# CVE Scraper: NVD Vulnerabilities, CVSS & KEV (`punkrecordsdata/cve-vulnerabilities-scraper`) Actor

Search the NVD CVE database and export vulnerabilities with CVSS scores, severity, CWE weaknesses, affected products and CISA KEV exploitation status. Export CSV, Excel, JSON, XML.

- **URL**: https://apify.com/punkrecordsdata/cve-vulnerabilities-scraper.md
- **Developed by:** [PunkRecordsData](https://apify.com/punkrecordsdata) (community)
- **Categories:** Developer tools, Automation
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $2.60 / 1,000 cve records

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.
Since this Actor supports Apify Store discounts, the price gets lower the higher subscription plan you have.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

<p align="center">
  <img src="https://api.apify.com/v2/key-value-stores/AAm3a1h3Z9nYfrvh9/records/banner?v=2" alt="PunkRecordsData" width="100%" />
</p>

## 🛡 CVE Vulnerabilities Scraper - NVD, CVSS & KEV - PunkRecordsData

> 🚀 **Export CVE vulnerability data in seconds.** Search the National Vulnerability Database by product, vendor or CVE ID and get structured rows with CVSS v3 scores and vectors, severity, CWE weakness classes, affected products (CPEs), advisory references and CISA Known Exploited Vulnerabilities status with remediation deadlines. Log4Shell comes back as CVSS 10.0, KEV since 2021-12-10, with 4 CWEs and 50 affected products. Export to CSV, Excel, JSON or XML.

The CVE Vulnerabilities Scraper reads the official NVD 2.0 API and enriches every row with the fields security teams actually triage on: severity, exploitability, whether CISA has catalogued active exploitation, and which CPE product strings are affected. Filters map 1:1 to the API: severity, KEV-only, publication date range, keyword and direct CVE lookup.

| 🎯 Target Audience | 💡 Primary Use Cases |
|---|---|
| Security and vulnerability-management teams | Prioritize patching with CVSS + KEV in one table |
| MSPs and consultants | Client-facing vulnerability reports by product stack |
| Threat intelligence analysts | Track new criticals for monitored vendors |
| GRC and compliance | Evidence of exposure review with remediation deadlines |

### 📋 What the CVE Scraper does

- **CVE records**: id, status, description, CVSS v3 base score/severity/vector, exploitability and impact subscores, CVSS v2 (legacy), publication and modification dates, source.
- **CISA KEV enrichment on every row**: known-exploited flag, date added, action-due deadline and required action, straight from NVD's integrated KEV data.
- **CWE weaknesses module**: the weakness classes behind each CVE.
- **References module**: advisory, patch and exploit links with NVD's own tags.
- **Affected products module**: CPE criteria strings (up to 50 per CVE) for stack matching.
- **Filters that mirror the API**: severity, KEV-only, date range, keyword search and exact CVE IDs.

> 💡 **Why it matters:** CVSS alone over-prioritizes; KEV alone under-covers. Triage needs both, next to the affected-product strings your asset inventory can match on. That is exactly one row of this dataset.

### 📊 Output of the CVE search

Real sample from a live run:

```json
{
  "cveId": "CVE-2021-44228",
  "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
  "cvssV3Score": 10,
  "cvssV3Severity": "CRITICAL",
  "cvssV3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
  "knownExploited": "Yes",
  "kevDateAdded": "2021-12-10",
  "kevActionDue": "2021-12-24",
  "weaknesses": ["CWE-20", "CWE-400", "CWE-502", "CWE-917"],
  "affectedCpes": ["cpe:2.3:a:apache:log4j:2.0:...", "..."],
  "error": null
}
```

### ✨ Why choose this CVE scraper

- **4 billable events** (CVEs, weaknesses, references, affected products), each switchable; measured alternatives ship 1.
- **KEV exploitation status with deadlines on every row**, not as a separate lookup.
- **CPE strings ready for asset matching**, the step most CVE exports leave out.
- **Registry-true filters** verified against the live NVD API, including the KEV-only switch.
- **Honest billing**: modules bill per CVE only when they contain real data.

