Skip to content

NVD CVE API

CVE records with CVSS scores from the US National Vulnerability Database.
Status
Working
API key
Not needed
Browser calls
Runs in the browser
Latency
574 ms

Build snapshot, not live. One verifier run on , from the machine that built this site. How we check

Example request

GEThttps://services.nvd.nist.gov/rest/json/cves/2.0?resultsPerPage=1

Sent from your browser straight to services.nvd.nist.gov. No proxy: this site never sees the request or the answer.

Copy the request

Shell
curl -s 'https://services.nvd.nist.gov/rest/json/cves/2.0?resultsPerPage=1'

Response stored by the verifier

This is what services.nvd.nist.gov answered when the verifier sent the request above on : HTTP 200, application/json. Arrays are cut to two items and long strings are shortened. It comes from the build snapshot.

application/json · stored
{
  "resultsPerPage": 1,
  "startIndex": 0,
  "totalResults": 400995,
  "format": "NVD_CVE",
  "version": "2.0",
  "timestamp": "2026-10-03T09:00:51.869",
  "vulnerabilities": [
    {
      "cve": {
        "id": "CVE-1999-0095",
        "sourceIdentifier": "cve@mitre.org",
        "published": "1988-10-01T04:00:00.000",
        "lastModified": "2026-06-16T21:47:34.460",
        "vulnStatus": "Modified",
        "cveTags": [],
        "descriptions": [],
        "affected": [],
        "metrics": {},
        "weaknesses": [],
        "configurations": [],
        "references": []
      }
    }
  ]
}

Availability

Up 1 of 1 day checked · 30-day window

What counts as up for this API: an answer within five seconds, a 2xx status, and the JSON body must contain the field "vulnerabilities".

Last check: — passed, HTTP 200 in 574 ms.

The check runs from our infrastructure, not from where you are. If you need certainty, send the request yourself above. How the verifier works.

Questions

Does the NVD CVE API need an API key?

No. The sample request on this page was answered without a key, token or account. Note: Without a key the limit is 5 requests per 30 seconds.

Can I call the NVD CVE API from the browser?

Yes. services.nvd.nist.gov answered our verifier with an Access-Control-Allow-Origin header on Oct 3, 2026, so a fetch call from a web page can read the response.

Is the NVD CVE API working?

At the check on Oct 3, 2026 it returned HTTP 200 with the expected data in 574 ms. The status at the top of this page shows the most recent result we have.