# National Vulnerability Database API

> National Vulnerability Database returns vulnerability searches and CVE details, available as a workflow and API.

National Vulnerability Database (NVD) searches vulnerabilities by required product or vendor name, with optional severity and date filters. Get vulnerability returns a CVE’s risk, affected products, weakness, attack conditions, dates, and references; it needs a CVE number.

- Page: https://fous.com/tools/national-vulnerability-database
- Handle: `@national-vulnerability-database`
- Category: [Security](https://fous.com/tools/category/security)
- Source website: https://nvd.nist.gov
- Last verified: Sep 30, 2026

## Methods

### Get vulnerability

Operation `get_vulnerability`, version 1. 1 credit per completed call. Failed calls without a completed billing receipt are free; completed work can remain charged if delivery is interrupted.

Get one CVE’s description, risk score, attack conditions, affected products, weakness, exploitation listing, dates, and references. The exploitation flag reflects CISA’s known-exploited catalog; a no does not rule out exploitation. Some affected-product matches require other products or conditions.

**Input**

| Field | Type | Required | Example | Description |
|---|---|---|---|---|
| `cve_number` | string | yes | `"2023-23397"` | The vulnerability number, such as CVE-2021-44228, 2021-44228, or cve-2021-44228. |

**Input schema**

```json
{
  "type": "object",
  "required": [
    "cve_number"
  ],
  "properties": {
    "cve_number": {
      "type": "string",
      "description": "The vulnerability number, such as CVE-2021-44228, 2021-44228, or cve-2021-44228.",
      "examples": [
        "2023-23397",
        "CVE-2021-44228",
        "cve-2024-3094"
      ]
    }
  },
  "additionalProperties": false,
  "examples": [
    {
      "cve_number": "2023-23397"
    },
    {
      "cve_number": "CVE-2021-44228"
    },
    {
      "cve_number": "cve-2024-3094"
    }
  ]
}
```

**Output**

| Field | Type | Example | Description |
|---|---|---|---|
| `nvd_link` | string | `"https://nvd.nist.gov/vuln/detail/CVE-2023-23397"` |  |
| `severity` | string or null | `"Critical"` |  |
| `cve_number` | string | `"CVE-2023-23397"` |  |
| `cvss_score` | number or null | `9.8` |  |
| `cwe_number` | string or null | `"CWE-294"` |  |
| `references` | array |  |  |
| `references[].link` | string | `"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397"` |  |
| `references[].source` | string | `"secure@microsoft.com"` |  |
| `cvss_vector` | string or null | `"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"` |  |
| `description` | string or null | `"Microsoft Outlook Elevation of Privilege Vulnerability"` |  |
| `cvss_version` | string or null | `"3.1"` |  |
| `attack_method` | string or null | `"over the network, no login needed, no user action"` |  |
| `weakness_type` | string or null | `"Authentication Bypass by Capture-replay"` |  |
| `published_date` | string or null | `"2023-03-14"` |  |
| `affected_products` | array |  |  |
| `last_modified_date` | string or null | `"2026-06-17"` |  |
| `known_exploited_in_the_wild` | boolean | `true` |  |

**Example input**

```json
{
  "cve_number": "2023-23397"
}
```

**Example output**

```json
{
  "nvd_link": "https://nvd.nist.gov/vuln/detail/CVE-2023-23397",
  "severity": "Critical",
  "cve_number": "CVE-2023-23397",
  "cvss_score": 9.8,
  "cwe_number": "CWE-294",
  "references": [
    {
      "link": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397",
      "source": "secure@microsoft.com"
    },
    {
      "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-23397",
      "source": "www.cisa.gov"
    }
  ],
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "description": "Microsoft Outlook Elevation of Privilege Vulnerability",
  "cvss_version": "3.1",
  "attack_method": "over the network, no login needed, no user action",
  "weakness_type": "Authentication Bypass by Capture-replay",
  "published_date": "2023-03-14",
  "affected_products": [
    "Microsoft 365 apps: version unspecified",
    "Microsoft office: version 2019",
    "Microsoft office long term servicing channel: version 2021"
  ],
  "last_modified_date": "2026-06-17",
  "known_exploited_in_the_wild": true
}
```

### Search vulnerabilities

Operation `search_vulnerabilities`, version 1. 1 credit per completed call. Failed calls without a completed billing receipt are free; completed work can remain charged if delivery is interrupted.

