入门
在 Duaer 里查NVD 漏洞库
在 Duaer 里:按关键词或 CVE 编号检索美国国家漏洞库(NVD)的 CVE 记录,按时间倒序,含 CVSS 评分、弱点类型与已被利用日期。一次成功查询用 1 额度。
能拿到什么
Duaer 数据市场里的「NVD 漏洞库」:按关键词或 CVE 编号检索美国国家漏洞库(NVD)的 CVE 记录,按时间倒序,含 CVSS 评分、弱点类型与已被利用日期。查到结果时用 1 额度,结果交给数字组织的下一个节点。
从节点创建器选 Duaer 数据 → NVD 漏洞库,或打开 数据市场。相关:OSV 开源漏洞、CISA 已被利用漏洞。
适合做什么
- 按关键词查找最新 CVE 及其 CVSS 评分。
- 核对某个 CVE 编号的描述与严重程度。
在画布里检索
- 打开节点创建器,选 Duaer 数据 → NVD CVE records。
- 填 Words(如 log4j),或填 CVE ID。
- Limit 默认 10,最大 20。执行。
查到结果才扣 1 额度;没有结果、输入有误或上游失败都不扣。
用 API 调用
- GET https://api.duaer.com/v1/data/nvd?words=openssl
- Authorization: Bearer <Duaer key>
下方是与数据市场「复制技能」相同的英文技能,含参数、示例与返回字段。
调用技能(英文)
与数据市场「复制技能」一致。
---
name: duaer-nvd
description: >-
Duaer NVD CVE records. CVE records from the US National Vulnerability Database by keyword or CVE id, newest first, with CVSS score, weakness, and known-exploited date.
One successful search uses 1 Duaer credit.
---
# Duaer NVD CVE records
Duaer NVD CVE records searches the US National Vulnerability Database. It returns the newest matching CVEs first, with the CVSS score NVD or the vendor assigned.
## When to use
- Get the CVSS score and description of a CVE.
- List recent CVEs for a product such as openssl.
## When not to use
- Affected package versions. Use https://skills.duaer.com/osv.md.
- Only CVEs attacked in the wild. Use https://skills.duaer.com/cisa-kev.md.
## Call
`GET https://api.duaer.com/v1/data/nvd?words=openssl`
Header: `Authorization: Bearer <Duaer key>`
Use an account key or a model API key.
Get a Duaer key: https://skills.duaer.com/keys.md
## Parameters
Provide `words` or `cve`.
- `words` — Keywords, such as openssl or log4j.
- `cve` — Optional. One record such as CVE-2021-44228.
- `limit` — Optional. Rows to return, from 1 to 20. Default 10.
## Examples
- `GET https://api.duaer.com/v1/data/nvd?words=openssl` — the newest OpenSSL CVEs.
- `GET https://api.duaer.com/v1/data/nvd?cve=CVE-2021-44228` — the Log4Shell record.
## Result
The response is `{ "items": [...] }`. Each item has `source`, `title`, `url`, and `summary`, plus:
- `cveId`, `description` — id and English description.
- `cvssScore`, `cvssSeverity`, `cvssVector`, `cvssVersion` — best available CVSS (4.0, 3.1, 3.0, then 2).
- `cwe`, `status` — weakness ids and NVD analysis status.
- `knownExploitedSince` — date CISA listed it as exploited, when it is.
- `published`, `lastModified` — dates.
NVD allows few anonymous calls; a busy period can return 503 at 0 credits.
Fields without a value are left out.
## Credits
A search that returns at least one row uses 1 credit.
An empty search, a search that finds nothing, or a failed search uses 0.
Wrong input returns 400 with a message and uses 0.
No remaining credits returns 402 and does not search.
A missing key returns 401.
## Related
- https://skills.duaer.com/osv.md — Duaer OSV vulnerabilities
- https://skills.duaer.com/cisa-kev.md — Duaer CISA known exploited vulnerabilities
常见问题
Duaer 的NVD 漏洞库检索扣多少额度?
查到结果时扣 1 额度;没有结果或出错不扣。
Duaer NVD 漏洞库为什么偶尔返回 503?
NVD 限制匿名调用频率;繁忙时 Duaer NVD 漏洞库返回 503,不扣额度,稍后重试即可。
同组