Skip to main content
Glama

search_cves

Read-onlyIdempotent

Search the catalog. Free text (q) and/or structured filters: vendor (slug), cwe (CWE-nnn), technique (ATT&CK id, such as T1190), year ("2024,2025"), sev ("critical,high"), kev (0|1), kev_from / kev_to (ISO days, half-open CISA listing window; imply kev=1), kev_vendor (the CISA vendorProject string verbatim, such as "Microsoft"), ransomware (0|1), detect (0|1, a detection signal we track), fix (0|1; fix=0 means the fix status was computed and this dataset holds no actionable vendor fix), automatable (0|1, CISA SSVC Automatable; 1=yes, 0=CISA assessed no, unassessed CVEs match neither), sighted (7|30: a named sensor network recorded the CVE in the last 7 or 30 days, a field sighting; presence per day, apart from the exploitation claims), malware (0|1: a published source ties a named malware family, tool, campaign or ransomware group to the CVE), watch (0|1: on KEV Watch at tier 1 or 2, reported exploited by trackers other than CISA and outside CISA KEV), epss_gte (0..1), ti (total|partial: CISA SSVC Technical impact, for CVEs with a CISA assessment held), triage_flag (0|1: CISA's forensic triage flag on the KEV entry), ssvc (0|1; ssvc=0 selects rows with no CISA SSVC assessment held), bod (3df|3d|14d|60d|fsu: the BOD 26-04 Table 1 read at the stated exposure, with exposed 0|1, default 1; a mapping at that exposure, and an agency's timeline still needs its own enumeration date), eco (OSS ecosystem, such as npm or PyPI), pkg (pkg_key, such as npm/lodash; for ranges use query_package), page, limit (1..50). Filter-only queries return the /browse slice ordered KEV-first then EPSS.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
qNo
tiNoCISA SSVC Technical impact, for CVEs with a CISA assessment held
bodNoBOD 26-04 Table 1 read at the stated exposure: a mapping of KEV status and CISA SSVC values to a timeline key at that exposure
cweNo
ecoNo
fixNo
kevNo
pkgNo
sevNo
pageNo
ssvcNoWhether this dataset holds a CISA SSVC assessment for the CVE
yearNo
limitNo
watchNoOn KEV Watch at tier 1 or 2: reported as exploited by trackers other than CISA, outside CISA KEV
detectNo
kev_toNoISO day, exclusive upper bound on the CISA listing date
vendorNo
chainedNoIn a known exploit chain: a cited source reports the CVE was used together with another CVE in one exploit chain
exposedNoThe exposure branch for bod: 1 publicly exposed (default), 0 internal
malwareNoA published source ties a named malware family, tool, campaign or ransomware group to the CVE
sightedNoField sighting window in days: a named sensor network recorded the CVE within the last 7 or 30 days
epss_gteNo
kev_fromNoISO day, inclusive lower bound on the CISA listing date
techniqueNoATT&CK technique id, such as T1190 or T1059.001
kev_vendorNoCISA's vendorProject, verbatim (for example 'Palo Alto Networks')
ransomwareNo
automatableNo
triage_flagNoCISA's forensic triage flag on the KEV entry (BOD 26-04)
chainabilityNoOn KCV Watch™: the CVE carries at least one chain candidate at tier A or B, a pair whose extracted exploit capabilities connect or whose records tie the two CVEs together; a candidate is not a confirmed chain

