NIST NVD MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| search_cvesC | Search CVEs with comprehensive filtering options including keywords, CVSS scores, dates, and more |
| get_cveA | Get detailed information about a specific CVE by its ID |
| search_cves_by_cpeB | Find CVEs affecting specific products using Common Platform Enumeration (CPE) |
| search_cves_by_cvssC | Search CVEs by CVSS vector strings and severity ratings |
| search_recent_cvesB | Get recently published CVEs within a specified date range |
| search_modified_cvesB | Get CVEs that were recently modified within a specified date range |
| get_cve_change_historyA | Get change history for a specific CVE or all changes within a date range |
| search_high_priority_cvesB | Search for high-priority CVEs using multiple risk indicators |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 8 tools
Each tool targets a distinct search or retrieval operation: specific CVE by ID, change history, comprehensive search, CPE-based, CVSS-based, high-priority, modified, or recent. No overlap in functionality.
All tool names begin with 'get' or 'search', followed by a descriptive noun phrase in snake_case. The pattern is uniform across all 8 tools.
8 tools is an appropriate scope for a CVE database server, providing essential retrieval operations without being too few or excessive.
The server covers all typical read operations for CVE data: single lookup, history, and multiple search dimensions (keywords, CPE, CVSS, priority, modification date, publication date). No gaps for its read-only purpose.