Skip to content

CVEs

The CVE resource is the core of the BreachSpider platform. 367,000+ CVEs enriched with AI analysis, EPSS scoring, KEV tracking, BCS prioritization, ICS/OT relevance classification, and CVSS decomposition.

Endpoints

The CVE read endpoints are public (optional auth). Anonymous callers are capped at 10 results per page; authenticated paid tiers get up to 100 per page (with no pagination depth cap) and, where relevant, BCS and watchlist ranking.

Method Path Description Auth
GET /api/v1/cves List CVEs with filtering and pagination Public
GET /api/v1/cves/{cve_id} Get single CVE full detail Public
GET /api/v1/cves/kev List KEV entries Public
GET /api/v1/cves/vendor/{slug} CVEs by vendor slug Public
GET /api/v1/cves/protocol/{name} CVEs by ICS protocol Public
GET /api/v1/cves/stats/summary CVE corpus statistics Public
GET /api/v1/cves/stats/dashboard Dashboard-optimized stats Public

GET /api/v1/cves

List CVEs with filtering, sorting, and pagination.

Query Parameters

Parameter Type Default Description
page integer 1 Page number
per_page integer 20 Results per page (max 100)
q string - Full-text search (CVE ID, vendor, keyword)
severity string - CRITICAL, HIGH, MEDIUM, LOW
cvss_min number - Minimum CVSS score (0-10)
cvss_max number - Maximum CVSS score (0-10)
bcs_min number - Minimum BreachSpider Criticality Score (0-10)
bcs_max number - Maximum BreachSpider Criticality Score (0-10)
kev boolean - Filter to KEV entries only
vendor string - Vendor name filter
protocol string - ICS protocol filter
unpatched boolean - Only unpatched CVEs
has_exploit boolean - Only CVEs with a public exploit or PoC
patch_status string - patched, unpatched, partial, unknown
date_from date - ISO 8601 date (2025-01-01)
date_to date - ISO 8601 date
sort_by string - date, cvss, or epss
ranked boolean false Rank by watchlist relevance (auth required)

Example Request

curl -H "Authorization: Bearer bs_live_..." \
  "https://breachspider.com/api/v1/cves?severity=CRITICAL&kev=true&per_page=10"

List Item Shape

Each item in the collection is a lightweight summary card:

{
  "cve_id": "CVE-2025-32433",
  "bsid": "BS-2025-254014-C",
  "title": "Erlang/OTP SSH Server Unauthenticated Remote Code Execution",
  "severity": "CRITICAL",
  "cvss_score": 10.0,
  "bcs_score": 10.0,
  "epss_score": 0.59973,
  "epss_percentile": 0.98298,
  "epss_top_10_pct": true,
  "kev_flagged": true,
  "exploit_maturity": "POC",
  "poc_available": true,
  "has_public_exploit": false,
  "patch_status": "patched",
  "ics_relevant": true,
  "primary_vendor": "Erlang",
  "primary_product": "Erlang/OTP",
  "vendor_count": 7,
  "published_at": "2025-04-16T22:15:14+00:00",
  "_links": {
    "self": "/api/v1/cves/CVE-2025-32433",
    "html": "https://breachspider.com/ics-cve/CVE-2025-32433"
  }
}

GET /api/v1/cves/{cve_id}

Full CVE detail with all scoring blocks, AI analysis, CVSS decomposition, exploitation signals, affected vendor/product list, and remediation data.

Path Parameters

Parameter Description
cve_id CVE identifier (e.g. CVE-2025-32433)

Example Request

curl -H "Authorization: Bearer bs_live_..." \
  "https://breachspider.com/api/v1/cves/CVE-2025-32433"

