CVE Vulnerability Scraper avatar

CVE Vulnerability Scraper

Pricing

from $1.50 / 1,000 results

Go to Apify Store
CVE Vulnerability Scraper

CVE Vulnerability Scraper

Search and extract CVE vulnerability data from NIST NVD. Get CVSS scores, affected products, and references. No API key required.

Pricing

from $1.50 / 1,000 results

Rating

0.0

(0)

Developer

cloud9

cloud9

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

0

Monthly active users

a day ago

Last modified

Categories

Share

Search and extract CVE vulnerability data from NIST NVD. Get CVSS scores, affected products, and references. No API key required.

Use cases

  • Feed a vulnerability dashboard with CVSS-scored CVEs
  • Alert on new HIGH/CRITICAL CVEs affecting your stack
  • Build a compliance evidence trail for audits
  • Enrich asset inventories with known vulnerabilities
  • Research vulnerability trends over a date range

Input

A NIST NVD API key is optional. The Actor works without one; adding a key from https://nvd.nist.gov/developers/request-an-api-key raises the rate limit the source applies.

ParameterTypeRequiredDefaultDescription
modestringYes"search"Search mode: 'search' for keyword search, 'recent' for recently published CVEs Allowed: search, recent.
keywordstringNo"apache"Search keyword for CVEs (e.g., 'apache log4j', 'openssl'). Used in 'search' mode.
severitystringNo"HIGH"Filter by CVSS v3 severity level Allowed: LOW, MEDIUM, HIGH, CRITICAL.
pubStartDatestringNoFilter CVEs published on or after this date (YYYY-MM-DD format)
pubEndDatestringNoFilter CVEs published on or before this date (YYYY-MM-DD format)
maxResultsintegerNo20Maximum number of CVEs to retrieve (default: 20, max: 200)
apiKeystringNoOptional NVD API key to increase rate limit (without key: 1 req/6s, with key: 1 req/0.6s). Get free key at https://nvd.nist.gov/developers/request-an-api-key

Example input

{
"mode": "search",
"keyword": "apache",
"severity": "HIGH",
"maxResults": 20
}

Output

The exact fields depend on the mode you run. This is real output from an actual run of this Actor:

{
"cveId": "CVE-1999-0236",
"description": "ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.",
"publishedDate": "1997-01-01T05:00:00.000",
"lastModifiedDate": "2026-06-16T21:47:58.393",
"cvssV3Score": 7.5,
"cvssV3Severity": "HIGH",
"cvssV3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"affectedProducts": [
"cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*",
"cpe:2.3:a:illinois:ncsa_httpd:-:*:*:*:*:*:*:*"
],
"references": [
"https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0236",
"https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0236"
],
"nistUrl": "https://nvd.nist.gov/vuln/detail/CVE-1999-0236"
}
FieldType
cveIdstring
descriptionstring
publishedDatestring
lastModifiedDatestring
cvssV3Scorenumber
cvssV3Severitystring
cvssV3Vectorstring
affectedProductsarray
referencesarray
nistUrlstring

Results are exportable from Apify Console or the API as JSON, CSV, Excel, or XML.

How to run it

In Apify Console — open the Actor, fill in the input form, click Start, then download the results from the Dataset tab.

With the JavaScript client

import { ApifyClient } from 'apify-client';
const client = new ApifyClient({ token: 'YOUR_APIFY_TOKEN' });
const run = await client.actor('cloud9_ai/cve-scraper').call({
"mode": "search",
"keyword": "apache",
"severity": "HIGH",
"maxResults": 20
});
const { items } = await client.dataset(run.defaultDatasetId).listItems();
console.log(items);

With the Python client

from apify_client import ApifyClient
client = ApifyClient('YOUR_APIFY_TOKEN')
run = client.actor('cloud9_ai/cve-scraper').call(run_input={
"mode": "search",
"keyword": "apache",
"severity": "HIGH",
"maxResults": 20
})
for item in client.dataset(run['defaultDatasetId']).iterate_items():
print(item)

With the APIPOST https://api.apify.com/v2/acts/cloud9_ai~cve-scraper/run-sync-get-dataset-items?token=YOUR_APIFY_TOKEN with the input JSON as the body.

Notes and limits

  • A NIST NVD key is optional (https://nvd.nist.gov/developers/request-an-api-key); supplying one raises the source's rate limit. It is a secret input, so it is not written to the dataset or the log.
  • maxResults caps how much a single run collects, which is also what caps the run's cost.
  • Requests are paced and failed requests are retried automatically, so runs stay inside the source's rate limits.
  • Only publicly available data is collected. How you use the output is your responsibility, including the source's terms of use and any applicable data-protection law.

Support

Found a bug, or need a field that isn't in the output? Open an issue on the Issues tab of this Actor in Apify Console. Issues there are read and answered.

License

Apache-2.0