CVEs
The CVE resource is the core of the BreachSpider platform. 367,000+ CVEs enriched with AI analysis, EPSS scoring, KEV tracking, BCS prioritization, ICS/OT relevance classification, and CVSS decomposition.
Endpoints
The CVE read endpoints are public (optional auth). Anonymous callers are capped at 10 results per page; authenticated paid tiers get up to 100 per page (with no pagination depth cap) and, where relevant, BCS and watchlist ranking.
| Method | Path | Description | Auth |
|---|---|---|---|
| GET | /api/v1/cves | List CVEs with filtering and pagination | Public |
| GET | /api/v1/cves/{cve_id} | Get single CVE full detail | Public |
| GET | /api/v1/cves/kev | List KEV entries | Public |
| GET | /api/v1/cves/vendor/{slug} | CVEs by vendor slug | Public |
| GET | /api/v1/cves/protocol/{name} | CVEs by ICS protocol | Public |
| GET | /api/v1/cves/stats/summary | CVE corpus statistics | Public |
| GET | /api/v1/cves/stats/dashboard | Dashboard-optimized stats | Public |
GET /api/v1/cves
List CVEs with filtering, sorting, and pagination.
Query Parameters
| Parameter | Type | Default | Description |
|---|---|---|---|
| page | integer | 1 | Page number |
| per_page | integer | 20 | Results per page (max 100) |
| q | string | - | Full-text search (CVE ID, vendor, keyword) |
| severity | string | - | CRITICAL, HIGH, MEDIUM, LOW |
| cvss_min | number | - | Minimum CVSS score (0-10) |
| cvss_max | number | - | Maximum CVSS score (0-10) |
| bcs_min | number | - | Minimum BreachSpider Criticality Score (0-10) |
| bcs_max | number | - | Maximum BreachSpider Criticality Score (0-10) |
| kev | boolean | - | Filter to KEV entries only |
| vendor | string | - | Vendor name filter |
| protocol | string | - | ICS protocol filter |
| unpatched | boolean | - | Only unpatched CVEs |
| has_exploit | boolean | - | Only CVEs with a public exploit or PoC |
| patch_status | string | - | patched, unpatched, partial, unknown |
| date_from | date | - | ISO 8601 date (2025-01-01) |
| date_to | date | - | ISO 8601 date |
| sort_by | string | - | date, cvss, or epss |
| ranked | boolean | false | Rank by watchlist relevance (auth required) |
Example Request
curl -H "Authorization: Bearer bs_live_..." \
"https://breachspider.com/api/v1/cves?severity=CRITICAL&kev=true&per_page=10"
List Item Shape
Each item in the collection is a lightweight summary card:
{
"cve_id": "CVE-2025-32433",
"bsid": "BS-2025-254014-C",
"title": "Erlang/OTP SSH Server Unauthenticated Remote Code Execution",
"severity": "CRITICAL",
"cvss_score": 10.0,
"bcs_score": 10.0,
"epss_score": 0.59973,
"epss_percentile": 0.98298,
"epss_top_10_pct": true,
"kev_flagged": true,
"exploit_maturity": "POC",
"poc_available": true,
"has_public_exploit": false,
"patch_status": "patched",
"ics_relevant": true,
"primary_vendor": "Erlang",
"primary_product": "Erlang/OTP",
"vendor_count": 7,
"published_at": "2025-04-16T22:15:14+00:00",
"_links": {
"self": "/api/v1/cves/CVE-2025-32433",
"html": "https://breachspider.com/ics-cve/CVE-2025-32433"
}
}
GET /api/v1/cves/{cve_id}
Full CVE detail with all scoring blocks, AI analysis, CVSS decomposition, exploitation signals, affected vendor/product list, and remediation data.
