CVE Record
MITRE CVE · Security · 1 endpoint
One CVE record from the registry itself — description, CVSS score and severity, affected products and versions, and the reference links.
Base URL
Endpoint
Snippet
Request — cURL
v1
curl https://api.diraz.ae/v1/security/cve/%7Bid%7D \
-H "Authorization: Bearer drz_live_…"Query parameters
- idpath segment · required
- A CVE identifier.
- max_ageinteger (seconds) · optional
- Ask for data no older than this. Clamped to the product's own floor, so it can narrow the window but never force a refresh on every call.Default: 300
Example response
200 OK
v1
{
"data": {
"id": "CVE-2024-3094",
"state": "Published",
"title": null,
"description": "XZ Utils 5.6.0 and 5.6.1 contain malicious code...",
"cvss_score": 10,
"cvss_severity": "CRITICAL",
"cwe": ["CWE-506"],
"affected_products": [
{ "vendor": "Tukaani", "product": "XZ", "versions": ["5.6.0", "5.6.1"] }
],
"references": ["https://tukaani.org/xz-backdoor/"],
"published_at": "2024-03-29T00:00:00.000Z",
"updated_at": "2024-04-02T00:00:00.000Z"
},
"meta": {
"request_id": "req_7Q2fK4mZ",
"as_of": "2026-08-20T16:30:00.000Z",
"age_seconds": 120,
"next_update_at": "2026-08-20T17:00:00.000Z"
}
}- id / state / title
- The identifier, its publication state, and the record's own title when it has one.
- description
- The canonical English description of the vulnerability.
- cvss_score / cvss_severity
- The CVSS base score and its severity label, when the record carries metrics.
- cwe[]
- The weakness classifications the record asserts.
- affected_products[]
- Vendor, product, and the versions named in the record.
- references[] / published_at / updated_at
- The reference links and the record's own timestamps.
Errors
401 Unauthorized
v1
{
"error": {
"code": "UNAUTHORIZED",
"message": "The API key is invalid, expired, or revoked."
},
"meta": {
"request_id": "req_7Q2fK4mZ"
}
}Every failure carries a stable machine-readable code before the human message, and the same meta.request_id the successful responses carry. Quote it and we can find your exact request.
Errors are free
Nothing on this page is billed. You are charged for a 2xx and nothing else — a rejected key, a bad parameter, a rate limit, or an outage on our side all cost you zero. Retry without watching the meter.
- UNAUTHORIZEDHTTP 401
- Missing, malformed, expired, or revoked API key.
- FORBIDDENHTTP 403
- The key is valid but lacks the scope this product needs.
- VALIDATION_ERRORHTTP 422
- A query parameter is the wrong type or out of range.
- RATE_LIMITEDHTTP 429
- Rate limit exhausted. `Retry-After` says how long to wait.
- SERVICE_UNAVAILABLEHTTP 503
- No data recent enough to serve. Carries `Retry-After`, and is never billed.
- Status
- Operational
- Category
- Security
- Scope
- market:read
- Rate limit
- 120 requests / 60s per key
- Pricing
- 1 credit / request
- CVE Record
1/1 passing
Every response is timestamped. as_of is when the data was published, age_seconds how old that is now, and next_update_at when newer data is expected.
Three shapes to handle:
- Up to date200
The data is inside its published window. The overwhelming majority of requests.
- Delayeddelayed: true
Newer data is late. You still get the most recent there is, flagged so you can decide whether to use it.
- Unavailable503
Nothing recent enough to serve. Carries Retry-After, and is never billed.