Cve MCP
Unclaimed23-tool MCP server for CVE & vulnerability intelligence. NVD, EPSS, CISA KEV, GitHub Advisory, OSV — unified in one server. Risk scoring, bulk triage, exploit search. 2 dependencies, runs with npx.
Set up this server
01 / Choose your client
02 / Before you connect
Authentication is not specified. Check the project instructions before connecting.
Project instructions03 / Add the configuration
claude mcp add --transport stdio 'cve-mcp' -- 'npx' '-y' 'cve-mcp'04 / Check it in your client
Open your client’s MCP settings and confirm the server connects and lists its tools. A copied configuration does not confirm a working connection.
More in Search & Web
Browse the full directoryUnclaimed listing
Is this your MCP server?
This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.
Claim this serverSecurity profile
Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works
40 of 40 tools
Documented tools (40)
From project documentation. A server handshake does not verify each tool’s description or behavior.
attackerkb_assess
Community assessments from AttackerKB (attacker value, exploitability)
circl_cve
CIRCL CVE enrichment (CAPEC, alt references, impact vectors)
cpe_match
Get CPE matches for a specific CVE
cpe_search
Search NVD CPE dictionary by keyword
cve_by_product
Search CVEs by product name (CPE keyword match)
cve_compare
Side-by-side comparison of two CVEs
cve_enrich
Full enrichment: NVD + EPSS + KEV + GHSA + OSV + Shodan + Nuclei + MSF in parallel
cve_list_sources
List all 11 data sources and their availability
cve_prioritize
Rank CVEs by risk (CVSS × EPSS × KEV × Exploit multiplier)
cve_to_attack
Map CVE CWE IDs to MITRE ATT&CK techniques and tactics
cve_trending
Currently trending CVEs by exploitation probability
cvss_parse
Parse and explain CVSS v3.1 or v4.0 vector string with score calculation
cwe_get
Full CWE details from MITRE API (1000+ CWEs, mitigations, examples)
cwe_hierarchy
CWE parent/child hierarchy from MITRE API
cwe_lookup
Look up CWE weakness by ID or search by keyword (static DB)
cwe_top25
MITRE CWE Top 25 Most Dangerous Software Weaknesses
epss_score
EPSS exploitation probability for one or more CVEs
epss_top
Top CVEs by exploitation probability
exploit_search
Search for public PoC exploits (GitHub repositories)
ghsa_get
Get advisory details by GHSA ID or CVE ID
ghsa_search
Search GitHub security advisories by keyword, ecosystem, severity
kev_check
Check if CVE(s) are in CISA Known Exploited Vulnerabilities catalog
kev_recent
Recently added KEV entries
kev_search
Search KEV by vendor, product, or keyword
msf_check
Check if a Metasploit exploit module exists for a CVE
nuclei_check
Check if a Nuclei detection template exists for a CVE
nvd_get
Get full CVE details (CVSS, CWE, CPE, references)
nvd_recent
Recently published/modified CVEs
nvd_search
Search CVEs by keyword, severity, CWE, date range
osv_batch
Batch query multiple packages at once
osv_get
Get vulnerability details by OSV/GHSA/CVE ID
osv_query
Query vulnerabilities for a specific package version
shodan_cve
CVE lookup via Shodan CVEDB (EPSS, KEV, CPE integrated, zero-auth)
shodan_ip_vulns
Get known vulnerabilities for an IP address (InternetDB)
shodan_product
Find CVEs by product/vendor name via Shodan
vulncheck_cpe
CVE search by CPE string
vulncheck_kev
Extended KEV catalog (~80% more entries than CISA)
vulncheck_purl
CVE search by Package URL (purl)
vulners_lookup
CVE details from Vulners (200+ sources, exploit refs)
vulners_search
Full-text vulnerability search across Vulners database
Tool change history
FAQ
Questions about Cve MCP Server
- How do I connect Cve MCP Server to Claude?
- Run `claude mcp add cve-mcp -- npx -y cve-mcp` in Claude Code, or add the same command and arguments under mcpServers in Cursor's mcp.json or Claude Desktop's claude_desktop_config.json, then restart the client. The blocks above are ready to paste.
- Is Cve MCP Server free?
- The listed licence is MIT. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
- What can Cve MCP Server do?
- Cve MCP Server documents 40 tools to the agent, including attackerkb_assess, circl_cve, cpe_match. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.