# NVD CVE Vulnerability Search & Monitor API (`koalastuff/nvd-cve-vulnerability-monitor`) Actor

Search NIST NVD CVE records by product, date, CVSS severity, CWE, CVE ID, or CISA KEV status. Export normalized vulnerability data for security workflows.

- **URL**: https://apify.com/koalastuff/nvd-cve-vulnerability-monitor.md
- **Developed by:** [Timo Schmidt](https://apify.com/koalastuff) (community)
- **Categories:** Developer tools, Automation
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $1.00 / 1,000 normalized cves

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-event

## What's an Apify Actor?

Actors are a software tools running on the Apify platform, for all kinds of web data extraction and automation use cases.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

In JavaScript/TypeScript projects, use official [JavaScript/TypeScript client](https://docs.apify.com/api/client/js/docs.md):

```bash
npm install apify-client
```

In Python projects, use official [Python client library](https://docs.apify.com/api/client/python/docs.md):

```bash
pip install apify-client
```

In shell scripts, use [Apify CLI](https://docs.apify.com/cli/docs.md):

````bash
# MacOS / Linux
curl -fsSL https://apify.com/install-cli.sh | bash
# Windows
irm https://apify.com/install-cli.ps1 | iex
```bash

In AI frameworks, you might use the [Apify MCP server](https://docs.apify.com/integrations/mcp.md).

If your project is in a different language, use the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).


# README

## NVD CVE Vulnerability Monitor & Normalizer

Search NIST NVD CVE records by product, date, CVSS severity, CWE, CVE ID, or CISA KEV status. Export normalized vulnerability data for security workflows.

This product uses data from the NVD API but is not endorsed or certified by the NVD.

### Try this first

Start with the example input below to find recently modified critical CVEs in CISA KEV. Results include CVSS, CWE, affected CPEs, references, and canonical NVD links.

[![NVD CVE Vulnerability Monitor icon](https://api.apify.com/v2/key-value-stores/JoHkELuyqjk6waZJX/records/icon-nvd-cve-vulnerability-monitor.png)](https://apify.com/koalastuff/nvd-cve-vulnerability-monitor)

#### Example output

[![Example output preview](https://api.apify.com/v2/key-value-stores/JoHkELuyqjk6waZJX/records/preview-nvd-cve-vulnerability-monitor.svg)](https://apify.com/koalastuff/nvd-cve-vulnerability-monitor)

This preview is generated from a checked-in official-source fixture. It shows the normalized output shape without inventing live demand or results.

### Use cases

- Monitor newly published or recently modified CVEs.
- Track CISA Known Exploited Vulnerabilities from the NVD record.
- Filter by keyword, CVSS v3/v4 severity, CWE, or exact CVE IDs.
- Feed security dashboards, ticketing, asset-risk, and vulnerability-management workflows.

### Input

| Field | Description | Default |
| --- | --- | --- |
| `cveIds` | Up to 100 exact CVE IDs; omits the date window | none |
| `keywordSearch` | Official NVD description search | none |
| `dateMode` | `PUBLISHED` or `LAST_MODIFIED` | `LAST_MODIFIED` |
| `daysBack` | Rolling UTC window from 1 to 120 days | `7` |
| `cvssVersion` | Version for the severity filter: `ANY`, `V3`, or `V4` | `ANY` |
| `severity` | `LOW`, `MEDIUM`, `HIGH`, or `CRITICAL` | none |
| `cweId` | Exact CWE identifier | none |
| `hasKev` | Only CVEs in the CISA KEV catalog | `false` |
| `maxResults` | Hard unique-output and billing limit | `100` |
| `requestDelayMs` | Delay between anonymous NVD API pages | `6000` |

```json
{
  "dateMode": "LAST_MODIFIED",
  "daysBack": 7,
  "cvssVersion": "V3",
  "severity": "CRITICAL",
  "hasKev": true,
  "maxResults": 100
}
````

### Output

Every row includes the CVE ID, English description, publication and modification timestamps, status, best available CVSS v4/v3/v2 metric, CWE identifiers, affected CPEs, references, CISA KEV fields when present, and canonical NVD links.

