API

NVD API Compatibility

Point an existing NVD API 2.0 integration at VulnCheck by changing the base URL and the API key

VulnCheck serves the five NVD API 2.0 endpoints at their original paths. An existing integration moves across by changing the base URL and the API key. The request shape, the query parameters and the response schema are unchanged.

Quick start

curl "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2024-1234" \
    --header 'apiKey: insert_nvd_key_here'

Both header styles work. apiKey exists so an NVD client needs no code change; Authorization: Bearer is accepted too, so the compat endpoints behave like the rest of the VulnCheck API.

curl "https://api.vulncheck.com/rest/json/cves/2.0?cveId=CVE-2024-1234" \
    --header 'apiKey: insert_token_here'

Endpoint mapping

NVDVulnCheck
services.nvd.nist.gov/rest/json/cves/2.0api.vulncheck.com/rest/json/cves/2.0
services.nvd.nist.gov/rest/json/cvehistory/2.0api.vulncheck.com/rest/json/cvehistory/2.0
services.nvd.nist.gov/rest/json/cpes/2.0api.vulncheck.com/rest/json/cpes/2.0
services.nvd.nist.gov/rest/json/cpematch/2.0api.vulncheck.com/rest/json/cpematch/2.0
services.nvd.nist.gov/rest/json/source/2.0api.vulncheck.com/rest/json/source/2.0

Migration steps

Update the base URL

Replace services.nvd.nist.gov with api.vulncheck.com. Everything after the hostname stays the same.

Replace the API key

Use a VulnCheck token in place of your NVD API key. Keep sending it in the apiKey header, or switch to Authorization: Bearer.

Run your existing sync

No other change is required. Responses validate against NVD's published JSON schemas.

Verify the enrichment fields

Check for the added coverage described in What changes — CVEs that previously had no CVSS score, no CWE, or no CPE configurations may now have them.

Check how you read source and type

If your code assumes type: Primary always means NIST, read Reading source and type before going to production. This is the one behaviour that can change a result silently.

What is not supported in v1

Search and filter parameters are not implemented. A request using one returns 400 with a message saying the parameter is deferred, so you can tell a gap from a typo:

{
  "message": "parameter \"keywordSearch\" is not supported in v1; deferred to v2",
  "status": 400
}

The full list is on each endpoint page.

VulnCheck-proprietary data — CVSS-BT, VulnCheck KEV, exploit maturity is deliberately not served here. If you are interested in this data check out the native VulnCheck API and our exploit and vulnerability intelligence.