Skip to content
Vinkius

NIST NVD Connector for AI agents.

10 live capabilities

Pull authoritative CVE and CPE data for security research.

Live agent request NIST NVD / Connector

Waiting for input…

AI Agent

Why people use NIST NVD

NIST NVD for Faster Vulnerability Research

With this Connector, your agent does the hunting for you. You just describe the product or the severity level you're worried about, and the agent pulls the data directly from the source. You get a clean list of risks without ever opening a browser.

  • Claude
  • ChatGPT
  • Gemini
  • Cursor
  • Visual Studio Code
  • Windsurf

What Vinkius changes

You get a direct line to authoritative vulnerability data without the manual searching.

Use it from Claude, ChatGPT, Cursor or another AI client you already have.

One account · 5,900+ Connectors

  1. Real-world use case 01

    Identifying risks for a specific router

    A user asks the agent to find CVEs for a specific CPE string.

  2. Real-world use case 02

    Finding high-severity flaws in a recent update

    A developer asks for all 'Critical' vulnerabilities published in the last month.

  3. Real-world use case 03

    Researching specific weakness types

    A researcher wants to see all flaws related to Cross-Site Scripting.

Complete set · 10capabilities

The complete NIST NVD capability set.

These are the exact actions your AI can choose when you ask it to work with NIST NVD.

Capability set01 / 03

01—04

4 capabilities in this set.

Part of 10 available through NIST NVD.

  1. 01 Capability

    Search cpe by keyword

    Find specific software or hardware products using a simple keyword search in the dictionary.

  2. 02 Capability

    Search cve by cpe

    Identify all vulnerabilities associated with a specific product or version string.

  3. 03 Capability

    Search cve by cwe

    Find flaws based on the specific type of weakness like SQL injection or buffer overflows.

  4. 04 Capability

    Search cve by date

    Filter the database for vulnerabilities published or modified during a specific timeframe.

Capability set02 / 03

05—07

3 capabilities in this set.

Part of 10 available through NIST NVD.

  1. 05 Capability

    Search cve by keyword

    Search for CVEs using general terms or specific vulnerability descriptions.

  2. 06 Capability

    Search cve by severity

    Filter results to only show vulnerabilities with specific CVSS severity levels.

  3. 07 Capability

    Get cpe by id

    Retrieve the specific product entry from the CPE dictionary using its unique UUID.

Capability set03 / 03

08—10

3 capabilities in this set.

Part of 10 available through NIST NVD.

  1. 08 Capability

    Get cve change history

    See the timeline of updates and modifications for a specific vulnerability record.

  2. 09 Capability

    List cpe matches

    Get a list of valid CPE strings that match your specific product search terms.

  3. 10 Capability

    Get cve by id

    Pull the full details for a specific vulnerability record using its CVE identifier.

Set up in minutes

One URL. Then ask NIST NVD to work.

Claude and ChatGPT only need the Connector URL. Copy it once, add it in settings, and use NIST NVD from the conversation.

Choose your client

Live preview
Advanced clients IDE · CLI

Claude · Web + desktop

Official guide ↗

Connector URL · ready to paste

Streamable HTTP
https://edge.vinkius.com/vk_preview_di1FzaR2p54s3bOkX9Kq05itOme6MTw3QnOWExLr/mcp
  1. Step 01

    Open Connectors

    In Claude Web or Claude Desktop, open Settings and choose Connectors.

  2. Step 02

    Add the URL

    Choose Add custom connector, name it NIST NVD, and paste the URL above.

  3. Step 03

    Turn it on in chat

    Select +, open Connectors, and enable NIST NVD for the conversation.

Where the request belongs

Work NIST NVD can move forward.

Built around the request

This is for the security professional who needs to move faster than a browser tab allows. It's for people who handle high-stakes risk assessments where accuracy and speed are non-negotiable.

01

Security Researcher

Investigating new CVEs to see how they affect specific software stacks during a threat hunt.

02

DevOps Engineer

Checking if a new library update introduces known critical vulnerabilities before it hits production.

03

Compliance Officer

Gathering evidence of vulnerability management and CVSS scores for security audits and reporting.

Bring your own AI

Change the model, client or framework. Keep NIST NVD connected.

  • Claude
  • ChatGPT
  • Gemini
  • Cursor
  • VS Code
  • Windsurf
  • ZCode
  • Cline
  • Zed
  • Continue
  • Kiro
  • Roo Code
  • Zencoder
  • Goose
  • Void
  • Augment Code
  • Amp
  • Qodo
  • Tabnine
  • Pieces
  • Sourcegraph Cody
  • JetBrains
  • Warp
  • Amazon Q
  • Antigravity
  • BoltAI
  • Raycast
  • Jan
  • LM Studio
  • AnythingLLM
  • Open WebUI
  • Msty
  • Cherry Studio
  • LibreChat
  • TypingMind
  • Chorus
  • 5ire
  • n8n
  • LangChain
  • LlamaIndex
  • CrewAI
  • Vercel AI SDK

Before you connect

Questions about NIST NVD.

The practical details behind the request, access and result.

Can the NIST NVD MCP help me identify which products are at risk?

Yes, it allows your agent to search for specific hardware and software products using keywords or official identifiers to see exactly what vulnerabilities apply to them.

How does the NIST NVD MCP handle different security severity levels?

You can ask your agent to filter results by CVSS scores, letting you focus only on the most critical threats that need immediate attention.

Can I use the NIST NVD MCP to track changes to a specific vulnerability?

Yes, the Connector can pull the full change history for a CVE, showing you how the database record has been updated over time.

Is the NIST NVD MCP good for security audits?

It's excellent for audits because it pulls authoritative data directly from the National Vulnerability Database, ensuring your reports are based on official records.

Can the NIST NVD MCP search for vulnerabilities by weakness type?

Yes, you can search by CWE (Common Weakness Enumeration) to find all vulnerabilities related to specific issues like buffer overflows or cross-site scripting.

Does the NIST NVD MCP require an API key?

While it works without one, providing your NIST NVD API key will give your agent higher rate limits for more frequent searches.

Is an API Key mandatory?

No. The NVD API allows public access without a key. However, using a key increases your rate limit significantly (up to 50 requests per 30 seconds).

What is a CPE string?

CPE (Common Platform Enumeration) is a structured naming scheme for information technology systems, software, and packages (e.g., cpe:2.3:a:microsoft:exchange_server:2019).

How far back can I search for vulnerabilities?

The NVD contains vulnerabilities dating back to the late 1990s. You can search the entire database by ID or keyword.

One connection away

Give your agent a direct line to NIST NVD.

Connect NIST NVD once. Keep it beside 5,900+ managed Connectors when the next task needs more.

Explore every Connector No credit card required · Free tier available