cve-intelligence

CVE intelligence: exploitation (KEV/EPSS), detection coverage, fixed versions. All tools keyless.

我該用這個嗎

品質與安全性

A
說明品質
100%
結構描述完整度
83%
命名品質
98%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

根據工具定義與協定合規性的自動化分析。

上下文成本

~3,431Token(工具定義)
~1.6 KB典型回應大小
顯著的注意力影響(128k 上下文的 2.68%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "cve-intelligence": {
      "url": "https://cve-security.com/api/mcp"
    }
  }
}

遠端端點

https://cve-security.com/api/mcpstreamable-http

它能做什麼

工具清單

工具(9)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
🟢get_cve(id)

Full intelligence record for one CVE: per-scorer CVSS, EPSS, CISA KEV/ransomware/SSVC, four remote-detection modalities (the checks that work over the network) plus a host-check tier (self-contained Nuclei templates and Metasploit local modules that run on the system itself) and the Sigma log-detection layer, both kept out of scannable coverage, per-product fixed versions (fixed = first patched build; affected_through = the last vulnerable build, so upgrade past it), news/community coverage, intelligence summary, and bod_26_04: the BOD 26-04 Table 1 read on both exposure branches (CISA's row numbers and timelines from KEV status and CISA's SSVC Automatable and Technical impact) with CISA's KEV due date, forensic triage flag and the KEV entry's action text (kev_required_action, CISA's requiredAction field); the agency's exposure tag decides the row. No key required over MCP; an API key on the HTTP request (Authorization: Bearer cvs_live_…) is honored for attribution. Absence semantics: a null field means this dataset holds no such record. The source may still hold one.

輸入結構描述

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "description": "CVE id, such as CVE-2024-3400"
    }
  },
  "required": [
    "id"
  ]
}
🟢search_cves(q, vendor, cwe, technique, year, ...)

Search the catalog. Free text (q) and/or structured filters: vendor (slug), cwe (CWE-nnn), technique (ATT&CK id, such as T1190), year ("2024,2025"), sev ("critical,high"), kev (0|1), kev_from / kev_to (ISO days, half-open CISA listing window; imply kev=1), kev_vendor (the CISA vendorProject string verbatim, such as "Microsoft"), ransomware (0|1), detect (0|1, a detection signal we track), fix (0|1; fix=0 means the fix status was computed and this dataset holds no actionable vendor fix), automatable (0|1, CISA SSVC Automatable; 1=yes, 0=CISA assessed no, unassessed CVEs match neither), sighted (7|30: a named sensor network recorded the CVE in the last 7 or 30 days, a field sighting; presence per day, apart from the exploitation claims), malware (0|1: a published source ties a named malware family, tool, campaign or ransomware group to the CVE), watch (0|1: on KEV Watch at tier 1 or 2, reported exploited by trackers other than CISA and outside CISA KEV), epss_gte (0..1), ti (total|partial: CISA SSVC Technical impact, for CVEs with a CISA assessment held), triage_flag (0|1: CISA's forensic triage flag on the KEV entry), ssvc (0|1; ssvc=0 selects rows with no CISA SSVC assessment held), bod (3df|3d|14d|60d|fsu: the BOD 26-04 Table 1 read at the stated exposure, with exposed 0|1, default 1; a mapping at that exposure, and an agency's timeline still needs its own enumeration date), eco (OSS ecosystem, such as npm or PyPI), pkg (pkg_key, such as npm/lodash; for ranges use query_package), page, limit (1..50). Filter-only queries return the /browse slice ordered KEV-first then EPSS.

