CVE Vulnerability Scraper
Pricing
from $1.50 / 1,000 results
CVE Vulnerability Scraper
Search and extract CVE vulnerability data from NIST NVD. Get CVSS scores, affected products, and references. No API key required.
Pricing
from $1.50 / 1,000 results
Rating
0.0
(0)
Developer
cloud9
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
0
Monthly active users
18 days ago
Last modified
Categories
Share
Search and extract CVE vulnerability data from NIST NVD. Get CVSS scores, affected products, and references. No API key required.
Use cases
- Feed a vulnerability dashboard with CVSS-scored CVEs
- Alert on new HIGH/CRITICAL CVEs affecting your stack
- Build a compliance evidence trail for audits
- Enrich asset inventories with known vulnerabilities
- Research vulnerability trends over a date range
Input
A NIST NVD API key is optional. The Actor works without one; adding a key from https://nvd.nist.gov/developers/request-an-api-key raises the rate limit the source applies.
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
mode | string | Yes | "search" | Search mode: 'search' for keyword search, 'recent' for recently published CVEs Allowed: search, recent. |
keyword | string | No | "apache" | Search keyword for CVEs (e.g., 'apache log4j', 'openssl'). Used in 'search' mode. |
severity | string | No | "HIGH" | Filter by CVSS v3 severity level Allowed: LOW, MEDIUM, HIGH, CRITICAL. |
pubStartDate | string | No | — | Filter CVEs published on or after this date (YYYY-MM-DD format) |
pubEndDate | string | No | — | Filter CVEs published on or before this date (YYYY-MM-DD format) |
maxResults | integer | No | 20 | Maximum number of CVEs to retrieve (default: 20, max: 200) |
apiKey | string | No | — | Optional NVD API key to increase rate limit (without key: 1 req/6s, with key: 1 req/0.6s). Get free key at https://nvd.nist.gov/developers/request-an-api-key |
Example input
{"mode": "search","keyword": "apache","severity": "HIGH","maxResults": 20}
Output
The exact fields depend on the mode you run. This is real output from an actual run of this Actor:
{"cveId": "CVE-1999-0236","description": "ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.","publishedDate": "1997-01-01T05:00:00.000","lastModifiedDate": "2026-06-16T21:47:58.393","cvssV3Score": 7.5,"cvssV3Severity": "HIGH","cvssV3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","affectedProducts": ["cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*","cpe:2.3:a:illinois:ncsa_httpd:-:*:*:*:*:*:*:*"],"references": ["https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0236","https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0236"],"nistUrl": "https://nvd.nist.gov/vuln/detail/CVE-1999-0236"}
| Field | Type |
|---|---|
cveId | string |
description | string |
publishedDate | string |
lastModifiedDate | string |
cvssV3Score | number |
cvssV3Severity | string |
cvssV3Vector | string |
affectedProducts | array |
references | array |
nistUrl | string |
Results are exportable from Apify Console or the API as JSON, CSV, Excel, or XML.
How to run it
In Apify Console — open the Actor, fill in the input form, click Start, then download the results from the Dataset tab.
With the JavaScript client
import { ApifyClient } from 'apify-client';const client = new ApifyClient({ token: 'YOUR_APIFY_TOKEN' });const run = await client.actor('cloud9_ai/cve-scraper').call({"mode": "search","keyword": "apache","severity": "HIGH","maxResults": 20});const { items } = await client.dataset(run.defaultDatasetId).listItems();console.log(items);
With the Python client
from apify_client import ApifyClientclient = ApifyClient('YOUR_APIFY_TOKEN')run = client.actor('cloud9_ai/cve-scraper').call(run_input={"mode": "search","keyword": "apache","severity": "HIGH","maxResults": 20})for item in client.dataset(run['defaultDatasetId']).iterate_items():print(item)
With the API — POST https://api.apify.com/v2/acts/cloud9_ai~cve-scraper/run-sync-get-dataset-items?token=YOUR_APIFY_TOKEN with the input JSON as the body.
Notes and limits
- A NIST NVD key is optional (https://nvd.nist.gov/developers/request-an-api-key); supplying one raises the source's rate limit. It is a secret input, so it is not written to the dataset or the log.
maxResultscaps how much a single run collects, which is also what caps the run's cost.- Requests are paced and failed requests are retried automatically, so runs stay inside the source's rate limits.
- Only publicly available data is collected. How you use the output is your responsibility, including the source's terms of use and any applicable data-protection law.
Support
Found a bug, or need a field that isn't in the output? Open an issue on the Issues tab of this Actor in Apify Console. Issues there are read and answered.
License
Apache-2.0