NVD CVE API
- Status
- Working
- API key
- Not needed
- Browser calls
- Runs in the browser
- Latency
- 574 ms
- Docs
- nvd.nist.gov ↗
Build snapshot, not live. One verifier run on , from the machine that built this site. How we check
Example request
GEThttps://services.nvd.nist.gov/rest/json/cves/2.0?resultsPerPage=1
Sent from your browser straight to services.nvd.nist.gov. No proxy: this site never sees the request or the answer.
Copy the request
curl -s 'https://services.nvd.nist.gov/rest/json/cves/2.0?resultsPerPage=1'const res = await fetch("https://services.nvd.nist.gov/rest/json/cves/2.0?resultsPerPage=1");
if (!res.ok) throw new Error(`HTTP ${res.status}`);
const data = await res.json();
console.log(data);import requests
res = requests.get("https://services.nvd.nist.gov/rest/json/cves/2.0?resultsPerPage=1", timeout=10)
res.raise_for_status()
print(res.json())Response stored by the verifier
This is what services.nvd.nist.gov answered when the verifier sent the request above on : HTTP 200, application/json. Arrays are cut to two items and long strings are shortened. It comes from the build snapshot.
{
"resultsPerPage": 1,
"startIndex": 0,
"totalResults": 400995,
"format": "NVD_CVE",
"version": "2.0",
"timestamp": "2026-10-03T09:00:51.869",
"vulnerabilities": [
{
"cve": {
"id": "CVE-1999-0095",
"sourceIdentifier": "cve@mitre.org",
"published": "1988-10-01T04:00:00.000",
"lastModified": "2026-06-16T21:47:34.460",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [],
"affected": [],
"metrics": {},
"weaknesses": [],
"configurations": [],
"references": []
}
}
]
}Availability
Up 1 of 1 day checked · 30-day window
What counts as up for this API: an answer within five seconds, a 2xx status, and the JSON body must contain the field "vulnerabilities".
Last check: — passed, HTTP 200 in 574 ms.
The check runs from our infrastructure, not from where you are. If you need certainty, send the request yourself above. How the verifier works.
Questions
Does the NVD CVE API need an API key?
No. The sample request on this page was answered without a key, token or account. Note: Without a key the limit is 5 requests per 30 seconds.
Can I call the NVD CVE API from the browser?
Yes. services.nvd.nist.gov answered our verifier with an Access-Control-Allow-Origin header on Oct 3, 2026, so a fetch call from a web page can read the response.
Is the NVD CVE API working?
At the check on Oct 3, 2026 it returned HTTP 200 with the expected data in 574 ms. The status at the top of this page shows the most recent result we have.