VulnCheck serves the five NVD API 2.0 endpoints at their original paths. An existing integration moves across by changing the base URL and the API key. The request shape, the query parameters and the response schema are unchanged.
curl "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2024-1234" \
--header 'apiKey: insert_nvd_key_here'
curl "https://api.vulncheck.com/rest/json/cves/2.0?cveId=CVE-2024-1234" \
--header 'apiKey: insert_vulncheck_token_here'
Both header styles work. apiKey exists so an NVD client needs no code change; Authorization: Bearer is accepted too, so the compat endpoints behave like the rest of the VulnCheck API.
curl "https://api.vulncheck.com/rest/json/cves/2.0?cveId=CVE-2024-1234" \
--header 'apiKey: insert_token_here'
curl "https://api.vulncheck.com/rest/json/cves/2.0?cveId=CVE-2024-1234" \
--header 'Authorization: Bearer insert_token_here'
| NVD | VulnCheck |
|---|---|
services.nvd.nist.gov/rest/json/cves/2.0 | api.vulncheck.com/rest/json/cves/2.0 |
services.nvd.nist.gov/rest/json/cvehistory/2.0 | api.vulncheck.com/rest/json/cvehistory/2.0 |
services.nvd.nist.gov/rest/json/cpes/2.0 | api.vulncheck.com/rest/json/cpes/2.0 |
services.nvd.nist.gov/rest/json/cpematch/2.0 | api.vulncheck.com/rest/json/cpematch/2.0 |
services.nvd.nist.gov/rest/json/source/2.0 | api.vulncheck.com/rest/json/source/2.0 |
Replace services.nvd.nist.gov with api.vulncheck.com. Everything after the hostname stays the same.
Use a VulnCheck token in place of your NVD API key. Keep sending it in the apiKey header, or switch to Authorization: Bearer.
No other change is required. Responses validate against NVD's published JSON schemas.
Check for the added coverage described in What changes — CVEs that previously had no CVSS score, no CWE, or no CPE configurations may now have them.
source and typeIf your code assumes type: Primary always means NIST, read Reading source and type before going to production. This is the one behaviour that can change a result silently.
Search and filter parameters are not implemented. A request using one returns 400 with a message saying the parameter is deferred, so you can tell a gap from a typo:
{
"message": "parameter \"keywordSearch\" is not supported in v1; deferred to v2",
"status": 400
}
The full list is on each endpoint page.
VulnCheck-proprietary data — CVSS-BT, VulnCheck KEV, exploit maturity is deliberately not served here. If you are interested in this data check out the native VulnCheck API and our exploit and vulnerability intelligence.