MCP servercom.cve-security/cve-intelligence
CVE intelligence: exploitation (KEV/EPSS), detection coverage, fixed versions.
Read more
CVE intelligence: exploitation (KEV/EPSS), detection coverage, fixed versions. All tools keyless.Overview
Score?
UNRATED 0.812
of what a free look can see, on 32 looks
Looks
36
last 4 hr ago
Tools
9
changed 2 days ago
More info
URL
cve-security.com/api/mcp
streamable-http
Says it is
cve-security 1.6.0
protocol 2025-06-18
In the record since
32 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.812 · highest on record 0.8561
Toolsfrom sha256:e8ae86f3e2…7cc7f6 · +0 −0 2 days ago
| Tool | Schema |
|---|---|
| get_chains Known Chained Vulnerabilities™: pairs of CVEs that a cited source reports were used together in one exploit chain (VulnCheck KEV entry text, Metasploit modules, SigmaHQ rules, pres |
input · no output |
| get_cve Full intelligence record for one CVE: per-scorer CVSS, EPSS, CISA KEV/ransomware/SSVC, four remote-detection modalities (the checks that work over the network) plus a host-check ti |
input · no output |
| get_epss_movers CVEs whose EPSS exploitation probability rose the most recently. window is "7d" (default) or "30d". Each rise is measured between same-EPSS-model-version scores, so a model release |
input · no output |
| get_scoreboard The Defender Scoreboard report (CC BY 4.0): exploited vs detectable vs patchable, every figure with its method, caveat and denominator, plus the corpus block and any method-change |
input · no output |
| get_sightings Field sightings: CVEs a named sensor network recorded in the last 7 or 30 days, most sighting days first. A field sighting is a day on which Shadowserver honeypots (cited by VulnCh |
input · no output |
| get_updates The publication change stream: what this site published, stamped with OUR publish time (first_published, kev_added, detection_added, remediation_added, first_sighted, chain_added, |
input · no output |
| query_package CVEs affecting one open-source package, by purl (pkg:npm/lodash) or ecosystem + name (Maven names are group:artifact). Returns the CVE list KEV-first with each OSV version range VE |
input · no output |
| search_cves Search the catalog. Free text (q) and/or structured filters: vendor (slug), cwe (CWE-nnn), technique (ATT&CK id, such as T1190), year ("2024,2025"), sev ("critical,high"), kev (0|1 |
input · no output |
| table1_read BOD 26-04 Table 1 read for up to 50 CVEs at a stated asset exposure. Per CVE this dataset supplies CISA KEV status and due date, CISA's SSVC Automatable and Technical impact (Vulnr |
input · no output |
Verify it yourself
npx teppi-check https://cve-security.com/api/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ25VWDYFADD0CYNVER3W3