Skip to main content
Glama

Look up a CVE in the NIST NVD

get_cve
Read-only

Look up authoritative NIST NVD data for one exact CVE ID (e.g. "CVE-2026-2950"), or browse/search NVD by keyword, CVSS severity, CWE, or a publication-date range. Every result is enriched with CISA KEV status (kev, non-null only if this CVE is a confirmed, actively-exploited-in-the-wild vulnerability — treat that as an urgent-patch signal regardless of CVSS score) and FIRST.org EPSS (epss, the probability of exploitation in the next 30 days — a better prioritization signal than CVSS severity alone, which measures impact, not likelihood). If the KEV or EPSS lookup itself fails (network/timeout/upstream outage), kev/epss come back null only because those fields have to be nullable — kevCheckFailed/epssCheckFailed (true in that case) is the real signal, and means "unknown", not "confirmed absent/unscored". For a search, a failed EPSS batch call sets epssCheckFailed on every result in that response, since one call scores every id together; kevCheckFailed is tracked per-CVE since each is looked up independently. For a single cveId lookup, if NVD has no record yet or hasn't scored it, this falls back to the raw MITRE CVE record automatically (source: "mitre" on the result) rather than returning nothing. NVD is NOT npm-scoped — unlike query_vulnerabilities/get_latest_advisories, search results can include CVEs for any ecosystem, so pass keywordSearch (e.g. the package name) to narrow it. Prefer this for the authoritative CVSS score/vector/KEV/EPSS data on a CVE already found via another tool, or when a user pastes a CVE ID/link directly; prefer get_latest_advisories for npm-specific browsing. NVD enforces a strict shared rate limit, so this tool may occasionally ask you to retry in a few seconds — do so rather than assuming failure.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
cveIdNoExact CVE ID for a single lookup, e.g. "CVE-2026-2950". When given, search filters below are ignored and should be omitted.
cweIdNoFilter by weakness type, e.g. "CWE-79"
severityNoFilter by CVSS v3 base severity
startIndexNoPagination offset for a search
keywordSearchNoFree-text search, e.g. a package or product name
publishedSinceNoPublication date range start (YYYY-MM-DD). Must be given together with publishedUntil.
publishedUntilNoPublication date range end (YYYY-MM-DD). Must be given together with publishedSince; range is capped at 120 days.
resultsPerPageNoMax results for a search (default 10, capped at 50)

