Cve MCP logo

Cve MCP

未认领

作者:badchars

23-tool MCP server for CVE & vulnerability intelligence. NVD, EPSS, CISA KEV, GitHub Advisory, OSV — unified in one server. Risk scoring, bulk triage, exploit search. 2 dependencies, runs with npx.

ai-securitycisaclaudecvecvsscybersecurityepssghsakevmcp

01 / 选择客户端

02 / 连接前的准备

认证方式尚未指定。连接前请查看项目说明。

安装项目所需的运行环境,并确保客户端能够使用它。

项目说明

输入项目说明中的变量名,用逗号分隔。只输入名称,不要输入密钥值。

03 / 添加配置

来源:根据公开安装说明生成

claude mcp add --transport stdio 'cve-mcp' -- 'npx' '-y' 'cve-mcp'

替换占位符后在终端中运行。

04 / 在客户端中确认

打开客户端的 MCP 设置,确认服务器已连接并列出工具。复制配置不代表连接成功。

更多Search & Web服务器

浏览完整目录

未认领列表

这个 MCP 服务器是你的吗?

此列表根据公开信息自动生成。认领后,你可以编辑页面、设置兼容性并解锁增长工具。全程不超两分钟。

认领此服务器

安全概况

已认领和已认证的服务器每周接受一次静态扫描,显示代码能触及的范围(外部服务、环境变量、shell 命令、代理配置目录)以及带有已知公告的依赖。认领此列表即可获得。 安全概况的工作原理

40 个工具中显示 40 个

文档中列出的工具 (40)

内容来自项目文档。服务器握手不会验证每个工具的说明或行为。

attackerkb_assess

Community assessments from AttackerKB (attacker value, exploitability)

circl_cve

CIRCL CVE enrichment (CAPEC, alt references, impact vectors)

cpe_match

Get CPE matches for a specific CVE

cpe_search

Search NVD CPE dictionary by keyword

cve_by_product

Search CVEs by product name (CPE keyword match)

cve_compare

Side-by-side comparison of two CVEs

cve_enrich

Full enrichment: NVD + EPSS + KEV + GHSA + OSV + Shodan + Nuclei + MSF in parallel

cve_list_sources

List all 11 data sources and their availability

cve_prioritize

Rank CVEs by risk (CVSS × EPSS × KEV × Exploit multiplier)

cve_to_attack

Map CVE CWE IDs to MITRE ATT&CK techniques and tactics

cve_trending

Currently trending CVEs by exploitation probability

cvss_parse

Parse and explain CVSS v3.1 or v4.0 vector string with score calculation

cwe_get

Full CWE details from MITRE API (1000+ CWEs, mitigations, examples)

cwe_hierarchy

CWE parent/child hierarchy from MITRE API

cwe_lookup

Look up CWE weakness by ID or search by keyword (static DB)

cwe_top25

MITRE CWE Top 25 Most Dangerous Software Weaknesses

epss_score

EPSS exploitation probability for one or more CVEs

epss_top

Top CVEs by exploitation probability

exploit_search

Search for public PoC exploits (GitHub repositories)

ghsa_get

Get advisory details by GHSA ID or CVE ID

ghsa_search

Search GitHub security advisories by keyword, ecosystem, severity

kev_check

Check if CVE(s) are in CISA Known Exploited Vulnerabilities catalog

kev_recent

Recently added KEV entries

kev_search

Search KEV by vendor, product, or keyword

msf_check

Check if a Metasploit exploit module exists for a CVE

nuclei_check

Check if a Nuclei detection template exists for a CVE

nvd_get

Get full CVE details (CVSS, CWE, CPE, references)

nvd_recent

Recently published/modified CVEs

nvd_search

Search CVEs by keyword, severity, CWE, date range

osv_batch

Batch query multiple packages at once

osv_get

Get vulnerability details by OSV/GHSA/CVE ID

osv_query

Query vulnerabilities for a specific package version

shodan_cve

CVE lookup via Shodan CVEDB (EPSS, KEV, CPE integrated, zero-auth)

shodan_ip_vulns

Get known vulnerabilities for an IP address (InternetDB)

shodan_product

Find CVEs by product/vendor name via Shodan

vulncheck_cpe

CVE search by CPE string

vulncheck_kev

Extended KEV catalog (~80% more entries than CISA)

vulncheck_purl

CVE search by Package URL (purl)

vulners_lookup

CVE details from Vulners (200+ sources, exploit refs)

vulners_search

Full-text vulnerability search across Vulners database

工具变更历史

比较相同配置的完整检查。只列出工具,未调用工具。此处不测量输入结构的变化。

尚无完整工具检查。