Skip to main content
Glama
d4ngkh04w

NVD/NIST MCP server

by d4ngkh04w

Related Servers

Alternatives to NVD/NIST MCP server

No user-submitted related servers found.

    Related Servers

    • A
      license
      A
      quality
      C
      maintenance
      MCP server that provides tools to search, filter, and retrieve CVE data from the NVD API, including by ID, keyword, severity, and recency.
      4
      MIT
    • F
      license
      A
      quality
      B
      maintenance
      Enables querying and analyzing a legacy, file-based vulnerability registry via MCP tools for CVE lookup, search, vendor navigation, and aggregate statistics.
      5
      -
    • A
      license
      Not graded
      quality
      D
      maintenance
      A Model Context Protocol (MCP) server for querying the NIST National Vulnerability Database (NVD) API, enabling search and retrieval of CVE details, temporal context, and KEV catalog entries.
      14
      MIT
    • A
      license
      B
      quality
      D
      maintenance
      A Model Context Protocol (MCP) server for querying the CVE-Search API. This server provides comprehensive access to CVE-Search, browse vendor and product、get CVE per CVE-ID、get the last updated CVEs.
      6
      107
      MIT
    • A
      license
      Not graded
      quality
      C
      maintenance
      MCP server for searching NIST's National Vulnerability Database, enabling retrieval of recent CVEs, keyword/CPE/CWE searches, and detailed CVE information.
      Apache 2.0

    TDQS

    A4.3/5.0

    Scored across 10 tools

    Disambiguation4/5

    Tool names and descriptions clearly delineate resource+action, but nvd_get_recent_cves and nvd_get_modified_cves are nearly identical except for ordering, and nvd_get_cve, nvd_get_cve_summary, and nvd_get_cves all target CVE records with overlapping semantics. The descriptions do distinguish scope and detail level, but an agent could easily misselect between the full, summary, and batch variants without careful reading.

    Naming Consistency5/5

    Every tool follows a consistent nvd_ verb_noun pattern (get, search, and entity names like cve, cves, cpe). Variants like nvd_get_cve_summary and nvd_get_cve_history extend the base name predictably. No mixed conventions or inconsistent casing.

    Tool Count5/5

    Ten tools is well within the sweet spot for a domain-specific API wrapper. Each tool maps to a distinct NVD endpoint or use case (single record, batch, search, history, CPE dictionary, CPE matches), so the surface feels scoped rather than padded.

    Completeness4/5

    The surface covers CVE retrieval (single, batch, summary, search, history, recent, modified) and CPE lookup (search, get, matches), which is core NVD functionality. Missing operations like CVE creation or modification don't apply since NVD is read-only, but there is no tool for bulk CPE dictionary listing or NVD API status, which could be minor gaps for some workflows.

    Maintenance

    ActivityMaintained
    ResponsivenessNo issues