Cybersecurity Vulnerability Intel

安全与合规

by martc03

通过 NIST NVD、CISA KEV、EPSS 和 MITRE ATT&CK 查询 CVE 信息,内含 7 个安全漏洞情报工具。

什么是 Cybersecurity Vulnerability Intel

通过 NIST NVD、CISA KEV、EPSS 和 MITRE ATT&CK 查询 CVE 信息,内含 7 个安全漏洞情报工具。

README

Cybersecurity Vulnerability Intelligence MCP Server

Unified vulnerability intelligence from 4 government data sources in a single MCP server. Get enriched CVE lookups with CVSS scores, active exploitation status, exploitation probability, and ATT&CK techniques in one call.

SourceWhat It ProvidesUpdate Frequency
NIST NVD 2.0CVE details, CVSS scores, descriptions, references, CWE classificationsContinuous
CISA KEVActively exploited vulnerabilities catalog, remediation deadlinesDaily
FIRST.org EPSSExploitation probability scores (0-1) predicting likelihood of exploitation in next 30 daysDaily
MITRE ATT&CKAdversary techniques mapped to CVEsQuarterly

Tools

vuln_lookup_cve — Enriched CVE Lookup

The killer feature. Look up any CVE and get intelligence from all 4 sources in a single call.

  • Input: { cveId: "CVE-2021-44228" }
  • Returns: NVD details + CVSS score + KEV exploitation status + EPSS probability + ATT&CK techniques

vuln_search — Search CVEs

Search the NVD by keyword, severity, and date range. Optionally filter to only actively exploited (KEV) vulnerabilities.

  • Input: { keyword: "apache log4j", severity: "CRITICAL", hasKev: true, limit: 20 }

vuln_kev_latest — Recently Exploited Vulnerabilities

Get vulnerabilities recently added to CISA's Known Exploited Vulnerabilities catalog.

  • Input: { days: 7, limit: 20 }

vuln_kev_due_soon — Upcoming Remediation Deadlines

Get KEV entries with remediation deadlines approaching. Critical for federal compliance.

  • Input: { days: 14, limit: 20 }

vuln_epss_top — Highest Exploitation Probability

Get CVEs most likely to be exploited in the next 30 days based on EPSS machine learning model.

  • Input: { threshold: 0.7, limit: 20 }

vuln_trending — Newly Published Critical CVEs

Get recently published high/critical severity CVEs from the NVD.

  • Input: { days: 3, severity: "CRITICAL", limit: 20 }

vuln_by_vendor — Vendor Vulnerability Assessment

Search CVEs for a specific vendor/product. Cross-references with CISA KEV to flag actively exploited issues.

  • Input: { vendor: "microsoft", product: "windows", limit: 20 }

Use Cases

  • Vulnerability triage: Look up a CVE and instantly know if it's actively exploited, its EPSS score, and what ATT&CK techniques apply
  • Patch prioritization: Combine KEV status + EPSS scores to prioritize remediation
  • Compliance tracking: Monitor upcoming CISA KEV remediation deadlines
  • Threat intelligence: Track trending CVEs and newly weaponized vulnerabilities
  • Vendor risk assessment: Assess a vendor's vulnerability exposure and active exploitation status

Quick Start

Glama (hosted)

Install from Glama.ai.

Apify (hosted)

json
{
  "mcpServers": {
    "cybersecurity": {
      "url": "https://cybersecurity-vuln-mcp.apify.actor/mcp"
    }
  }
}

Claude Desktop / Claude Code

json
{
  "mcpServers": {
    "cybersecurity": {
      "command": "node",
      "args": ["path/to/servers/cybersecurity-vuln-mcp/dist/stdio.js"],
      "env": {
        "NVD_API_KEY": "your-key-here"
      }
    }
  }
}

Local (stdio)

bash
git clone https://github.com/martc03/gov-mcp-servers.git
cd gov-mcp-servers/servers/cybersecurity-vuln-mcp
npm install && npm run build
node dist/stdio.js

Environment Variables

VariableRequiredDescription
NVD_API_KEYNoNVD API key for higher rate limits (50 req/30s vs 5 req/30s). Register here.