Find known vulnerabilities matching a product or vendor name, newest first. Includes published date, severity, affected versions when reported, and whether each CVE appears in CISA’s known exploited catalog. Keyword matches may include related products.

**Input**

| Field | Type | Required | Example | Description |
|---|---|---|---|---|
| `product` | string | yes | `"Apache Tomcat"` | Product and/or vendor name, such as Apache Tomcat. |
| `severity` | string | no | `"critical"` | Severity to include, such as critical; any includes unrated flaws. |
| `max_results` | integer | no | `3` | Maximum number of results, such as 20 (up to 100). |
| `published_after` | string | no | `"2025-01-01"` | Include vulnerabilities published on or after this date, such as 2025-01-01. |

**Input schema**

```json
{
  "type": "object",
  "required": [
    "product"
  ],
  "properties": {
    "product": {
      "type": "string",
      "minLength": 1,
      "description": "Product and/or vendor name, such as Apache Tomcat.",
      "examples": [
        "Apache Tomcat",
        "Zzxzznoexistentbrand98765",
        "Fortinet FortiOS"
      ]
    },
    "severity": {
      "enum": [
        "any",
        "low",
        "medium",
        "high",
        "critical"
      ],
      "type": "string",
      "default": "any",
      "description": "Severity to include, such as critical; any includes unrated flaws.",
      "examples": [
        "critical"
      ]
    },
    "max_results": {
      "type": "integer",
      "default": 20,
      "maximum": 100,
      "minimum": 1,
      "description": "Maximum number of results, such as 20 (up to 100).",
      "x-fous-developer": true,
      "examples": [
        3,
        5
      ]
    },
    "published_after": {
      "type": "string",
      "format": "date",
      "description": "Include vulnerabilities published on or after this date, such as 2025-01-01.",
      "examples": [
        "2025-01-01"
      ]
    }
  },
  "additionalProperties": false,
  "examples": [
    {
      "product": "Apache Tomcat"
    },
    {
      "product": "Zzxzznoexistentbrand98765",
      "max_results": 3
    },
    {
      "product": "Fortinet FortiOS",
      "severity": "critical",
      "max_results": 5,
      "published_after": "2025-01-01"
    }
  ]
}
```

**Output**

| Field | Type | Example | Description |
|---|---|---|---|
| `vulnerabilities` | array |  |  |
| `vulnerabilities[].nvd_link` | string | `"https://nvd.nist.gov/vuln/detail/CVE-2026-86247"` | NVD vulnerability page. |
| `vulnerabilities[].severity` | string | `"High"` | Severity in words, or Unknown when unrated. |
| `vulnerabilities[].cve_number` | string | `"CVE-2026-86247"` | CVE identifier. |
| `vulnerabilities[].cvss_score` | number or null | `7.4` | CVSS base score from 0 to 10 when available. |
| `vulnerabilities[].description` | string or null | `"Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requiremen` | English-language vulnerability description. |
| `vulnerabilities[].published_date` | string | `"2026-09-23"` | Publication date. |
| `vulnerabilities[].affected_versions` | string or null | `"Apache Software Foundation Apache Tomcat Native: from 2.0.0 through 2.0.15; Apache Software Foundation Apache Tomcat Na` | Affected product versions when reported. |
| `vulnerabilities[].known_exploited_in_the_wild` | boolean | `false` | Whether this CVE appears in the CISA known exploited catalog. |

