CVE Scraper: NVD Vulnerabilities, CVSS & KEV avatar

CVE Scraper: NVD Vulnerabilities, CVSS & KEV

Pricing

from $2.60 / 1,000 cve records

Go to Apify Store
CVE Scraper: NVD Vulnerabilities, CVSS & KEV

CVE Scraper: NVD Vulnerabilities, CVSS & KEV

Search the NVD CVE database and export vulnerabilities with CVSS scores, severity, CWE weaknesses, affected products and CISA KEV exploitation status. Export CSV, Excel, JSON, XML.

Pricing

from $2.60 / 1,000 cve records

Rating

0.0

(0)

Developer

PunkRecordsData

PunkRecordsData

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

13 hours ago

Last modified

Share

PunkRecordsData

๐Ÿ›ก CVE Vulnerabilities Scraper - NVD, CVSS & KEV - PunkRecordsData

๐Ÿš€ Export CVE vulnerability data in seconds. Search the National Vulnerability Database by product, vendor or CVE ID and get structured rows with CVSS v3 scores and vectors, severity, CWE weakness classes, affected products (CPEs), advisory references and CISA Known Exploited Vulnerabilities status with remediation deadlines. Log4Shell comes back as CVSS 10.0, KEV since 2021-12-10, with 4 CWEs and 50 affected products. Export to CSV, Excel, JSON or XML.

The CVE Vulnerabilities Scraper reads the official NVD 2.0 API and enriches every row with the fields security teams actually triage on: severity, exploitability, whether CISA has catalogued active exploitation, and which CPE product strings are affected. Filters map 1:1 to the API: severity, KEV-only, publication date range, keyword and direct CVE lookup.

๐ŸŽฏ Target Audience๐Ÿ’ก Primary Use Cases
Security and vulnerability-management teamsPrioritize patching with CVSS + KEV in one table
MSPs and consultantsClient-facing vulnerability reports by product stack
Threat intelligence analystsTrack new criticals for monitored vendors
GRC and complianceEvidence of exposure review with remediation deadlines

๐Ÿ“‹ What the CVE Scraper does

  • CVE records: id, status, description, CVSS v3 base score/severity/vector, exploitability and impact subscores, CVSS v2 (legacy), publication and modification dates, source.
  • CISA KEV enrichment on every row: known-exploited flag, date added, action-due deadline and required action, straight from NVD's integrated KEV data.
  • CWE weaknesses module: the weakness classes behind each CVE.
  • References module: advisory, patch and exploit links with NVD's own tags.
  • Affected products module: CPE criteria strings (up to 50 per CVE) for stack matching.
  • Filters that mirror the API: severity, KEV-only, date range, keyword search and exact CVE IDs.

๐Ÿ’ก Why it matters: CVSS alone over-prioritizes; KEV alone under-covers. Triage needs both, next to the affected-product strings your asset inventory can match on. That is exactly one row of this dataset.

Real sample from a live run:

{
"cveId": "CVE-2021-44228",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
"cvssV3Score": 10,
"cvssV3Severity": "CRITICAL",
"cvssV3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"knownExploited": "Yes",
"kevDateAdded": "2021-12-10",
"kevActionDue": "2021-12-24",
"weaknesses": ["CWE-20", "CWE-400", "CWE-502", "CWE-917"],
"affectedCpes": ["cpe:2.3:a:apache:log4j:2.0:...", "..."],
"error": null
}

โœจ Why choose this CVE scraper

  • 4 billable events (CVEs, weaknesses, references, affected products), each switchable; measured alternatives ship 1.
  • KEV exploitation status with deadlines on every row, not as a separate lookup.
  • CPE strings ready for asset matching, the step most CVE exports leave out.
  • Registry-true filters verified against the live NVD API, including the KEV-only switch.
  • Honest billing: modules bill per CVE only when they contain real data.