輸入結構描述

{
  "type": "object",
  "properties": {
    "q": {
      "type": "string"
    },
    "vendor": {
      "type": "string"
    },
    "cwe": {
      "type": "string"
    },
    "technique": {
      "type": "string",
      "description": "ATT&CK technique id, such as T1190 or T1059.001"
    },
    "year": {
      "type": "string"
    },
    "sev": {
      "type": "string"
    },
    "kev": {
      "type": "string",
      "enum": [
        "0",
        "1"
      ]
    },
    "kev_from": {
      "type": "string",
      "description": "ISO day, inclusive lower bound on the CISA listing date"
    },
    "kev_to": {
      "type": "string",
      "description": "ISO day, exclusive upper bound on the CISA listing date"
    },
    "kev_vendor": {
      "type": "string",
      "description": "CISA's vendorProject, verbatim (for example 'Palo Alto Networks')"
    },
    "ransomware": {
      "type": "string",
      "enum": [
        "0",
        "1"
      ]
    },
    "detect": {
      "type": "string",
      "enum": [
        "0",
        "1"
      ]
    },
    "fix": {
      "type": "string",
      "enum": [
        "0",
        "1"
      ]
    },
    "automatable": {
      "type": "string",
      "enum": [
        "0",
        "1"
      ]
    },
    "epss_gte": {
      "type": "number"
    },
    "sighted": {
      "type": "string",
      "enum": [
        "7",
        "30"
      ],
      "description": "Field sighting window in days: a named sensor network recorded the CVE within the last 7 or 30 days"
    },
    "malware": {
      "type": "string",
      "enum": [
        "0",
        "1"
      ],
      "description": "A published source ties a named malware family, tool, campaign or ransomware group to the CVE"
    },
    "watch": {
      "type": "string",
      "enum": [
        "0",
        "1"
      ],
      "description": "On KEV Watch at tier 1 or 2: reported as exploited by trackers other than CISA, outside CISA KEV"
    },
    "chained": {
      "type": "string",
      "enum": [
        "0",
        "1"
      ],
      "description": "In a known exploit chain: a cited source reports the CVE was used together with another CVE in one exploit chain"
    },
    "chainability": {
      "type": "string",
      "enum": [
        "0",
        "1"
      ],
      "description": "On KCV Watch™: the CVE carries at least one chain candidate, a same-product pair whose extracted exploit capabilities connect, derived from exploit-capability analysis; a candidate is not a confirmed chain"
    },
    "ti": {
      "type": "string",
      "enum": [
        "total",
        "partial"
      ],
      "description": "CISA SSVC Technical impact, for CVEs with a CISA assessment held"
    },
    "triage_flag": {
      "type": "string",
      "enum": [
        "0",
        "1"
      ],
      "description": "CISA's forensic triage flag on the KEV entry (BOD 26-04)"
    },
    "ssvc": {
      "type": "string",
      "enum": [
        "0",
        "1"
      ],
      "description": "Whether this dataset holds a CISA SSVC assessment for the CVE"
    },
    "bod": {
      "type": "string",
      "enum": [
        "3df",
        "3d",
        "14d",
        "60d",
        "fsu"
      ],
      "description": "BOD 26-04 Table 1 read at the stated exposure: a mapping of KEV status and CISA SSVC values to a timeline key at that exposure"
    },
    "exposed": {
      "type": "string",
      "enum": [
        "0",
        "1"
      ],
      "description": "The exposure branch for bod: 1 publicly exposed (default), 0 internal"
    },
    "eco": {
      "type": "string"
    },
    "pkg": {
      "type": "string"
    },
    "page": {
      "type": "integer"
    },
    "limit": {
      "type": "integer"
    }
  }
}
🟢query_package(purl, ecosystem, name)

CVEs affecting one open-source package, by purl (pkg:npm/lodash) or ecosystem + name (Maven names are group:artifact). Returns the CVE list KEV-first with each OSV version range VERBATIM: `events` plus one render-safe projection: `fixed` (the upgrade targets) or `affected_through` (the last VULNERABLE version, so upgrade past it). This tool does not evaluate version membership; compare versions on your side with your ecosystem’s own semantics. Covers CVE-linked, GitHub-reviewed OSS advisories via OSV.dev; absence is not evidence of safety.

輸入結構描述

{
  "type": "object",
  "properties": {
    "purl": {
      "type": "string",
      "description": "Package URL, such as pkg:npm/lodash or pkg:maven/org.apache.logging.log4j/log4j-core"
    },
    "ecosystem": {
      "type": "string",
      "description": "OSV ecosystem (npm, PyPI, Maven, Go, crates.io, Packagist, RubyGems, NuGet, …) or purl type (pypi, cargo, composer, gem, golang, …)"
    },
    "name": {
      "type": "string",
      "description": "Package name, verbatim (for example @babel/core or org.jenkins-ci.main:jenkins-core)"
    }
  }
}
🟢get_updates(since, cursor, type, cve, limit)

The publication change stream: what this site published, stamped with OUR publish time (first_published, kev_added, detection_added, remediation_added, first_sighted, chain_added, and the BOD 26-04 Table 1 input changes ssvc_changed, kev_due_changed, kev_triage_flag_changed, kev_notes_changed, which fire on value changes between snapshots; a timestamp refresh alone fires none). Pass since (YYYY-MM-DD, strictly-after) on the first call, then the returned next_cursor to continue. Optional cve scopes the stream to one CVE's change history. Events for withdrawn CVE ids are omitted.

輸入結構描述

{
  "type": "object",
  "properties": {
    "since": {
      "type": "string"
    },
    "cursor": {
      "type": "string"
    },
    "type": {
      "type": "string",
      "enum": [
        "first_published",
        "kev_added",
        "detection_added",
        "remediation_added",
        "first_sighted",
        "chain_added",
        "ssvc_changed",
        "kev_due_changed",
        "kev_triage_flag_changed",
        "kev_notes_changed"
      ]
    },
    "cve": {
      "type": "string",
      "description": "Scope to one CVE's change history, such as CVE-2024-3400"
    },
    "limit": {
      "type": "integer"
    }
  }
}
🟢get_scoreboard

The Defender Scoreboard report (CC BY 4.0): exploited vs detectable vs patchable, every figure with its method, caveat and denominator, plus the corpus block and any method-change notes. Cite as "CVE Security Defender Scoreboard, cve-security.com/scoreboard".

