NVD API Compatibility

Endpoint reference

Supported and deferred parameters for each of the five endpoints, plus per-endpoint quirks

Every endpoint keeps NVD's path, parameter names and response shape. This page lists what is supported in v1, what is deferred, and the behaviours worth knowing per endpoint.

All five also accept the pagination parameters described in Pagination.

/rest/json/cves/2.0

The primary endpoint. Returns CVE records in NVD 2.0 format, with the enrichment described in What changes.

Supported: cveId, cpeName, isVulnerable, virtualMatchString, versionStart, versionStartType, versionEnd, versionEndType, vulnStatus, cveTag, hasKev, noRejected, sourceIdentifier, pubStartDate, pubEndDate, lastModStartDate, lastModEndDate

Deferred to v2: keywordSearch, keywordExactMatch, cweId, hasCertAlerts, hasCertNotes, hasOval, kevStartDate, kevEndDate

VulnCheck extensions: vcVulnerableCPEs, a flag that adds the vcVulnerableCPEs field to each record. Off by default; see Requesting vcVulnerableCPEs.

This endpoint carries the source / type behaviour and the added vcConfigurations field, plus vcVulnerableCPEs when requested. Read What changes before relying on metrics, weaknesses or CPE data.

/rest/json/cvehistory/2.0

Change history for CVE records.

Supported: cveId, eventName, changeStartDate, changeEndDate

Deferred to v2: none

oldValue and newValue are polymorphic — a string, an array or an object depending on the change type. Affected details carry arrays, SSVC details carry objects, most others carry strings. Do not strictly type them as string; roughly a fifth of records also carry an empty details array.

/rest/json/cpes/2.0

The NVD CPE dictionary.

Supported: cpeNameId, cpeMatchString, matchCriteriaId, lastModStartDate, lastModEndDate

Deferred to v2: keywordSearch, keywordExactMatch

cpeName retains CPE 2.3 escape sequences verbatim, exactly as NVD emits them — for example cpe:2.3:a:apache:xerces-c\+\+:-:*:*:*:*:*:*:*. Do not unescape before comparing.

/rest/json/cpematch/2.0

CPE match criteria, and the CPE names each one resolves to.

Supported: cveId, matchCriteriaId, lastModStartDate, lastModEndDate

Deferred to v2: matchStringSearch

/rest/json/source/2.0

The registry of data source identifiers, what source fields elsewhere in the API resolve to.

Supported: sourceIdentifier, lastModStartDate, lastModEndDate

Deferred to v2: none

Record fields sit at the top of each sources[] entry rather than nested in a sub-object. Some records carry no contactEmail.

VulnCheck's own identifier, disclosure@vulncheck.com, resolves here like any other, so the advice in Reading source and type to key on source works against this endpoint.

Date ranges

Every date-range pair must be supplied together a start without its end, or vice versa, is a 400. Timestamps use NVD's format, with no UTC offset and milliseconds present:

2026-08-24T11:27:43.187

This is not RFC 3339, and it is deliberate: matching NVD exactly matters more than correcting the format, since a client written against NVD parses it as-is.