CVE Tools Logo

CVE Tools

AI-enriched CVE intelligence platform with exploit links, EPSS, and ATT&CK mappings.

Product
Vulnerability Management
MCP

The Entire Cybersecurity Market, One Prompt Away

Connect your AI assistant to 10,000+ tools and 5,000+ vendors. Ask anything about the cybersecurity market.

Try MCP

CVE Tools Description

CVE Tools is a vulnerability intelligence platform that aggregates, enriches, and provides searchable access to CVE (Common Vulnerabilities and Exposures) data. The platform continuously syncs vulnerability records from multiple authoritative sources including the official CVEProject repository, NIST National Vulnerability Database (NVD), GitHub Security Advisories (GHSA), CISA Known Exploited Vulnerabilities (KEV) catalog, and the Russian FSTEC BDU database. Each CVE record in the database is enriched with additional context including: - CVSS severity scores and EPSS (Exploit Prediction Scoring System) probability scores - Linked proof-of-concept exploits from GitHub, ExploitDB, and Metasploit modules - Nuclei scanner templates for active validation - MITRE ATT&CK technique and kill chain stage mappings - CPE-based affected product and version range details - CWE weakness classifications The platform offers several core capabilities. A full-text and semantic search engine (powered by Typesense) allows users to query over 320,000 CVEs by ID, vendor, description, CWE, or natural language. An AI assistant enables conversational analysis of vulnerabilities, including impact assessment, remediation guidance, and detection rule generation. An attack surface graph provides interactive visualization linking products to CVEs to ATT&CK techniques. CVE Tools also exposes a REST API and a Model Context Protocol (MCP) server for integration with external tools such as SIEMs, ticketing systems, and AI coding environments like Claude and Cursor. The platform is available with a free tier requiring account registration. It targets security teams, vulnerability management practitioners, and developers who need structured, enriched vulnerability data and tooling for triage and remediation prioritization.