> For the complete documentation index, see [llms.txt](https://doc.duaer.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/getting-started/nvd.md).

# NVD CVE records in Duaer

In Duaer: CVE records from the US National Vulnerability Database by keyword or CVE id, newest first, with CVSS score, weakness, and known-exploited date. One successful search uses 1 credit.
## What you get

Duaer NVD CVE records searches the US National Vulnerability Database. It returns the newest matching CVEs first, with the CVSS score NVD or the vendor assigned.

Pick Duaer Data → NVD CVE records in the node creator, or open the [data market](/getting-started/data-market.md). Related: [OSV vulnerabilities](/getting-started/osv.md), [CISA known exploited vulnerabilities](/getting-started/cisa-kev.md).

## When to use it

- Get the CVSS score and description of a CVE.
- List recent CVEs for a product such as openssl.

## When not to use it

- Affected package versions. Use [OSV vulnerabilities](/getting-started/osv.md).
- Only CVEs attacked in the wild. Use [CISA known exploited vulnerabilities](/getting-started/cisa-kev.md).

## Search on the canvas

1. Open the node creator and pick Duaer Data → NVD CVE records.
2. Fill Words (such as log4j), or CVE ID.
3. Limit defaults to 10, max 20. Execute.

A search uses 1 credit only when it returns rows. No rows, wrong input, or an upstream failure uses 0.

## Call the API

- GET https://api.duaer.com/v1/data/nvd?words=openssl
- Authorization: Bearer <Duaer key>

The call skill below matches Copy skill in the Duaer data market, with parameters, examples, and result fields.

## Call skill

Same text as Copy skill.

```
---
name: duaer-nvd
description: >-
  Duaer NVD CVE records. CVE records from the US National Vulnerability Database by keyword or CVE id, newest first, with CVSS score, weakness, and known-exploited date.
  One successful search uses 1 Duaer credit.
---

# Duaer NVD CVE records

Duaer NVD CVE records searches the US National Vulnerability Database. It returns the newest matching CVEs first, with the CVSS score NVD or the vendor assigned.

## When to use

- Get the CVSS score and description of a CVE.
- List recent CVEs for a product such as openssl.

## When not to use

- Affected package versions. Use https://skills.duaer.com/osv.md.
- Only CVEs attacked in the wild. Use https://skills.duaer.com/cisa-kev.md.

## Call

`GET https://api.duaer.com/v1/data/nvd?words=openssl`

Header: `Authorization: Bearer <Duaer key>`

Use an account key or a model API key.

Get a Duaer key: https://skills.duaer.com/keys.md

## Parameters

Provide `words` or `cve`.

- `words` — Keywords, such as openssl or log4j.
- `cve` — Optional. One record such as CVE-2021-44228.
- `limit` — Optional. Rows to return, from 1 to 20. Default 10.

## Examples

- `GET https://api.duaer.com/v1/data/nvd?words=openssl` — the newest OpenSSL CVEs.
- `GET https://api.duaer.com/v1/data/nvd?cve=CVE-2021-44228` — the Log4Shell record.

## Result

The response is `{ "items": [...] }`. Each item has `source`, `title`, `url`, and `summary`, plus:

- `cveId`, `description` — id and English description.
- `cvssScore`, `cvssSeverity`, `cvssVector`, `cvssVersion` — best available CVSS (4.0, 3.1, 3.0, then 2).
- `cwe`, `status` — weakness ids and NVD analysis status.
- `knownExploitedSince` — date CISA listed it as exploited, when it is.
- `published`, `lastModified` — dates.

NVD allows few anonymous calls; a busy period can return 503 at 0 credits.

Fields without a value are left out.

## Credits

A search that returns at least one row uses 1 credit.
An empty search, a search that finds nothing, or a failed search uses 0.
Wrong input returns 400 with a message and uses 0.
No remaining credits returns 402 and does not search.
A missing key returns 401.

## Related

- https://skills.duaer.com/osv.md — Duaer OSV vulnerabilities
- https://skills.duaer.com/cisa-kev.md — Duaer CISA known exploited vulnerabilities

```
## Questions

### How many credits does a NVD CVE records search use in Duaer?

One credit when Duaer returns rows. A search with no rows or an error uses 0.

### Why does Duaer NVD CVE records sometimes return 503?

NVD limits anonymous calls. When it is busy, Duaer NVD CVE records returns 503 at 0 credits; try again later.

## Related

- [OSV vulnerabilities in Duaer](https://doc.duaer.com/getting-started/osv.md)
- [CISA known exploited vulnerabilities in Duaer](https://doc.duaer.com/getting-started/cisa-kev.md)