### 📈 How this NVD CVE scraper compares to alternatives

Measured against the CVE actors on the Apify Store (September 2026):

| | This actor | Closest alternatives |
|---|---|---|
| Billable data events | 4 | 1 |
| CISA KEV status + deadlines | Yes, every row | No |
| CWE weaknesses / CPEs | Yes, modules | Rarely |
| KEV-only and severity filters | Yes | Partial |
| Price per 1,000 CVEs | $3.20 | $2.00 to $3.00 |

### 🚀 How to use the CVE Vulnerabilities Scraper

1. Create a free Apify account (with $5 of credit) at console.apify.com.
2. Open this actor's page and click **Try for free**.
3. Enter product/vendor keywords or CVE IDs; set severity or KEV-only if you want.
4. Toggle weaknesses, references and affected products.
5. Click **Start** and download CSV, Excel, JSON or XML.

### 💼 Business use cases

#### Patch prioritization

All criticals for your vendor list with KEV flags and deadlines; sort by kevActionDue and start there.

#### Client vulnerability reporting

Per-client product keywords, one scheduled run each, branded CSV out.

#### Threat landscape tracking

New CVEs for a technology over a date window, diffed weekly.

#### Asset exposure matching

Join `affectedCpes` against your CMDB's CPE inventory to find exposed systems.

### 🔌 Automating the CVE Scraper

Connect to **Make**, **Zapier**, **Slack**, **Airbyte**, **GitHub** or **Google Drive**: KEV alerts to your incident channel, weekly severity digests, or SIEM-side syncs via the API.

### 🌟 Beyond business use cases

- **Research:** vulnerability-trend studies with clean panel data.
- **Personal:** watch CVEs for the software you self-host.
- **Non-profit:** security advisories for under-resourced orgs.
- **Experimentation:** a structured playground over the NVD API.

### 🤖 Ask an AI assistant about this scraper

> "I need all critical CVEs for my vendor list with CVSS vectors, CWEs, affected CPEs and CISA KEV deadlines as CSV, weekly. Would the CVE Vulnerabilities Scraper on Apify (apify.com/punkrecordsdata/cve-vulnerabilities-scraper) do this?"

### ❓ Frequently Asked Questions

#### 🛡 How do I export NVD CVE data for a product to CSV?

Enter the product or vendor keyword, click Start, and download from the Storage tab.

#### 🔥 How do I find actively exploited vulnerabilities only?

Switch on "Only CISA KEV"; every returned CVE is in the Known Exploited Vulnerabilities catalog, with dateAdded and actionDue.

#### 📊 Does it include the full CVSS vector?

Yes, v3.1/v3.0 base score, severity, vector string, exploitability and impact subscores, plus legacy v2 where present.

#### 🧩 What are CWE weaknesses?

The weakness classes (e.g. CWE-502 deserialization) behind each CVE; useful for secure-coding and root-cause analytics.

#### 🖥 How do I know which products are affected?

Enable the affected-products module: up to 50 CPE criteria strings per CVE, matchable against asset inventories.

#### 🆔 Can I look up specific CVE IDs?

Yes, paste them (CVE-YYYY-NNNN) and they run before any keyword search.

#### 📅 Can I filter by publication date?

Yes; note NVD requires date ranges of 120 days or less, which the input documents.

#### 💵 Do I pay for empty modules?

No. Weaknesses, references and CPEs bill per CVE only when data exists.

#### 📦 How many CVEs can one run return?

Up to 1,000,000 on paid plans; NVD serves 2,000 per request and the actor paces itself under the no-key rate limits. Free users get a 10-CVE preview.

#### ⚙️ Does it need an NVD API key?

No. It respects the public no-key rate window (which makes very large runs slower but reliable).

