NVD CVE Vulnerability Search avatar

NVD CVE Vulnerability Search

Pricing

$0.35 / 1,000 cves

Go to Apify Store
NVD CVE Vulnerability Search

NVD CVE Vulnerability Search

Search the NIST National Vulnerability Database for a keyword or exact CVE ID. Filter by CVSS severity, publication or modification dates, and an affected CPE name, then save structured CVE details with CVSS, CWE, product, reference, and optional CISA KEV data.

Pricing

$0.35 / 1,000 cves

Rating

0.0

(0)

Developer

Maxime Dupré

Maxime Dupré

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

5 days ago

Last modified

Share

🔎 Find the CVEs behind a vulnerability keyword

Security teams, developers, and researchers can search the NIST National Vulnerability Database by keyword or exact CVE ID. Each saved dataset row keeps source-backed CVE details, CVSS metrics, CWE weaknesses, affected product matches, references, and optional CISA KEV context. Use those fields for vulnerability review, software checks, or security reports. No NVD credential is needed for the public catalog search.

📦 CVE records with security context

Each saved row represents one CVE returned by the NVD. It includes the CVE identifier, English description, NVD status, publication and last-modified timestamps, source identifier, the selected CVSS assessment, CWE weaknesses, affected product matches, reference links, and CISA KEV context when available.

The cvss.version field identifies the selected assessment as CVSS 2.0, 3.0, 3.1, or 4.0. Version-specific metric fields appear when the NVD assessment supplies them. The optional cisaKev object appears when the CVE is listed in the CISA Known Exploited Vulnerabilities catalog.

▶️ Search the NVD catalog in one run

Choose one search mode, add any filters, and start the run. Choose Keyword to search NVD vulnerability descriptions, or choose CVE ID to look up one exact identifier. Severity, publication dates, modification dates, and an affected CPE name can filter either mode. Fields for the inactive mode are ignored, and one run uses one search mode.

The Actor saves one row per CVE. If the same CVE appears again while the source is being read, the first eligible match is saved and later matches are ignored. Open the Dataset tab when the run finishes to review or export the rows.

⚙️ Input

Use searchBy to choose a keyword search or an exact CVE ID lookup. Add the matching value, then use the shared filters when needed.

FieldTypeWhat it does
searchBystringRequired. Choose keyword or cveId.
keywordstringWhen searchBy is keyword, finds CVEs whose NVD record matches this keyword.
maxItemsintegerStops after this many matching CVEs. Leave empty to return all available results until the source is exhausted or the run ends.
cveIdstringWhen searchBy is cveId, retrieves one vulnerability by its exact CVE identifier.
severityarray of stringsKeeps CVEs in the selected CVSS categories: LOW, MEDIUM, HIGH, or CRITICAL. Leave empty to include all categories.
publicationDateRangeobjectKeeps CVEs published in the selected UTC date range.
publicationDateRange.fromstringFirst publication date to include, in UTC, using YYYY-MM-DD.
publicationDateRange.tostringLast publication date to include, in UTC, using YYYY-MM-DD.
modificationDateRangeobjectKeeps CVEs last modified in the selected UTC date range.
modificationDateRange.fromstringFirst last-modified date to include, in UTC, using YYYY-MM-DD.
modificationDateRange.tostringLast last-modified date to include, in UTC, using YYYY-MM-DD.
cpeNamestringKeeps CVEs that list this affected software CPE name.

Successful beta default-input example

{
"searchBy": "keyword",
"keyword": "log4j",
"maxItems": 25
}

maxItems is the Actor Work Limit. Leave it empty when you want all available matching results until the NVD source is exhausted or the run ends.

🧾 Output

Output link

FieldTypeWhat it does
resultsstringLink to the CVE result rows in the dataset.

All dataset rows use the same top-level shape. The selected CVSS version changes which nested metric fields are present. Optional fields are omitted when the source does not supply them.

