Duaer

入门

在 Duaer 里查NVD 漏洞库

在 Duaer 里:按关键词或 CVE 编号检索美国国家漏洞库(NVD)的 CVE 记录,按时间倒序,含 CVSS 评分、弱点类型与已被利用日期。一次成功查询用 1 额度。

能拿到什么

Duaer 数据市场里的「NVD 漏洞库」:按关键词或 CVE 编号检索美国国家漏洞库(NVD)的 CVE 记录,按时间倒序,含 CVSS 评分、弱点类型与已被利用日期。查到结果时用 1 额度,结果交给数字组织的下一个节点。

从节点创建器选 Duaer 数据 → NVD 漏洞库,或打开 数据市场。相关:OSV 开源漏洞、CISA 已被利用漏洞。

适合做什么

  • 按关键词查找最新 CVE 及其 CVSS 评分。
  • 核对某个 CVE 编号的描述与严重程度。

在画布里检索

  1. 打开节点创建器,选 Duaer 数据 → NVD CVE records。
  2. 填 Words(如 log4j),或填 CVE ID。
  3. Limit 默认 10,最大 20。执行。

查到结果才扣 1 额度;没有结果、输入有误或上游失败都不扣。

用 API 调用

  • GET https://api.duaer.com/v1/data/nvd?words=openssl
  • Authorization: Bearer <Duaer key>

下方是与数据市场「复制技能」相同的英文技能,含参数、示例与返回字段。

调用技能(英文)

与数据市场「复制技能」一致。

---
name: duaer-nvd
description: >-
  Duaer NVD CVE records. CVE records from the US National Vulnerability Database by keyword or CVE id, newest first, with CVSS score, weakness, and known-exploited date.
  One successful search uses 1 Duaer credit.
---

# Duaer NVD CVE records

Duaer NVD CVE records searches the US National Vulnerability Database. It returns the newest matching CVEs first, with the CVSS score NVD or the vendor assigned.

## When to use

- Get the CVSS score and description of a CVE.
- List recent CVEs for a product such as openssl.

## When not to use

- Affected package versions. Use https://skills.duaer.com/osv.md.
- Only CVEs attacked in the wild. Use https://skills.duaer.com/cisa-kev.md.

## Call

`GET https://api.duaer.com/v1/data/nvd?words=openssl`

Header: `Authorization: Bearer <Duaer key>`

Use an account key or a model API key.

Get a Duaer key: https://skills.duaer.com/keys.md

## Parameters

Provide `words` or `cve`.

- `words` — Keywords, such as openssl or log4j.
- `cve` — Optional. One record such as CVE-2021-44228.
- `limit` — Optional. Rows to return, from 1 to 20. Default 10.

## Examples

- `GET https://api.duaer.com/v1/data/nvd?words=openssl` — the newest OpenSSL CVEs.
- `GET https://api.duaer.com/v1/data/nvd?cve=CVE-2021-44228` — the Log4Shell record.

## Result

The response is `{ "items": [...] }`. Each item has `source`, `title`, `url`, and `summary`, plus:

- `cveId`, `description` — id and English description.
- `cvssScore`, `cvssSeverity`, `cvssVector`, `cvssVersion` — best available CVSS (4.0, 3.1, 3.0, then 2).
- `cwe`, `status` — weakness ids and NVD analysis status.
- `knownExploitedSince` — date CISA listed it as exploited, when it is.
- `published`, `lastModified` — dates.

NVD allows few anonymous calls; a busy period can return 503 at 0 credits.

Fields without a value are left out.

## Credits

A search that returns at least one row uses 1 credit.
An empty search, a search that finds nothing, or a failed search uses 0.
Wrong input returns 400 with a message and uses 0.
No remaining credits returns 402 and does not search.
A missing key returns 401.

## Related

- https://skills.duaer.com/osv.md — Duaer OSV vulnerabilities
- https://skills.duaer.com/cisa-kev.md — Duaer CISA known exploited vulnerabilities

常见问题

Duaer 的NVD 漏洞库检索扣多少额度?

查到结果时扣 1 额度;没有结果或出错不扣。

Duaer NVD 漏洞库为什么偶尔返回 503?

NVD 限制匿名调用频率;繁忙时 Duaer NVD 漏洞库返回 503,不扣额度,稍后重试即可。

同组