### Reliability and limits

- Official public JSON API only; no page scraping, browser, proxy, API key, account, or paid service.
- Anonymous NVD access permits 5 requests in a rolling 30-second window. This Actor enforces at least 6 seconds between pages and fetches sequentially.
- Date ranges are bounded to the official maximum of 120 days.
- Up to 2,000 CVEs per API page and five pages per run.
- Duplicate removal uses the stable CVE ID; maximum 10,000 unique outputs.
- Optional NVD enrichment fields remain `null` or empty arrays when the source has not published them.
- NVD does not test referenced software and provides the data as-is. Verify vendor advisories before remediation decisions.

### Pricing

Pay per event:

- Actor start: USD 0.00005
- Normalized CVE: USD 0.001

No proxy, browser, paid API, or external subscription is required. The user's configured maximum charge per run remains the hard billing limit.

A two-result Apify smoke run on 256 MB used USD 0.0007587613 of platform resources and completed in 50.767 seconds.

### Data source and reuse

Source: <https://services.nvd.nist.gov/rest/json/cves/2.0>.

NIST states that its publications are available in the public domain and asks applications using the NVD to display this notice prominently: “This product uses data from the NVD API but is not endorsed or certified by the NVD.” The Actor includes the notice in its Store documentation and every dataset row.

### Support

Report reproducible problems with the input, run link, expected field, and affected CVE ID. Do not include private asset inventories, credentials, or unpublished vulnerability details.

### Related Actors

- [CISA KEV Priority & Remediation Monitor](https://apify.com/koalastuff/cisa-kev-priority-monitor) for known-exploited-vulnerability due dates and ransomware-use data.
- [EU Safety Gate Product Alert Monitor](https://apify.com/koalastuff/eu-safety-gate-alert-monitor) for product-safety risk monitoring.

# Actor input Schema

## `cveIds` (type: `array`):

Optional exact CVE IDs. When set, the date window is omitted.

## `keywordSearch` (type: `string`):

NVD description search. Multiple words use the official API's AND behavior.

## `dateMode` (type: `string`):

Search newly published or recently modified CVE records.

## `daysBack` (type: `integer`):

Rolling UTC date window. NVD permits at most 120 consecutive days.

## `cvssVersion` (type: `string`):

Version used by the optional severity filter.

## `severity` (type: `string`):

Optional server-side severity filter. Requires CVSS version V3 or V4.

## `cweId` (type: `string`):

Optional exact weakness identifier, for example CWE-287.

## `hasKev` (type: `boolean`):

Return only CVEs that appear in CISA's KEV catalog.

## `maxResults` (type: `integer`):

Hard unique-output and billing limit.

## `requestDelayMs` (type: `integer`):

NVD recommends six seconds between anonymous API requests.

## Actor input object example

```json
{
  "dateMode": "LAST_MODIFIED",
  "daysBack": 7,
  "cvssVersion": "ANY",
  "hasKev": false,
  "maxResults": 100,
  "requestDelayMs": 6000
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {};

// Run the Actor and wait for it to finish
const run = await client.actor("koalastuff/nvd-cve-vulnerability-monitor").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {}

# Run the Actor and wait for it to finish
run = client.actor("koalastuff/nvd-cve-vulnerability-monitor").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print("💾 Check your data here: https://console.apify.com/storage/datasets/" + run["defaultDatasetId"])
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{}' |
apify call koalastuff/nvd-cve-vulnerability-monitor --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "command": "npx",
            "args": [
                "mcp-remote",
                "https://mcp.apify.com/?tools=koalastuff/nvd-cve-vulnerability-monitor",
                "--header",
                "Authorization: Bearer <YOUR_API_TOKEN>"
            ]
        }
    }
}

