Skip to content
All APIs

CVE Record

MITRE CVE · Security · 1 endpoint

One CVE record from the registry itself — description, CVSS score and severity, affected products and versions, and the reference links.

Base URL

https://api.diraz.ae
0 requests30m cache1 credit / request

Endpoint

GET/v1/security/cve/{id}

Snippet

Request — cURL

v1

curl https://api.diraz.ae/v1/security/cve/%7Bid%7D \
  -H "Authorization: Bearer drz_live_…"

Query parameters

idpath segment · required
A CVE identifier.
max_ageinteger (seconds) · optional
Ask for data no older than this. Clamped to the product's own floor, so it can narrow the window but never force a refresh on every call.Default: 300

Example response

200 OK

v1

{
  "data": {
    "id": "CVE-2024-3094",
    "state": "Published",
    "title": null,
    "description": "XZ Utils 5.6.0 and 5.6.1 contain malicious code...",
    "cvss_score": 10,
    "cvss_severity": "CRITICAL",
    "cwe": ["CWE-506"],
    "affected_products": [
      { "vendor": "Tukaani", "product": "XZ", "versions": ["5.6.0", "5.6.1"] }
    ],
    "references": ["https://tukaani.org/xz-backdoor/"],
    "published_at": "2024-03-29T00:00:00.000Z",
    "updated_at": "2024-04-02T00:00:00.000Z"
  },
  "meta": {
    "request_id": "req_7Q2fK4mZ",
    "as_of": "2026-08-20T16:30:00.000Z",
    "age_seconds": 120,
    "next_update_at": "2026-08-20T17:00:00.000Z"
  }
}
id / state / title
The identifier, its publication state, and the record's own title when it has one.
description
The canonical English description of the vulnerability.
cvss_score / cvss_severity
The CVSS base score and its severity label, when the record carries metrics.
cwe[]
The weakness classifications the record asserts.
affected_products[]
Vendor, product, and the versions named in the record.
references[] / published_at / updated_at
The reference links and the record's own timestamps.

Errors

401 Unauthorized

v1

{
  "error": {
    "code": "UNAUTHORIZED",
    "message": "The API key is invalid, expired, or revoked."
  },
  "meta": {
    "request_id": "req_7Q2fK4mZ"
  }
}

Every failure carries a stable machine-readable code before the human message, and the same meta.request_id the successful responses carry. Quote it and we can find your exact request.

Errors are free

Nothing on this page is billed. You are charged for a 2xx and nothing else — a rejected key, a bad parameter, a rate limit, or an outage on our side all cost you zero. Retry without watching the meter.

UNAUTHORIZEDHTTP 401
Missing, malformed, expired, or revoked API key.
FORBIDDENHTTP 403
The key is valid but lacks the scope this product needs.
VALIDATION_ERRORHTTP 422
A query parameter is the wrong type or out of range.
RATE_LIMITEDHTTP 429
Rate limit exhausted. `Retry-After` says how long to wait.
SERVICE_UNAVAILABLEHTTP 503
No data recent enough to serve. Carries `Retry-After`, and is never billed.
Total requests0
Cache30m
Status
Operational
Category
Security
Scope
market:read
Rate limit
120 requests / 60s per key
Pricing
1 credit / request
Request a keyView as Markdown
  • CVE Record

1/1 passing

Every response is timestamped. as_of is when the data was published, age_seconds how old that is now, and next_update_at when newer data is expected.

Three shapes to handle:

  • Up to date200

    The data is inside its published window. The overwhelming majority of requests.

  • Delayeddelayed: true

    Newer data is late. You still get the most recent there is, flagged so you can decide whether to use it.

  • Unavailable503

    Nothing recent enough to serve. Carries Retry-After, and is never billed.