Caching

Data SourceTTLNotes
NVD CVE lookups1 hourPer-CVE
CISA KEV catalog2 hoursFull catalog
EPSS scores24 hoursPer-CVE
ATT&CK mappingsStaticBundled with server

Architecture

  • Protocol: MCP over stdio (Glama/local) or Streamable HTTP (Apify)
  • Runtime: Node.js 18+, TypeScript
  • Data: Direct API calls to free government data sources, zero cost
  • Caching: In-memory with configurable TTLs

Other Servers in This Repo

This repository contains 13 MCP servers for US government data. See each server's README for details.

ServerToolsData Sources
us-safety-recalls-mcp4NHTSA recalls, FDA recalls
natural-disaster-intel-mcp4FEMA disasters, NOAA weather, USGS earthquakes
federal-financial-intel-mcp4SEC EDGAR, CFPB complaints, BLS employment
immigration-travel-mcp3Visa bulletins, border wait times
environmental-compliance-mcp3EPA air quality, HUD foreclosures
gov-contracts-mcp4SAM.gov contracts, USAspending
court-records-mcp4PACER, federal court records
public-health-mcp4NIH clinical trials, FDA adverse events
business-entity-mcp4SEC company search, SBA resources
regulatory-monitor-mcp4Federal Register, regulations.gov
grant-finder-mcp4Grants.gov, USAspending
competitive-intel-mcp4SEC filings, patent data, trade data

A REST API gateway with 45 endpoints is also available at govdata-api.netlify.app.

Attribution

  • NVD: This product uses data from the NVD API but is not endorsed or certified by the NVD.
  • EPSS: Data provided by FIRST.org (https://www.first.org/epss/).
  • ATT&CK: Registered trademark of The MITRE Corporation. Licensed under Apache 2.0.
  • KEV: CISA Known Exploited Vulnerabilities Catalog, US Government public domain.

Custom MCP Server Development

Need a custom MCP server for your business? Visit mcpdev.netlify.app or email codee.mcpdev@gmail.com.

License

MIT

常见问题

Cybersecurity Vulnerability Intel 是什么?

通过 NIST NVD、CISA KEV、EPSS 和 MITRE ATT&CK 查询 CVE 信息,内含 7 个安全漏洞情报工具。

相关 Skills

安全专家

by alirezarezvani

Universal
热门

覆盖威胁建模、漏洞评估、安全架构设计、代码审计与渗透测试,内置 STRIDE、OWASP、加密模式和安全扫描流程,适合系统设计评审与上线前安全排查。

安全专家把威胁建模、漏洞分析到渗透测试串成一套流程,内置 STRIDE 与 OWASP 指南,做安全设计和排查更省心。

安全与合规
未扫描17.9k

安全运营

by alirezarezvani

Universal
热门

覆盖应用安全、漏洞管理与合规审计,支持代码/依赖扫描、CVE 评估、Secrets 检测和安全自动化,适合做安全基线落地、漏洞响应、审计检查与安全开发治理。

应用安全、漏洞管理和合规检查一套打通,还能自动化扫描与响应,帮团队更早发现并收敛风险。

安全与合规
未扫描17.9k

安全审计

by alirezarezvani

Universal
热门

安装前审计 Claude Code Skill 的代码执行、Prompt 注入和依赖供应链风险,支持本地目录或 Git 仓库扫描,输出 PASS/WARN/FAIL 结论及修复建议

把代码审查、漏洞扫描和合规检查串成一条线,帮团队更早发现风险,做安全治理更省心。

安全与合规
未扫描17.9k

相关 MCP Server

热门

搜索和分析 Sentry 错误报告,辅助调试。

把零散的 Sentry 错误报告变成可检索线索,帮你在海量报错里更快定位线上故障,排障调试明显省时。

安全与合规
725

为 AI agents 提供安全层:拦截 prompt injection、识别伪造 packages,并扫描漏洞风险。

给 AI Agent 补上关键安全层,能拦截 prompt 注入、识别伪造包并扫描漏洞风险,把防护前置更省心。

安全与合规
110

强化安全性的 NotebookLM MCP,集成 post-quantum encryption,提升数据防护能力。

安全与合规
68

评论