CVE API

JSON over HTTPS. No API key, no account, no signup. Everything below works from a terminal right now.

Try it
curl "https://vuln.mlab.sh/api/v1/cve/CVE-2021-44228"

Returns the full record: CVSS score and vector breakdown, CWEs, EPSS, CISA KEV status with its remediation deadline, affected products and references.

Endpoints
Endpoint What it returns
GET /api/v1/cve Search. q, severity, dateStart, dateEnd, minCvss, kevOnly, exact, page, limit (max 100). Actively-exploited matches lead the first page, then newest first.
GET /api/v1/cve/{id} One CVE, in full. Served from a multi-source pool, so it keeps working when any single upstream is throttled.
GET /api/v1/cve/latest The newest CVEs, published in the last 7 days.
GET /api/v1/cve/dump Bulk export for a date range, filtered by minimum CVSS. Requires dateStart and dateEnd, max 31 days apart.
POST /api/v2/query OSV-compatible, package-scoped lookup. Send an OSV request body, get OSV's native {"vulns": […]} back — usable as a drop-in source for any OSV client.
POST /api/v2/scan Whole-manifest SBOM scan in one request, instead of one call per package.
GET /api/v1/stats Corpus totals and the severity breakdown.
GET /api/v1/sources Live health of every upstream: token budget, cooldowns, request counters.
GET /rss · /feed RSS. Accepts the same filters as search, so you can subscribe to a query.
GET /export/csv CSV export of a search.
Limits

Read endpoints are unmetered and cached at the edge; use them freely.

/api/v1/cve/dump is the one exception: 12 calls per hour per IP, 15 seconds between calls, and a 31-day maximum range. Exceeding it returns 429 with Retry-After.

One-shot /scan takes 40 dependencies anonymously, 512 signed in.

Reading a failure

Status codes are meant to be acted on, which matters if you gate a build on them:

200 with an empty list means no known vulnerabilities. 502 and 503 mean an upstream is down or throttled.

Never treat a 5xx as "clean" — it is an outage, not an answer.

Full reference

Every parameter, response field and error, with worked examples.

Read the docs