# National Vulnerability Database API

> National Vulnerability Database returns vulnerability searches and CVE details, available as a workflow and API.

National Vulnerability Database (NVD) searches vulnerabilities by required product or vendor name, with optional severity and date filters. Get vulnerability returns a CVE’s risk, affected products, weakness, attack conditions, dates, and references; it needs a CVE number.

- Page: https://fous.com/workflows/national-vulnerability-database
- Handle: `@national-vulnerability-database`
- Category: [Security](https://fous.com/workflows/category/security)
- Source website: https://nvd.nist.gov
- Last verified: Sep 30, 2026
- Fous is not affiliated with National Vulnerability Database.

## Methods

### Get vulnerability

Operation `get_vulnerability`, version 1. 1 credit per call.

Get one CVE’s description, risk score, attack conditions, affected products, weakness, exploitation listing, dates, and references. The exploitation flag reflects CISA’s known-exploited catalog; a no does not rule out exploitation. Some affected-product matches require other products or conditions.

**Input**

| Field | Type | Required | Example | Description |
|---|---|---|---|---|
| `cve_number` | string | yes | `"2023-23397"` | The vulnerability number, such as CVE-2021-44228, 2021-44228, or cve-2021-44228. |

**Input schema**

```json
{
  "type": "object",
  "required": [
    "cve_number"
  ],
  "properties": {
    "cve_number": {
      "type": "string",
      "description": "The vulnerability number, such as CVE-2021-44228, 2021-44228, or cve-2021-44228.",
      "examples": [
        "2023-23397",
        "CVE-2021-44228",
        "cve-2024-3094"
      ]
    }
  },
  "additionalProperties": false,
  "examples": [
    {
      "cve_number": "2023-23397"
    },
    {
      "cve_number": "CVE-2021-44228"
    },
    {
      "cve_number": "cve-2024-3094"
    }
  ]
}
```

**Output**

| Field | Type | Example | Description |
|---|---|---|---|
| `nvd_link` | string | `"https://nvd.nist.gov/vuln/detail/CVE-2023-23397"` |  |
| `severity` | string or null | `"Critical"` |  |
| `cve_number` | string | `"CVE-2023-23397"` |  |
| `cvss_score` | number or null | `9.8` |  |
| `cwe_number` | string or null | `"CWE-294"` |  |
| `references` | array |  |  |
| `references[].link` | string | `"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397"` |  |
| `references[].source` | string | `"secure@microsoft.com"` |  |
| `cvss_vector` | string or null | `"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"` |  |
| `description` | string or null | `"Microsoft Outlook Elevation of Privilege Vulnerability"` |  |
| `cvss_version` | string or null | `"3.1"` |  |
| `attack_method` | string or null | `"over the network, no login needed, no user action"` |  |
| `weakness_type` | string or null | `"Authentication Bypass by Capture-replay"` |  |
| `published_date` | string or null | `"2023-03-14"` |  |
| `affected_products` | array |  |  |
| `last_modified_date` | string or null | `"2026-06-17"` |  |
| `known_exploited_in_the_wild` | boolean | `true` |  |

**Example input**

```json
{
  "cve_number": "2023-23397"
}
```

**Example output**

```json
{
  "nvd_link": "https://nvd.nist.gov/vuln/detail/CVE-2023-23397",
  "severity": "Critical",
  "cve_number": "CVE-2023-23397",
  "cvss_score": 9.8,
  "cwe_number": "CWE-294",
  "references": [
    {
      "link": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397",
      "source": "secure@microsoft.com"
    },
    {
      "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-23397",
      "source": "www.cisa.gov"
    }
  ],
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "description": "Microsoft Outlook Elevation of Privilege Vulnerability",
  "cvss_version": "3.1",
  "attack_method": "over the network, no login needed, no user action",
  "weakness_type": "Authentication Bypass by Capture-replay",
  "published_date": "2023-03-14",
  "affected_products": [
    "Microsoft 365 apps: version unspecified",
    "Microsoft office: version 2019",
    "Microsoft office long term servicing channel: version 2021"
  ],
  "last_modified_date": "2026-06-17",
  "known_exploited_in_the_wild": true
}
```

### Search vulnerabilities

Operation `search_vulnerabilities`, version 1. 1 credit per call.

Find known vulnerabilities matching a product or vendor name, newest first. Includes published date, severity, affected versions when reported, and whether each CVE appears in CISA’s known exploited catalog. Keyword matches may include related products.