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
idNo
kevNo
cvesNo
cvssNo
cwesNo
epssNo
noteNo
cveIdNo
foundNo
sourceNo
publishedNo
npmscanUrlNo
referencesNo
startIndexNo
vulnStatusNo
descriptionNo
lastModifiedNo
totalResultsNo
kevCheckFailedNo
resultsPerPageNo
epssCheckFailedNo
dateRangeClampedNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed5 schema fields changed
    • addedOutput schema / properties / cves / items / properties / epssCheckFailed
      Added value: +{
      +  "$ref": "#/properties/epssCheckFailed"
      +}
    • addedOutput schema / properties / cves / items / properties / kevCheckFailed
      Added value: +{
      +  "$ref": "#/properties/kevCheckFailed"
      +}
    • changedOutput schema / properties / cves / items / required
      Previous value: -[
      -  "id",
      -  "npmscanUrl",
      -  "vulnStatus",
      -  "description",
      -  "published",
      -  "lastModified",
      -  "cvss",
      -  "cwes",
      -  "references",
      -  "source",
      -  "kev",
      -  "epss"
      -]New value: +[
      +  "id",
      +  "npmscanUrl",
      +  "vulnStatus",
      +  "description",
      +  "published",
      +  "lastModified",
      +  "cvss",
      +  "cwes",
      +  "references",
      +  "source",
      +  "kev",
      +  "epss",
      +  "kevCheckFailed",
      +  "epssCheckFailed"
      +]
    • addedOutput schema / properties / epssCheckFailed
      Added value: +{
      +  "type": "boolean"
      +}
    • addedOutput schema / properties / kevCheckFailed
      Added value: +{
      +  "type": "boolean"
      +}
  2. Changed4 schema fields changed
    • changedInput schema / properties / cveId / description
      Previous value: -"Exact CVE ID for a single lookup, e.g. \"CVE-2026-2950\". When given, all search filters below are ignored."New value: +"Exact CVE ID for a single lookup, e.g. \"CVE-2026-2950\". When given, search filters below are ignored and should be omitted."
    • addedInput schema / properties / publishedUntil / $ref
      Added value: +"#/properties/publishedSince"
    • removedInput schema / properties / publishedUntil / pattern
      Removed value: -"^\\d{4}-\\d{2}-\\d{2}$"
    • removedInput schema / properties / publishedUntil / type
      Removed value: -"string"
  3. Changed1 schema field changed
    • changedOutput schema / (root)
      Previous value: -nullNew value: +{
      +  "$schema": "http://json-schema.org/draft-07/schema#",
      +  "additionalProperties": false,
      +  "properties": {
      +    "cveId": {
      +      "type": "string"
      +    },
      +    "cves": {
      +      "items": {
      +        "additionalProperties": false,
      +        "properties": {
      +          "cvss": {
      +            "$ref": "#/properties/cvss"
      +          },
      +          "cwes": {
      +            "$ref": "#/properties/cwes"
      +          },
      +          "description": {
      +            "$ref": "#/properties/description"
      +          },
      +          "epss": {
      +            "$ref": "#/properties/epss"
      +          },
      +          "id": {
      +            "$ref": "#/properties/id"
      +          },
      +          "kev": {
      +            "$ref": "#/properties/kev"
      +          },
      +          "lastModified": {
      +            "$ref": "#/properties/lastModified"
      +          },
      +          "npmscanUrl": {
      +            "$ref": "#/properties/npmscanUrl"
      +          },
      +          "published": {
      +            "$ref": "#/properties/published"
      +          },
      +          "references": {
      +            "$ref": "#/properties/references"
      +          },
      +          "source": {
      +            "$ref": "#/properties/source"
      +          },
      +          "vulnStatus": {
      +            "$ref": "#/properties/vulnStatus"
      +          }
      +        },
      +        "required": [
      +          "id",
      +          "npmscanUrl",
      +          "vulnStatus",
      +          "description",
      +          "published",
      +          "lastModified",
      +          "cvss",
      +          "cwes",
      +          "references",
      +          "source",
      +          "kev",
      +          "epss"
      +        ],
      +        "type": "object"
      +      },
      +      "type": "array"
      +    },
      +    "cvss": {
      +      "anyOf": [
      +        {
      +          "additionalProperties": false,
      +          "properties": {
      +            "baseScore": {
      +              "type": "number"
      +            },
      +            "baseSeverity": {
      +              "type": [
      +                "string",
      +                "null"
      +              ]
      +            },
      +            "vectorString": {
      +              "type": "string"
      +            },
      +            "version": {
      +              "enum": [
      +                "3.1",
      +                "3.0",
      +                "2.0"
      +              ],
      +              "type": "string"
      +            }
      +          },
      +          "required": [
      +            "version",
      +            "baseScore",
      +            "baseSeverity",
      +            "vectorString"
      +          ],
      +          "type": "object"
      +        },
      +        {
      +          "type": "null"
      +        }
      +      ]
      +    },
      +    "cwes": {
      +      "items": {
      +        "type": "string"
      +      },
      +      "type": "array"
      +    },
      +    "dateRangeClamped": {
      +      "type": "boolean"
      +    },
      +    "description": {
      +      "type": [
      +        "string",
      +        "null"
      +      ]
      +    },
      +    "epss": {
      +      "anyOf": [
      +        {
      +          "additionalProperties": false,
      +          "properties": {
      +            "date": {
      +              "type": "string"
      +            },
      +            "percentile": {
      +              "type": "number"
      +            },
      +            "score": {
      +              "type": "number"
      +            }
      +          },
      +          "required": [
      +            "score",
      +            "percentile",
      +            "date"
      +          ],
      +          "type": "object"
      +        },
      +        {
      +          "type": "null"
      +        }
      +      ]
      +    },
      +    "found": {
      +      "type": "boolean"
      +    },
      +    "id": {
      +      "type": "string"
      +    },
      +    "kev": {
      +      "anyOf": [
      +        {
      +          "additionalProperties": false,
      +          "properties": {
      +            "dateAdded": {
      +              "type": "string"
      +            },
      +            "dueDate": {
      +              "type": "string"
      +            },
      +            "knownRansomwareCampaignUse": {
      +              "type": "string"
      +            },
      +            "requiredAction": {
      +              "type": "string"
      +            }
      +          },
      +          "required": [
      +            "dateAdded",
      +            "dueDate",
      +            "knownRansomwareCampaignUse",
      +            "requiredAction"
      +          ],
      +          "type": "object"
      +        },
      +        {
      +          "type": "null"
      +        }
      +      ]
      +    },
      +    "lastModified": {
      +      "type": [
      +        "string",
      +        "null"
      +      ]
      +    },
      +    "note": {
      +      "type": "string"
      +    },
      +    "npmscanUrl": {
      +      "type": "string"
      +    },
      +    "published": {
      +      "type": [
      +        "string",
      +        "null"
      +      ]
      +    },
      +    "references": {
      +      "items": {
      +        "additionalProperties": false,
      +        "properties": {
      +          "source": {
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "tags": {
      +            "items": {
      +              "type": "string"
      +            },
      +            "type": "array"
      +          },
      +          "url": {
      +            "type": "string"
      +          }
      +        },
      +        "required": [
      +          "url",
      +          "source",
      +          "tags"
      +        ],
      +        "type": "object"
      +      },
      +      "type": "array"
      +    },
      +    "resultsPerPage": {
      +      "type": "number"
      +    },
      +    "source": {
      +      "enum": [
      +        "nvd",
      +        "mitre"
      +      ],
      +      "type": "string"
      +    },
      +    "startIndex": {
      +      "type": "number"
      +    },
      +    "totalResults": {
      +      "type": "number"
      +    },
      +    "vulnStatus": {
      +      "type": [
      +        "string",
      +        "null"
      +      ]
      +    }
      +  },
      +  "type": "object"
      +}
  4. Added

