v1

latestOpenAPI 3.0.0Proprietary2026-07-244990150.4 KB
CVE

List CVEs

Return CVE records tracked by GreyNoise, ordered by publication date, last-update date, or CVSS score. Default cap is 100 records, configurable up to 1000 via the limit query parameter.

This endpoint requires the feature-search-cves-bulk entitlement. Response payload is shaped according to the caller's CVE Insights tier (minimal, basic, or advanced).

get/v3/cves/list

Query parameters

sort'published' | 'updated' | 'cvss'

Field to sort by.

order'desc' | 'asc'

Sort direction.

exploitable_onlyboolean

When true, restrict to CVEs with attack_vector="Network".

limitinteger

Maximum number of CVE records to return.

Response

OK - request successful.

generated_atstring date-time

Timestamp when the response was produced.

Example response

{
  "cves": [
    {
      "id": "CVE-2024-12345",
      "details": {
        "vulnerability_name": "Sample Vulnerability",
        "vulnerability_description": "This vulnerability allows remote attackers to execute arbitrary code.",
        "cve_cvss_score": 7.5,
        "product": "Sample Product",
        "vendor": "Sample Vendor",
        "published_to_nist_nvd": true
      },
      "timeline": {
        "cve_published_date": "2024-01-01",
        "cve_last_updated_date": "2024-01-02",
        "first_known_published_date": "2024-01-01",
        "cisa_kev_date_added": "2024-01-03"
      },
      "exploitation_details": {
        "attack_vector": "Network",
        "exploit_found": true,
        "exploitation_registered_in_kev": true,
        "epss_score": 0.8
      },
      "exploitation_stats": {
        "number_of_available_exploits": 5,
        "number_of_threat_actors_exploiting_vulnerability": 3,
        "number_of_botnets_exploiting_vulnerability": 2
      },
      "exploitation_activity": {
        "activity_seen": true,
        "benign_ip_count_1d": 100,
        "benign_ip_count_10d": 500,
        "benign_ip_count_30d": 1000,
        "threat_ip_count_1d": 10,
        "threat_ip_count_10d": 50,
        "threat_ip_count_30d": 100
      }
    }
  ]
}