vamp-cve-oracle
CVE Intelligence & Risk-Based Vulnerability Management Engine — VampSecure Labs
Overview
vamp-cve-oracle is an asynchronous CVE intelligence platform that enriches vulnerability data from four authoritative sources and applies a Risk-Based Vulnerability Management (RBVM) scoring model to prioritize remediation effort.
It correlates threat intelligence from the NVD, AlienVault OTX, FIRST.org EPSS, and the CISA KEV catalog, then computes a composite priority score using the formula:
Priority = EPSS_probability × CVSS_base_score
EPSS (Exploit Prediction Scoring System) quantifies the probability of exploitation in the wild within 30 days, making this metric a reliable signal for distinguishing theoretically severe CVEs from those actively being exploited. An optional asset inventory CSV allows per-host correlation, weighting findings by asset criticality.
Features
- Four-source intelligence aggregation: NVD, AlienVault OTX, FIRST.org EPSS, CISA KEV
- RBVM priority scoring:
EPSS × CVSSwith configurable asset criticality weighting - CISA KEV integration — immediately flags vulnerabilities under active exploitation
- Asset inventory correlation via CSV (
host,software,version,criticality) - Batch CVE processing from file — handles large sets of identifiers efficiently
- Four output formats: Rich console, JSON, dark-theme HTML, and Markdown (GFM)
- Configurable API keys for higher rate limits on both NVD and OTX
Requirements
Python 3.11+
aiohttp >= 3.9.0
rich >= 13.7.0
Install dependencies:
pip install -r requirements.txt
Installation
git clone https://github.com/belky-me/vamp-cve-oracle.git
cd vamp-cve-oracle
pip install -r requirements.txt
Configuration
API keys are optional but strongly recommended to avoid rate limiting on large batches:
| Variable | Source | Default rate limit |
|---|---|---|
NVD_API_KEY |
https://nvd.nist.gov/developers/request-an-api-key | 5 req / 30 s → 50 req / 30 s |
OTX_API_KEY |
https://otx.alienvault.com | Anonymous access |
export NVD_API_KEY=your_nvd_key
export OTX_API_KEY=your_otx_key
Usage
python vamp_cve_oracle.py [CVE-ID ...] [OPTIONS]
Positional:
CVE-ID [CVE-ID ...] One or more CVE identifiers (e.g. CVE-2024-21762)
Input:
-f, --file FILE File with one CVE ID per line
Asset correlation:
--inventory FILE CSV file: host,software,version,criticality
Output:
-o, --output FILE Write findings to JSON
--html FILE Generate standalone HTML report (dark theme)
--markdown FILE Generate Markdown report (GFM-compatible)
Examples
Query a single CVE with full intelligence context:
python vamp_cve_oracle.py CVE-2024-21762
Process a list of CVEs from a penetration test and write a JSON report:
python vamp_cve_oracle.py -f pentest_cves.txt -o results.json
Correlate findings against an asset inventory and generate an HTML report:
python vamp_cve_oracle.py -f cves.txt --inventory assets.csv --html rbvm_report.html
Query multiple CVEs and export Markdown for wiki or ticket integration:
python vamp_cve_oracle.py CVE-2023-27997 CVE-2022-40684 CVE-2024-21762 --markdown findings.md
Output Formats
| Format | How to enable | Description |
|---|---|---|
| Console | Default | Rich panel per CVE with CVSS, EPSS score, KEV status, and OTX pulse count |
| JSON | -o FILE |
Full structured output including all source data and priority scores |
| HTML | --html FILE |
Dark-theme standalone report, browser-ready |
| Markdown | --markdown FILE |
GFM-compatible export for GitHub, Confluence, or Jira tickets |
Exit Codes
| Code | Meaning | CI/CD usage |
|---|---|---|
0 |
All CVEs processed cleanly, no critical KEV hits | Pass gate |
1 |
Findings present — review RBVM scores | Review recommended |
2 |
Critical or KEV-confirmed exploited vulnerabilities found | Fail gate — remediate immediately |
Part of VampSecure Labs Toolkit
vamp-cve-oracle is part of the VampSecure Labs Security Research Toolkit — a collection of professional-grade, self-hosted security assessment tools.
| Tool | Purpose |
|---|---|
| vamp-forticheck | Multi-vendor edge device CVE scanner |
| vamp-cve-oracle | CVE intelligence and RBVM engine |
| vamp-passive-recon | Passive recon and attack surface mapping |
| vamp-subdomain-takeover | Subdomain takeover vulnerability scanner |
| vamp-cloud-enum | Cloud storage bucket enumerator |
| vamp-orchestrator | Multi-tool assessment orchestrator |
© VampSecure Studios — VampSecure Labs Security Research Division
For authorized security assessments only. Unauthorized use is prohibited.
Metadata
Release files for vamp-cve-oracle 3.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vamp_cve_oracle-3.1.tar.gz | 33.6 kB | Details |
Release files / vamp_cve_oracle-3.1.tar.gz
| Download URL | vamp_cve_oracle-3.1.tar.gz |
|---|---|
| Size | 33.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
b557853652025067273292a89e43331496fc5dcf75ac5d93d9908d27d3edd1ed
|
|
BLAKE2b-256 checksum How to use checksums |
70bc48587ec28d851d1f0abd8342bfcf434e58bd67e2f4705055fa5dd96b9918
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|