NIST NVD CVE Scraper
Pricing
from $22.50 / 1,000 results
NIST NVD CVE Scraper
Scrape CVE vulnerabilities from the NIST National Vulnerability Database (NVD) API 2.0. Filter by severity, CWE, keyword, date range, or single CVE ID. Returns CVSS v3/v2 scores, CWE weaknesses, CPE configurations, and references.
Pricing
from $22.50 / 1,000 results
Rating
0.0
(0)
Developer
ParseForge
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
0
Monthly active users
6 days ago
Last modified
Categories
Share

π‘οΈ NIST NVD CVE Scraper
π Export the global CVE catalogue in seconds. Pull 240,000+ CVE records from the official NIST National Vulnerability Database with CVSS v4, v3.1, and v2 scores, CWE weaknesses, CPE configurations, and full reference lists. No sign-up, no rate-limit headaches, no parser engineering.
The NIST NVD CVE Scraper pulls vulnerabilities from the official NIST National Vulnerability Database (NVD) and returns 21 normalised fields per record, including CVSS v4 / v3 / v2 base scores, weakness classifications, CPE 2.3 configurations, and curated reference links. The underlying catalogue is the canonical source of truth for U.S. federal vulnerability tracking and is consumed by every major SIEM, vulnerability scanner, and cloud security platform on the planet.
The catalogue covers every published CVE since 1999, four CVSS scoring systems, hundreds of CWE weakness families, and millions of CPE product mappings spanning operating systems, applications, libraries, and firmware. This Actor makes that data downloadable as CSV, Excel, JSON, or XML in minutes. Filters apply at the source, so you skip pagination, rate-limit handling, and field normalisation entirely.
| π― Target Audience | π‘ Primary Use Cases |
|---|---|
| Security teams, vulnerability managers, threat researchers, SOC analysts, DevSecOps engineers, compliance officers, security tool builders | CVE feed enrichment, patch prioritisation, SIEM integration, CVSS-based reporting, CPE matching, supply-chain risk, security dashboard automation |
π What the NIST NVD CVE Scraper does
Five workflows in a single Actor:
- π Single CVE lookup. Fetch one record by its identifier, e.g.
CVE-2021-44228. - π¦ Batch CVE lookup. Pass an array of IDs and get every match in one run.
- π Keyword search. Free-text search across CVE descriptions for terms like
openssl,log4j, orremote code execution. - ποΈ Severity + CWE filters. Restrict to Critical / High / Medium / Low or to a specific weakness type.
- π Date-window crawl. Pull every CVE published inside a 120-day window for incremental syncs.
Each record includes the CVE identifier, source CNA, publication and modification timestamps, English description, all available CVSS scores, weakness list, affected configurations (CPE 2.3 with version ranges), and curated references with tags.
π‘ Why it matters: the NVD is the foundation of every vulnerability scanner, patch-management workflow, and security advisory pipeline. Building your own ingestion means handling pagination, the 120-day window cap, retry-after headers, and CVSS v2/v3/v4 normalisation by hand. This Actor skips all of that and gives you a clean, downloadable dataset.
π Data fields
Each record includes: configurations, cveId, cvssV2BaseScore, cvssV2BaseSeverity, cvssV2VectorString, cvssV3BaseScore, cvssV3BaseSeverity, cvssV3VectorString, cvssV4BaseScore, cvssV4Severity, cvssV4VectorString, description, lastModified, published, references, scrapedAt, sourceIdentifier, url, vulnStatus, weaknesses. All 20 field names come from a real production run, so what you see here is what lands in your dataset.
π How to use
- π Sign up. Create a free account with $5 credit (takes 2 minutes).
- π Open the Actor. Go to the NIST NVD CVE Scraper page on the Apify Store.
- π― Set input. Pick a severity, keyword, CVE ID, or date window, then set
maxItems. - π Run it. Click Start and let the Actor collect your data.
- π₯ Download. Grab your results in the Dataset tab as CSV, Excel, JSON, or XML.
β±οΈ Total time from signup to downloaded dataset: 3-5 minutes. No coding required.
π Recommended Actors
- π¨ CISA KEV Scraper - Known Exploited Vulnerabilities catalogue with due dates
- π EPSS Exploit Prediction Scraper - 30-day exploitation probability scores
- π GitHub Security Advisories Scraper - GHSA + CVE advisories with patched versions
- π¦ OSV Vulnerabilities Scraper - Open source vulnerabilities across PyPI, npm, Go, Maven and more
- π¬ CIRCL CVE Scraper - CIRCL Luxembourg CVE catalogue with CWE and CAPEC
π‘ Pro Tip: browse the complete ParseForge collection for more security and reference-data scrapers.
β οΈ Disclaimer: this Actor is an independent tool and is not affiliated with, endorsed by, or sponsored by NIST, the U.S. government, or any of the CNAs that contribute to the NVD catalogue. All trademarks mentioned are the property of their respective owners. Only publicly available vulnerability data is collected.
π Need Help?
If you hit a bug, have questions about setup, or need a scraper we haven't built yet, open our contact form or write to parseforge@protonmail.com. We also take on paid custom data projects.
For faster answers, join our Discord. It's the best place to get support and suggest new actors.