Open Source Vulnerability Scraper (OSV.dev) avatar

Open Source Vulnerability Scraper (OSV.dev)

Pricing

$1.00 / 1,000 records

Go to Apify Store
Open Source Vulnerability Scraper (OSV.dev)

Open Source Vulnerability Scraper (OSV.dev)

Look up open-source security vulnerabilities from OSV.dev for any package across npm, PyPI, Go, Maven, crates and more. Returns CVE IDs, severity, summary and references. No API key. Pay per vulnerability; empty runs free.

Pricing

$1.00 / 1,000 records

Rating

0.0

(0)

Developer

Christian Pichichero

Christian Pichichero

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

7 days ago

Last modified

Categories

Share

Open Source Vulnerability Scraper (OSV.dev) — a fast, reliable vulnerability scraper that needs no API key. You pay only for the results you get: failed or empty runs are always free.

This vulnerability scraper runs on the Apify platform, so you can call it from the API, run it on a schedule, or export results to JSON, CSV, Excel, or Google Sheets.

What this scraper does

  • Extracts structured vulnerability data with no browser or API key required
  • Returns clean JSON, one record per result — ready for sheets, databases, or apps
  • Pay-per-result pricing: you are never charged for a run that returns nothing
  • Runs on demand or on a schedule, and integrates with 5,000+ apps via the Apify API and webhooks

What data you get

Each result record includes fields such as:

  • Id (id) — e.g. "GHSA-29mw-wpgm-hmr9"
  • Summary (summary) — e.g. "Regular Expression Denial of Service (ReDoS) in lodash"
  • Details (details) — e.g. "All versions of package lodash prior to 4.17.21 are vuln...
  • Aliases (aliases) — e.g. ["CVE-2020-28500"]
  • Cve Ids (cveIds) — e.g. ["CVE-2020-28500"]
  • Package Name (packageName) — e.g. "lodash"
  • Ecosystem (ecosystem) — e.g. "npm"
  • Severity (severity) — e.g. "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
  • Severity Rating (severityRating) — e.g. "MODERATE"
  • Cvss Vector (cvssVector) — e.g. "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
  • Cwe Ids (cweIds) — e.g. ["CWE-1333", "CWE-400"]
  • Published (published) — e.g. "2022-01-06T20:30:46Z"
  • Modified (modified) — e.g. "2025-09-29T21:12:31.102523Z"
  • Affected Packages (affectedPackages) — e.g. ["lodash", "lodash-es", "lodash.trimend", "lodash.trim", ...
  • References (references) — e.g. ["https://nvd.nist.gov/vuln/detail/CVE-2020-28500", "http...

Input

FieldTypeDescription
packagesarrayPackage names to look up vulnerabilities for (one query per name), e.g. lodash, express. Names must match t...
ecosystemstringPackage ecosystem the names belong to. Applied to every package in this run.
versionstringOptional exact package version. When set, results are narrowed to vulnerabilities affecting that specific v...
maxResultsintegerMaximum number of vulnerability records to return per package.

Example output

{
"type": "vulnerability",
"id": "GHSA-29mw-wpgm-hmr9",
"summary": "Regular Expression Denial of Service (ReDoS) in lodash",
"details": "All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.",
"aliases": [
"CVE-2020-28500"
],
"cveIds": [
"CVE-2020-28500"
],
"packageName": "lodash",
"ecosystem": "npm",
"severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"severityRating": "MODERATE",
"cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"cweIds": [
"CWE-1333",
"CWE-400"
],
"published": "2022-01-06T20:30:46Z",
"modified": "2025-09-29T21:12:31.102523Z",
"affectedPackages": [
"lodash",
"lodash-es",
"lodash.trimend",
"lodash.trim",
"lodash-rails"
],
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2020-28500",
"https://github.com/lodash/lodash"
],
"url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9",
"query": "lodash (npm)",
"scrapedAt": "2026-07-11T00:00:00Z"
}

Use cases

  • Monitor packages, repos, and dependencies
  • Automate security and license audits
  • Build developer dashboards and alerts
  • Enrich internal tools and integrations

Run it as a monitor (alerts on new vulnerability)

Schedule this vulnerability scraper to run automatically — hourly, daily, or on any cron schedule — with the built-in Apify Scheduler, and have results pushed to you by webhook, email, Slack, or your own app the moment they're ready. It's the easiest way to monitor vulnerability for changes over time and get alerted the instant something new appears — no manual runs. Because pricing is per result, a scheduled monitor only ever charges you for the data each run actually returns.

Pricing

This actor uses pay-per-result pricing at $0.0006 per record. There is no monthly fee and no start fee — and empty or failed runs cost $0, so you only ever pay for data you actually receive.

Frequently asked questions

Do I need an API key or account for the source? No. This vulnerability scraper works out of the box with no API key required.

What happens if a run returns no results? You are not charged. Billing is per result, so empty or failed runs are free.

Can I run the vulnerability scraper on a schedule? Yes. Use the Apify Scheduler to run it hourly, daily, or on any cron schedule, and get results by webhook or API.

What export formats are supported? Results can be exported as JSON, CSV, Excel, HTML, or pushed to Google Sheets, a database, or your own app via the Apify API.

Is the data structured? Yes. Every vulnerability result is a clean, flat JSON record you can use immediately.