Full Response Shape

{
  "api": {
    "version": "1.0.0",
    "request_id": "bs-req-75d2ecafebce",
    "timestamp": "2026-06-07T13:34:43.930705Z",
    "processing_ms": 21
  },
  "data": {
    "cve_id": "CVE-2025-32433",
    "bsid": "BS-2025-254014-C",
    "title": "Erlang/OTP SSH Server Unauthenticated Remote Code Execution",
    "description": "Full vulnerability description...",
    "scoring": {
      "cvss": {
        "score": 10.0,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "version": "3.1",
        "severity": "CRITICAL",
        "attack_vector": "NETWORK",
        "attack_complexity": "LOW",
        "privileges_required": "NONE",
        "user_interaction": "NONE",
        "scope": "CHANGED",
        "confidentiality_impact": "HIGH",
        "integrity_impact": "HIGH",
        "availability_impact": "HIGH"
      },
      "epss": {
        "score": 0.59973,
        "percentile": 0.98298,
        "interpretation": "Top 5% most likely to be exploited"
      },
      "bcs": {
        "score": 10.0,
        "tier": "CRITICAL",
        "factors": {
          "kev_flagged": true,
          "poc_available": true,
          "has_public_exploit": false,
          "patch_available": true,
          "ics_relevance": 0.94
        }
      }
    },
    "exploitation": {
      "kev_flagged": true,
      "kev_added_at": "2025-04-20T00:00:00+00:00",
      "has_public_exploit": false,
      "poc_available": true,
      "exploit_maturity": "POC",
      "actively_exploited": true
    },
    "affected": {
      "vendors": ["Cisco", "Erlang", "Siemens"],
      "products": ["Erlang/OTP", "NCS 1001"],
      "primary_vendor": "Erlang",
      "primary_product": "Erlang/OTP",
      "vendor_count": 7,
      "device_types": ["networking"],
      "protocols": ["SSH"],
      "ics_relevance_score": 0.94,
      "ics_relevant": true
    },
    "patch": {
      "status": "patched",
      "patch_available": true,
      "patch_version": "OTP-27.3.3",
      "patch_url": "https://github.com/erlang/otp/releases",
      "patch_notes": "Upgrade to OTP-27.3.3, OTP-26.2.5.11, or OTP-25.3.2.20",
      "note": null,
      "fixed_in": null
    },
    "classification": {
      "cwes": [
        {"id": 306, "url": "https://cwe.mitre.org/data/definitions/306.html"}
      ],
      "attack_vector": "NETWORK",
      "attack_complexity": "LOW",
      "privileges_required": "NONE",
      "user_interaction": "NONE",
      "scope": "CHANGED",
      "layer": "OS",
      "category": "authentication-bypass"
    },
    "capec": [
      {
        "capec_id": 540,
        "name": "Overread Buffers",
        "slug": "capec-540",
        "typical_severity": "High",
        "via_cwe": [125]
      }
    ],
    "sage": {
      "model": "SAGE-v1",
      "tier": "full",
      "executive_summary": "Critical pre-auth RCE in Erlang/OTP SSH server...",
      "ics_context": "Erlang/OTP is used in industrial messaging and SCADA middleware...",
      "remediation_guidance": "Patch immediately. If patching is not possible within 24h...",
      "confidence_score": 0.94,
      "confidence_tier": "SOVEREIGN_AUDIT_PASS",
      "_upgrade_required": false,
      "_upgrade_url": null
    },
    "temporal": {
      "published_at": "2025-04-16T22:15:14+00:00",
      "modified_at": "2025-05-01T10:00:00+00:00",
      "enriched_at": "2025-04-17T00:03:11+00:00",
      "kev_added_at": "2025-04-20T00:00:00+00:00"
    },
    "references": {
      "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32433",
      "cisa_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "breachspider_url": "https://breachspider.com/ics-cve/CVE-2025-32433",
      "vendor_advisories": [],
      "cve_org_url": "https://www.cve.org/CVERecord?id=CVE-2025-32433",
      "cisa_ics_advisories": [
        {
          "advisory_id": "ICSA-25-140-07",
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-140-07",
          "title": "Schneider Electric Galaxy VS, Galaxy VL, Galaxy VXL (Update A)",
          "published": "2025-05-13"
        },
        {
          "advisory_id": "ICSA-26-043-06",
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-06",
          "title": "Siemens SINEC OS",
          "published": "2026-01-28"
        }
      ],
      "other_references": [
        {
          "url": "https://github.com/erlang/otp/commit/0fcd9c56524b28615e8ece65fc0c3f66ef6e4c12",
          "tags": [
            "Patch"
          ],
          "provided_by": "[email protected]"
        },
        {
          "url": "https://github.com/erlang/otp/commit/6eef04130afc8b0ccb63c9a0d8650209cf54892f",
          "tags": [
            "Patch"
          ],
          "provided_by": "[email protected]"
        }
      ],
      "other_references_total": 14
    },
    "_links": {
      "self": "/api/v1/cves/CVE-2025-32433",
      "pdf": "/api/v1/ics-cve/CVE-2025-32433/pdf",
      "html": "https://breachspider.com/ics-cve/CVE-2025-32433"
    }
  },
  "meta": {
    "enrichment_version": "2.1",
    "sage_model": "SAGE-v1",
    "source": "breachspider-enriched",
    "capec_source": {
      "catalog": "MITRE CAPEC",
      "version": "3.9",
      "mapping": "CWE-to-CAPEC per MITRE"
    }
  }
}

Fix status. patch.status is patched or unknown, or varies_by_product when the vendor's advisory states fixed versions per product. In that case patch.note says so: send the device's vendor, product and version to POST /api/v1/assets/correlate-cves for the exact fix that applies to it. When the advisory lists a fix for only one product, patch.fixed_in gives it as {"product", "version"} and the note states it (for example "Fixed in 11.36.46 for Commvault Web Server"). patch.note and patch.fixed_in are null otherwise.

patch.patch_available is true exactly when patch.status is patched: one of the CVE's references matches a known patch or fix source (a release, commit or pull request on GitHub, a distribution or vendor security page, or a CISA ICS advisory). It does not confirm a fix for any particular product or version. false means no such reference was found, not that no fix exists; it is also false for varies_by_product. patch_url is filled separately and can be present with any status, so on its own it is not proof of a fix.

