CVE intelligence: exploitation (KEV/EPSS), detection coverage, fixed versions. All tools keyless.
Abgeleitet aus den Transporten, die dieser Eintrag deklariert (streamable-http). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.
Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.
Aus einem echten MCP-Handshake initialize → tools/list gegen den deklarierten Endpunkt gelesen. Es wurde nie ein Tool aufgerufen — tools/list ist der lesende Introspektionsaufruf, den das Protokoll dafür vorsieht. Es spiegelt wider, was der Server in diesem Moment angeboten hat; ein gehosteter Endpunkt ist an keine Version gebunden und kann sich ohne Ankündigung ändern.
https://cve-security.com/api/mcp8 Tools · 111 msget_cveFull intelligence record for one CVE: per-scorer CVSS, EPSS, CISA KEV/ransomware/SSVC, four remote-detection modalities (the checks that work over the network) plus a host-check tier (self-contained Nuclei templates and Metasploit local modules that run on the system itself) and the Sigma log-detec…Full intelligence record for one CVE: per-scorer CVSS, EPSS, CISA KEV/ransomware/SSVC, four remote-detection modalities (the checks that work over the network) plus a host-check tier (self-contained Nuclei templates and Metasploit local modules that run on the system itself) and the Sigma log-detec…
| Parameter | Typ | Beschreibung |
|---|---|---|
| id* | string | CVE id, such as CVE-2024-3400 |
search_cvesSearch the catalog. Free text (q) and/or structured filters: vendor (slug), cwe (CWE-nnn), technique (ATT&CK id, such as T1190), year ("2024,2025"), sev ("critical,high"), kev (0|1), kev_from / kev_to (ISO days, half-open CISA listing window; imply kev=1), kev_vendor (the CISA vendorProject string…Search the catalog. Free text (q) and/or structured filters: vendor (slug), cwe (CWE-nnn), technique (ATT&CK id, such as T1190), year ("2024,2025"), sev ("critical,high"), kev (0|1), kev_from / kev_to (ISO days, half-open CISA listing window; imply kev=1), kev_vendor (the CISA vendorProject string…
| Parameter | Typ | Beschreibung |
|---|---|---|
| q | string | — |
| vendor | string | — |
| cwe | string | — |
| technique | string | ATT&CK technique id, such as T1190 or T1059.001 |
| year | string | — |
| sev | string | — |
| kev | string | — |
| kev_from | string | ISO day, inclusive lower bound on the CISA listing date |
| kev_to | string | ISO day, exclusive upper bound on the CISA listing date |
| kev_vendor | string | CISA's vendorProject, verbatim (for example 'Palo Alto Networks') |
| ransomware | string | — |
| detect | string | — |
| fix | string | — |
| automatable | string | — |
| epss_gte | number | — |
| sighted | string | Field sighting window in days: a named sensor network recorded the CVE within the last 7 or 30 days |
| malware | string | A published source ties a named malware family, tool, campaign or ransomware group to the CVE |
| watch | string | On KEV Watch at tier 1 or 2: reported as exploited by trackers other than CISA, outside CISA KEV |
| chained | string | In a known exploit chain: a cited source reports the CVE was used together with another CVE in one exploit chain |
| chainability | string | KCV Watch™ tier: a structural pattern (same product, published within 365 days or within 30 days inside the largest products, complementary weakness class) pub… |
| eco | string | — |
| pkg | string | — |
| page | integer | — |
| limit | integer | — |
query_packageCVEs affecting one open-source package, by purl (pkg:npm/lodash) or ecosystem + name (Maven names are group:artifact). Returns the CVE list KEV-first with each OSV version range VERBATIM: `events` plus one render-safe projection: `fixed` (the upgrade targets) or `affected_through` (the last VULNERA…CVEs affecting one open-source package, by purl (pkg:npm/lodash) or ecosystem + name (Maven names are group:artifact). Returns the CVE list KEV-first with each OSV version range VERBATIM: `events` plus one render-safe projection: `fixed` (the upgrade targets) or `affected_through` (the last VULNERA…
| Parameter | Typ | Beschreibung |
|---|---|---|
| purl | string | Package URL, such as pkg:npm/lodash or pkg:maven/org.apache.logging.log4j/log4j-core |
| ecosystem | string | OSV ecosystem (npm, PyPI, Maven, Go, crates.io, Packagist, RubyGems, NuGet, …) or purl type (pypi, cargo, composer, gem, golang, …) |
| name | string | Package name, verbatim (for example @babel/core or org.jenkins-ci.main:jenkins-core) |
get_updatesThe publication change stream: what this site published, stamped with OUR publish time (first_published, kev_added, detection_added, remediation_added). Pass since (YYYY-MM-DD, strictly-after) on the first call, then the returned next_cursor to continue. Optional cve scopes the stream to one CVE's…The publication change stream: what this site published, stamped with OUR publish time (first_published, kev_added, detection_added, remediation_added). Pass since (YYYY-MM-DD, strictly-after) on the first call, then the returned next_cursor to continue. Optional cve scopes the stream to one CVE's…
| Parameter | Typ | Beschreibung |
|---|---|---|
| since | string | — |
| cursor | string | — |
| type | string | — |
| cve | string | Scope to one CVE's change history, such as CVE-2024-3400 |
| limit | integer | — |
get_scoreboardThe Defender Scoreboard report (CC BY 4.0): exploited vs detectable vs patchable, every figure with its method, caveat and denominator, plus the corpus block and any method-change notes. Cite as "CVE Security Defender Scoreboard, cve-security.com/scoreboard".The Defender Scoreboard report (CC BY 4.0): exploited vs detectable vs patchable, every figure with its method, caveat and denominator, plus the corpus block and any method-change notes. Cite as "CVE Security Defender Scoreboard, cve-security.com/scoreboard".
