search_cves
Search NVD for CVEs by keyword, product name, severity, or date range
How to use it
search_cves is exposed by the Cve MCP Server MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the search_cves tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.
Install Cve MCP Server
claude mcp add cve-mcp -- python -m cve_mcp.serverOther tools in Cve MCP Server (27)
Batch-fetch details for up to 20 CVEs in a single call with parallel enrichment
Compute composite 0–100 risk score using CVSS, EPSS, KEV status, and PoC availability
Query GreyNoise for IP scan/attack activity, classification, and associated CVEs
Check whether a CVE appears in CISA's Known Exploited Vulnerabilities catalog
Determine if known proof-of-concept code exists for a CVE across multiple sources
Look up ransomware payment addresses and transaction data from Ransomwhere
Generate a formatted executive security report for one or more CVEs with recommendations
Retrieve CAPEC attack pattern details associated with a CWE or CVE
Extract and categorize all reference links for a CVE (patches, advisories, exploits)
Parse and explain a CVSS v3.1 vector string with per-metric breakdown
Look up Common Weakness Enumeration details by CWE ID from embedded database
Get EPSS exploitation probability (0–1) and percentile for one or more CVEs
Map a CVE or CWE to relevant MITRE ATT&CK techniques, tactics, and mitigations
Retrieve trending CVEs based on high EPSS scores and recent KEV additions
Fetch detailed CVE record from NVD including CVSS scores, CWEs, affected products, references, and timeline
Check IP address abuse history and confidence score via AbuseIPDB
Retrieve historical DNS resolution data for a domain from CIRCL Passive DNS
Rank a list of CVEs by composite risk score for triage prioritization
Scan package names and versions against OSV.dev for known vulnerabilities
Search GitHub Security Advisories by ecosystem, package, or severity
Search GitHub for public proof-of-concept exploits and exploit code repositories
Query ThreatFox for Indicators of Compromise linked to malware families
Search MalwareBazaar for malware samples by hash, tag, or signature
Get open ports, services, banners, and vulnerabilities for an IP via Shodan
One-call triage that fans out NVD + EPSS + CISA KEV (+ public PoC for depth != "quick") concurrently, computes the composite risk score with a KEV hard override, falls back to VulnCheck NVD++ when NIST NVD is throttled, and on depth="deep" emits the SSVC v2 gated decision
Submit a URL for scanning or retrieve previous scan results from URLScan.io
Analyze file hashes, URLs, domains, or IPs against 70+ antivirus engines