NVD CVE Vulnerability Feed avatar

NVD CVE Vulnerability Feed

Pricing

$1.50 / 1,000 cve records

Go to Apify Store
NVD CVE Vulnerability Feed

NVD CVE Vulnerability Feed

NVD CVE vulnerability feed for security-data research. Export vulnerability records as JSON with available scores, affected products, references and known-exploited-vulnerability fields.

Pricing

$1.50 / 1,000 cve records

Rating

0.0

(0)

Developer

Grit

Grit

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

3 days ago

Last modified

Share

NVD CVE scraper returns vulnerability records with available scores, affected products, references, and KEV fields.

NVD CVE scraper uses the public source named below and writes its results to the Actor dataset.

This actor uses the NVD CVE API 2.0. CVE means Common Vulnerabilities and Exposures; CVSS is the Common Vulnerability Scoring System; CPE identifies a product and version; KEV is CISA's Known Exploited Vulnerabilities catalog.

What it returns

Fields vary by result type and optional enrichment. The examples below are from sample_output.json.

Output fieldTypeExample value or excerpt from saved sample
cveIdstring"CVE-2021-44228"
sourceIdentifierstring"security@apache.org"
vulnStatusstring"Analyzed"
publishedstring"2021-12-10T10:15:09.143Z"
lastModifiedstring"2026-08-11T19:33:44.513Z"
descriptionstring"Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI…
descriptionsarray[{"lang": "en"}]
cvssV3object{"version": "3.1"}
cvssV3Scorenumber10.0
cvssV3Severitystring"CRITICAL"
cvssV3Vectorstring"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
cvssV4nullnull
cvssV4Scorenullnull
cvssV4Severitynullnull
cvssV4Vectornullnull
cvssMetricsarray[{"version": "3.1"}]
kevbooleantrue
kevDateAddedstring"2021-12-10"
kevDueDatestring"2021-12-24"
kevRequiredActionstring"For all affected software assets for which updates exist, the only acceptable remediation actions a…
kevVulnerabilityNamestring"Apache Log4j2 Remote Code Execution Vulnerability"
cwesarray["CWE-20"]
affectedProductsarray[{"vulnerable": true}]
configurationsarray[{"operator": "AND"}]
referencesarray[{"source": "security@apache.org"}]
nvdUrlstring"https://nvd.nist.gov/vuln/detail/CVE-2021-44228"
retrievedAtstring"2026-10-05T11:42:41.434Z"
errorsarray[]

One row per distinct returned CVE. A malformed record or exhausted request produces an error row with an errors array, without a custom result charge.

FieldsMeaning
cveId, nvdUrlCVE identifier and official detail page
description, descriptionsEnglish description when available, plus original language entries
published, lastModified, retrievedAtUTC ISO-8601 timestamps; retrieval time records this run's freshness
sourceIdentifier, vulnStatusPublishing source and NVD record status
cvssV3Score, cvssV3Severity, cvssV3VectorSelected v3 base score, severity and vector; null when absent
cvssV4Score, cvssV4Severity, cvssV4VectorSelected v4 base score, severity and vector; null when absent
cvssV3, cvssV4Detailed assessment with version, source, type, attack vector, privileges, interaction and version-specific impact fields
cvssMetricsAvailable v3/v4 assessments from all returned sources, including alternative scores
kev, kevDateAdded, kevDueDateKEV status as reflected by NVD, date added and CISA action deadline
kevRequiredAction, kevVulnerabilityNameCISA action and vulnerability name supplied by NVD
cwesReturned weakness classifications, including any NVD placeholders
affectedProductsCPE match criteria, vulnerable flags, match IDs and version bounds
configurationsOriginal applicability logic, including AND/OR and negation context
referencesPublished reference URLs, sources and tags; linked pages are not fetched
errorsEmpty for a normal record; safe error messages for failed records/requests

For v3, the actor prefers v3.1 over v3.0. Within each version it prefers a Primary assessment, then NVD among assessments of equal type, then original source order. It retains alternative assessments in cvssMetrics; it does not compute scores or replace missing scores with zero.

Input

{
"keyword": "log4j",
"cvssSeverity": "CRITICAL",
"cvssVersion": "3",
"publishedAfter": "2021-12-01T00:00:00Z",
"publishedBefore": "2021-12-31T23:59:59Z",
"hasKev": true,
"maxItems": 2
}
InputDefaultBehavior
keywordomittedNVD description keyword search
cpeNameomittedFull CPE 2.3 name with concrete part, vendor, product and version
cvssSeverityomittedLOW, MEDIUM, HIGH or CRITICAL
cvssVersion"3"Apply the severity filter to v3.x or v4.0 ("4"); both versions remain in output
publishedAfter, publishedBeforeomittedInclusive published-time window; both endpoints required
modifiedAfter, modifiedBeforeomittedInclusive last-modified window; both endpoints required
hasKevfalsetrue includes only NVD records carrying KEV data; false adds no KEV restriction
apiKeyomittedOptional secret user NVD key, sent in the apiKey request header
maxItems100Output row cap, including error rows; range 1–100,000
pageSize2000NVD request page size, reduced to the remaining cap; range 1–2,000
concurrency1Fixed at one request in flight

If no effective filter is provided, the actor searches the previous seven days by published time. Date inputs must include time and timezone, such as 2026-10-01T00:00:00Z; each window may span at most 120 days. To search a product version, use a CPE such as cpe:2.3:a:apache:log4j:2.14.1:*:*:*:*:*:*:*. Wildcard vendor, product or version values are rejected.

