Getting Started
Search, filter, and fetch CVEs from the vuln.mlab.sh API.
Everything is a plain GET against https://vuln.mlab.sh, no auth required.
Search
Full-text search with optional faceted filters:
curl "https://vuln.mlab.sh/api/v1/cve?q=openssl&severity=HIGH&limit=10&page=0"Supported query parameters: q, page, limit (max 100), severity
(CRITICAL/HIGH/MEDIUM/LOW), dateStart, dateEnd (YYYY-MM-DD), and
exact (0/1). See the API Reference
for the full response schema.
Latest CVEs
The 40 most recently published CVEs:
curl "https://vuln.mlab.sh/api/v1/cve/latest"A single CVE
curl "https://vuln.mlab.sh/api/v1/cve/CVE-2024-3094"Each record includes CVSS (score, severity, parsed vector), EPSS, CISA KEV
status, CWE weaknesses, affected products and a computed risk_score.
Bulk dump
Every CVE in a date window above a minimum CVSS, sorted by score (capped at 10 000):
curl "https://vuln.mlab.sh/api/v1/cve/dump?dateStart=2024-01-01&dateEnd=2024-12-31&minCvss=7.5"Feeds & exports
# RSS 2.0 (latest 20) - also at /feed
curl "https://vuln.mlab.sh/rss"
# CSV export (up to 100 rows)
curl -OJ "https://vuln.mlab.sh/export/csv?q=log4j"Need a blocking, package-scoped gate instead of keyword search? See OSV integration.