```

## OpenAPI specification

```json
{
    "openapi": "3.0.1",
    "info": {
        "title": "NVD CVE Vulnerability Search & Monitor API",
        "description": "Search NIST NVD CVE records by product, date, CVSS severity, CWE, CVE ID, or CISA KEV status. Export normalized vulnerability data for security workflows.",
        "version": "0.1",
        "x-build-id": "zJm3aeL8zyVJSz2h4"
    },
    "servers": [
        {
            "url": "https://api.apify.com/v2"
        }
    ],
    "paths": {
        "/acts/koalastuff~nvd-cve-vulnerability-monitor/run-sync-get-dataset-items": {
            "post": {
                "operationId": "run-sync-get-dataset-items-koalastuff-nvd-cve-vulnerability-monitor",
                "x-openai-isConsequential": false,
                "summary": "Executes an Actor, waits for its completion, and returns Actor's dataset items in response.",
                "tags": [
                    "Run Actor"
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/inputSchema"
                            }
                        }
                    }
                },
                "parameters": [
                    {
                        "name": "token",
                        "in": "query",
                        "required": true,
                        "schema": {
                            "type": "string"
                        },
                        "description": "Enter your Apify token here"
                    }
                ],
                "responses": {
                    "200": {
                        "description": "OK"
                    }
                }
            }
        },
        "/acts/koalastuff~nvd-cve-vulnerability-monitor/runs": {
            "post": {
                "operationId": "runs-sync-koalastuff-nvd-cve-vulnerability-monitor",
                "x-openai-isConsequential": false,
                "summary": "Executes an Actor and returns information about the initiated run in response.",
                "tags": [
                    "Run Actor"
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/inputSchema"
                            }
                        }
                    }
                },
                "parameters": [
                    {
                        "name": "token",
                        "in": "query",
                        "required": true,
                        "schema": {
                            "type": "string"
                        },
                        "description": "Enter your Apify token here"
                    }
                ],
                "responses": {
                    "200": {
                        "description": "OK",
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/runsResponseSchema"
                                }
                            }
                        }
                    }
                }
            }
        },
        "/acts/koalastuff~nvd-cve-vulnerability-monitor/run-sync": {
            "post": {
                "operationId": "run-sync-koalastuff-nvd-cve-vulnerability-monitor",
                "x-openai-isConsequential": false,
                "summary": "Executes an Actor, waits for completion, and returns the OUTPUT from Key-value store in response.",
                "tags": [
                    "Run Actor"
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/inputSchema"
                            }
                        }
                    }
                },
                "parameters": [
                    {
                        "name": "token",
                        "in": "query",
                        "required": true,
                        "schema": {
                            "type": "string"
                        },
                        "description": "Enter your Apify token here"
                    }
                ],
                "responses": {
                    "200": {
                        "description": "OK"
                    }
                }
            }
        }
    },
    "components": {
        "schemas": {
            "inputSchema": {
                "type": "object",
                "properties": {
                    "cveIds": {
                        "title": "CVE IDs",
                        "maxItems": 100,
                        "uniqueItems": true,
                        "type": "array",
                        "description": "Optional exact CVE IDs. When set, the date window is omitted.",
                        "items": {
                            "type": "string",
                            "pattern": "^CVE-[0-9]{4}-[0-9]{4,}$"
                        }
                    },
                    "keywordSearch": {
                        "title": "Keywords",
                        "maxLength": 200,
                        "type": "string",
                        "description": "NVD description search. Multiple words use the official API's AND behavior."
                    },
                    "dateMode": {
                        "title": "Date mode",
                        "enum": [
                            "PUBLISHED",
                            "LAST_MODIFIED"
                        ],
                        "type": "string",
                        "description": "Search newly published or recently modified CVE records.",
                        "default": "LAST_MODIFIED"
                    },
                    "daysBack": {
                        "title": "Days back",
                        "minimum": 1,
                        "maximum": 120,
                        "type": "integer",
                        "description": "Rolling UTC date window. NVD permits at most 120 consecutive days.",
                        "default": 7
                    },
                    "cvssVersion": {
                        "title": "CVSS filter version",
                        "enum": [
                            "ANY",
                            "V3",
                            "V4"
                        ],
                        "type": "string",
                        "description": "Version used by the optional severity filter.",
                        "default": "ANY"
                    },
                    "severity": {
                        "title": "CVSS severity",
                        "enum": [
                            "LOW",
                            "MEDIUM",
                            "HIGH",
                            "CRITICAL"
                        ],
                        "type": "string",
                        "description": "Optional server-side severity filter. Requires CVSS version V3 or V4."
                    },
                    "cweId": {
                        "title": "CWE ID",
                        "pattern": "^(CWE-[0-9]+|NVD-CWE-(Other|noinfo))$",
                        "type": "string",
                        "description": "Optional exact weakness identifier, for example CWE-287."
                    },
                    "hasKev": {
                        "title": "CISA Known Exploited Vulnerabilities only",
                        "type": "boolean",
                        "description": "Return only CVEs that appear in CISA's KEV catalog.",
                        "default": false
                    },
