vamp-cve-oracle
CVE Intelligence & Risk-Based Vulnerability Management Engine — VampSecure Labs
Overview
vamp-cve-oracle is an asynchronous CVE intelligence platform that enriches vulnerability data from four authoritative sources and applies a Risk-Based Vulnerability Management (RBVM) scoring model to prioritize remediation effort.
It correlates threat intelligence from the NVD, AlienVault OTX, FIRST.org EPSS, and the CISA KEV catalog, then computes a composite priority score using the formula:
Priority = EPSS_probability × CVSS_base_score
EPSS (Exploit Prediction Scoring System) quantifies the probability of exploitation in the wild within 30 days, making this metric a reliable signal for distinguishing theoretically severe CVEs from those actively being exploited. An optional asset inventory CSV allows per-host correlation, weighting findings by asset criticality.
Features
- Four-source intelligence aggregation: NVD, AlienVault OTX, FIRST.org EPSS, CISA KEV
- RBVM priority scoring:
EPSS × CVSSwith configurable asset criticality weighting - CISA KEV integration — immediately flags vulnerabilities under active exploitation
- Asset inventory correlation via CSV (
host,software,version,criticality) - Batch CVE processing from file — handles large sets of identifiers efficiently
- Four output formats: Rich console, JSON, dark-theme HTML, and Markdown (GFM)
- Configurable API keys for higher rate limits on both NVD and OTX
Requirements
Python 3.11+
aiohttp >= 3.9.0
rich >= 13.7.0
Install dependencies:
pip install -r requirements.txt
Installation
git clone https://github.com/belky-me/vamp-cve-oracle.git
cd vamp-cve-oracle
pip install -r requirements.txt
Configuration
API keys are optional but strongly recommended to avoid rate limiting on large batches:
| Variable | Source | Default rate limit |
|---|---|---|
NVD_API_KEY |
https://nvd.nist.gov/developers/request-an-api-key | 5 req / 30 s → 50 req / 30 s |
OTX_API_KEY |
https://otx.alienvault.com | Anonymous access |
export NVD_API_KEY=your_nvd_key
export OTX_API_KEY=your_otx_key
Usage
python vamp_cve_oracle.py [CVE-ID ...] [OPTIONS]
Positional:
CVE-ID [CVE-ID ...] One or more CVE identifiers (e.g. CVE-2024-21762)
Input:
-f, --file FILE File with one CVE ID per line
Asset correlation:
--inventory FILE CSV file: host,software,version,criticality
Output:
-o, --output FILE Write findings to JSON
--html FILE Generate standalone HTML report (dark theme)
--markdown FILE Generate Markdown report (GFM-compatible)
Examples
Query a single CVE with full intelligence context:
python vamp_cve_oracle.py CVE-2024-21762
Process a list of CVEs from a penetration test and write a JSON report:
python vamp_cve_oracle.py -f pentest_cves.txt -o results.json
Correlate findings against an asset inventory and generate an HTML report:
python vamp_cve_oracle.py -f cves.txt --inventory assets.csv --html rbvm_report.html
Query multiple CVEs and export Markdown for wiki or ticket integration:
python vamp_cve_oracle.py CVE-2023-27997 CVE-2022-40684 CVE-2024-21762 --markdown findings.md
Output Formats
| Format | How to enable | Description |
|---|---|---|
| Console | Default | Rich panel per CVE with CVSS, EPSS score, KEV status, and OTX pulse count |
| JSON | -o FILE |
Full structured output including all source data and priority scores |
| HTML | --html FILE |
Dark-theme standalone report, browser-ready |
| Markdown | --markdown FILE |
GFM-compatible export for GitHub, Confluence, or Jira tickets |
Exit Codes
| Code | Meaning | CI/CD usage |
|---|---|---|
0 |
All CVEs processed cleanly, no critical KEV hits | Pass gate |
1 |
Findings present — review RBVM scores | Review recommended |
2 |
Critical or KEV-confirmed exploited vulnerabilities found | Fail gate — remediate immediately |
Part of VampSecure Labs Toolkit
vamp-cve-oracle is part of the VampSecure Labs Security Research Toolkit — a collection of professional-grade, self-hosted security assessment tools.
| Tool | Purpose |
|---|---|
| vamp-forticheck | Multi-vendor edge device CVE scanner |
| vamp-cve-oracle | CVE intelligence and RBVM engine |
| vamp-passive-recon | Passive recon and attack surface mapping |
| vamp-subdomain-takeover | Subdomain takeover vulnerability scanner |
| vamp-cloud-enum | Cloud storage bucket enumerator |
| vamp-orchestrator | Multi-tool assessment orchestrator |
© VampSecure Studios — VampSecure Labs Security Research Division
For authorized security assessments only. Unauthorized use is prohibited.
Metadata
Release files for vamp-cve-oracle 3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vamp_cve_oracle-3.0.tar.gz | 31.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vamp_cve_oracle-3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 64.0 kB
Release files / vamp_cve_oracle-3.0.tar.gz
| Download URL | vamp_cve_oracle-3.0.tar.gz |
|---|---|
| Size | 31.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
fab04b6852286e408b907edd1a37d9c2815c128f6fe5cac2d621cac0bfa8ed8c
|
|
BLAKE2b-256 checksum How to use checksums |
21269de0d556bf7592031e791f10b983cee8620a96110ca9ca253621e6c202e2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|
Release files / vamp_cve_oracle-3.0-py3-none-any.whl
| Download URL | vamp_cve_oracle-3.0-py3-none-any.whl |
|---|---|
| Size | 32.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
adb28b5c8f84782fedaacb81fe2ac32d01234b8f1dabe176184368b5623c1128
|
|
BLAKE2b-256 checksum How to use checksums |
3622651364580c8c55197102ce0c3693c1e1897132cd49362488828adac28292
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|