> For the complete documentation index, see [llms.txt](https://doc.duaer.com/zh/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/zh/getting-started/nvd.md).

# 在 Duaer 里查NVD 漏洞库

在 Duaer 里：按关键词或 CVE 编号检索美国国家漏洞库（NVD）的 CVE 记录，按时间倒序，含 CVSS 评分、弱点类型与已被利用日期。一次成功查询用 1 额度。
## 能拿到什么

Duaer 数据市场里的「NVD 漏洞库」：按关键词或 CVE 编号检索美国国家漏洞库（NVD）的 CVE 记录，按时间倒序，含 CVSS 评分、弱点类型与已被利用日期。查到结果时用 1 额度，结果交给数字组织的下一个节点。

从节点创建器选 Duaer 数据 → NVD 漏洞库，或打开 [数据市场](/zh/getting-started/data-market.md)。相关：[OSV 开源漏洞](/zh/getting-started/osv.md)、[CISA 已被利用漏洞](/zh/getting-started/cisa-kev.md)。

## 适合做什么

- 按关键词查找最新 CVE 及其 CVSS 评分。
- 核对某个 CVE 编号的描述与严重程度。

## 在画布里检索

1. 打开节点创建器，选 Duaer 数据 → NVD CVE records。
2. 填 Words（如 log4j），或填 CVE ID。
3. Limit 默认 10，最大 20。执行。

查到结果才扣 1 额度；没有结果、输入有误或上游失败都不扣。

## 用 API 调用

- GET https://api.duaer.com/v1/data/nvd?words=openssl
- Authorization: Bearer <Duaer key>

下方是与数据市场「复制技能」相同的英文技能，含参数、示例与返回字段。

## 调用技能（英文）

与数据市场「复制技能」一致。

```
---
name: duaer-nvd
description: >-
  Duaer NVD CVE records. CVE records from the US National Vulnerability Database by keyword or CVE id, newest first, with CVSS score, weakness, and known-exploited date.
  One successful search uses 1 Duaer credit.
---

# Duaer NVD CVE records

Duaer NVD CVE records searches the US National Vulnerability Database. It returns the newest matching CVEs first, with the CVSS score NVD or the vendor assigned.

## When to use

- Get the CVSS score and description of a CVE.
- List recent CVEs for a product such as openssl.

## When not to use

- Affected package versions. Use https://skills.duaer.com/osv.md.
- Only CVEs attacked in the wild. Use https://skills.duaer.com/cisa-kev.md.

## Call

`GET https://api.duaer.com/v1/data/nvd?words=openssl`

Header: `Authorization: Bearer <Duaer key>`

Use an account key or a model API key.

Get a Duaer key: https://skills.duaer.com/keys.md

## Parameters

Provide `words` or `cve`.

- `words` — Keywords, such as openssl or log4j.
- `cve` — Optional. One record such as CVE-2021-44228.
- `limit` — Optional. Rows to return, from 1 to 20. Default 10.

## Examples

- `GET https://api.duaer.com/v1/data/nvd?words=openssl` — the newest OpenSSL CVEs.
- `GET https://api.duaer.com/v1/data/nvd?cve=CVE-2021-44228` — the Log4Shell record.

## Result

The response is `{ "items": [...] }`. Each item has `source`, `title`, `url`, and `summary`, plus:

- `cveId`, `description` — id and English description.
- `cvssScore`, `cvssSeverity`, `cvssVector`, `cvssVersion` — best available CVSS (4.0, 3.1, 3.0, then 2).
- `cwe`, `status` — weakness ids and NVD analysis status.
- `knownExploitedSince` — date CISA listed it as exploited, when it is.
- `published`, `lastModified` — dates.

NVD allows few anonymous calls; a busy period can return 503 at 0 credits.

Fields without a value are left out.

## Credits

A search that returns at least one row uses 1 credit.
An empty search, a search that finds nothing, or a failed search uses 0.
Wrong input returns 400 with a message and uses 0.
No remaining credits returns 402 and does not search.
A missing key returns 401.

## Related

- https://skills.duaer.com/osv.md — Duaer OSV vulnerabilities
- https://skills.duaer.com/cisa-kev.md — Duaer CISA known exploited vulnerabilities

```
## Questions

### Duaer 的NVD 漏洞库检索扣多少额度？

查到结果时扣 1 额度；没有结果或出错不扣。

### Duaer NVD 漏洞库为什么偶尔返回 503？

NVD 限制匿名调用频率；繁忙时 Duaer NVD 漏洞库返回 503，不扣额度，稍后重试即可。

## 相关

- [在 Duaer 里查OSV 开源漏洞](https://doc.duaer.com/zh/getting-started/osv.md)
- [在 Duaer 里查CISA 已被利用漏洞](https://doc.duaer.com/zh/getting-started/cisa-kev.md)

