Official CLI for CVEFinder.io API
Project description
CVEFinder CLI
Official command-line interface for CVEFinder.io API.
Scan websites for CVEs, vulnerabilities, and technology stacks directly from your terminal.
Features
- 🔍 Scan websites for CVEs and vulnerabilities
- 📊 Get scan results with detailed CVE information
- 📦 Dependency analysis in
scan get(summary by default, full list with--full) - 🔑 Manage API keys (create, list, revoke, rotate)
- 📈 Export data to JSON, CSV, or table formats
- 🎨 Rich terminal output with colors and tables
- ⚙️ Simple configuration with API key via command or environment
- 🚀 Fast and lightweight - pure Python implementation
Installation
From PyPI (Recommended)
pip install cvefinder-cli
From Source
git clone https://github.com/cvefinder/cli.git
cd cvefinder-cli
pip install -e .
Quick Start
1. Get Your API Key
Sign up at cvefinder.io and upgrade to Pro to get an API key.
2. Configure Your API Key
# Set your API key
cvefinder configure
# Or use environment variable
export CVEFINDER_API_KEY="your-api-key-here"
3. Scan a Website
# Basic scan
cvefinder scan run https://example.com
# Scan and save to file
cvefinder scan run https://example.com --output results.json
# Scan with specific output format
cvefinder scan run https://example.com --format table
Usage
Configuration
# Configure interactively
cvefinder configure
# Set specific values
cvefinder configure --api-key YOUR_API_KEY
# Show current configuration
cvefinder configure --show
Scanning
# Basic scan
cvefinder scan run https://example.com
# Scan with options
cvefinder scan run https://example.com \
--format json \
--output scan.json \
--severity critical,high
# Get scan result by ID
cvefinder scan get SCAN_ID
# Include full dependency package list
cvefinder scan get SCAN_ID --full
# List recent scans
cvefinder scan list --limit 10
# Show page 2
cvefinder scan list --limit 10 --page 2
# Bulk scan commands (Pro)
cvefinder bulk scan --url https://a.com --url https://b.com
cvefinder bulk list
cvefinder bulk get BULK_SCAN_ID
# Export scan reports (Pro)
cvefinder export SCAN_ID --json
cvefinder export SCAN_ID --pdf
# Show account usage and limits
cvefinder account
# Search CVEs, products, and vendors
cvefinder search wordpress --severity critical,high --published-year 2024
# Get exploit data for a CVE
cvefinder exploit CVE-2021-24176
# Monitor scans (Pro)
cvefinder monitor add
cvefinder monitor list
cvefinder monitor check --scan-id 123
API Key Management
# Create new API key
cvefinder api-keys create --name "CI/CD Pipeline"
# List all API keys
cvefinder api-keys list
# Revoke an API key
cvefinder api-keys revoke KEY_ID
# Rotate an API key
cvefinder api-keys rotate KEY_ID
Output Formats
# JSON output (default)
cvefinder scan run https://example.com --format json
# Table output (human-readable)
cvefinder scan run https://example.com --format table
# CSV output (for spreadsheets)
cvefinder scan run https://example.com --format csv
# Compact output (minimal)
cvefinder scan run https://example.com --format compact
Advanced Usage
# Verbose output for debugging
cvefinder --verbose scan run https://example.com
# Quiet mode (errors only)
cvefinder --quiet scan run https://example.com
Configuration File
CVEFinder CLI stores configuration in ~/.cvefinder/config.yaml:
default_profile: default
profiles:
default:
api_key: your-api-key-here
Environment Variables
# API key
export CVEFINDER_API_KEY="your-api-key"
Examples
CI/CD Integration
#!/bin/bash
# Scan production website and fail if critical CVEs found
RESULT=$(cvefinder scan run https://example.com --format json)
CRITICAL=$(echo "$RESULT" | jq '.severity_counts.critical')
if [ "$CRITICAL" -gt 0 ]; then
echo "❌ Critical CVEs found: $CRITICAL"
exit 1
fi
echo "✅ No critical CVEs found"
Scanning Multiple URLs
#!/bin/bash
# Scan multiple websites
URLS=(
"https://example.com"
"https://api.example.com"
"https://staging.example.com"
)
for url in "${URLS[@]}"; do
echo "Scanning $url..."
cvefinder scan run "$url" --format table
done
Export to CSV
# Scan and export to CSV
cvefinder scan run https://example.com --format csv > results.csv
# Open in Excel/Sheets
open results.csv
Commands Reference
Global Options
--api-key KEY Override API key
--verbose, -v Verbose output
--quiet, -q Quiet mode (errors only)
--help, -h Show help message
--version Show version
Commands
| Command | Description |
|---|---|
configure |
Configure API key and show current config |
scan run URL |
Scan a website for CVEs |
scan get ID |
Get scan results + dependency analysis summary |
scan list |
List recent scans |
export ID --json/--pdf |
Export a scan report as JSON or PDF |
account |
Show account details and daily scan usage |
search [QUERY] |
Search CVEs, products, and vendors |
exploit CVE_ID |
Get exploit information for a CVE |
bulk scan |
Start a bulk scan for multiple URLs |
bulk get ID |
Get bulk scan status/results |
bulk list |
List recent bulk scans |
monitor add |
Add/enable monitoring for a scan |
monitor list |
List monitored scans |
monitor check --scan-id ID |
Check monitoring status for a scan |
monitor enable |
Enable an existing monitored scan |
monitor disable |
Disable an existing monitored scan |
api-keys create |
Create new API key |
api-keys list |
List all API keys |
api-keys revoke ID |
Revoke an API key |
api-keys rotate ID |
Rotate an API key |
Requirements
- Python 3.7 or higher
- Pro subscription on cvefinder.io for API access
Plan Notes
- Free/guest users can run core scan commands.
- Pro is required for:
bulk *,export --json/--pdf, and full dependency package details.
Contributing
Contributions are welcome! Please read our Contributing Guide for details.
License
MIT License - see LICENSE file for details.
Support
- 📧 Email: support@cvefinder.io
- 🐛 Issues: GitHub Issues
- 📚 Documentation: docs.cvefinder.io
- 💬 Twitter: @CVEFinder_io
Links
- Website: https://cvefinder.io
- API Documentation: https://docs.cvefinder.io/api-reference
- GitHub: https://github.com/cvefinder/cli
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file cvefinder_io-1.0.0.tar.gz.
File metadata
- Download URL: cvefinder_io-1.0.0.tar.gz
- Upload date:
- Size: 31.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.11.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
6dd15b83fa72e25d32e57b8e3a7dcdc39791baed53967034cd7433f90d8cd368
|
|
| MD5 |
9678d3820ee054b8b12b13c5c75c6c62
|
|
| BLAKE2b-256 |
a8c82119ec2bcddd9070b446a6f7a8d58485dc650c5abb1c6a1e6d7fe33311fe
|
File details
Details for the file cvefinder_io-1.0.0-py3-none-any.whl.
File metadata
- Download URL: cvefinder_io-1.0.0-py3-none-any.whl
- Upload date:
- Size: 26.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.11.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
6e01a3f9aa0beae2551f47fc331e35337b93d5f310090869dba188e397dec761
|
|
| MD5 |
e75a52d04764b6bc1554b848425599e4
|
|
| BLAKE2b-256 |
4d7c6cccd683d650cfcf43140cedfc43105f8c25a047d84cb3082e738ac59026
|