
- any minute now
How to call it
# See the payment challenge (nothing is charged)
curl -i -X POST "https://agent402.tools/api/cve-lookup" \
-H "content-type: application/json" \
-d '{"cve":"CVE-2024-3094"}'import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client().register(
"eip155:8453",
new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);
// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fagent402.tools%2Fapi%2Fcve-lookup
const res = await pay("https://agent402.tools/api/cve-lookup", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify({"cve":"CVE-2024-3094"}),
});
console.log(await res.json());Example input
{
"cve": "CVE-2024-3094"
}Example output
{
"complete": true,
"fetchedAt": "2026-09-25T16:40:00.000Z",
"matched": 1,
"query": {
"cve": "CVE-2024-3094"
},
"results": [
{
"affected": {
"complete": true,
"products": [
{
"cpe": "cpe:2.3:a:tukaani:xz:5.6.0:*:*:*:*:*:*:*",
"product": "xz",
"vendor": "tukaani",
"version": "5.6.0"
}
],
"returned": 1,
"total": 1
},
"cvss": {
"v2": null,
"v31": {
"score": 10,
"severity": "CRITICAL",
"source": "[email protected]",
"type": "Primary",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
},
"v40": null
},
"cwes": [
"CWE-506"
],
"description": "Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0...",
"epss": {
"available": true,
"date": "2026-09-25",
"percentile": 0.99723,
"probability": 0.85974
},
"id": "CVE-2024-3094",
"kev": {
"available": true,
"catalogVersion": "2026.09.25",
"inCatalog": false
},
"lastModified": "2025-11-04T22:16:02.230",
"nvdUrl": "https://nvd.nist.gov/vuln/detail/CVE-2024-3094",
"published": "2024-03-29T17:15:21.150",
"references": {
"links": [
{
"tags": [
"Vendor Advisory"
],
"url": "https://access.redhat.com/security/cve/CVE-2024-3094"
}
],
"returned": 1,
"total": 1
},
"severity": "CRITICAL",
"status": "Modified"
}
],
"returned": 1,
"sources": {
"epss": {
"name": "EPSS, Exploit Prediction Scoring System (FIRST.org; scores by Empirical Security)"
},
"kev": {
"name": "CISA Known Exploited Vulnerabilities catalog (CC0)"
},
"nvd": {
"name": "NVD (NIST National Vulnerability Database)",
"notice": "This product uses the NVD API but is not endorsed or certified by the NVD."
}
},
"truncated": false
}Security scan
- No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.
Recent checks
| When | Result | HTTP | Time | Price |
|---|---|---|---|---|
| 40 min ago | Passed | 402 | 547 ms | $0.005 |
| 6 h ago | Passed | 402 | 197 ms | $0.005 |