**Example input**

```json
{
  "product": "Apache Tomcat"
}
```

**Example output**

```json
{
  "vulnerabilities": [
    {
      "nvd_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-86247",
      "severity": "High",
      "cve_number": "CVE-2026-86247",
      "cvss_score": 7.4,
      "description": "Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations.\n\n\n\nThis issue affects Apache Tomcat…",
      "published_date": "2026-09-23",
      "affected_versions": "Apache Software Foundation Apache Tomcat Native: from 2.0.0 through 2.0.15; Apache Software Foundation Apache Tomcat Native: from 1.3.0 through 1.3.8",
      "known_exploited_in_the_wild": false
    },
    {
      "nvd_link": "https://nvd.nist.gov/vuln/detail/CVE-2026-86246",
      "severity": "Critical",
      "cve_number": "CVE-2026-86246",
      "cvss_score": 9.1,
      "description": "Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default  including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE…",
      "published_date": "2026-09-23",
      "affected_versions": "Apache Software Foundation Apache Tomcat Native: from 2.0.0 through 2.0.15; Apache Software Foundation Apache Tomcat Native: from 1.3.0 through 1.3.8",
      "known_exploited_in_the_wild": false
    }
  ]
}
```

## Quick start

Replace `YOUR_API_KEY` with a Fous API key. To create one, open Developers at the bottom of Fous Studio, turn on Developer mode, then go to API keys (https://app.fous.com/keys). Change the values in `input` to run the same tool on new data.

```bash
curl 'https://api.fous.com/v1/query' \
  --fail-with-body --silent --show-error --max-time 180 \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H 'Content-Type: application/json' \
  --data-raw '{
  "api": "@national-vulnerability-database",
  "visibility": "public",
  "operation": "get_vulnerability",
  "version": 1,
  "input": {
    "cve_number": "2023-23397"
  },
  "response": {
    "format": "json"
  }
}'
```

```python
# Save as fous.py and run with python3 fous.py. No packages needed.
import json
import urllib.error
import urllib.request

api_key = "YOUR_API_KEY"

body = json.loads("{\n  \"api\": \"@national-vulnerability-database\",\n  \"visibility\": \"public\",\n  \"operation\": \"get_vulnerability\",\n  \"version\": 1,\n  \"input\": {\n    \"cve_number\": \"2023-23397\"\n  },\n  \"response\": {\n    \"format\": \"json\"\n  }\n}")
request = urllib.request.Request(
    "https://api.fous.com/v1/query",
    data=json.dumps(body).encode("utf-8"),
    headers={
        "Authorization": f"Bearer {api_key}",
        "Content-Type": "application/json",
    },
    method="POST",
)
try:
    with urllib.request.urlopen(request, timeout=180) as response:
        result = json.load(response)
except urllib.error.HTTPError as error:
    raise RuntimeError(f"HTTP {error.code}: {error.read().decode('utf-8', errors='replace')}") from error
if result.get("success") is False:
    raise RuntimeError(result.get("error", {}).get("message", "Request failed"))
print(json.dumps(result["data"]["output"], indent=2))
```

```typescript
// Save as fous.mts and run with npx tsx fous.mts.
const apiKey = "YOUR_API_KEY";

const response = await fetch("https://api.fous.com/v1/query", {
  method: "POST",
  headers: {
    "Authorization": `Bearer ${apiKey}`,
    "Content-Type": "application/json",
  },
  signal: AbortSignal.timeout(180_000),
  body: JSON.stringify({
  "api": "@national-vulnerability-database",
  "visibility": "public",
  "operation": "get_vulnerability",
  "version": 1,
  "input": {
    "cve_number": "2023-23397"
  },
  "response": {
    "format": "json"
  }
}),
});
type ApiResult = { success: boolean; data?: { output: unknown }; error?: { message: string } };
const result: ApiResult = await response.json();
if (!response.ok || result.success === false) {
  throw new Error(result.error?.message ?? `HTTP ${response.status}`);
}
if (!result.data) throw new Error("Missing API response data");
console.log(result.data.output);
```

## Use from an AI assistant

Connect this tool to Claude Code, Claude Desktop, Cursor, VS Code, Codex and any MCP client as its own MCP server. Each method is a typed tool whose arguments are the method’s input.

