Skip to content

CVE.report

CVE records with NVD KEV and EPSS enrichment

Open documentation ↗
No keyHTTPSNo CORSSecurity

Verified 4 days ago: 100% uptime

API key

Not required

HTTPS

Supported

Browser calls

No, needs a proxy

Status

Live · 100/100

What our checks found

Health score
100/100
Reliability
100%
Average latency
332ms

Last checked 2026-09-18. Measured independently, not self-reported by the provider.

How to call it

A starting template for CVE.report. Replace ENDPOINT with the path from the official documentation, which we link above rather than guess at.

# No authentication required.
curl -s "https://cve.report/ENDPOINT" \
  -H "Accept: application/json"

This API does not send CORS headers, so a browser will block a direct call from your front end. Call it from your server, or put a small proxy in front of it.

Where this listing comes from

Aggregated from one public source (public-api-lists), then normalised and checked by us. If something here is wrong, tell us and we will correct it.

Other Security APIs

See all 71

Blooms

Security

Distribute keys once for serverless applications

No keyCORSHTTPS

Verified 4 days ago: 100% uptime

View Details

dead-drop

Security

Ephemeral zero-knowledge encrypted data sharing

No keyCORSHTTPS

Verified 4 days ago: 100% uptime

View Details

Presend

Security

Security and developer utility API -- malware, vulnerability, and domain checks, no signup

No keyCORSHTTPS

Verified 4 days ago: 100% uptime

View Details

FishFish

Security

FishFish is an automated service designed to quickly detect and mitigate phishing threats before they can be exploited for malicious purposes. It provides a streamlined solution for identifying harmful resources efficiently.

No keyCORSHTTPS

Verified 4 days ago: 100% uptime

View Details

CVE.report — common questions

Answered from what our own scheduled checks found, not from the provider's marketing.

Is CVE.report free to use?

CVE.report is listed in our free catalogue and required no credential when we called it. It needs no authentication at all, so you can send a request without signing up. Free tiers can still carry rate limits or non-commercial terms, so check the provider's own terms before shipping.

Does CVE.report need an API key?

No. We called CVE.report on 2026-09-18 with no key, no token and no Authorization header, and it responded. That is what puts it in our no-key collection.

Can I call CVE.report from browser JavaScript?

Not directly. CVE.report did not return CORS headers when we checked, so the browser will block your page from reading the response even though the request itself succeeds. Call it from a server, or put a small proxy in front of it.

Is CVE.report still working?

Yes, as of 2026-09-18. Our automated check reached CVE.report and recorded a 100% reliability score with a median response time of 332 ms. We re-check on a schedule, and this page updates with the result.

Is CVE.report available over HTTPS?

Yes. CVE.report serves over HTTPS, so you can call it from a secure page without triggering a mixed-content block.