輸入結構描述

{
  "type": "object",
  "properties": {}
}
🟢get_sightings(window, kev, limit)

Field sightings: CVEs a named sensor network recorded in the last 7 or 30 days, most sighting days first. A field sighting is a day on which Shadowserver honeypots (cited by VulnCheck KEV and published as daily lists by CIRCL Vulnerability-Lookup) or VulnCheck canary sensors recorded traffic aimed at the CVE. Each row carries first and last sighting day, days sighted in the last 7 and 30, the sensors, and per-sensor detail including a 30-day presence strip. Presence per day, without volume; a sighting stays apart from the exploitation claims and from CISA KEV. Filters: window (7|30, default 7), kev (0|1), limit (1..500).

輸入結構描述

{
  "type": "object",
  "properties": {
    "window": {
      "type": "string",
      "enum": [
        "7",
        "30"
      ],
      "description": "Sighting window in days (default 7)"
    },
    "kev": {
      "type": "string",
      "enum": [
        "0",
        "1"
      ],
      "description": "Restrict to CVEs outside (0) or inside (1) CISA KEV"
    },
    "limit": {
      "type": "integer",
      "description": "1..500 (default 100)"
    }
  }
}
🟢get_chains(source, since, claim, limit)

Known Chained Vulnerabilities™: pairs of CVEs that a cited source reports were used together in one exploit chain (VulnCheck KEV entry text, Metasploit modules, SigmaHQ rules, press, research or academic sentences, community text judged by a local model). Each row carries both CVEs with their CISA KEV status, the claim kind (observed: the source reports attacks; potential: the source reports they can be chained), the quoted evidence with its source, URL and date, and community discussion counts, which show discussion and are not chain claims. The per-CVE record carries chains.known and chains.candidates (KCV Watch: possible chains for teams to research, same-product pairs whose extracted exploit capabilities connect, derived and never confirmed, each with its tier, basis, shared product, bridge, grade, a caption and the entry step); search_cves accepts chained=1 and chainability=1. Filters: source (vulncheck_kev, metasploit, sigma, press, research, community), since (YYYY-MM-DD, first seen), claim (observed|potential), limit (1..500).

輸入結構描述

{
  "type": "object",
  "properties": {
    "source": {
      "type": "string",
      "description": "Evidence lane: vulncheck_kev, metasploit, sigma, press, research, academic, community, github_poc, exploitdb or exploit_code"
    },
    "since": {
      "type": "string",
      "description": "Pairs first seen on or after this day (YYYY-MM-DD)"
    },
    "claim": {
      "type": "string",
      "enum": [
        "observed",
        "potential"
      ],
      "description": "observed: the source reports attacks that chained them; potential: the source reports they can be chained"
    },
    "limit": {
      "type": "integer",
      "description": "1..500 (default 100)"
    }
  }
}
🟢get_epss_movers(window, limit)

CVEs whose EPSS exploitation probability rose the most recently. window is "7d" (default) or "30d". Each rise is measured between same-EPSS-model-version scores, so a model release (which shifts the whole distribution) never appears as a mover. A rise raises the priority of a CVE; observed exploitation is recorded through CISA KEV. Returns cve_id, current score, the delta, KEV status and url, largest rise first.

輸入結構描述

{
  "type": "object",
  "properties": {
    "window": {
      "type": "string",
      "enum": [
        "7d",
        "30d"
      ],
      "description": "Rise window (default 7d)"
    },
    "limit": {
      "type": "integer",
      "description": "1..100 (default 25)"
    }
  }
}
🟢table1_read(ids, exposure)

BOD 26-04 Table 1 read for up to 50 CVEs at a stated asset exposure. Per CVE this dataset supplies CISA KEV status and due date, CISA's SSVC Automatable and Technical impact (Vulnrichment) and CISA's forensic triage flag on the KEV entry; you supply exposure for the asset (yes, no, or unknown, which returns both branches). Each item carries the Table 1 row and timeline for the stated exposure, both branches, kev_feed (which branch reproduces CISA's due date and flag pair, if any) and the fix and detection state held, lanes listed separately. A row is a mapping; an agency's timeline for an asset also needs the agency's own enumeration date, so no date is returned beyond CISA's KEV due date. basis says where the values came from: cisa_ssvc, cisa_interim (a CVE outside KEV with no CISA assessment held takes CISA's interim values) or kev_unassessed (a KEV entry with no values held gets no rows).

輸入結構描述

{
  "type": "object",
  "properties": {
    "ids": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "minItems": 1,
      "maxItems": 50,
      "description": "CVE ids, such as CVE-2024-3400 (1 to 50)"
    },
    "exposure": {
      "type": "string",
      "enum": [
        "yes",
        "no",
        "unknown"
      ],
      "description": "Whether the asset is publicly exposed, the agency's own per-asset value; unknown returns both branches"
    }
  },
  "required": [
    "ids"
  ]
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本9 個工具
已驗證未記錄版本8 個工具