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Despite annotations (readOnlyHint=true, openWorldHint=true, destructiveHint=false) already covering the read-only profile, the description adds substantial behavioral disclosure: the automatic MITRE fallback for unscored CVEs (`source: "mitre"`), the precise nullable-field semantics (`kev`/`epss` null means 'unknown' via `kevCheckFailed`/`epssCheckFailed`, not 'confirmed absent'), the distinction between batch EPSS failure vs per-CVE KEV failure, and the shared NVD rate limit prompting retries. This goes well beyond what annotations convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The core purpose is front-loaded in the first sentence, and the dense follow-on sentences earn their place given the tool's complexity: dual lookup/search modes, nullable-field error semantics, fallback routing, and rate limiting all need explanation. It is verbose, and the educational aside about CVSS measuring impact vs likelihood is slightly extraneous to tool invocation, preventing a 5, but nothing is filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a tool with 8 parameters, 0 required, an output schema, and annotations, the description covers every operational concern an agent needs: mode selection, sibling routing, fallback behavior, null/error-flag interpretation, rate-limit handling, and ecosystem scope. With the output schema present, the description rightly does not need to explain return values. Nothing material is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the baseline is 3. The description adds value beyond the schema by explaining parameter interplay: that cveId supersedes search filters, that keywordSearch (e.g. a package name) should be used to narrow broad ecosystem-wide search results, and that severity filtering alone is a weaker prioritization signal than the returned EPSS score. This crosses the baseline into genuinely helpful parameter guidance.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb+resource pairing: 'Look up authoritative NIST NVD data for one exact CVE ID... or browse/search NVD by keyword, CVSS severity, CWE, or a publication-date range.' It explicitly distinguishes itself from siblings: 'NVD is NOT npm-scoped — unlike query_vulnerabilities/get_latest_advisories' and 'prefer get_latest_advisories for npm-specific browsing.' An agent can tell exactly what this tool does and how it differs from its siblings.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives explicit when-to-use and when-not-to-use guidance: 'Prefer this for the authoritative CVSS score/vector/KEV/EPSS data on a CVE already found via another tool, or when a user pastes a CVE ID/link directly; prefer get_latest_advisories for npm-specific browsing.' It also names the alternative (query_vulnerabilities/get_latest_advisories) and explains the ecosystem-scope reason for choosing the sibling.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources