Skip to main content
Glama

Related Servers

Alternatives to CVE MCP Server

No user-submitted related servers found.

    Related Servers

    • F
      license
      A
      quality
      D
      maintenance
      An MCP server that brings NIST National Vulnerability Database (NVD) intelligence directly into Claude, enabling CVE lookup, product search, and prioritized risk assessment via natural language.
      3
      -
    • A
      license
      A
      quality
      B
      maintenance
      Unifies NVD, EPSS, CISA KEV, GitHub Advisory, and OSV into a single MCP server, enabling AI agents to query vulnerability intelligence conversationally with 23 tools for incident response, prioritization, dependency audits, and threat monitoring.
      41
      245 npm
      28
      MIT
    • A
      license
      Not graded
      quality
      B
      maintenance
      MCP server for querying live CISA KEV, EPSS, and enriched vulnerability feeds with full provenance. Enables natural-language access to auditable security-intelligence data from Claude Desktop and other MCP clients.
      MIT
    • A
      license
      A
      quality
      A
      maintenance
      An MCP server for vulnerability management that provides tools for automated severity and CWE classification using NLP models. It enables AI agents to query the Vulnerability Lookup API for detailed CVE information and search for security vulnerabilities across various sources.
      16
      42
      AGPL 3.0
    • A
      license
      C
      quality
      C
      maintenance
      AI-powered security scanning MCP server that exposes 25+ professional tools, enabling penetration testing and security assessments through natural language interaction with AI agents like Claude Desktop.
      31
      MIT

    TDQS

    B3.1/5.0

    Scored across 28 tools

    Disambiguation3/5

    Most tools have distinct purposes, but there is redundancy: check_kev duplicates KEV status already in lookup_cve, and get_cve_summary overlaps lookup_cve plus EPSS/KEV. Overall, however, the majority of tools serve clearly different functions.

    Naming Consistency2/5

    Tool names mix multiple verb styles (lookup, search, check, get, parse, scan) without a consistent mapping between verb and action type. For example, check_kev, lookup_cve, and get_cve_summary use different verbs for overlapping CVE data access, making the API harder to predict.

    Tool Count2/5

    28 tools is heavy, and some are redundant (check_kev duplicates part of lookup_cve; get_cve_summary assembles existing tools). The number feels inflated for the actual domain and could be consolidated.

    Completeness4/5

    The toolset covers CVE lookup, search, EPSS, KEV, CVSS parsing, vendor advisories, exploits, ATT&CK mapping, package scanning, plus general threat intel on IPs, domains, URLs, hashes, and ransomware. Main gaps are modest (e.g., no CPE matching or Exploit-DB search), but the domain is well covered.

    Maintenance

    ActivityInactive
    ResponsivenessWithin a week