public-data-apis · prepared

NIST NVD Vulnerabilities API boundary

Official-source access, authentication, request-shaping, paging, freshness, legal, and interpretation boundaries for NIST NVD Vulnerabilities API.

version 1.0.0freshness currentobserved 2026-08-27T09:30:00Z

resource.public-data.nist-nvd-vulnerabilities-api
sha256:5264fe3bcc2b66a22ac66fb9d22be3065a7ec0bb8e4b6c9e60a8efaa2239a47c

Open canonical machine JSON →

Evidence-backed facts

  1. The NVD Vulnerabilities API 2.0 exposes CVE records and NVD enrichment with identifiers, date windows, keyword, weakness, configuration, and severity filters. informative
  2. An API key is optional for lower-volume access and is recommended for sustained synchronization; keys are credentials and belong in headers rather than public assets. informative
  3. Clients should use modification windows, results-per-page, start index, backoff, and the published rate limits instead of repeatedly downloading the full collection. informative
  4. NVD enrichment and CVE source data can change or remain incomplete and do not prove exploitability, affected deployment, remediation success, or a complete risk assessment. informative

Primary sources

NVD Vulnerabilities API

U.S. National Institute of Standards and Technology · observed 2026-08-27T09:30:00Z