Nist Nvd MCP Server is answering right now. Last checked 6 min ago. 328 installs a week from npm. It exposes 5 tools. Last commit 20 Sep 2026.
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
Over the last week it answered 99.1% of our checks. We check every 15 minutes, so you hear about the next outage within the hour — not from your users.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 6 min ago.
claude mcp add nist-nvd-mcp-server --transport http https://nist-nvd.caseyjhand.com/mcp
{
"mcpServers": {
"nist-nvd-mcp-server": {
"url": "https://nist-nvd.caseyjhand.com/mcp"
}
}
}
[mcp_servers.nist-nvd-mcp-server]
url = "https://nist-nvd.caseyjhand.com/mcp"
{
"mcpServers": {
"nist-nvd-mcp-server": {
"url": "https://nist-nvd.caseyjhand.com/mcp"
}
}
}
{
"mcpServers": {
"nist-nvd-mcp-server": {
"url": "https://nist-nvd.caseyjhand.com/mcp"
}
}
}
This one needs environment variables set before it will start:
NVD_API_KEY (NVD API key. Without it, rate limit is 5 req/30s; with it, 50 req/30s. Get one free at nvd.nist.gov/developers/request-an-api-key.), NVD_REQUEST_TIMEOUT_MS (Per-request timeout in milliseconds. Raise to 60000 when using nvd_get_cve_history without an API key.), MCP_HTTP_HOST (The hostname for the HTTP server.), MCP_HTTP_PORT (The port to run the HTTP server on.), MCP_HTTP_ENDPOINT_PATH (The endpoint path for the MCP server.), MCP_AUTH_MODE (Authentication mode to use: 'none', 'jwt', or 'oauth'.), MCP_LOG_LEVEL (Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').).
The author declared them in the registry entry; get the values from the project itself.
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
nvd_audit_cpe
nvd_get_cve
nvd_get_cve_history
nvd_search_cpes
nvd_search_cves
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://nist-nvd.caseyjhand.com/mcp | streamable-http | answering | 402 ms | 6 min ago |
Search emoji by name or keyword locally. No network and no key.
Discover events from Luma — search by category, city, distance, and keywords with calendar export
Search jobs on NextJobz by keyword, location, work type, salary, and experience level.
AI-powered keyword research, SEO audits, and AI-visibility scans via the JackpotKeywords REST API.
Search volume, keyword ideas, difficulty, clickstream volumes and search trends.
SEO MCP server for keyword research, SERP analysis, audits, and Search Console workflows.
Search bounded RSS, Atom, and RDF feed matches by keyword or regex.
Search CVE vulnerability records from the NIST NVD database. No key required.
Answers built from our own checks of this server.