CVE Scraper: NVD Vulnerabilities, CVSS & KEV
Pricing
from $2.60 / 1,000 cve records
CVE Scraper: NVD Vulnerabilities, CVSS & KEV
Search the NVD CVE database and export vulnerabilities with CVSS scores, severity, CWE weaknesses, affected products and CISA KEV exploitation status. Export CSV, Excel, JSON, XML.
Pricing
from $2.60 / 1,000 cve records
Rating
0.0
(0)
Developer
PunkRecordsData
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
13 hours ago
Last modified
Categories
Share
๐ก CVE Vulnerabilities Scraper - NVD, CVSS & KEV - PunkRecordsData
๐ Export CVE vulnerability data in seconds. Search the National Vulnerability Database by product, vendor or CVE ID and get structured rows with CVSS v3 scores and vectors, severity, CWE weakness classes, affected products (CPEs), advisory references and CISA Known Exploited Vulnerabilities status with remediation deadlines. Log4Shell comes back as CVSS 10.0, KEV since 2021-12-10, with 4 CWEs and 50 affected products. Export to CSV, Excel, JSON or XML.
The CVE Vulnerabilities Scraper reads the official NVD 2.0 API and enriches every row with the fields security teams actually triage on: severity, exploitability, whether CISA has catalogued active exploitation, and which CPE product strings are affected. Filters map 1:1 to the API: severity, KEV-only, publication date range, keyword and direct CVE lookup.
| ๐ฏ Target Audience | ๐ก Primary Use Cases |
|---|---|
| Security and vulnerability-management teams | Prioritize patching with CVSS + KEV in one table |
| MSPs and consultants | Client-facing vulnerability reports by product stack |
| Threat intelligence analysts | Track new criticals for monitored vendors |
| GRC and compliance | Evidence of exposure review with remediation deadlines |
๐ What the CVE Scraper does
- CVE records: id, status, description, CVSS v3 base score/severity/vector, exploitability and impact subscores, CVSS v2 (legacy), publication and modification dates, source.
- CISA KEV enrichment on every row: known-exploited flag, date added, action-due deadline and required action, straight from NVD's integrated KEV data.
- CWE weaknesses module: the weakness classes behind each CVE.
- References module: advisory, patch and exploit links with NVD's own tags.
- Affected products module: CPE criteria strings (up to 50 per CVE) for stack matching.
- Filters that mirror the API: severity, KEV-only, date range, keyword search and exact CVE IDs.
๐ก Why it matters: CVSS alone over-prioritizes; KEV alone under-covers. Triage needs both, next to the affected-product strings your asset inventory can match on. That is exactly one row of this dataset.
๐ Output of the CVE search
Real sample from a live run:
{"cveId": "CVE-2021-44228","url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228","cvssV3Score": 10,"cvssV3Severity": "CRITICAL","cvssV3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","knownExploited": "Yes","kevDateAdded": "2021-12-10","kevActionDue": "2021-12-24","weaknesses": ["CWE-20", "CWE-400", "CWE-502", "CWE-917"],"affectedCpes": ["cpe:2.3:a:apache:log4j:2.0:...", "..."],"error": null}
โจ Why choose this CVE scraper
- 4 billable events (CVEs, weaknesses, references, affected products), each switchable; measured alternatives ship 1.
- KEV exploitation status with deadlines on every row, not as a separate lookup.
- CPE strings ready for asset matching, the step most CVE exports leave out.
- Registry-true filters verified against the live NVD API, including the KEV-only switch.
- Honest billing: modules bill per CVE only when they contain real data.
๐ How this NVD CVE scraper compares to alternatives
Measured against the CVE actors on the Apify Store (September 2026):
| This actor | Closest alternatives | |
|---|---|---|
| Billable data events | 4 | 1 |
| CISA KEV status + deadlines | Yes, every row | No |
| CWE weaknesses / CPEs | Yes, modules | Rarely |
| KEV-only and severity filters | Yes | Partial |
| Price per 1,000 CVEs | $3.20 | $2.00 to $3.00 |
๐ How to use the CVE Vulnerabilities Scraper
- Create a free Apify account (with $5 of credit) at console.apify.com.