CVE row fields

FieldTypeWhat it does
cveIdstringCVE identifier for the vulnerability.
descriptionstringEnglish vulnerability description from NVD.
statusstringStatus recorded by NVD for the CVE.
publishedAtstringUTC date and time when NVD published the CVE record.
lastModifiedAtstringUTC date and time when NVD last modified the CVE record.
sourceIdentifierstringNVD identifier for the organization that supplied or assigned the CVE.
cvssobjectSelected NVD CVSS assessment.
cvss.versionstringCVSS version that supplied the assessment: 2.0, 3.0, 3.1, or 4.0.
cvss.scorenumberCVSS base score.
cvss.severitystringCVSS severity category.
cvss.vectorstringCVSS vector string.
cvss.attackVectorstringCVSS attack vector, when supplied.
cvss.attackComplexitystringCVSS attack complexity, when supplied.
cvss.attackRequirementsstringCVSS 4.0 attack requirements, when supplied.
cvss.privilegesRequiredstringPrivileges required by the CVSS attack, when supplied.
cvss.userInteractionstringUser interaction required by the CVSS attack, when supplied.
cvss.scopestringCVSS scope, when supplied.
cvss.confidentialitystringCVSS confidentiality impact, when supplied.
cvss.integritystringCVSS integrity impact, when supplied.
cvss.availabilitystringCVSS availability impact, when supplied.
cvss.accessVectorstringCVSS 2.0 access vector, when supplied.
cvss.accessComplexitystringCVSS 2.0 access complexity, when supplied.
cvss.authenticationstringCVSS 2.0 authentication requirement, when supplied.
cvss.vulnerableSystemConfidentialitystringCVSS 4.0 confidentiality impact on the vulnerable system, when supplied.
cvss.vulnerableSystemIntegritystringCVSS 4.0 integrity impact on the vulnerable system, when supplied.
cvss.vulnerableSystemAvailabilitystringCVSS 4.0 availability impact on the vulnerable system, when supplied.
cvss.subsequentSystemConfidentialitystringCVSS 4.0 confidentiality impact on a subsequent system, when supplied.
cvss.subsequentSystemIntegritystringCVSS 4.0 integrity impact on a subsequent system, when supplied.
cvss.subsequentSystemAvailabilitystringCVSS 4.0 availability impact on a subsequent system, when supplied.
cvss.exploitabilityScorenumberCVSS exploitability score, when supplied.
cvss.impactScorenumberCVSS impact score, when supplied.
weaknessesarray of objectsCWE weaknesses listed by NVD for the CVE.
weaknesses[].idstringCWE identifier.
weaknesses[].namestringHuman-readable CWE name when NVD provides one.
affectedProductsarray of objectsSoftware and version matches listed by NVD.
affectedProducts[].vendorstringVendor from the NVD product identifier.
affectedProducts[].productstringProduct from the NVD product identifier.
affectedProducts[].versionstringProduct version when specified.
affectedProducts[].versionStartIncludingstringFirst affected version in the range, when supplied.
affectedProducts[].versionStartExcludingstringFirst excluded version before the affected range, when supplied.
affectedProducts[].versionEndIncludingstringLast affected version in the range, when supplied.
affectedProducts[].versionEndExcludingstringFirst excluded version after the affected range, when supplied.
affectedProducts[].vulnerablebooleanWhether NVD marks this product match as vulnerable.
referencesarray of objectsReference links listed by NVD, such as advisories or patches.
references[].urlstringReference URL.
references[].sourcestringSource named by NVD for the reference, when supplied.
references[].tagsarray of stringsTags describing the reference, when supplied.
cisaKevobjectCISA Known Exploited Vulnerabilities context when this CVE is listed.
cisaKev.dateAddedstringDate CISA added the CVE to its catalog.
cisaKev.dueDatestringAction due date listed by CISA.
cisaKev.knownRansomwareCampaignUsebooleanWhether CISA marks the CVE as used in known ransomware campaigns.
cisaKev.requiredActionstringAction CISA requires for the CVE.
cisaKev.notesstringAdditional notes from the CISA catalog, when supplied.

