Simple NIST NVD API wrapper library
NVDlib is a Python library that allows you to interface with the NIST National Vulnerability Database (NVD), pull vulnerabilities (CVEs), and Common Platform Enumeration (CPEs) into easily accessible objects.
Features
- Search the NVD for CVEs using all parameters allowed by the NVD API version 2. Including search criteria such as CVE publish and modification date, keywords, CVSS V2/V3/V4 severity or metrics, CPE name, CVE tags, and KEV catalog dates.
- Search CPE names by keywords, CPE match strings, or modification dates, and search CPE match strings.
- Retrieve details on individual CVEs, their relevant CPE names, CVSS 4.0 metrics, and more.
- Search the CVE change history and the organizations (sources) that provide NVD data.
- Get results as easily accessible objects, or pass
asDict=Trueto get the plain dictionaries from the NVD API. - Built in rate limiting according to NIST NVD recommendations.
Get an API key (https://nvd.nist.gov/developers/request-an-api-key) to allow for a delay argument to be passed. Otherwise it is 6 seconds between requests by default.
Install
$ pip install nvdlib
Demo
>>> import nvdlib
>>> r = nvdlib.searchCVE(cveId='CVE-2021-26855')[0]
>>> print(r.v31severity + ' - ' + str(r.v31score))
CRITICAL - 9.1
>>> print(r.descriptions[0].value)
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412,
CVE-2021-26854, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
>>> print(r.v31vector)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Development
Run the tests with
$ pip install -e '.[dev]'
$ pytest
Documentation
More information
This is my first attempt at creating a library while utilizing all my Python experience from classes to functions.
For more information on the NIST NVD API for CPE and CVEs, see the documentation here: https://nvd.nist.gov/developers
This product uses data from the NVD API but is not endorsed or certified by the NVD.
Metadata
Release files for nvdlib 0.9.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| nvdlib-0.9.0.tar.gz | 24.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| nvdlib-0.9.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 46.3 kB
Release files / nvdlib-0.9.0.tar.gz
| Download URL | nvdlib-0.9.0.tar.gz |
|---|---|
| Size | 24.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d066b1696cd39c6258c52c00219ef7020651fd93606bc6a026e5de6da97e6949
|
|
BLAKE2b-256 checksum How to use checksums |
c66d0a91a0807238f663f0abbd0409145af8a1ec96aca0bf9918bde33e8c644e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.4
|
Release files / nvdlib-0.9.0-py3-none-any.whl
| Download URL | nvdlib-0.9.0-py3-none-any.whl |
|---|---|
| Size | 21.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6f4a6d74c18264bd3b4b18b0f1a7ddfda2e74e547a26355c42cbea30165dd277
|
|
BLAKE2b-256 checksum How to use checksums |
1926f6866275914d41cc6a3ff621e032aa08390b5f946d6fb985a6666c44fef1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.4
|