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • changedInput schema / properties / chainability / description
      Previous value: -"On KCV Watch™: the CVE carries at least one chain candidate, a same-product pair whose extracted exploit capabilities connect, derived from exploit-capability analysis; a candidate is not a confirmed chain"New value: +"On KCV Watch™: the CVE carries at least one chain candidate at tier A or B, a pair whose extracted exploit capabilities connect or whose records tie the two CVEs together; a candidate is not a confirmed chain"
  2. Changed5 schema fields changed
    • addedInput schema / properties / bod
      Added value: +{
      +  "description": "BOD 26-04 Table 1 read at the stated exposure: a mapping of KEV status and CISA SSVC values to a timeline key at that exposure",
      +  "enum": [
      +    "3df",
      +    "3d",
      +    "14d",
      +    "60d",
      +    "fsu"
      +  ],
      +  "type": "string"
      +}
    • addedInput schema / properties / exposed
      Added value: +{
      +  "description": "The exposure branch for bod: 1 publicly exposed (default), 0 internal",
      +  "enum": [
      +    "0",
      +    "1"
      +  ],
      +  "type": "string"
      +}
    • addedInput schema / properties / ssvc
      Added value: +{
      +  "description": "Whether this dataset holds a CISA SSVC assessment for the CVE",
      +  "enum": [
      +    "0",
      +    "1"
      +  ],
      +  "type": "string"
      +}
    • addedInput schema / properties / ti
      Added value: +{
      +  "description": "CISA SSVC Technical impact, for CVEs with a CISA assessment held",
      +  "enum": [
      +    "total",
      +    "partial"
      +  ],
      +  "type": "string"
      +}
    • addedInput schema / properties / triage_flag
      Added value: +{
      +  "description": "CISA's forensic triage flag on the KEV entry (BOD 26-04)",
      +  "enum": [
      +    "0",
      +    "1"
      +  ],
      +  "type": "string"
      +}
  3. Changed2 schema fields changed
    • changedInput schema / properties / chainability / description
      Previous value: -"KCV Watch™ tier: a structural pattern (same product, published within 365 days or within 30 days inside the largest products, complementary weakness class) published with its measured rate; a tier is not a confirmed chain"New value: +"On KCV Watch™: the CVE carries at least one chain candidate, a same-product pair whose extracted exploit capabilities connect, derived from exploit-capability analysis; a candidate is not a confirmed chain"
    • changedInput schema / properties / chainability / enum
      Previous value: -[
      -  "1",
      -  "2",
      -  "3"
      -]New value: +[
      +  "0",
      +  "1"
      +]
  4. Changed1 schema field changed
    • changedInput schema / properties / chainability / description
      Previous value: -"KCV Watch™ tier: a structural pattern (same product, published within 30 or 90 days, complementary weakness class) published with its measured rate; a tier is not a confirmed chain"New value: +"KCV Watch™ tier: a structural pattern (same product, published within 365 days or within 30 days inside the largest products, complementary weakness class) published with its measured rate; a tier is not a confirmed chain"
  5. Changed1 schema field changed
    • changedInput schema / properties / chainability / description
      Previous value: -"Chainability™ watch tier: a structural pattern (same product, published within 30 or 90 days, complementary weakness class) published with its measured rate; a tier is not a confirmed chain"New value: +"KCV Watch™ tier: a structural pattern (same product, published within 30 or 90 days, complementary weakness class) published with its measured rate; a tier is not a confirmed chain"
  6. Changed2 schema fields changed
    • addedInput schema / properties / chainability
      Added value: +{
      +  "description": "Chainability™ watch tier: a structural pattern (same product, published within 30 or 90 days, complementary weakness class) published with its measured rate; a tier is not a confirmed chain",
      +  "enum": [
      +    "1",
      +    "2",
      +    "3"
      +  ],
      +  "type": "string"
      +}
    • addedInput schema / properties / chained
      Added value: +{
      +  "description": "In a known exploit chain: a cited source reports the CVE was used together with another CVE in one exploit chain",
      +  "enum": [
      +    "0",
      +    "1"
      +  ],
      +  "type": "string"
      +}
  7. Changed2 schema fields changed
    • addedInput schema / properties / malware
      Added value: +{
      +  "description": "A published source ties a named malware family, tool, campaign or ransomware group to the CVE",
      +  "enum": [
      +    "0",
      +    "1"
      +  ],
      +  "type": "string"
      +}
    • addedInput schema / properties / watch
      Added value: +{
      +  "description": "On KEV Watch at tier 1 or 2: reported as exploited by trackers other than CISA, outside CISA KEV",
      +  "enum": [
      +    "0",
      +    "1"
      +  ],
      +  "type": "string"
      +}
  8. Changed1 schema field changed
    • addedInput schema / properties / sighted
      Added value: +{
      +  "description": "Field sighting window in days: a named sensor network recorded the CVE within the last 7 or 30 days",
      +  "enum": [
      +    "7",
      +    "30"
      +  ],
      +  "type": "string"
      +}
  9. Changed2 schema fields changed
    • changedInput schema / properties / kev_vendor / description
      Previous value: -"CISA's vendorProject, verbatim (e.g. 'Palo Alto Networks')"New value: +"CISA's vendorProject, verbatim (for example 'Palo Alto Networks')"
    • changedInput schema / properties / technique / description
      Previous value: -"ATT&CK technique id, e.g. T1190 or T1059.001"New value: +"ATT&CK technique id, such as T1190 or T1059.001"
  10. Changed3 schema fields changed
    • addedInput schema / properties / kev_from
      Added value: +{
      +  "description": "ISO day, inclusive lower bound on the CISA listing date",
      +  "type": "string"
      +}
    • addedInput schema / properties / kev_to
      Added value: +{
      +  "description": "ISO day, exclusive upper bound on the CISA listing date",
      +  "type": "string"
      +}
    • addedInput schema / properties / kev_vendor
      Added value: +{
      +  "description": "CISA's vendorProject, verbatim (e.g. 'Palo Alto Networks')",
      +  "type": "string"
      +}
  11. Changed2 schema fields changed
    • addedInput schema / properties / automatable
      Added value: +{
      +  "enum": [
      +    "0",
      +    "1"
      +  ],
      +  "type": "string"
      +}
    • addedInput schema / properties / technique
      Added value: +{
      +  "description": "ATT&CK technique id, e.g. T1190 or T1059.001",
      +  "type": "string"
      +}
  12. Changed2 schema fields changed
    • addedInput schema / properties / eco
      Added value: +{
      +  "type": "string"
      +}
    • addedInput schema / properties / pkg
      Added value: +{
      +  "type": "string"
      +}
  13. First observed

