Vulnerabilities · GraphQL type

CVE type

Type CVE represents a Common Vulnerabilities and Exposures entry with comprehensive security information

Fields

Field Name Description
id - ID! The unique Common Vulnerabilities and Exposures identifier (e.g., CVE-2024-1234).
source - String! The data source or organization that provided this CVE information
vulnerabilityStatus - CVEVulnerabilityStatus! Current NVD analysis workflow state of the vulnerability
published - Time! The date and time when this CVE was first published
lastModified - Time! The date and time when this CVE was last updated
evaluator - CVEEvaluator Internal evaluator assessment including comments, solutions, and impact analysis
cisa - CVECISA CISA Known Exploited Vulnerabilities catalog information, if applicable
tags - [CVESourceTag!] Classification tags from various sources describing the vulnerability type
descriptions - [CVEDescription!]! Human-readable descriptions of the vulnerability in various languages
references - [CVEReference!]! External references and links providing additional information about the vulnerability
metrics - [CVSSMetric!]! CVSS scoring metrics from various sources and versions
weaknesses - [CVEWeakness!]! CWE (Common Weakness Enumeration) classifications associated with this vulnerability
configurations - [CVEConfiguration!]! CPE configurations defining which products and versions are affected
vendorComments - [CVEVendorComment!]! Official statements and comments from affected vendors
severity - CVSSSeverity The CVE's severity: its CVSS base severity, raised when its CVEEPSS score shows it's likely to be exploited in the next 30 days. EPSS never lowers the CVSS severity. Null when the CVE has neither a CVSS rating nor an EPSS score high enough to raise it.
epss - CVEEPSS The CVE's current EPSS score. Null when EPSS hasn't scored the CVE.

Returned by

  • vulnerabilityFetchCVE query: Retrieves one published CVE (Common Vulnerabilities and Exposures) record by its id, with its description, severity, and EPSS (Exploit Prediction…

Used by

  • CVEIdsPayload type: Type CVEIdsPayload represents a collection of CVE identifiers
  • PlatformVulnerabilities type: Type PlatformVulnerabilities pairs the CPE (Common Platform Enumeration) identifiers determined for an object with the CVEs (Common Vulnerabilities…

Example

Example

{
  "id": 4,
  "source": "xyz789",
  "vulnerabilityStatus": "ANALYZED",
  "published": "2021-10-07T18:23:25.829Z",
  "lastModified": "2021-10-07T18:23:25.829Z",
  "evaluator": CVEEvaluator,
  "cisa": CVECISA,
  "tags": [CVESourceTag],
  "descriptions": [CVEDescription],
  "references": [CVEReference],
  "metrics": [CVSSMetric],
  "weaknesses": [CVEWeakness],
  "configurations": [CVEConfiguration],
  "vendorComments": [CVEVendorComment],
  "severity": "NONE",
  "epss": CVEEPSS
}