Path Parameters
| Parameter | Description |
|---|---|
| cve_id | CVE identifier (e.g. CVE-2025-32433) |
Example Request
curl -H "Authorization: Bearer bs_live_..." \
"https://breachspider.com/api/v1/cves/CVE-2025-32433"
Full Response Shape
{
"api": {
"version": "1.0.0",
"request_id": "bs-req-75d2ecafebce",
"timestamp": "2026-06-07T13:34:43.930705Z",
"processing_ms": 21
},
"data": {
"cve_id": "CVE-2025-32433",
"bsid": "BS-2025-254014-C",
"title": "Erlang/OTP SSH Server Unauthenticated Remote Code Execution",
"description": "Full vulnerability description...",
"scoring": {
"cvss": {
"score": 10.0,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1",
"severity": "CRITICAL",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "NONE",
"user_interaction": "NONE",
"scope": "CHANGED",
"confidentiality_impact": "HIGH",
"integrity_impact": "HIGH",
"availability_impact": "HIGH"
},
"epss": {
"score": 0.59973,
"percentile": 0.98298,
"interpretation": "Top 5% most likely to be exploited"
},
"bcs": {
"score": 10.0,
"tier": "CRITICAL",
"factors": {
"kev_flagged": true,
"poc_available": true,
"has_public_exploit": false,
"patch_available": true,
"ics_relevance": 0.94
}
}
},
"exploitation": {
"kev_flagged": true,
"kev_added_at": "2025-04-20T00:00:00+00:00",
"has_public_exploit": false,
"poc_available": true,
"exploit_maturity": "POC",
"actively_exploited": true
},
"affected": {
"vendors": ["Cisco", "Erlang", "Siemens"],
"products": ["Erlang/OTP", "NCS 1001"],
"primary_vendor": "Erlang",
"primary_product": "Erlang/OTP",
"vendor_count": 7,
"device_types": ["networking"],
"protocols": ["SSH"],
"ics_relevance_score": 0.94,
"ics_relevant": true
},
"patch": {
"status": "patched",
"patch_available": true,
"patch_version": "OTP-27.3.3",
"patch_url": "https://github.com/erlang/otp/releases",
"patch_notes": "Upgrade to OTP-27.3.3, OTP-26.2.5.11, or OTP-25.3.2.20",
"note": null,
"fixed_in": null
},
"classification": {
"cwes": [
{"id": 306, "url": "https://cwe.mitre.org/data/definitions/306.html"}
],
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "NONE",
"user_interaction": "NONE",
"scope": "CHANGED",
"layer": "OS",
"category": "authentication-bypass"
},
"capec": [
{
"capec_id": 540,
"name": "Overread Buffers",
"slug": "capec-540",
"typical_severity": "High",
"via_cwe": [125]
}
],
"sage": {
"model": "SAGE-v1",
"tier": "full",
"executive_summary": "Critical pre-auth RCE in Erlang/OTP SSH server...",
"ics_context": "Erlang/OTP is used in industrial messaging and SCADA middleware...",
"remediation_guidance": "Patch immediately. If patching is not possible within 24h...",
"confidence_score": 0.94,
"confidence_tier": "SOVEREIGN_AUDIT_PASS",
"_upgrade_required": false,
"_upgrade_url": null
},
"temporal": {
"published_at": "2025-04-16T22:15:14+00:00",
"modified_at": "2025-05-01T10:00:00+00:00",
"enriched_at": "2025-04-17T00:03:11+00:00",
"kev_added_at": "2025-04-20T00:00:00+00:00"
},
"references": {
"nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32433",
"cisa_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
"breachspider_url": "https://breachspider.com/ics-cve/CVE-2025-32433",
"vendor_advisories": [],
"cve_org_url": "https://www.cve.org/CVERecord?id=CVE-2025-32433",
"cisa_ics_advisories": [
{
"advisory_id": "ICSA-25-140-07",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-140-07",
"title": "Schneider Electric Galaxy VS, Galaxy VL, Galaxy VXL (Update A)",
"published": "2025-05-13"
},
{
"advisory_id": "ICSA-26-043-06",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-06",
"title": "Siemens SINEC OS",
"published": "2026-01-28"
}
],
"other_references": [
{
"url": "https://github.com/erlang/otp/commit/0fcd9c56524b28615e8ece65fc0c3f66ef6e4c12",
"tags": [
"Patch"
],
"provided_by": "[email protected]"
},
{
"url": "https://github.com/erlang/otp/commit/6eef04130afc8b0ccb63c9a0d8650209cf54892f",
"tags": [
"Patch"
],
"provided_by": "[email protected]"
}
],
"other_references_total": 14
},
"_links": {
"self": "/api/v1/cves/CVE-2025-32433",
"pdf": "/api/v1/ics-cve/CVE-2025-32433/pdf",
"html": "https://breachspider.com/ics-cve/CVE-2025-32433"
}
},
"meta": {
"enrichment_version": "2.1",
"sage_model": "SAGE-v1",
"source": "breachspider-enriched",
"capec_source": {
"catalog": "MITRE CAPEC",
"version": "3.9",
"mapping": "CWE-to-CAPEC per MITRE"
}
}
}
Fix status. patch.status is patched or unknown, or varies_by_product when the vendor's advisory states fixed versions per product. In that case patch.note says so: send the device's vendor, product and version to POST /api/v1/assets/correlate-cves for the exact fix that applies to it. When the advisory lists a fix for only one product, patch.fixed_in gives it as {"product", "version"} and the note states it (for example "Fixed in 11.36.46 for Commvault Web Server"). patch.note and patch.fixed_in are null otherwise.
patch.patch_available is true exactly when patch.status is patched: one of the CVE's references matches a known patch or fix source (a release, commit or pull request on GitHub, a distribution or vendor security page, or a CISA ICS advisory). It does not confirm a fix for any particular product or version. false means no such reference was found, not that no fix exists; it is also false for varies_by_product. patch_url is filled separately and can be present with any status, so on its own it is not proof of a fix.