๐Ÿ“ˆ How this NVD CVE scraper compares to alternatives

Measured against the CVE actors on the Apify Store (September 2026):

This actorClosest alternatives
Billable data events41
CISA KEV status + deadlinesYes, every rowNo
CWE weaknesses / CPEsYes, modulesRarely
KEV-only and severity filtersYesPartial
Price per 1,000 CVEs$3.20$2.00 to $3.00

๐Ÿš€ How to use the CVE Vulnerabilities Scraper

  1. Create a free Apify account (with $5 of credit) at console.apify.com.
  2. Open this actor's page and click Try for free.
  3. Enter product/vendor keywords or CVE IDs; set severity or KEV-only if you want.
  4. Toggle weaknesses, references and affected products.
  5. Click Start and download CSV, Excel, JSON or XML.

๐Ÿ’ผ Business use cases

Patch prioritization

All criticals for your vendor list with KEV flags and deadlines; sort by kevActionDue and start there.

Client vulnerability reporting

Per-client product keywords, one scheduled run each, branded CSV out.

Threat landscape tracking

New CVEs for a technology over a date window, diffed weekly.

Asset exposure matching

Join affectedCpes against your CMDB's CPE inventory to find exposed systems.

๐Ÿ”Œ Automating the CVE Scraper

Connect to Make, Zapier, Slack, Airbyte, GitHub or Google Drive: KEV alerts to your incident channel, weekly severity digests, or SIEM-side syncs via the API.

๐ŸŒŸ Beyond business use cases

  • Research: vulnerability-trend studies with clean panel data.
  • Personal: watch CVEs for the software you self-host.
  • Non-profit: security advisories for under-resourced orgs.
  • Experimentation: a structured playground over the NVD API.

๐Ÿค– Ask an AI assistant about this scraper

"I need all critical CVEs for my vendor list with CVSS vectors, CWEs, affected CPEs and CISA KEV deadlines as CSV, weekly. Would the CVE Vulnerabilities Scraper on Apify (apify.com/punkrecordsdata/cve-vulnerabilities-scraper) do this?"

โ“ Frequently Asked Questions

๐Ÿ›ก How do I export NVD CVE data for a product to CSV?

Enter the product or vendor keyword, click Start, and download from the Storage tab.

๐Ÿ”ฅ How do I find actively exploited vulnerabilities only?

Switch on "Only CISA KEV"; every returned CVE is in the Known Exploited Vulnerabilities catalog, with dateAdded and actionDue.

๐Ÿ“Š Does it include the full CVSS vector?

Yes, v3.1/v3.0 base score, severity, vector string, exploitability and impact subscores, plus legacy v2 where present.

๐Ÿงฉ What are CWE weaknesses?

The weakness classes (e.g. CWE-502 deserialization) behind each CVE; useful for secure-coding and root-cause analytics.

๐Ÿ–ฅ How do I know which products are affected?

Enable the affected-products module: up to 50 CPE criteria strings per CVE, matchable against asset inventories.

๐Ÿ†” Can I look up specific CVE IDs?

Yes, paste them (CVE-YYYY-NNNN) and they run before any keyword search.

๐Ÿ“… Can I filter by publication date?

Yes; note NVD requires date ranges of 120 days or less, which the input documents.

๐Ÿ’ต Do I pay for empty modules?

No. Weaknesses, references and CPEs bill per CVE only when data exists.

๐Ÿ“ฆ How many CVEs can one run return?

Up to 1,000,000 on paid plans; NVD serves 2,000 per request and the actor paces itself under the no-key rate limits. Free users get a 10-CVE preview.

โš™๏ธ Does it need an NVD API key?

No. It respects the public no-key rate window (which makes very large runs slower but reliable).

๐Ÿ•’ How fresh is the data?

Live from NVD at run time; lastModified per row shows each record's currency.

๐Ÿ”Œ Integrate with any app

Datasets are available via the Apify API in JSON, CSV, Excel or XML, with webhooks, ready for SIEMs, Python, Sheets or BI tools.

๐Ÿ’ก Pro Tip: browse the complete PunkRecordsData collection for more data tools.

๐Ÿ†˜ Need Help? contact.punkrecordsdata@gmail.com

โš ๏ธ Disclaimer: independent tool, not affiliated with NIST, NVD or CISA; only publicly available data.