Genuine CVSS 3.1 row from the current beta build

{
"cveId": "CVE-2018-16843",
"description": "nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.",
"status": "Modified",
"publishedAt": "2018-11-07T14:29:00.777Z",
"lastModifiedAt": "2026-06-17T01:44:53.387Z",
"sourceIdentifier": "secalert@redhat.com",
"cvss": {
"version": "3.1",
"score": 7.5,
"severity": "HIGH",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentiality": "NONE",
"integrity": "NONE",
"availability": "HIGH",
"exploitabilityScore": 3.9,
"impactScore": 3.6
},
"weaknesses": [
{
"id": "CWE-400",
"name": "Uncontrolled Resource Consumption (4.20)"
}
],
"affectedProducts": [
{
"vendor": "f5",
"product": "nginx",
"vulnerable": true,
"versionStartExcluding": "1.9.5",
"versionEndExcluding": "1.14.1"
},
{
"vendor": "f5",
"product": "nginx",
"vulnerable": true,
"versionStartExcluding": "1.15.0",
"versionEndExcluding": "1.15.6"
},
{
"vendor": "debian",
"product": "debian_linux",
"vulnerable": true,
"version": "9.0"
},
{
"vendor": "canonical",
"product": "ubuntu_linux",
"vulnerable": true,
"version": "14.04"
},
{
"vendor": "canonical",
"product": "ubuntu_linux",
"vulnerable": true,
"version": "16.04"
},
{
"vendor": "canonical",
"product": "ubuntu_linux",
"vulnerable": true,
"version": "18.04"
},
{
"vendor": "canonical",
"product": "ubuntu_linux",
"vulnerable": true,
"version": "18.10"
},
{
"vendor": "opensuse",
"product": "leap",
"vulnerable": true,
"version": "15.1"
},
{
"vendor": "apple",
"product": "xcode",
"vulnerable": true,
"versionEndExcluding": "13.0"
}
],
"references": [
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html",
"source": "secalert@redhat.com",
"tags": [
"Mailing List",
"Third Party Advisory"
]
},
{
"url": "http://mailman.nginx.org/pipermail/nginx-announce/2018/000220.html",
"source": "secalert@redhat.com",
"tags": [
"Mailing List",
"Vendor Advisory"
]
},
{
"url": "http://seclists.org/fulldisclosure/2021/Sep/36",
"source": "secalert@redhat.com",
"tags": [
"Mailing List",
"Third Party Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/105868",
"source": "secalert@redhat.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "http://www.securitytracker.com/id/1042038",
"source": "secalert@redhat.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://access.redhat.com/errata/RHSA-2018:3653",
"source": "secalert@redhat.com",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://access.redhat.com/errata/RHSA-2018:3680",
"source": "secalert@redhat.com",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://access.redhat.com/errata/RHSA-2018:3681",
"source": "secalert@redhat.com",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16843",
"source": "secalert@redhat.com",
"tags": [
"Issue Tracking",
"Third Party Advisory"
]
},
{
"url": "https://support.apple.com/kb/HT212818",
"source": "secalert@redhat.com",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://usn.ubuntu.com/3812-1/",
"source": "secalert@redhat.com",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://www.debian.org/security/2018/dsa-4335",
"source": "secalert@redhat.com",
"tags": [
"Third Party Advisory"
]
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Mailing List",
"Third Party Advisory"
]
},
{
"url": "http://mailman.nginx.org/pipermail/nginx-announce/2018/000220.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Mailing List",
"Vendor Advisory"
]
},
{
"url": "http://seclists.org/fulldisclosure/2021/Sep/36",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Mailing List",
"Third Party Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/105868",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "http://www.securitytracker.com/id/1042038",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://access.redhat.com/errata/RHSA-2018:3653",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://access.redhat.com/errata/RHSA-2018:3680",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://access.redhat.com/errata/RHSA-2018:3681",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16843",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Issue Tracking",
"Third Party Advisory"
]
},
{
"url": "https://support.apple.com/kb/HT212818",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://usn.ubuntu.com/3812-1/",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://www.debian.org/security/2018/dsa-4335",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
]
}
]
}

