Cve MCP Server logo

Cve MCP Server

Unclaimed

by mukul975

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.

Install

$claude mcp add cve-mcp -- python -m cve_mcp.server

Set up this server

This server needs project-specific setup. Follow the project instructions; no reusable public launch command is available yet.

Project instructions
cisa-kevclaude-aicvecybersecuritydevsecopsepssfastmcpmcpmitre-attackmodel-context-protocolnvdosvpythonsecurityshodanthreat-intelligencevirustotalvulnerability-management

More in Security

Browse the full directory

Unclaimed listing

Is this your MCP server?

This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.

Claim this server

Security profile

Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works

28 of 28 tools

Documented tools (28)

From project documentation. A server handshake does not verify each tool’s description or behavior.

bulk_cve_lookup

Batch-fetch details for up to 20 CVEs in a single call with parallel enrichment

calculate_risk_score

Compute composite 0–100 risk score using CVSS, EPSS, KEV status, and PoC availability

check_ip_noise

Query GreyNoise for IP scan/attack activity, classification, and associated CVEs

check_kev_status

Check whether a CVE appears in CISA's Known Exploited Vulnerabilities catalog

check_poc_availability

Determine if known proof-of-concept code exists for a CVE across multiple sources

check_ransomware

Look up ransomware payment addresses and transaction data from Ransomwhere

generate_risk_report

Generate a formatted executive security report for one or more CVEs with recommendations

get_attack_patterns

Retrieve CAPEC attack pattern details associated with a CWE or CVE

get_cve_references

Extract and categorize all reference links for a CVE (patches, advisories, exploits)

get_cvss_details

Parse and explain a CVSS v3.1 vector string with per-metric breakdown

get_cwe_info

Look up Common Weakness Enumeration details by CWE ID from embedded database

get_epss_score

Get EPSS exploitation probability (0–1) and percentile for one or more CVEs

get_mitre_techniques

Map a CVE or CWE to relevant MITRE ATT&CK techniques, tactics, and mitigations

get_trending_cves

Retrieve trending CVEs based on high EPSS scores and recent KEV additions

lookup_cve

Fetch detailed CVE record from NVD including CVSS scores, CWEs, affected products, references, and timeline

lookup_ip_reputation

Check IP address abuse history and confidence score via AbuseIPDB

passive_dns_lookup

Retrieve historical DNS resolution data for a domain from CIRCL Passive DNS

prioritize_cves

Rank a list of CVEs by composite risk score for triage prioritization

scan_dependencies

Scan package names and versions against OSV.dev for known vulnerabilities

scan_github_advisories

Search GitHub Security Advisories by ecosystem, package, or severity

search_cves

Search NVD for CVEs by keyword, product name, severity, or date range

search_exploits

Search GitHub for public proof-of-concept exploits and exploit code repositories

search_iocs

Query ThreatFox for Indicators of Compromise linked to malware families

search_malware

Search MalwareBazaar for malware samples by hash, tag, or signature

shodan_host_lookup

Get open ports, services, banners, and vulnerabilities for an IP via Shodan

triage_cve

One-call triage that fans out NVD + EPSS + CISA KEV (+ public PoC for depth != "quick") concurrently, computes the composite risk score with a KEV hard override, falls back to VulnCheck NVD++ when NIST NVD is throttled, and on depth="deep" emits the SSVC v2 gated decision

urlscan_check

Submit a URL for scanning or retrieve previous scan results from URLScan.io

virustotal_lookup

Analyze file hashes, URLs, domains, or IPs against 70+ antivirus engines

Tool change history

Compared across complete checks of the same configuration. Tools were listed, not invoked. Input-schema changes are not measured here.

No complete tool checks yet.

FAQ

Questions about Cve MCP Server

How do I connect Cve MCP Server to Claude?
The listing records `claude mcp add cve-mcp -- python -m cve_mcp.server` as its setup step. Run it, then follow the repository's instructions for the client configuration; the listing names Claude Desktop, Claude Code as compatible clients.
Is Cve MCP Server free?
The listed licence is Apache-2.0. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
What can Cve MCP Server do?
Cve MCP Server documents 28 tools to the agent, including bulk_cve_lookup, calculate_risk_score, check_ip_noise. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.