Search CVEs
nvd_search_cvesSearch CVE records using NVD 2.0 filters such as keyword, CVE IDs, CPE, CWE, CVSS, dates, and CISA KEV to find vulnerabilities and page through results.
Instructions
Search CVE records with the NVD 2.0 filters: keyword, CVE IDs, CPE name or match string, CWE, source identifier, vuln statuses, published/last-modified windows, KEV window, CVSS metrics and CERT flags. Rules: keywordExactMatch requires keyword; isVulnerable requires cpeName; cpeName and virtualMatchString are mutually exclusive; date windows are limited to 120 days. NVD evaluates every filter, so totalResults is the exact upstream total. Cached for 15 minutes; paginate by passing pagination.nextCursor back as cursor with the same filters and pageSize.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| kev | No | ||
| cvss | No | CVSS metric filter; requires at least one of severity or metrics | |
| cweId | No | CWE identifier such as CWE-79 | |
| cursor | No | Opaque signed cursor from the previous page: pass the response's pagination.nextCursor. Never build it by hand; it expires after 30 minutes and is bound to the filters, pageSize and date window. | |
| cveIds | No | Restrict the search to these CVE identifiers | |
| cpeName | No | CPE name filter; translates to the upstream cpeName parameter | |
| hasOval | No | Only CVEs with OVAL definitions | |
| keyword | No | Keyword matched against CVE descriptions | |
| pageSize | No | Page size (default 20, maximum 50) | |
| published | No | Filter on the published date (max 120 days) | |
| noRejected | No | Exclude rejected CVEs (upstream noRejected) | |
| hasCertNotes | No | Only CVEs with CERT notes | |
| isVulnerable | No | Only CVEs where cpeName is marked vulnerable; requires cpeName, incompatible with virtualMatchString | |
| lastModified | No | Filter on the last-modified date (max 120 days) | |
| vulnStatuses | No | Vulnerability statuses (Received, Awaiting Analysis, Undergoing Analysis, Analyzed, Modified, Deferred, Rejected). Spaced and camel-case spellings are both canonicalized, and the filter is applied by NVD. | |
| hasCertAlerts | No | Only CVEs with CERT alerts | |
| sourceIdentifier | No | CNA or NVD source identifier, for example secalert@redhat.com | |
| keywordExactMatch | No | Require the exact keyword phrase (requires keyword) | |
| virtualMatchString | No | CPE match string (supports wildcards and version ranges); mutually exclusive with cpeName |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| meta | Yes | Cache/freshness metadata; warnings carries stale-fallback and truncation notices | |
| items | Yes | ||
| pagination | Yes | Pagination block; nextCursor is null on the last page |