year | 2015–2026 or all; default 2026 | CVE publication-year scope. |
|---|
q | Text, CVE ID or EUVD ID; maximum 120 characters | Search identifiers, vendor, product, title, description and CWE text. |
|---|
severity | Critical, High, Medium, Low, None, Unknown | Repeat or comma-separate values. |
|---|
patch | Patch available, Mitigation available, Awaiting fix | Repeat or comma-separate remediation states. |
|---|
urgency | Patch now, Within 72 hours, Within 7 days, Needs assessment, Scheduled, Monitor | Repeat or comma-separate urgency labels. |
|---|
cvssVersion | 4.0, 3.1, 3.0, 2.0 | Repeat or comma-separate scoring versions. |
|---|
epssMin | 0 through 1 | Minimum FIRST EPSS probability; missing scores are excluded. |
|---|
epssPercentileMin | 0 through 1 | Minimum FIRST EPSS percentile; missing scores are excluded. |
|---|
wild | true | Require CISA KEV confirmation. |
|---|
lab | true | Require a recorded public exploit or proof-of-concept reference. |
|---|
euvd | true | Require an active official ENISA EUVD mapping. |
|---|
euKev | true | Require a current known-exploited record in the ENISA EUVD dataset. |
|---|
vexState | known_affected, first_affected, last_affected, under_investigation, fixed, first_fixed, known_not_affected, recommended or none | Repeat or comma-separate vendor product states. none is distinct from known_not_affected. |
|---|
language | de, es, fr, hu, it, nl, pl | Repeat or comma-separate national-authority guidance languages. |
|---|
sort | newest, priority, cvss, epss; default newest | Result ordering. |
|---|
page | Integer 1 or higher; default 1 | One-based page. |
|---|
limit | 10 through 50; default 30 | Records per page; out-of-range values are clamped. |
|---|