mlab docs

Getting Started

Search, filter, and fetch CVEs from the vuln.mlab.sh API.

Everything is a plain GET against https://vuln.mlab.sh, no auth required.

Full-text search with optional faceted filters:

curl "https://vuln.mlab.sh/api/v1/cve?q=openssl&severity=HIGH&limit=10&page=0"

Supported query parameters: q, page, limit (max 100), severity (CRITICAL/HIGH/MEDIUM/LOW), dateStart, dateEnd (YYYY-MM-DD), and exact (0/1). See the API Reference for the full response schema.

Latest CVEs

The 40 most recently published CVEs:

curl "https://vuln.mlab.sh/api/v1/cve/latest"

A single CVE

curl "https://vuln.mlab.sh/api/v1/cve/CVE-2024-3094"

Each record includes CVSS (score, severity, parsed vector), EPSS, CISA KEV status, CWE weaknesses, affected products and a computed risk_score.

Bulk dump

Every CVE in a date window above a minimum CVSS, sorted by score (capped at 10 000):

curl "https://vuln.mlab.sh/api/v1/cve/dump?dateStart=2024-01-01&dateEnd=2024-12-31&minCvss=7.5"

Feeds & exports

# RSS 2.0 (latest 20) - also at /feed
curl "https://vuln.mlab.sh/rss"

# CSV export (up to 100 rows)
curl -OJ "https://vuln.mlab.sh/export/csv?q=log4j"

Need a blocking, package-scoped gate instead of keyword search? See OSV integration.

On this page