**Input**

| Field | Type | Required | Example | Description |
|---|---|---|---|---|
| `product` | string | yes | `"Apache Tomcat"` | Product and/or vendor name, such as Apache Tomcat. |
| `severity` | string | no | `"critical"` | Severity to include, such as critical; any includes unrated flaws. |
| `max_results` | integer | no | `3` | Maximum number of results, such as 20 (up to 100). |
| `published_after` | string | no | `"2025-01-01"` | Include vulnerabilities published on or after this date, such as 2025-01-01. |

**Input schema**

```json
{
  "type": "object",
  "required": [
    "product"
  ],
  "properties": {
    "product": {
      "type": "string",
      "minLength": 1,
      "description": "Product and/or vendor name, such as Apache Tomcat.",
      "examples": [
        "Apache Tomcat",
        "Zzxzznoexistentbrand98765",
        "Fortinet FortiOS"
      ]
    },
    "severity": {
      "enum": [
        "any",
        "low",
        "medium",
        "high",
        "critical"
      ],
      "type": "string",
      "default": "any",
      "description": "Severity to include, such as critical; any includes unrated flaws.",
      "examples": [
        "critical"
      ]
    },
    "max_results": {
      "type": "integer",
      "default": 20,
      "maximum": 100,
      "minimum": 1,
      "description": "Maximum number of results, such as 20 (up to 100).",
      "x-fous-developer": true,
      "examples": [
        3,
        5
      ]
    },
    "published_after": {
      "type": "string",
      "format": "date",
      "description": "Include vulnerabilities published on or after this date, such as 2025-01-01.",
      "examples": [
        "2025-01-01"
      ]
    }
  },
  "additionalProperties": false,
  "examples": [
    {
      "product": "Apache Tomcat"
    },
    {
      "product": "Zzxzznoexistentbrand98765",
      "max_results": 3
    },
    {
      "product": "Fortinet FortiOS",
      "severity": "critical",
      "max_results": 5,
      "published_after": "2025-01-01"
    }
  ]
}
```

**Output**

| Field | Type | Example | Description |
|---|---|---|---|
| `vulnerabilities` | array |  |  |
| `vulnerabilities[].nvd_link` | string | `"https://nvd.nist.gov/vuln/detail/CVE-2026-24858"` | NVD vulnerability page. |
| `vulnerabilities[].severity` | string | `"Critical"` | Severity in words, or Unknown when unrated. |
| `vulnerabilities[].cve_number` | string | `"CVE-2026-24858"` | CVE identifier. |
| `vulnerabilities[].cvss_score` | number or null | `9.8` | CVSS base score from 0 to 10 when available. |
| `vulnerabilities[].description` | string or null | `"A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiO` | English-language vulnerability description. |
| `vulnerabilities[].published_date` | string | `"2026-01-27"` | Publication date. |
| `vulnerabilities[].affected_versions` | string or null | `"Fortinet FortiSwitchManager: from 7.2.2 through 7.2.5; Fortinet FortiOS: from 7.6.0 through 7.6.2; Fortinet FortiOS: fr` | Affected product versions when reported. |
| `vulnerabilities[].known_exploited_in_the_wild` | boolean | `true` | Whether this CVE appears in the CISA known exploited catalog. |

**Example input**

```json
{
  "product": "Zzxzznoexistentbrand98765",
  "max_results": 3
}
```

**Example output**

```json
{
  "vulnerabilities": []
}
```

## Quick start

Call the API with a Fous API key (`FOUS_API_KEY`). To create one, turn on Developer mode in Fous Studio, then open Keys & connections → API keys (https://app.fous.com/keys).

```bash
# First set your key: export FOUS_API_KEY='YOUR_FOUS_API_KEY'
: "${FOUS_API_KEY:?Set FOUS_API_KEY before running this example}"

curl 'https://api.fous.com/v1/query' \
  --fail-with-body --silent --show-error --max-time 120 \
  -H "Authorization: Bearer $FOUS_API_KEY" \
  -H 'Content-Type: application/json' \
  --data-raw '{
  "api": "@national-vulnerability-database",
  "visibility": "public",
  "operation": "get_vulnerability",
  "version": 1,
  "input": {
    "cve_number": "2023-23397"
  },
  "response": {
    "format": "json"
  }
}'
```

```python
# Save as fous.py and run with python3 fous.py. No packages needed.
# First set your key: export FOUS_API_KEY='YOUR_FOUS_API_KEY'
import json
import os
import urllib.error
import urllib.request

api_key = os.environ.get("FOUS_API_KEY")
if not api_key:
    raise RuntimeError("Set FOUS_API_KEY before running this example")

body = json.loads("{\n  \"api\": \"@national-vulnerability-database\",\n  \"visibility\": \"public\",\n  \"operation\": \"get_vulnerability\",\n  \"version\": 1,\n  \"input\": {\n    \"cve_number\": \"2023-23397\"\n  },\n  \"response\": {\n    \"format\": \"json\"\n  }\n}")
request = urllib.request.Request(
    "https://api.fous.com/v1/query",
    data=json.dumps(body).encode("utf-8"),
    headers={
        "Authorization": f"Bearer {api_key}",
        "Content-Type": "application/json",
    },
    method="POST",
)
try:
    with urllib.request.urlopen(request, timeout=120) as response:
        result = json.load(response)
except urllib.error.HTTPError as error:
    raise RuntimeError(f"HTTP {error.code}: {error.read().decode('utf-8', errors='replace')}") from error
if result.get("success") is False:
    raise RuntimeError(result.get("error", {}).get("message", "Request failed"))
print(json.dumps(result["data"]["output"], indent=2))
```

```typescript
// Save as fous.mts and run with npx tsx fous.mts.
// First set your key: export FOUS_API_KEY='YOUR_FOUS_API_KEY'
const apiKey = process.env.FOUS_API_KEY;
if (!apiKey) throw new Error("Set FOUS_API_KEY before running this example");

const response = await fetch("https://api.fous.com/v1/query", {
  method: "POST",
  headers: {
    "Authorization": `Bearer ${apiKey}`,
    "Content-Type": "application/json",
  },
  signal: AbortSignal.timeout(120_000),
  body: JSON.stringify({
  "api": "@national-vulnerability-database",
  "visibility": "public",
  "operation": "get_vulnerability",
  "version": 1,
  "input": {
    "cve_number": "2023-23397"
  },
  "response": {
    "format": "json"
  }
}),
});
type ApiResult = { success: boolean; data?: { output: unknown }; error?: { message: string } };
const result: ApiResult = await response.json();
if (!response.ok || result.success === false) {
  throw new Error(result.error?.message ?? `HTTP ${response.status}`);
}
if (!result.data) throw new Error("Missing API response data");
console.log(result.data.output);
```

