vamp-cve-oracle
CVE Intelligence & Risk-Based Vulnerability Management Engine — VampSecure Labs
Overview
vamp-cve-oracle is an asynchronous CVE intelligence platform that enriches vulnerability data from four authoritative sources and applies a Risk-Based Vulnerability Management (RBVM) scoring model to prioritize remediation effort.
It correlates threat intelligence from the NVD, AlienVault OTX, FIRST.org EPSS, and the CISA KEV catalog, then computes a composite priority score using the formula:
Priority = EPSS_probability × CVSS_base_score
EPSS (Exploit Prediction Scoring System) quantifies the probability of exploitation in the wild within 30 days, making this metric a reliable signal for distinguishing theoretically severe CVEs from those actively being exploited. An optional asset inventory CSV allows per-host correlation, weighting findings by asset criticality.
Features
- Four-source intelligence aggregation: NVD, AlienVault OTX, FIRST.org EPSS, CISA KEV
- RBVM priority scoring:
EPSS × CVSSwith configurable asset criticality weighting - CISA KEV integration — immediately flags vulnerabilities under active exploitation
- Asset inventory correlation via CSV (
host,software,version,criticality) - Batch CVE processing from file — handles large sets of identifiers efficiently
- Four output formats: Rich console, JSON, dark-theme HTML, and Markdown (GFM)
- Configurable API keys for higher rate limits on both NVD and OTX
Requirements
Python 3.11+
aiohttp >= 3.9.0
rich >= 13.7.0
Install dependencies:
pip install -r requirements.txt
Installation
git clone https://github.com/belky-me/vamp-cve-oracle.git
cd vamp-cve-oracle
pip install -r requirements.txt
Configuration
API keys are optional but strongly recommended to avoid rate limiting on large batches:
| Variable | Source | Default rate limit |
|---|---|---|
NVD_API_KEY |
https://nvd.nist.gov/developers/request-an-api-key | 5 req / 30 s → 50 req / 30 s |
OTX_API_KEY |
https://otx.alienvault.com | Anonymous access |
export NVD_API_KEY=your_nvd_key
export OTX_API_KEY=your_otx_key
Usage
python vamp_cve_oracle.py [CVE-ID ...] [OPTIONS]
Positional:
CVE-ID [CVE-ID ...] One or more CVE identifiers (e.g. CVE-2024-21762)
Input:
-f, --file FILE File with one CVE ID per line
Asset correlation:
--inventory FILE CSV file: host,software,version,criticality
Output:
-o, --output FILE Write findings to JSON
--html FILE Generate standalone HTML report (dark theme)
--markdown FILE Generate Markdown report (GFM-compatible)
Examples
Query a single CVE with full intelligence context:
python vamp_cve_oracle.py CVE-2024-21762
Process a list of CVEs from a penetration test and write a JSON report:
python vamp_cve_oracle.py -f pentest_cves.txt -o results.json
Correlate findings against an asset inventory and generate an HTML report:
python vamp_cve_oracle.py -f cves.txt --inventory assets.csv --html rbvm_report.html
Query multiple CVEs and export Markdown for wiki or ticket integration:
python vamp_cve_oracle.py CVE-2023-27997 CVE-2022-40684 CVE-2024-21762 --markdown findings.md
Output Formats
| Format | How to enable | Description |
|---|---|---|
| Console | Default | Rich panel per CVE with CVSS, EPSS score, KEV status, and OTX pulse count |
| JSON | -o FILE |
Full structured output including all source data and priority scores |
| HTML | --html FILE |
Dark-theme standalone report, browser-ready |
| Markdown | --markdown FILE |
GFM-compatible export for GitHub, Confluence, or Jira tickets |
Exit Codes
| Code | Meaning | CI/CD usage |
|---|---|---|
0 |
All CVEs processed cleanly, no critical KEV hits | Pass gate |
1 |
Findings present — review RBVM scores | Review recommended |
2 |
Critical or KEV-confirmed exploited vulnerabilities found | Fail gate — remediate immediately |
Part of VampSecure Labs Toolkit
vamp-cve-oracle is part of the VampSecure Labs Security Research Toolkit — a collection of professional-grade, self-hosted security assessment tools.
| Tool | Purpose |
|---|---|
| vamp-forticheck | Multi-vendor edge device CVE scanner |
| vamp-cve-oracle | CVE intelligence and RBVM engine |
| vamp-passive-recon | Passive recon and attack surface mapping |
| vamp-subdomain-takeover | Subdomain takeover vulnerability scanner |
| vamp-cloud-enum | Cloud storage bucket enumerator |
| vamp-orchestrator | Multi-tool assessment orchestrator |
© VampSecure Studios — VampSecure Labs Security Research Division
For authorized security assessments only. Unauthorized use is prohibited.
Metadata
Release files for vamp-cve-oracle 3.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vamp_cve_oracle-3.2.tar.gz | 36.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vamp_cve_oracle-3.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 73.9 kB
Release files / vamp_cve_oracle-3.2.tar.gz
| Download URL | vamp_cve_oracle-3.2.tar.gz |
|---|---|
| Size | 36.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
63f26d1879a18e3a886d77156b33556ebb1ee0a7cd6820f8e8b6835774f79cbe
|
|
BLAKE2b-256 checksum How to use checksums |
31bb8e78238e2af5a838601dd52f52a8997ecf43739204a55ce948cd28bd7f2b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|
Release files / vamp_cve_oracle-3.2-py3-none-any.whl
| Download URL | vamp_cve_oracle-3.2-py3-none-any.whl |
|---|---|
| Size | 37.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d97a1a9b43f514ce2ad375a15bf14bef5bb8cf834126af4020e40a86d6f140d4
|
|
BLAKE2b-256 checksum How to use checksums |
5f08888524496a0ec7a1904b53fdf33595efc64fc51025c662d5d480fa27c4f7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|