What is NVDAPI.com?
NVDAPI.com is an NVD API alternative powered by Volerion. It provides NVD 2.0-compatible access to fully enriched CVE records.
What exactly is covered by NVDAPI.com?
We fill the huge gaps the NVD now leaves in CVE data. Every new CVE the NVD defers, usually thousands per week, we enrich ourselves. For every CVE the NVD does enrich, we proxy their data directly for full compatibility and coverage. That makes our API the best drop-in option to swap to.
What CVE enrichment does NVDAPI.com include?
Records include CVSS 3.1 and 4.0 vectors, validated CPEs, affected versions, improved descriptions, and categorized references.
How quickly does NVDAPI.com enrich new CVEs?
Most new CVEs are enriched within 10 minutes. Complex or unusually large records can take up to a few hours.
How does NVDAPI.com ensure CVE data quality?
We've spent over 3 years automating CVE enrichment and specializing in standards like CVSS, CPE, and SSVC. During that time, we developed a unique graph-based approach that models each vulnerability as auditable attack paths. Enrichment such as CVSS is then derived from that structured analysis. You can watch our VulnCon26 talk to learn how it works. Our public CISA Vulnrichment corrections also show real examples of us identifying and correcting problems in public vulnerability data.
Is NVDAPI.com compatible with NVD API 2.0?
Yes. Most integrations can keep their existing requests, parsers, and workflows. You only need to change the base URL.
Do I need an NVD API key to use NVDAPI.com?
No. NVDAPI.com uses credentials issued by Volerion instead of a NIST NVD API key.
Can NVDAPI.com help with NVD API downtime and 503 errors?
Yes. NVDAPI.com uses a separate production endpoint, reducing your dependency on NVD availability and helping prevent failed synchronization cycles.
What are NVDAPI.com's rate limits?
Rate limits vary by plan. We offer options for evaluation, regular ingestion, and high-volume production use.