cve-search_mcp
[](https://mseep.ai/app/roadwy-cve-search-mcp)
## CVE-Search MCP Server
----

<a href="https://glama.ai/mcp/servers/@roadwy/cve-search_mcp">
<img width="380" height="200" src="https://glama.ai/mcp/servers/@roadwy/cve-search_mcp/badge" alt="cve-search_mcp MCP server" />
</a>
A Model Context Protocol (MCP) server for querying the [CVE-Search](https://www.cve-search.org/api/) API. This server provides comprehensive access to CVE-Search, browse vendor and product、get CVE per CVE-ID、get the last updated CVEs.
## Requirements
- python 3.10+
- uv
- Cline、Roo Code etc
## Tools
- To get a JSON with all the vendors
- To get a JSON with all the products associated to a vendor
- To get a JSON with all the vulnerabilities per vendor and a specific product
- To get a JSON of a specific CVE ID
- To get a JSON of the last 30 CVEs including CAPEC, CWE and CPE expansions
- To get more information about the current databases in use and when it was updated
## Quick Start
1. Git clone this repository
```
git clone https://github.com/roadwy/cve-search_mcp.git
```
2. Install the dependencies
```
cd cve-search_mcp
uv sync
```
3.Add to your mcp client(vscode with cline/roo code) configuration file, modify the `"YOU_CVE_SEARCH_MCP_DIR_PATH"` as you self dir.
```
"cve-search_mcp": {
"command": "uv",
"args": [
"--directory",
"YOU_CVE_SEARCH_MCP_DIR_PATH",
"run",
"main.py"
],
"disabled": false,
"autoApprove": []
}
```
## Reference
https://github.com/cve-search/cve-searchTDQS
Scored across 6 tools
Each tool has a clearly distinct purpose targeting specific CVE-related queries: searching by ID, checking database status, retrieving recent CVEs, finding vulnerabilities by vendor/product, listing products per vendor, and listing all vendors. There is no overlap in functionality, making tool selection unambiguous.
All tools follow a consistent 'vul_' prefix and snake_case naming pattern (e.g., vul_cve_search, vul_vendor_products), with clear and descriptive names that indicate the resource and action. This uniformity enhances readability and predictability.
With 6 tools, the server is well-scoped for CVE search and vulnerability management, covering key operations like lookup, updates, recent entries, and vendor/product queries. Each tool serves a specific, non-redundant purpose, making the count appropriate for the domain.
The tool set provides comprehensive coverage for querying CVE data, including searches by ID, vendor, product, and recent entries, plus database status. A minor gap is the lack of tools for filtering or sorting beyond basic queries, but core workflows are fully supported without dead ends.