References. references always has nvd_url and cve_org_url (the official CVE record). vendor_advisories holds the vendor's own advisories: links on the vendor's own domain that NVD tagged "Vendor Advisory" or that the vendor published as the CVE's CNA (here the only "Vendor Advisory" link is on GitHub, so it is not listed). With no asset matched, the vendor is the CVE's catalog vendor. cisa_ics_advisories lists CISA ICS advisories that name the CVE, with the page URL each CISA document states. other_references is every other NVD reference (not vendor-verified), capped at 25, with other_references_total the full count. No link is constructed or guessed. The example shows the first two other_references only.
data.capec
Every CVE that carries a CWE weakness also carries the CAPEC attack patterns MITRE relates to that CWE. This gives attack-pattern context per CVE without any per-CVE labeling. It is built entirely from the CWE data already held plus the published MITRE CAPEC catalog, so no CVE is hand-tagged.
data.capec is an array deduplicated by capec_id. It is always present: an empty array (never null) is returned when a CVE has no related CAPEC.
| Field | Type | Description |
|---|---|---|
| capec_id | integer | CAPEC attack-pattern identifier |
| name | string | CAPEC attack-pattern name |
| slug | string | URL slug, capec-{capec_id} |
| typical_severity | string | MITRE typical severity for the pattern |
| via_cwe | array | Bridging CWE ids that cite this mapping |
The via_cwe array is the citation anchor: it names the CWE (or CWEs) on the CVE that MITRE maps to this attack pattern. When one attack pattern is reachable through more than one bridging CWE, the CAPEC still appears once, with every bridging CWE listed in via_cwe.
The meta.capec_source block records provenance for the whole array:
"capec_source": {
"catalog": "MITRE CAPEC",
"version": "3.9",
"mapping": "CWE-to-CAPEC per MITRE"
}
The CWE-to-CAPEC relationship is authoritative and published by MITRE. It is a real mapping cited by the bridging CWE, not an inference made by BreachSpider.
Example: single bridging CWE
GET /api/v1/cves/CVE-2014-0160 (Heartbleed) returns CAPEC-540 through its CWE-125 weakness:
"capec": [
{
"capec_id": 540,
"name": "Overread Buffers",
"slug": "capec-540",
"typical_severity": "High",
"via_cwe": [125]
}
]
Example: one CAPEC, multiple bridging CWEs
GET /api/v1/cves/CVE-2007-0197 carries both CWE-20 and CWE-119. MITRE maps CAPEC-8 from both, so it is returned once with both CWE ids in via_cwe:
{
"capec_id": 8,
"name": "Buffer Overflow in an API Call",
"slug": "capec-8",
"typical_severity": "High",
"via_cwe": [20, 119]
}
GET /api/v1/cves/kev
Known Exploited Vulnerabilities catalog filtered to BreachSpider's enriched corpus. 1,700+ entries with full scoring and AI analysis.
curl -H "Authorization: Bearer bs_live_..." \
"https://breachspider.com/api/v1/cves/kev?per_page=20"
Response includes same collection envelope as /cves with KEV-specific meta:
"meta": {
"kev_program_launched": "2021-11-03",
"source": "Known Exploited Vulnerabilities Catalog",
"catalog_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
"corpus_size": 1600
}
GET /api/v1/cves/vendor/{slug}
CVEs affecting a specific vendor. Get the slug from the /api/v1/catalog/vendors response — it is returned on every vendor object. Do not derive it from the vendor name: slugs are assigned server-side and are not always the lowercased, hyphenated name (some retain underscores or punctuation), so a guessed slug will silently 404.
# Siemens CVEs
curl -H "Authorization: Bearer bs_live_..." \
"https://breachspider.com/api/v1/cves/vendor/siemens"
# Schneider Electric CVEs
curl -H "Authorization: Bearer bs_live_..." \
"https://breachspider.com/api/v1/cves/vendor/schneider-electric"
Example vendor slugs (as returned by /api/v1/catalog/vendors): siemens, schneider-electric, cisco, abb, advantech, moxa, microsoft, vmware, rockwellautomation
GET /api/v1/cves/protocol/{name}
CVEs affecting a specific ICS protocol.
curl -H "Authorization: Bearer bs_live_..." \
"https://breachspider.com/api/v1/cves/protocol/modbus"
Supported protocols: modbus, dnp3, opc-ua, iec-61850, profinet, ethernet-ip, bacnet, ssh, http, ftp