# nvd.cves.search

Search the National Vulnerability Database for CVE records by keyword, vendor, product, CVSS severity, or publication date range. Returns CVE-ID, summary, CVSS v3 base score, severity (LOW/MEDIUM/HIGH/CRITICAL), affected CPE configurations, references. Distinct from OSV: NVD provides canonical NIST records with CVSS v3 scores, CWE weakness types, and CPE configurations.

Agent View of the PolicyLayer registry record for `nvd.cves.search`. HTML page: https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/nvd.cves.search

## Facts

- Tool: `nvd.cves.search`
- Server: Apibase (`apibase-mcp-client`) — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase.md
- Install: `npx -y apibase-mcp-client`
- Homepage: https://github.com/whiteknightonhorse/APIbase
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 6
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `keyword` | string | no | Free-text keyword to search CVE records. Examples: 'log4j', 'OpenSSL CVE-2023', 'Linux kernel use-after-free'. Combined with other filters using AND logic. |
| `start_index` | integer | no | Zero-based offset for pagination. Use with results_per_page to page through large result sets. Default: 0. |
| `pub_end_date` | string | no | Latest CVE publication date in ISO 8601 extended format with timezone offset (e.g. '2024-12-31T23:59:59.999+00:00'). Must be paired with pub_start_date. Maximum |
| `pub_start_date` | string | no | Earliest CVE publication date in ISO 8601 extended format with timezone offset (e.g. '2024-01-01T00:00:00.000+00:00'). Maximum 120-day window per request when c |
| `cvss_v3_severity` | string | no | Filter by CVSS v3 base severity. LOW = 0.1–3.9, MEDIUM = 4.0–6.9, HIGH = 7.0–8.9, CRITICAL = 9.0–10.0. Omit to return all severities. |
| `results_per_page` | integer | no | Number of CVE records to return per page. Range: 1–2000. Default: 20. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "nvd.cves.search",
    "arguments": {}
  }
}
```

## Why nvd.cves.search is rated Low

Tool searches and retrieves public vulnerability data without modifying systems or triggering actions.

From the tool's own definition: "Search the National Vulnerability Database for CVE records by keyword, vendor, product, CVSS severity, or publication date range. Returns CVE-ID, summary, CVSS v3 base score."

## Use case

AI agents call nvd.cves.search to retrieve information from Apibase without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Apibase:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "nvd.cves.search": {}
  }
}
```

## Other tools on Apibase (1383)

- `infra.cloudflare.dns_delete` — Destructive — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/infra.cloudflare.dns-delete.md
- `infra.cloudflare.purge_cache` — Destructive — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/infra.cloudflare.purge-cache.md
- `polymarket.trading.cancel_order` — Destructive — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/polymarket.trading.cancel-order.md
- `ai.image.generate` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/ai.image.generate.md
- `aipush.market.report` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/aipush.market.report.md
- `audio.transcribe.submit` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/audio.transcribe.submit.md
- `dev.code.execute` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/dev.code.execute.md
- `device.registry.command` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/device.registry.command.md
- `document.convert.from_pdf` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/document.convert.from-pdf.md
- `document.convert.to_pdf` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/document.convert.to-pdf.md
- `document.convert.web_to_pdf` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/document.convert.web-to-pdf.md
- `hf_inference.nlp.translate` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/hf-inference.nlp.translate.md
- `infra.browser.create_session` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/infra.browser.create-session.md
- `phone.telnyx.sms_world` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/phone.telnyx.sms-world.md
- `phone.twilio.sms` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/phone.twilio.sms.md
- `platform.batch.call` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/platform.batch.call.md
- `scb.tables.query` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/scb.tables.query.md
- `socrata.datasets.query` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/socrata.datasets.query.md
- `web.screenshot.capture` — Execute — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/web.screenshot.capture.md
- `domain.namesilo.register` — Financial — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/domain.namesilo.register.md
- `phone.telnyx.sms_premium` — Financial — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/phone.telnyx.sms-premium.md
- `polymarket.trading.place_order` — Financial — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/polymarket.trading.place-order.md
- `abr.business.abn_lookup` — Read — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/abr.business.abn-lookup.md
- `abr.business.acn_lookup` — Read — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/abr.business.acn-lookup.md
- `abr.business.name_search` — Read — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/abr.business.name-search.md
- `abs.demographics.population` — Read — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/abs.demographics.population.md
- `abs.economy.cpi` — Read — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/abs.economy.cpi.md
- `abs.economy.gdp` — Read — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/abs.economy.gdp.md
- `abs.economy.labour_force` — Read — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/abs.economy.labour-force.md
- `abs.economy.trade` — Read — https://policylayer.com/tools/io-github-whiteknightonhorse-apibase/abs.economy.trade.md
- …and 1353 more: https://policylayer.com/tools/io-github-whiteknightonhorse-apibase.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=io-github-whiteknightonhorse-apibase · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/io-github-whiteknightonhorse-apibase