- Open this actor's page and click Try for free.
- Enter product/vendor keywords or CVE IDs; set severity or KEV-only if you want.
- Toggle weaknesses, references and affected products.
- Click Start and download CSV, Excel, JSON or XML.
๐ผ Business use cases
Patch prioritization
All criticals for your vendor list with KEV flags and deadlines; sort by kevActionDue and start there.
Client vulnerability reporting
Per-client product keywords, one scheduled run each, branded CSV out.
Threat landscape tracking
New CVEs for a technology over a date window, diffed weekly.
Asset exposure matching
Join affectedCpes against your CMDB's CPE inventory to find exposed systems.
๐ Automating the CVE Scraper
Connect to Make, Zapier, Slack, Airbyte, GitHub or Google Drive: KEV alerts to your incident channel, weekly severity digests, or SIEM-side syncs via the API.
๐ Beyond business use cases
- Research: vulnerability-trend studies with clean panel data.
- Personal: watch CVEs for the software you self-host.
- Non-profit: security advisories for under-resourced orgs.
- Experimentation: a structured playground over the NVD API.
๐ค Ask an AI assistant about this scraper
"I need all critical CVEs for my vendor list with CVSS vectors, CWEs, affected CPEs and CISA KEV deadlines as CSV, weekly. Would the CVE Vulnerabilities Scraper on Apify (apify.com/punkrecordsdata/cve-vulnerabilities-scraper) do this?"
โ Frequently Asked Questions
๐ก How do I export NVD CVE data for a product to CSV?
Enter the product or vendor keyword, click Start, and download from the Storage tab.
๐ฅ How do I find actively exploited vulnerabilities only?
Switch on "Only CISA KEV"; every returned CVE is in the Known Exploited Vulnerabilities catalog, with dateAdded and actionDue.
๐ Does it include the full CVSS vector?
Yes, v3.1/v3.0 base score, severity, vector string, exploitability and impact subscores, plus legacy v2 where present.
๐งฉ What are CWE weaknesses?
The weakness classes (e.g. CWE-502 deserialization) behind each CVE; useful for secure-coding and root-cause analytics.
๐ฅ How do I know which products are affected?
Enable the affected-products module: up to 50 CPE criteria strings per CVE, matchable against asset inventories.
๐ Can I look up specific CVE IDs?
Yes, paste them (CVE-YYYY-NNNN) and they run before any keyword search.
๐ Can I filter by publication date?
Yes; note NVD requires date ranges of 120 days or less, which the input documents.
๐ต Do I pay for empty modules?
No. Weaknesses, references and CPEs bill per CVE only when data exists.
๐ฆ How many CVEs can one run return?
Up to 1,000,000 on paid plans; NVD serves 2,000 per request and the actor paces itself under the no-key rate limits. Free users get a 10-CVE preview.
โ๏ธ Does it need an NVD API key?
No. It respects the public no-key rate window (which makes very large runs slower but reliable).
๐ How fresh is the data?
Live from NVD at run time; lastModified per row shows each record's currency.
๐ Integrate with any app
Datasets are available via the Apify API in JSON, CSV, Excel or XML, with webhooks, ready for SIEMs, Python, Sheets or BI tools.
๐ Recommended Actors
- Federal Register Scraper - the regulatory side of security mandates
- Hugging Face Scraper - audit the AI models entering your stack
- SEC EDGAR Filings Scraper - breach disclosures in 8-Ks
- Steam Games Player Stats - another live-API data product
๐ก Pro Tip: browse the complete PunkRecordsData collection for more data tools.
๐ Need Help? contact.punkrecordsdata@gmail.com
โ ๏ธ Disclaimer: independent tool, not affiliated with NIST, NVD or CISA; only publicly available data.