Filters combine according to NVD's API behavior. Severity filtering can match an assessment from any source; the selected primary assessment in the row can have a different severity. Inspect cvssMetrics for the alternatives.

Real output example

Selected fields from sample_output.json, obtained by running the input above:

{
"cveId": "CVE-2021-44228",
"published": "2021-12-10T10:15:09.143Z",
"cvssV3Score": 10.0,
"cvssV3Severity": "CRITICAL",
"cvssV4Score": null,
"kev": true,
"kevDateAdded": "2021-12-10",
"nvdUrl": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
"errors": []
}

The default dataset offers overview, scoring, product and KEV views. Export JSON for nested fields or select flat fields for CSV. RUN_SUMMARY in the default key-value store records saved rows, CVE count, error rows, API requests, duration and whether the run stopped for its charge limit.

Pricing

Proposed custom price: $0.0015 per successful CVE, or $1.50 per 1,000 CVEs. Errors and duplicate IDs do not trigger cve. Platform startup charges are separate and must be confirmed before publishing.

The proposal is 50% below the observed $0.003 CVE result event of ryanclinton/nvd-cve-vulnerability-search, the most used comparable NVD actor by total users in the Store API queries on 2026-10-05. See PRICING.md for the query receipts, comparison scope and Console setup.

Limits and reliability

Requests start at least 6.1 seconds apart, including retries, with one in flight. This conservative pacing follows NVD's rate-limit guidance with or without a key. Transient HTTP failures and transport/JSON errors receive at most four attempts with exponential backoff and Retry-After handling. A server wait longer than 300 seconds becomes a clear error row instead of an early retry. Permanent HTTP errors are reported without repeated requests.

NVD pages are ordered by publication time, so a capped recent-week query returns the earliest matching records in that week. There is no automatic splitting of windows longer than 120 days or persisted pagination checkpoint. NVD updates during pagination can affect completeness; IDs are deduplicated within the run. Error rows consume the row cap. Increase maxItems or narrow the search when a query exceeds the cap.

NVD records can lack scoring, product details or KEV data. A false KEV flag means NVD did not supply KEV membership in that response; it does not establish that a vulnerability has never been exploited. Product applicability logic is retained because a flattened CPE list alone does not establish that a deployed system is vulnerable.

FAQ

What limits a search? maxItems caps distinct CVE and error rows. Date-window filters must stay within the schema’s allowed span.

Do I need a proxy, login, or API key? No key is required; an optional personal NVD key can be supplied. The actor does not configure a proxy.

How is it priced? The proposed pay-per-event model charges cve for each distinct successfully saved CVE. Errors, duplicates, and empty searches have no custom event charge.

How are NVD rate limits handled? The client sends requests sequentially with a minimum interval and retries temporary failures. A long Retry-After beyond its budget stops the request.

How fresh is vulnerability data? published and lastModified are NVD source timestamps; retrievedAt records this fetch. Re-run a modified-date search to see later source changes.

Why is a CVSS score absent? NVD may omit that version or publish several assessments. Inspect cvssMetrics and the source record.

Use with AI agents / MCP

After the owner publishes it, call this actor through Apify's API or the Apify MCP server. Use small maxItems values for an agent request, keep the NVD links as evidence, and check errors before using a record. Prefer cvssV3Score/cvssV4Score for sorting and retain metric sources and applicability logic for interpretation. No model calls are made by the actor.

Local development

Runtime dependencies are apify and httpx; tests use the existing pytest. No additional package installation was required.

From this directory, run unit tests and the separately marked live smoke test:

C:/GritWork/earn/.venv/Scripts/python.exe -m pytest tests --ignore=tests/test_live.py -q -p no:cacheprovider
C:/GritWork/earn/.venv/Scripts/python.exe -m pytest tests/test_live.py -m live -q -p no:cacheprovider

The helper below writes storage/key_value_stores/default/INPUT.json, sets APIFY_LOCAL_STORAGE_DIR, and launches the same Python as python -m src, without the Apify CLI. Use a fresh storage path each time:

C:/GritWork/earn/.venv/Scripts/python.exe tools/local_run.py --input examples/log4j_kev.json --storage storage/new-run --output sample_output.json

Local pay-per-event charges are simulated by the SDK; the SDK's fallback test prices are not the proposed Store prices. The real sample contains two CVEs. Test and run receipts are in evidence/ and the ignored local storage/ directories. The Docker image and Apify cloud build have not been exercised in this delivery.