mcpbeat Sign in

Cve Intelligence MCP Server

by cve-security Your server? Claim it
answering

Cve Intelligence is answering right now. Last checked 11 min ago. It exposes 8 tools.

CVE intelligence: exploitation (KEV/EPSS), detection coverage, fixed versions. All tools keyless.

Uptime history 50 days of history · worst day 98%
50 days agonow
98.9%
Uptime 24h
90 of 91 checks
8
Tools
read from the server
221 ms
Response time
average over 24h
open, no key
Access
streamable-http

What changed 42

Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 10 August 2026. No other catalogue keeps this.

21 Sep a tool description was rewritten get_chains
21 Sep a tool changed the parameters it asks for get_chains
20 Sep a tool description was rewritten get_chains
19 Sep a tool description was rewritten get_chains
19 Sep a tool changed the parameters it asks for search_cves
17 Sep a tool changed the parameters it asks for search_cves
15 Sep 2 tools changed the parameters they ask for4 times that day get_updates, search_cves
15 Sep a tool appeared get_chains
15 Sep a tool description was rewritten get_chains
15 Sep a tool changed version
and 31 more, back to 10 August 2026

Cve Intelligence does not always answer

Over the last week it answered 99.4% of our checks. We check every 15 minutes, so you hear about the next outage within the hour — not from your users.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 11 min ago.

run in your terminal
claude mcp add cve-intelligence --transport http https://cve-security.com/api/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "cve-intelligence": {
      "url": "https://cve-security.com/api/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.cve-intelligence]
url = "https://cve-security.com/api/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "cve-intelligence": {
      "url": "https://cve-security.com/api/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "cve-intelligence": {
      "url": "https://cve-security.com/api/mcp"
    }
  }
}

Available tools 8

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

chains
get_chains
Known Chained Vulnerabilities™: pairs of CVEs that a cited source reports were used together in one exploit chain (VulnCheck KEV entry text, Metasploit modules, SigmaHQ rules, press, research or academic sentences, community text judged by a local model). Each row carries both CVEs with their CISA KEV status, the claim kind (observed: the source reports attacks; potential: the source reports they can be chained), the quoted evidence with its source, URL and date, and community discussion counts, which show discussion and are not chain claims. The per-CVE record carries chains.known and chains.candidates (KCV Watch: possible chains for teams to research, same-product pairs whose extracted exploit capabilities connect, derived and never confirmed, each with its tier, basis, shared product, bridge, grade, a caption and the entry step); search_cves accepts chained=1 and chainability=1. Filters: source (vulncheck_kev, metasploit, sigma, press, research, community), since (YYYY-MM-DD, first seen), claim (observed|potential), limit (1..500).
cve
get_cve
Full intelligence record for one CVE: per-scorer CVSS, EPSS, CISA KEV/ransomware/SSVC, four remote-detection modalities (the checks that work over the network) plus a host-check tier (self-contained Nuclei templates and Metasploit local modules that run on the system itself) and the Sigma log-detection layer, both kept out of scannable coverage, per-product fixed versions (fixed = first patched build; affected_through = the last vulnerable build, so upgrade past it), news/community coverage, intelligence summary. No key required over MCP; an API key on the HTTP request (Authorization: Bearer cvs_live_…) is honored for attribution. Absence semantics: a null field means this dataset holds no such record. The source may still hold one.
cves
search_cves
Search the catalog. Free text (q) and/or structured filters: vendor (slug), cwe (CWE-nnn), technique (ATT&CK id, such as T1190), year ("2024,2025"), sev ("critical,high"), kev (0|1), kev_from / kev_to (ISO days, half-open CISA listing window; imply kev=1), kev_vendor (the CISA vendorProject string verbatim, such as "Microsoft"), ransomware (0|1), detect (0|1, a detection signal we track), fix (0|1; fix=0 means the fix status was computed and this dataset holds no actionable vendor fix), automatable (0|1, CISA SSVC Automatable; 1=yes, 0=CISA assessed no, unassessed CVEs match neither), sighted (7|30: a named sensor network recorded the CVE in the last 7 or 30 days, a field sighting; presence per day, apart from the exploitation claims), malware (0|1: a published source ties a named malware family, tool, campaign or ransomware group to the CVE), watch (0|1: on KEV Watch at tier 1 or 2, reported exploited by trackers other than CISA and outside CISA KEV), epss_gte (0..1), eco (OSS ecosystem, such as npm or PyPI), pkg (pkg_key, such as npm/lodash; for ranges use query_package), page, limit (1..50). Filter-only queries return the /browse slice ordered KEV-first then EPSS.
epss
get_epss_movers
CVEs whose EPSS exploitation probability rose the most recently. window is "7d" (default) or "30d". Each rise is measured between same-EPSS-model-version scores, so a model release (which shifts the whole distribution) never appears as a mover. A rise raises the priority of a CVE; observed exploitation is recorded through CISA KEV. Returns cve_id, current score, the delta, KEV status and url, largest rise first.
package
query_package
CVEs affecting one open-source package, by purl (pkg:npm/lodash) or ecosystem + name (Maven names are group:artifact). Returns the CVE list KEV-first with each OSV version range VERBATIM: `events` plus one render-safe projection: `fixed` (the upgrade targets) or `affected_through` (the last VULNERABLE version, so upgrade past it). This tool does not evaluate version membership; compare versions on your side with your ecosystem’s own semantics. Covers CVE-linked, GitHub-reviewed OSS advisories via OSV.dev; absence is not evidence of safety.
scoreboard
get_scoreboard
The Defender Scoreboard report (CC BY 4.0): exploited vs detectable vs patchable, every figure with its method, caveat and denominator, plus the corpus block and any method-change notes. Cite as "CVE Security Defender Scoreboard, cve-security.com/scoreboard".
sightings
get_sightings
Field sightings: CVEs a named sensor network recorded in the last 7 or 30 days, most sighting days first. A field sighting is a day on which Shadowserver honeypots (cited by VulnCheck KEV and published as daily lists by CIRCL Vulnerability-Lookup) or VulnCheck canary sensors recorded traffic aimed at the CVE. Each row carries first and last sighting day, days sighted in the last 7 and 30, the sensors, and per-sensor detail including a 30-day presence strip. Presence per day, without volume; a sighting stays apart from the exploitation claims and from CISA KEV. Filters: window (7|30, default 7), kev (0|1), limit (1..500).
updates
get_updates
The publication change stream: what this site published, stamped with OUR publish time (first_published, kev_added, detection_added, remediation_added). Pass since (YYYY-MM-DD, strictly-after) on the first call, then the returned next_cursor to continue. Optional cve scopes the stream to one CVE's change history. Events for withdrawn CVE ids are omitted.

