Cve Mcp Server

general MCP Server

Query vulnerability databases and security feeds directly through the Model Context Protocol.

VerifiedFresh
generalgeneral
4 views0 stars0 forksApache-2.0

Why This Matters

Discovered via github-topic:model-context-protocol and last synced Today.

VerifiedFresh
Source
github-topic:model-context-protocol
Stars
0
Last synced
Today
Install
Check source

Install

Install instructions not detected yet

Check the source repository for the latest setup steps.

View source instructions
63
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (63)

generate_risk_report

Generate a formatted executive security report for one or more CVEs with recommendations

get_attack_patterns

Retrieve CAPEC attack pattern details associated with a CWE or CVE

shodan_host_lookup

Get open ports, services, banners, and vulnerabilities for an IP via Shodan

SHODAN_KEY

Host/port/service reconnaissance

calculate_risk_score

Compute composite 0–100 risk score using CVSS, EPSS, KEV status, and PoC availability

lookup_cve

Fetch detailed CVE record from NVD including CVSS scores, CWEs, affected products, references, and timeline

search_exploits

Search GitHub for public proof-of-concept exploits and exploit code repositories

get_epss_score

Get EPSS exploitation probability (0–1) and percentile for one or more CVEs

check_ip_noise

Query GreyNoise for IP scan/attack activity, classification, and associated CVEs

scan_dependencies

Scan package names and versions against OSV.dev for known vulnerabilities

GREYNOISE_API_KEY

IP noise/scan activity intelligence

3

**CISA KEV**

search_cves

Search NVD for CVEs by keyword, product name, severity, or date range

get_trending_cves

Retrieve trending CVEs based on high EPSS scores and recent KEV additions

2

**EPSS**

7

**AbuseIPDB**

15

**CIRCL PDNS**

16

**GitHub Code Search**

Resource

TTL

lookup_ip_reputation

Check IP address abuse history and confidence score via AbuseIPDB

check_ransomware

Look up ransomware payment addresses and transaction data from Ransomwhere

Enables

How to Get

Component

Weight

4

**OSV.dev**

10

**VirusTotal**

17

**Exploit-DB**

21

**Ubuntu Security**

get_cvss_details

Parse and explain a CVSS v3.1 vector string with per-metric breakdown

bulk_cve_lookup

Batch-fetch details for up to 20 CVEs in a single call with parallel enrichment

get_mitre_techniques

Map a CVE or CWE to relevant MITRE ATT&CK techniques, tactics, and mitigations

prioritize_cves

Rank a list of CVEs by composite risk score for triage prioritization

passive_dns_lookup

Retrieve historical DNS resolution data for a domain from CIRCL Passive DNS

Tool

Description

virustotal_lookup

Analyze file hashes, URLs, domains, or IPs against 70+ antivirus engines

search_malware

Search MalwareBazaar for malware samples by hash, tag, or signature

search_iocs

Query ThreatFox for Indicators of Compromise linked to malware families

scan_github_advisories

Search GitHub Security Advisories by ecosystem, package, or severity

urlscan_check

Submit a URL for scanning or retrieve previous scan results from URLScan.io

NVD_API_KEY

10× faster NVD lookups (50 req/30s vs 5)

GITHUB_TOKEN

GitHub Advisory search + exploit PoC search

ABUSEIPDB_KEY

IP reputation lookups

VIRUSTOTAL_KEY

File/URL/domain/IP malware scanning

URLSCAN_KEY

URL scanning and website analysis

Score

Label

Source

Data Provided

1

**NVD**

None

No published limit

5

**GitHub Advisories**

6

**MITRE ATT&CK**

9

**Shodan**

11

**MalwareBazaar**

12

**ThreatFox**

13

**Ransomwhere**

14

**URLScan.io**

18

**Nuclei Templates**

19

**MSRC**

20

**Red Hat Security**

get_cve_references

Extract and categorize all reference links for a CVE (patches, advisories, exploits)

Optional

> **⚡ Zero-key start:** Eight tools work without any API key — EPSS, CISA KEV, OSV.dev, MITRE ATT&CK, CWE lookups, CVSS parsing, Ransomwhere, and NVD (at reduced rate). You can start using the server immediately and add keys progressively. --- ## ⚙️ Configuration ### Environment variables (.env.example) ```env # NVD API key — free at https://nvd.nist.gov/developers/request-an-api-key # Without key: 5 req/30s

check_kev_status

Check whether a CVE appears in CISA's Known Exploited Vulnerabilities catalog

get_cwe_info

Look up Common Weakness Enumeration details by CWE ID from embedded database

check_poc_availability

Determine if known proof-of-concept code exists for a CVE across multiple sources

8

**GreyNoise**