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
get_sightingsField sightings: CVEs a named sensor network recorded in the last 7 or 30 days, most sighting days first. A field sighting is a day on which Shadowserver honeypots (cited by VulnCheck KEV and published as daily lists by CIRCL Vulnerability-Lookup) or VulnCheck canary sensors recorded traffic aimed…Field sightings: CVEs a named sensor network recorded in the last 7 or 30 days, most sighting days first. A field sighting is a day on which Shadowserver honeypots (cited by VulnCheck KEV and published as daily lists by CIRCL Vulnerability-Lookup) or VulnCheck canary sensors recorded traffic aimed…
| Parameter | Typ | Beschreibung |
|---|---|---|
| window | string | Sighting window in days (default 7) |
| kev | string | Restrict to CVEs outside (0) or inside (1) CISA KEV |
| limit | integer | 1..500 (default 100) |
get_chainsKnown Chained Vulnerabilities™: pairs of CVEs that a cited source reports were used together in one exploit chain (VulnCheck KEV entry text, Metasploit modules, SigmaHQ rules, press or research sentences, community text judged by a local model). Each row carries both CVEs with their CISA KEV status…Known Chained Vulnerabilities™: pairs of CVEs that a cited source reports were used together in one exploit chain (VulnCheck KEV entry text, Metasploit modules, SigmaHQ rules, press or research sentences, community text judged by a local model). Each row carries both CVEs with their CISA KEV status…
| Parameter | Typ | Beschreibung |
|---|---|---|
| source | string | Evidence lane: vulncheck_kev, metasploit, sigma, press, research, community, github_poc or exploitdb |
| since | string | Pairs first seen on or after this day (YYYY-MM-DD) |
| claim | string | observed: the source reports attacks that chained them; potential: the source reports they can be chained |
| limit | integer | 1..500 (default 100) |
get_epss_moversCVEs whose EPSS exploitation probability rose the most recently. window is "7d" (default) or "30d". Each rise is measured between same-EPSS-model-version scores, so a model release (which shifts the whole distribution) never appears as a mover. A rise raises the priority of a CVE; observed exploita…CVEs whose EPSS exploitation probability rose the most recently. window is "7d" (default) or "30d". Each rise is measured between same-EPSS-model-version scores, so a model release (which shifts the whole distribution) never appears as a mover. A rise raises the priority of a CVE; observed exploita…
| Parameter | Typ | Beschreibung |
|---|---|---|
| window | string | Rise window (default 7d) |
| limit | integer | 1..100 (default 25) |
8 von 8 Tools haben eine Beschreibung veröffentlicht.
Tool-Namen und -Beschreibungen stammen vom Publisher und werden wortgetreu als inerter Text angezeigt. Es sind die Zeichenketten, die ein MCP-Client an ein Modell übergibt, deshalb prüft Forge sie auf Prompt-Injection-Muster — jeder Befund erscheint oben beim Sicherheits-Scan. „Privilegiert“ ist ein Schlagwort-Treffer im Tool-Namen, keine Prüfung dessen, was das Tool tut: ein harmlos klingender Name kann trotzdem alles tun.
CVE intelligence: exploitation (KEV/EPSS), detection coverage, fixed versions. All tools keyless.
Verlinkte Namen öffnen den Forge-Index aller Einträge, bei denen dieses Tool beobachtet wurde. Alle indexierten Tools durchsuchen.
Dieser Eintrag veröffentlicht kein npm-Paket, daher hat Forge keinen Abhängigkeitsbaum dafür. Das ist eine Lücke in der Abdeckung — keine Aussage, dass er keine Abhängigkeiten hat.