References. references always has nvd_url and cve_org_url (the official CVE record). vendor_advisories holds the vendor's own advisories: links on the vendor's own domain that NVD tagged "Vendor Advisory" or that the vendor published as the CVE's CNA (here the only "Vendor Advisory" link is on GitHub, so it is not listed). With no asset matched, the vendor is the CVE's catalog vendor. cisa_ics_advisories lists CISA ICS advisories that name the CVE, with the page URL each CISA document states. other_references is every other NVD reference (not vendor-verified), capped at 25, with other_references_total the full count. No link is constructed or guessed. The example shows the first two other_references only.

data.capec

Every CVE that carries a CWE weakness also carries the CAPEC attack patterns MITRE relates to that CWE. This gives attack-pattern context per CVE without any per-CVE labeling. It is built entirely from the CWE data already held plus the published MITRE CAPEC catalog, so no CVE is hand-tagged.

data.capec is an array deduplicated by capec_id. It is always present: an empty array (never null) is returned when a CVE has no related CAPEC.

Field Type Description
capec_id integer CAPEC attack-pattern identifier
name string CAPEC attack-pattern name
slug string URL slug, capec-{capec_id}
typical_severity string MITRE typical severity for the pattern
via_cwe array Bridging CWE ids that cite this mapping

The via_cwe array is the citation anchor: it names the CWE (or CWEs) on the CVE that MITRE maps to this attack pattern. When one attack pattern is reachable through more than one bridging CWE, the CAPEC still appears once, with every bridging CWE listed in via_cwe.

The meta.capec_source block records provenance for the whole array:

"capec_source": {
  "catalog": "MITRE CAPEC",
  "version": "3.9",
  "mapping": "CWE-to-CAPEC per MITRE"
}

The CWE-to-CAPEC relationship is authoritative and published by MITRE. It is a real mapping cited by the bridging CWE, not an inference made by BreachSpider.

Example: single bridging CWE

GET /api/v1/cves/CVE-2014-0160 (Heartbleed) returns CAPEC-540 through its CWE-125 weakness:

"capec": [
  {
    "capec_id": 540,
    "name": "Overread Buffers",
    "slug": "capec-540",
    "typical_severity": "High",
    "via_cwe": [125]
  }
]

Example: one CAPEC, multiple bridging CWEs

GET /api/v1/cves/CVE-2007-0197 carries both CWE-20 and CWE-119. MITRE maps CAPEC-8 from both, so it is returned once with both CWE ids in via_cwe:

{
  "capec_id": 8,
  "name": "Buffer Overflow in an API Call",
  "slug": "capec-8",
  "typical_severity": "High",
  "via_cwe": [20, 119]
}

GET /api/v1/cves/kev

Known Exploited Vulnerabilities catalog filtered to BreachSpider's enriched corpus. 1,700+ entries with full scoring and AI analysis.

curl -H "Authorization: Bearer bs_live_..." \
  "https://breachspider.com/api/v1/cves/kev?per_page=20"

Response includes same collection envelope as /cves with KEV-specific meta:

"meta": {
  "kev_program_launched": "2021-11-03",
  "source": "Known Exploited Vulnerabilities Catalog",
  "catalog_url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
  "corpus_size": 1600
}

GET /api/v1/cves/vendor/{slug}

CVEs affecting a specific vendor. Get the slug from the /api/v1/catalog/vendors response — it is returned on every vendor object. Do not derive it from the vendor name: slugs are assigned server-side and are not always the lowercased, hyphenated name (some retain underscores or punctuation), so a guessed slug will silently 404.

# Siemens CVEs
curl -H "Authorization: Bearer bs_live_..." \
  "https://breachspider.com/api/v1/cves/vendor/siemens"

# Schneider Electric CVEs
curl -H "Authorization: Bearer bs_live_..." \
  "https://breachspider.com/api/v1/cves/vendor/schneider-electric"

Example vendor slugs (as returned by /api/v1/catalog/vendors): siemens, schneider-electric, cisco, abb, advantech, moxa, microsoft, vmware, rockwellautomation


GET /api/v1/cves/protocol/{name}

CVEs affecting a specific ICS protocol.

curl -H "Authorization: Bearer bs_live_..." \
  "https://breachspider.com/api/v1/cves/protocol/modbus"

Supported protocols: modbus, dnp3, opc-ua, iec-61850, profinet, ethernet-ip, bacnet, ssh, http, ftp