Genuine CVSS 2.0 row from the current beta build

{
"cveId": "CVE-2013-6450",
"description": "The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.",
"status": "Modified",
"publishedAt": "2014-01-01T16:05:15.017Z",
"lastModifiedAt": "2026-06-17T00:00:31.027Z",
"sourceIdentifier": "secalert@redhat.com",
"cvss": {
"version": "2.0",
"score": 5.8,
"severity": "MEDIUM",
"vector": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
"confidentiality": "NONE",
"integrity": "PARTIAL",
"availability": "PARTIAL",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"exploitabilityScore": 8.6,
"impactScore": 4.9
},
"weaknesses": [
{
"id": "CWE-310",
"name": "CWE CATEGORY: Cryptographic Issues (4.20)"
}
],
"affectedProducts": [
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.0"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.0a"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.0b"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.0c"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.0d"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.0e"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.0f"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.0g"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.0h"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.0i"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.0j"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.1"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.1a"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.1b"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.1c"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.1d"
},
{
"vendor": "openssl",
"product": "openssl",
"vulnerable": true,
"version": "1.0.1e"
}
],
"references": [
{
"url": "http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=34628967f1e65dc8f34e000f0f5518e21afbfc7b",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.html",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-01/msg00031.html",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-01/msg00032.html",
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-0015.html",
"source": "secalert@redhat.com"
},
{
"url": "http://seclists.org/fulldisclosure/2014/Dec/23",
"source": "secalert@redhat.com"
},
{
"url": "http://security.gentoo.org/glsa/glsa-201412-39.xml",
"source": "secalert@redhat.com"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=isg400001841",
"source": "secalert@redhat.com"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=isg400001843",
"source": "secalert@redhat.com"
},
{
"url": "http://www.debian.org/security/2014/dsa-2833",
"source": "secalert@redhat.com"
},
{
"url": "http://www.openssl.org/news/vulnerabilities.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/archive/1/534161/100/0/threaded",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/64618",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securitytracker.com/id/1029549",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securitytracker.com/id/1031594",
"source": "secalert@redhat.com"
},
{
"url": "http://www.ubuntu.com/usn/USN-2079-1",
"source": "secalert@redhat.com"
},
{
"url": "http://www.vmware.com/security/advisories/VMSA-2014-0012.html",
"source": "secalert@redhat.com"
},
{
"url": "https://puppet.com/security/cve/cve-2013-6450",
"source": "secalert@redhat.com"
},
{
"url": "https://security-tracker.debian.org/tracker/CVE-2013-6450",
"source": "secalert@redhat.com"
},
{
"url": "http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=34628967f1e65dc8f34e000f0f5518e21afbfc7b",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-01/msg00031.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-01/msg00032.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-0015.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2014/Dec/23",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://security.gentoo.org/glsa/glsa-201412-39.xml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=isg400001841",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=isg400001843",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2014/dsa-2833",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openssl.org/news/vulnerabilities.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/534161/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/64618",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1029549",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1031594",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-2079-1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vmware.com/security/advisories/VMSA-2014-0012.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://puppet.com/security/cve/cve-2013-6450",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security-tracker.debian.org/tracker/CVE-2013-6450",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}

Genuine CVSS 4.0 row from the current beta build

{
"cveId": "CVE-2025-0168",
"description": "A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part of the file /_parse/_feedback_system.php. The manipulation of the argument person leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
"status": "Analyzed",
"publishedAt": "2025-01-01T14:15:23.590Z",
"lastModifiedAt": "2026-06-17T08:26:00.070Z",
"sourceIdentifier": "cna@vuldb.com",
"cvss": {
"version": "4.0",
"score": 5.3,
"severity": "MEDIUM",
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"vulnerableSystemConfidentiality": "LOW",
"vulnerableSystemIntegrity": "LOW",
"vulnerableSystemAvailability": "LOW",
"subsequentSystemConfidentiality": "NONE",
"subsequentSystemIntegrity": "NONE",
"subsequentSystemAvailability": "NONE"
},
"weaknesses": [
{
"id": "CWE-74",
"name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') (4.20)"
},
{
"id": "CWE-89",
"name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (4.20)"
}
],
"affectedProducts": [
{
"vendor": "anisha",
"product": "job_recruitment",
"vulnerable": true,
"version": "1.0"
}
],
"references": [
{
"url": "https://code-projects.org/",
"source": "cna@vuldb.com",
"tags": [
"Product"
]
},
{
"url": "https://github.com/UnrealdDei/cve/blob/main/sql11.md",
"source": "cna@vuldb.com",
"tags": [
"Exploit",
"Third Party Advisory"
]
},
{
"url": "https://vuldb.com/?ctiid.289917",
"source": "cna@vuldb.com",
"tags": [
"Permissions Required",
"VDB Entry"
]
},
{
"url": "https://vuldb.com/?id.289917",
"source": "cna@vuldb.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://vuldb.com/?submit.473107",
"source": "cna@vuldb.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
}
]
}