TDQS

A3.9/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already establish readOnly/idempotent/closed-world, so the lower bar applies, and the description still adds real behavior: the result ordering (KEV-first then EPSS) for filter-only queries, the default for exposed (1), the half-open kev window, and the special meaning of fix=0 and automatable=0/unassessed. This is meaningful disclosure beyond the annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Purpose is front-loaded in a short first clause, but the remainder is a single dense run-on wall of parenthetical clauses that is hard to scan. For 29 parameters the length is arguably justified, yet the structure could be broken into a scannable list without losing content.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 29-parameter, no-output-schema search tool with readOnly annotations, the description covers facet semantics, defaults, and result ordering well enough to invoke correctly. Minor gaps (pagination behavior, whether page defaults, exact text-search fields) remain, but nothing critical is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is only 48%, so the description must carry the load, and it does: nearly every parameter's matching semantics are spelled out (kev_from/kev_to bounds and implied kev=1, sighted window meaning, automatable tri-state, bod exposure mapping plus the enumeration-date caveat, watch tiers, ssvc=0 meaning 'no assessment held'). This adds substantial meaning the schema alone lacks.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

Opens with 'Search the catalog' and immediately clarifies it is free-text and structured filtering over CVEs via the enumerated facets, so the verb+resource is discernible. It even routes package-range needs to query_package, giving partial sibling differentiation. The only weakness is that 'the catalog' is never named as a CVE catalog explicitly.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is one explicit alternative ('for ranges use query_package') and an implicit usage hint ('filter-only queries return the /browse slice'). However there is no clear statement of when to reach for this tool versus get_cve, get_chains, or table1_read, so usage is implied rather than specified.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources