Every endpoint keeps NVD's path, parameter names and response shape. This page lists what is supported in v1, what is deferred, and the behaviours worth knowing per endpoint.
All five also accept the pagination parameters described in Pagination.
/rest/json/cves/2.0The primary endpoint. Returns CVE records in NVD 2.0 format, with the enrichment described in What changes.
Supported: cveId, cpeName, isVulnerable, virtualMatchString, versionStart, versionStartType, versionEnd, versionEndType, vulnStatus, cveTag, hasKev, noRejected, sourceIdentifier, pubStartDate, pubEndDate, lastModStartDate, lastModEndDate
Deferred to v2: keywordSearch, keywordExactMatch, cweId, hasCertAlerts, hasCertNotes, hasOval, kevStartDate, kevEndDate
VulnCheck extensions: vcVulnerableCPEs, a flag that adds the vcVulnerableCPEs field to each record. Off by default; see Requesting vcVulnerableCPEs.
source / type behaviour and the added vcConfigurations field, plus vcVulnerableCPEs when requested. Read What changes before relying on metrics, weaknesses or CPE data./rest/json/cvehistory/2.0Change history for CVE records.
Supported: cveId, eventName, changeStartDate, changeEndDate
Deferred to v2: none
oldValue and newValue are polymorphic — a string, an array or an object depending on the change type. Affected details carry arrays, SSVC details carry objects, most others carry strings. Do not strictly type them as string; roughly a fifth of records also carry an empty details array./rest/json/cpes/2.0The NVD CPE dictionary.
Supported: cpeNameId, cpeMatchString, matchCriteriaId, lastModStartDate, lastModEndDate
Deferred to v2: keywordSearch, keywordExactMatch
cpeName retains CPE 2.3 escape sequences verbatim, exactly as NVD emits them — for example cpe:2.3:a:apache:xerces-c\+\+:-:*:*:*:*:*:*:*. Do not unescape before comparing./rest/json/cpematch/2.0CPE match criteria, and the CPE names each one resolves to.
Supported: cveId, matchCriteriaId, lastModStartDate, lastModEndDate
Deferred to v2: matchStringSearch
/rest/json/source/2.0The registry of data source identifiers, what source fields elsewhere in the API resolve to.
Supported: sourceIdentifier, lastModStartDate, lastModEndDate
Deferred to v2: none
sources[] entry rather than nested in a sub-object. Some records carry no contactEmail.VulnCheck's own identifier, disclosure@vulncheck.com, resolves here like any other, so the advice in Reading source and type to key on source works against this endpoint.
Every date-range pair must be supplied together a start without its end, or vice versa, is a 400. Timestamps use NVD's format, with no UTC offset and milliseconds present:
2026-08-24T11:27:43.187
This is not RFC 3339, and it is deliberate: matching NVD exactly matters more than correcting the format, since a client written against NVD parses it as-is.