#### 🕒 How fresh is the data?

Live from NVD at run time; `lastModified` per row shows each record's currency.

### 🔌 Integrate with any app

Datasets are available via the Apify API in JSON, CSV, Excel or XML, with webhooks, ready for SIEMs, Python, Sheets or BI tools.

### 🔗 Recommended Actors

- [Federal Register Scraper](https://apify.com/punkrecordsdata/federal-register-scraper) - the regulatory side of security mandates
- [Hugging Face Scraper](https://apify.com/punkrecordsdata/huggingface-hub-scraper) - audit the AI models entering your stack
- [SEC EDGAR Filings Scraper](https://apify.com/punkrecordsdata/sec-edgar-filings-scraper) - breach disclosures in 8-Ks
- [Steam Games Player Stats](https://apify.com/punkrecordsdata/steam-games-player-stats) - another live-API data product

> 💡 **Pro Tip:** browse the complete [PunkRecordsData collection](https://apify.com/punkrecordsdata) for more data tools.

**🆘 Need Help?** contact.punkrecordsdata@gmail.com

> **⚠️ Disclaimer:** independent tool, not affiliated with NIST, NVD or CISA; only publicly available data.

# Actor input Schema

## `keywords` (type: `array`):

One NVD search per keyword (product, vendor or technology, e.g. "openssl", "fortinet vpn", "wordpress plugin").

## `cveIds` (type: `array`):

Fetch exact CVEs (e.g. CVE-2021-44228). Runs in addition to keyword searches.

## `maxItems` (type: `integer`):

Free users: Limited to 10 items (preview). Paid users: Optional, max 1,000,000

## `severity` (type: `string`):

Only vulnerabilities of this severity.

## `onlyKnownExploited` (type: `boolean`):

Limit to vulnerabilities in CISA's Known Exploited Vulnerabilities catalog.

## `publishedAfter` (type: `string`):

Only CVEs published on or after this date. NVD requires the range to be 120 days or less when set.

## `publishedBefore` (type: `string`):

Only CVEs published on or before this date.

## `includeWeaknesses` (type: `boolean`):

Attach the CWE weakness classification per CVE. Billed per CVE when present.

## `includeReferences` (type: `boolean`):

Advisory and patch links with tags per CVE. Billed per CVE when present.

## `includeConfigurations` (type: `boolean`):

Affected product/version criteria (CPE strings, up to 50 per CVE). Billed per CVE when present.

## Actor input object example

```json
{
  "keywords": [
    "openssl"
  ],
  "cveIds": [],
  "maxItems": 10,
  "severity": "",
  "onlyKnownExploited": false,
  "includeWeaknesses": true,
  "includeReferences": true,
  "includeConfigurations": false
}
```

# Actor output Schema

## `overview` (type: `string`):

Key fields per CVE

## `fullData` (type: `string`):

Complete dataset with all fields

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "keywords": [
        "openssl"
    ],
    "cveIds": [],
    "maxItems": 10,
    "publishedAfter": "",
    "publishedBefore": ""
};

// Run the Actor and wait for it to finish
const run = await client.actor("punkrecordsdata/cve-vulnerabilities-scraper").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {
    "keywords": ["openssl"],
    "cveIds": [],
    "maxItems": 10,
    "publishedAfter": "",
    "publishedBefore": "",
}

# Run the Actor and wait for it to finish
run = client.actor("punkrecordsdata/cve-vulnerabilities-scraper").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "keywords": [
    "openssl"
  ],
  "cveIds": [],
  "maxItems": 10,
  "publishedAfter": "",
  "publishedBefore": ""
}' |
apify call punkrecordsdata/cve-vulnerabilities-scraper --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,punkrecordsdata/cve-vulnerabilities-scraper"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/83wvjnC5qaoZuZAmt/builds/wdZRNVqebD1yCiEXU/openapi.json
