How to hit the NVD (National Vulnerability Database) API

NIST's National Vulnerability Database at https://services.nvd.nist.gov/rest/json/cves/2.0 is the US government's record of CVEs, with severity scores and affected products.

Authentication

None, at a low rate limit. A free key, sent as the apiKey header, raises it.

Full reference: https://nvd.nist.gov/developers/vulnerabilities

Get a CVE

curl "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2021-44228"
Run in PostTaco
Example response (trimmed)
{
  "resultsPerPage": 1,
  "startIndex": 0,
  "totalResults": 1,
  "format": "NVD_CVE",
  "version": "2.0",
  "timestamp": "2026-09-23T21:50:59.357",
  "vulnerabilities": [
    {
      "cve": {
        "id": "CVE-2021-44228",
        "sourceIdentifier": "[email protected]",
        "published": "2021-12-10T10:15:09.143",
        "lastModified": "2026-08-11T19:33:44.513",
        "vulnStatus": "Analyzed",
        "cveTags": [],
        "descriptions": [],
        "affected": [],
        "metrics": {},
        "cisaExploitAdd": "2021-12-10",
        "cisaActionDue": "2021-12-24",
        "cisaVulnerabilityName": "Apache Log4j2 Remote Code Execution Vulnerability",
        "weaknesses": [],
        "configurations": [],
        "references": []
      }
    }
  ]
}

Search by keyword

curl "https://services.nvd.nist.gov/rest/json/cves/2.0?keywordSearch=curl&resultsPerPage=2"
Run in PostTaco
Example response (trimmed)
{
  "resultsPerPage": 2,
  "startIndex": 0,
  "totalResults": 339,
  "format": "NVD_CVE",
  "version": "2.0",
  "timestamp": "2026-09-23T21:50:59.675",
  "vulnerabilities": [
    {
      "cve": {
        "id": "CVE-2000-0973",
        "sourceIdentifier": "[email protected]",
        "published": "2000-12-19T05:00:00.000",
        "lastModified": "2026-09-23T10:10:00.673",
        "vulnStatus": "Modified",
        "cveTags": [],
        "descriptions": [],
        "affected": [],
        "metrics": {},
        "weaknesses": [],
        "configurations": [],
        "references": []
      }
    },
    {
      "cve": {
        "id": "CVE-2004-1392",
        "sourceIdentifier": "[email protected]",
        "published": "2004-12-31T05:00:00.000",
        "lastModified": "2026-06-16T22:07:36.883",
        "vulnStatus": "Modified",
        "cveTags": [],
        "descriptions": [],
        "affected": [],
        "metrics": {},
        "weaknesses": [],
        "configurations": [],
        "references": [],
        "vendorComments": []
      }
    }
  ]
}