Simple NIST NVD API wrapper library
NVDlib is a Python library that allows you to interface with the NIST National Vulnerability Database (NVD), pull vulnerabilities (CVEs), and Common Platform Enumeration (CPEs) into easily accessible objects.
Features
- Search the NVD for CVEs using all parameters allowed by the NVD API (recently updated to utilize version 2 of the API). Including search criteria such as CVE publish and modification date, keywords, severity, score, or CPE name.
- Search CPE names by keywords, CPE match strings, or modification dates. Then pull the CVE ID's that are relevant to those CPEs.
- Retrieve details on individual CVEs, their relevant CPE names, and more.
- Built in rate limiting according to NIST NVD recommendations.
Get an API key (https://nvd.nist.gov/developers/request-an-api-key) to allow for a delay argument to be passed. Otherwise it is 6 seconds between requests by default.
Install
$ pip install nvdlib
Demo
>>> import nvdlib
>>> r = nvdlib.searchCVE(cveId='CVE-2021-26855')[0]
>>> print(r.v31severity + ' - ' + str(r.v31score))
CRITICAL - 9.8
>>> print(r.descriptions[0].value)
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412,
CVE-2021-26854, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
>>> print(r.v31vector)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Development
Run the tests with
$ pip install -e '.[dev]'
$ pytest
Documentation
More information
This is my first attempt at creating a library while utilizing all my Python experience from classes to functions.
For more information on the NIST NVD API for CPE and CVEs, see the documentation here: https://nvd.nist.gov/General/News/New-NVD-CVE-CPE-API-and-SOAP-Retirement
This product uses data from the NVD API but is not endorsed or certified by the NVD.
Metadata
Release files for nvdlib 0.8.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| nvdlib-0.8.4.tar.gz | 18.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| nvdlib-0.8.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 33.8 kB
Release files / nvdlib-0.8.4.tar.gz
| Download URL | nvdlib-0.8.4.tar.gz |
|---|---|
| Size | 18.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
c81d8d25c8b7696afce6c030228846a95a62640d095b0b51d5a0b76dbfe6ff29
|
|
BLAKE2b-256 checksum How to use checksums |
4425807900996e91a1803787e89bc8990b91d546828b3bbdf21446bfd996bfc5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.4
|
Release files / nvdlib-0.8.4-py3-none-any.whl
| Download URL | nvdlib-0.8.4-py3-none-any.whl |
|---|---|
| Size | 15.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
21c8e3c9314d7ffe646c0bbde86925e54aa9a9e5e3e7fc4fd3ffa724e17b07f1
|
|
BLAKE2b-256 checksum How to use checksums |
ac71d1d710f07feb48a5f535df7b33f672a128eb8c8ab329fc1e4985871201b9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.4
|