- Server URL: `https://api.fous.com/mcp/tools/national-vulnerability-database`
- Authorization: `Authorization: Bearer <Fous API key>`

**Tools**

- `get_vulnerability`: Get vulnerability. 1 credit per completed call. Failed calls without a completed billing receipt are free; completed work can remain charged if delivery is interrupted.
- `search_vulnerabilities`: Search vulnerabilities. 1 credit per completed call. Failed calls without a completed billing receipt are free; completed work can remain charged if delivery is interrupted.
- `fous_get_run`: the result of a run that was still going, by its `request_id`. Free.

Claude Code:

```bash
claude mcp add --scope user --transport http fous-national-vulnerability-database https://api.fous.com/mcp/tools/national-vulnerability-database --header "Authorization: Bearer ${FOUS_API_KEY:?Set FOUS_API_KEY to your Fous API key}"
```

To give the assistant every tool, connect `https://api.fous.com/mcp`: it finds one with `fous_search_tools` and runs it with `fous_run_tool`. Setup for other clients: https://fous.com/llms-full.txt.

## Use cases

- Find vulnerabilities affecting a product or vendor.
- Prioritize vulnerabilities by severity and publication date.
- Review affected versions when planning software updates.
- Check whether a CVE appears in CISA’s known exploited catalog.
- Investigate a CVE’s attack conditions and references.

## FAQ

### Can I run it with my own inputs?

Yes. Change the inputs in Studio and press Run, or send new inputs from your code, or ask a connected AI assistant.

### Can I call this National Vulnerability Database tool as an API?

Yes. Send a POST request to /v1/query with your Fous API key and the inputs, and get JSON back.

### How much does it cost?

Each completed run costs 1 credit. Failed runs without a completed receipt are free; completed work can remain charged if delivery is interrupted. With pay as you go, a credit costs 1¢. Monthly plans cost less per credit.

### Do I need a National Vulnerability Database account?

No. You only need a Fous account.

### How current is the data?

Fous gets the data from nvd.nist.gov when you run it. Some results are reused for up to 24 hours, and results that use your account or key are never reused. It was last verified on Sep 30, 2026.

### Which vulnerabilities affect a particular product or vendor?

Search vulnerabilities finds matches and returns severity, publication dates, affected versions when reported, and whether each CVE appears in CISA’s known exploited catalog.

### What are the details for a specific CVE?

Get vulnerability returns the CVE’s description, risk score, attack conditions, affected products, weakness, dates, exploitation listing, and references.

### Does a CVE appear in CISA’s known exploited catalog?

Get vulnerability reports whether the CVE appears in CISA’s known exploited catalog. A no does not rule out exploitation.

## Related

- [Have I Been Pwned API](https://fous.com/tools/have-i-been-pwned.md): Find public records of known data breaches.
- [National Archives API](https://fous.com/tools/national-archives.md): Search the public U.S. National Archives Catalog for historical records.
- [NHTSA API](https://fous.com/tools/nhtsa.md): NHTSA provides vehicle details, model-level recalls, 5-Star Safety Ratings, owner complaints, and listed car, SUV, and truck models; data may be missing, and recalls do not confirm repairs.
- [npm API](https://fous.com/tools/npm.md): npm provides package details, search results and latest versions, plus weekly download and publish data; daily and historical download counts may lag by a day or more.
- [NPI Registry API](https://fous.com/tools/npi-registry.md): NPI Registry returns public US provider search results with contact and taxonomy details, plus individual 10-digit NPI records with registry dates; fields may be missing.
- [FDA API](https://fous.com/tools/fda.md): FDA provides drug safety data, latest matching drug labels, common reported side effects, and newest-first drug, food, and device recalls; recent drug and device recalls may be missing, and weekly food statuses may lag.
- [CDC API](https://fous.com/tools/cdc.md): CDC provides disease facts, age-based vaccine guidance, current travel notices, and destination-specific travel health recommendations; review dates appear only when CDC supplies them.
- [NPR API](https://fous.com/tools/npr.md): NPR returns displayed section headlines, searchable articles with summaries and publication details, and available article text; date-filtered searches may miss older stories edited much later.
- [All Security tools](https://fous.com/tools/category/security)