                    "maxResults": {
                        "title": "Maximum results",
                        "minimum": 1,
                        "maximum": 10000,
                        "type": "integer",
                        "description": "Hard unique-output and billing limit.",
                        "default": 100
                    },
                    "requestDelayMs": {
                        "title": "Delay between API pages",
                        "minimum": 6000,
                        "maximum": 60000,
                        "type": "integer",
                        "description": "NVD recommends six seconds between anonymous API requests.",
                        "default": 6000
                    }
                }
            },
            "runsResponseSchema": {
                "type": "object",
                "properties": {
                    "data": {
                        "type": "object",
                        "properties": {
                            "id": {
                                "type": "string"
                            },
                            "actId": {
                                "type": "string"
                            },
                            "userId": {
                                "type": "string"
                            },
                            "startedAt": {
                                "type": "string",
                                "format": "date-time",
                                "example": "2025-01-08T00:00:00.000Z"
                            },
                            "finishedAt": {
                                "type": "string",
                                "format": "date-time",
                                "example": "2025-01-08T00:00:00.000Z"
                            },
                            "status": {
                                "type": "string",
                                "example": "READY"
                            },
                            "meta": {
                                "type": "object",
                                "properties": {
                                    "origin": {
                                        "type": "string",
                                        "example": "API"
                                    },
                                    "userAgent": {
                                        "type": "string"
                                    }
                                }
                            },
                            "stats": {
                                "type": "object",
                                "properties": {
                                    "inputBodyLen": {
                                        "type": "integer",
                                        "example": 2000
                                    },
                                    "rebootCount": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "restartCount": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "resurrectCount": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "computeUnits": {
                                        "type": "integer",
                                        "example": 0
                                    }
                                }
                            },
                            "options": {
                                "type": "object",
                                "properties": {
                                    "build": {
                                        "type": "string",
                                        "example": "latest"
                                    },
                                    "timeoutSecs": {
                                        "type": "integer",
                                        "example": 300
                                    },
                                    "memoryMbytes": {
                                        "type": "integer",
                                        "example": 1024
                                    },
                                    "diskMbytes": {
                                        "type": "integer",
                                        "example": 2048
                                    }
                                }
                            },
                            "buildId": {
                                "type": "string"
                            },
                            "defaultKeyValueStoreId": {
                                "type": "string"
                            },
                            "defaultDatasetId": {
                                "type": "string"
                            },
                            "defaultRequestQueueId": {
                                "type": "string"
                            },
                            "buildNumber": {
                                "type": "string",
                                "example": "1.0.0"
                            },
                            "containerUrl": {
                                "type": "string"
                            },
                            "usage": {
                                "type": "object",
                                "properties": {
                                    "ACTOR_COMPUTE_UNITS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_WRITES": {
                                        "type": "integer",
                                        "example": 1
                                    },
                                    "KEY_VALUE_STORE_LISTS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_INTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_EXTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_RESIDENTIAL_TRANSFER_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_SERPS": {
                                        "type": "integer",
                                        "example": 0
                                    }
                                }
                            },
                            "usageTotalUsd": {
                                "type": "number",
                                "example": 0.00005
                            },
                            "usageUsd": {
                                "type": "object",
                                "properties": {
                                    "ACTOR_COMPUTE_UNITS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_WRITES": {
                                        "type": "number",
                                        "example": 0.00005
                                    },
                                    "KEY_VALUE_STORE_LISTS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_INTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_EXTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_RESIDENTIAL_TRANSFER_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_SERPS": {
                                        "type": "integer",
                                        "example": 0
                                    }
                                }
                            }
                        }
                    }
                }
            }
        }
    }
}
```
