CVE Vulnerability Scraper
Pricing
from $1.50 / 1,000 results
CVE Vulnerability Scraper
Search and extract CVE vulnerability data from NIST NVD. Get CVSS scores, affected products, and references. No API key required.
Pricing
from $1.50 / 1,000 results
Rating
0.0
(0)
Developer
cloud9
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
0
Monthly active users
a day ago
Last modified
Categories
Share
Search and extract CVE vulnerability data from NIST NVD. Get CVSS scores, affected products, and references. No API key required.
Use cases
- Feed a vulnerability dashboard with CVSS-scored CVEs
- Alert on new HIGH/CRITICAL CVEs affecting your stack
- Build a compliance evidence trail for audits
- Enrich asset inventories with known vulnerabilities
- Research vulnerability trends over a date range
Input
A NIST NVD API key is optional. The Actor works without one; adding a key from https://nvd.nist.gov/developers/request-an-api-key raises the rate limit the source applies.
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
mode | string | Yes | "search" | Search mode: 'search' for keyword search, 'recent' for recently published CVEs Allowed: search, recent. |
keyword | string | No | "apache" | Search keyword for CVEs (e.g., 'apache log4j', 'openssl'). Used in 'search' mode. |
severity | string | No | "HIGH" | Filter by CVSS v3 severity level Allowed: LOW, MEDIUM, HIGH, CRITICAL. |
pubStartDate | string | No | — | Filter CVEs published on or after this date (YYYY-MM-DD format) |
pubEndDate | string | No | — | Filter CVEs published on or before this date (YYYY-MM-DD format) |
maxResults | integer | No | 20 | Maximum number of CVEs to retrieve (default: 20, max: 200) |
apiKey | string | No | — | Optional NVD API key to increase rate limit (without key: 1 req/6s, with key: 1 req/0.6s). Get free key at https://nvd.nist.gov/developers/request-an-api-key |
Example input
{"mode": "search","keyword": "apache","severity": "HIGH","maxResults": 20}
Output
The exact fields depend on the mode you run. This is real output from an actual run of this Actor:
{"cveId": "CVE-1999-0236","description": "ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.","publishedDate": "1997-01-01T05:00:00.000","lastModifiedDate": "2026-06-16T21:47:58.393","cvssV3Score": 7.5,"cvssV3Severity": "HIGH","cvssV3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","affectedProducts": ["cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*","cpe:2.3:a:illinois:ncsa_httpd:-:*:*:*:*:*:*:*"],"references": ["https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0236","https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0236"],"nistUrl": "https://nvd.nist.gov/vuln/detail/CVE-1999-0236"}
| Field | Type |
|---|---|
cveId | string |
description | string |
publishedDate | string |
lastModifiedDate | string |
cvssV3Score | number |
cvssV3Severity | string |
cvssV3Vector | string |
affectedProducts | array |
references | array |
nistUrl | string |
Results are exportable from Apify Console or the API as JSON, CSV, Excel, or XML.
How to run it
In Apify Console — open the Actor, fill in the input form, click Start, then download the results from the Dataset tab.
With the JavaScript client
import { ApifyClient } from 'apify-client';const client = new ApifyClient({ token: 'YOUR_APIFY_TOKEN' });const run = await client.actor('cloud9_ai/cve-scraper').call({"mode": "search","keyword": "apache","severity": "HIGH","maxResults": 20});const { items } = await client.dataset(run.defaultDatasetId).listItems();console.log(items);
With the Python client
from apify_client import ApifyClientclient = ApifyClient('YOUR_APIFY_TOKEN')run = client.actor('cloud9_ai/cve-scraper').call(run_input={"mode": "search","keyword": "apache","severity": "HIGH","maxResults": 20})for item in client.dataset(run['defaultDatasetId']).iterate_items():print(item)
With the API — POST https://api.apify.com/v2/acts/cloud9_ai~cve-scraper/run-sync-get-dataset-items?token=YOUR_APIFY_TOKEN with the input JSON as the body.
Notes and limits
- A NIST NVD key is optional (https://nvd.nist.gov/developers/request-an-api-key); supplying one raises the source's rate limit. It is a secret input, so it is not written to the dataset or the log.
maxResultscaps how much a single run collects, which is also what caps the run's cost.- Requests are paced and failed requests are retried automatically, so runs stay inside the source's rate limits.
- Only publicly available data is collected. How you use the output is your responsibility, including the source's terms of use and any applicable data-protection law.
Support
Found a bug, or need a field that isn't in the output? Open an issue on the Issues tab of this Actor in Apify Console. Issues there are read and answered.
License
Apache-2.0