Or describe the data in plain language: send `{"api":"@national-vulnerability-database","prompt":"Describe the data you need, with every detail"}` to the same URL. Fous fills in the input, runs the method that fits and returns only the fields you asked for; `data.route.calls[].request` is the exact call it made. Routing is free; the run costs the same.

## Use cases

- Find vulnerabilities affecting a product or vendor.
- Prioritize vulnerabilities by severity and publication date.
- Review affected versions when planning software updates.
- Check whether a CVE appears in CISA’s known exploited catalog.
- Investigate a CVE’s attack conditions and references.

## FAQ

### Is Fous affiliated with National Vulnerability Database?

No. Fous is not affiliated with National Vulnerability Database. This workflow reads the public nvd.nist.gov website and returns its data.

### How much does it cost?

Each run costs 1 credit. With pay-as-you-go, a credit costs 1¢; monthly plans cost less per credit.

### Do I need a National Vulnerability Database account?

No. You only need a Fous account.

### How current is the data?

Fous gets the data from nvd.nist.gov when you run it; repeating the same request within a day may return the saved result. Fous checks this workflow automatically; it last passed a check on Sep 30, 2026.

### Which vulnerabilities affect a particular product or vendor?

Search vulnerabilities finds matches and returns severity, publication dates, affected versions when reported, and whether each CVE appears in CISA’s known exploited catalog.

### What are the details for a specific CVE?

Get vulnerability returns the CVE’s description, risk score, attack conditions, affected products, weakness, dates, exploitation listing, and references.

### Does a CVE appear in CISA’s known exploited catalog?

Get vulnerability reports whether the CVE appears in CISA’s known exploited catalog. A no does not rule out exploitation.

## Related

- [Have I Been Pwned API](https://fous.com/workflows/have-i-been-pwned.md): Find public records of known data breaches.
- [National Archives API](https://fous.com/workflows/national-archives.md): Search the public U.S. National Archives Catalog for historical records.
- [NHTSA API](https://fous.com/workflows/nhtsa.md): NHTSA provides vehicle details, model-level recalls, 5-Star Safety Ratings, owner complaints, and listed car, SUV, and truck models; data may be missing, and recalls do not confirm repairs.
- [npm API](https://fous.com/workflows/npm.md): npm provides package details, search results and latest versions, plus weekly download and publish data; daily and historical download counts may lag by a day or more.
- [NPI Registry API](https://fous.com/workflows/npi-registry.md): NPI Registry returns public US provider search results with contact and taxonomy details, plus individual 10-digit NPI records with registry dates; fields may be missing.
- [FDA API](https://fous.com/workflows/fda.md): FDA provides drug safety data, latest matching drug labels, common reported side effects, and newest-first drug, food, and device recalls; recent drug and device recalls may be missing, and weekly food statuses may lag.
- [CDC API](https://fous.com/workflows/cdc.md): CDC provides disease facts, age-based vaccine guidance, current travel notices, and destination-specific travel health recommendations; review dates appear only when CDC supplies them.
- [NPR API](https://fous.com/workflows/npr.md): NPR returns displayed section headlines, searchable articles with summaries and publication details, and available article text; date-filtered searches may miss older stories edited much later.
- [All Security workflows](https://fous.com/workflows/category/security)