CISA KEV context from a current beta row

The following genuine row is shortened because its affected product and reference arrays are large. The string value "..." marks omitted source data.

{
"cveId": "CVE-2021-44228",
"description": "Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.",
"status": "Analyzed",
"publishedAt": "2021-12-10T10:15:09.143Z",
"lastModifiedAt": "2026-08-11T19:33:44.513Z",
"sourceIdentifier": "security@apache.org",
"cvss": {
"version": "3.1",
"score": 10,
"severity": "CRITICAL",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentiality": "HIGH",
"integrity": "HIGH",
"availability": "HIGH",
"exploitabilityScore": 3.9,
"impactScore": 6
},
"weaknesses": [
{
"id": "CWE-20",
"name": "Improper Input Validation (4.20)"
},
{
"id": "CWE-400",
"name": "Uncontrolled Resource Consumption (4.20)"
},
{
"id": "CWE-502",
"name": "Deserialization of Untrusted Data (4.20)"
},
{
"id": "CWE-917",
"name": "Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') (4.20)"
}
],
"affectedProducts": "...",
"references": "...",
"cisaKev": {
"dateAdded": "2021-12-10",
"dueDate": "2021-12-24",
"knownRansomwareCampaignUse": true,
"requiredAction": "For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228"
}
}

💳 Pricing

Pricing is pay per event. You are charged $0.00035 for each CVE successfully saved to the dataset. A run with no saved CVEs has no CVE event to charge.

🔌 Integrations

Use the dataset in JSON, CSV, or Excel, or read it through the Apify API. You can also connect runs to webhooks and scheduled workflows using Apify.

❓ FAQ

What happens if I enter a CVE ID and a keyword?

Choose the search mode in searchBy. The field for the inactive mode is ignored, so use keyword with searchBy: "keyword" or cveId with searchBy: "cveId".

What does an empty maxItems value do?

Leave maxItems empty to return all available matching results until the NVD source is exhausted or the run ends. Set it when you want a smaller work limit.

Does every CVE include CVSS 4.0 data?

No. The row shows the selected NVD assessment and its cvss.version. The available metric fields depend on the CVSS version and the data supplied by NVD.

Will the output show affected software versions?

When NVD lists affected product matches, affectedProducts can include the vendor, product, version, and version range bounds. It does not expose the full CPE applicability tree.

Does every CVE have CISA KEV data?

No. The optional cisaKev object appears when the CVE is listed in the CISA Known Exploited Vulnerabilities catalog.

Do I need an NVD API key?

No. This Actor searches the public NVD catalog without a customer source credential.

Does this test my systems or assess my asset inventory?

No. It returns public CVE data. It does not test live targets, verify exploitability, assess installed versions, or make remediation decisions.

Why might a run return no rows?

Your keyword, CVE ID, severity, date, and CPE filters may match no source records. A dataset row is saved only for a matching CVE.

Can I use this for a complete CVE database export?

Use an empty maxItems value to continue through all available matching results until the source is exhausted or the run ends. The result is still limited by the source and the run, so this does not promise a complete copy of every NVD record.

📝 Changelog

v0.0 (27-09-2026)

  • Initial release.

🆘 Support

For issues, questions, or feature requests, file a ticket and I'll fix or implement it in less than 24h 🫡

Made with ❤️ by Maxime Dupré