Endpoints

URLTransportStateLatencyChecked
https://cve-security.com/api/mcp streamable-http answering 402 ms 11 min ago

Alternatives to Cve Intelligence

same job, measured the same way
NotCVE — CVE & Vulnerability Intelligence
by notcve

CVE & vulnerability search: 365k+ CVEs/NotCVEs, CVSS, EPSS, CISA KEV, exploits, patches, versions.

answering
Dependency Management MCP Server
by sonatype

Sonatype component intelligence: versions, security analysis, and Trust Score recommendations

3 tools answering
Injection Detector
by viridis-security

Formally-verified injection/exfiltration detector for AI agents (MCP-02).

2 tools answering
Stobox Intelligence & Tokenization
by stobox

Verified RWA tokenization knowledge — security tokens, regulation, standards — for any AI.

6 tools answering
PostgreSQL CVE & Release Intelligence
by meob

PostgreSQL security for AI agents: CVEs, yanked releases, exploits, and upgrade paths

105 installs/wk local only
Instilus compliance and business decision tools
by instilus

GPSR compliance check and small-business valuation estimate, from Instilus.

2 tools answering
Domainintel MCP
by bishop81

Domain intelligence for agents: WHOIS, DNS, SSL/TLS, security headers, reputation, subdomains.

38 installs/wk local only
Gapup MCP
by getgapup

271 agent-payable tools: competitive intel, finance, KYC, compliance, ESG. x402 per-call.

279 tools answering

Cve Intelligence — questions

Answers built from our own checks of this server.

What can Cve Intelligence do?
It exposes 8 tools, read directly from the server on our last check. Among them: get_chains, get_cve, get_epss_movers, get_scoreboard, get_sightings, get_updates and 2 more. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is Cve Intelligence working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 90 of 91 checks got a reply (98.9%), average response time 221 ms. The bar chart above shows every period we have measured.
How do I connect Cve Intelligence?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does Cve Intelligence need an API key?
No. Cve Intelligence completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 8 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is Cve Intelligence?
It answers our handshake in 221 ms on average, which is faster than 65% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.