CVE Enrichment.Within Minutes. Without Gaps.

Keep your existing NVD integrations and swap in a more complete data source. Get enriched CVSS, CPEs, affected versions, and deeper CVE analysis in the same API format your tools already use.

Independent service. Not affiliated with, endorsed by, or operated by NIST or the National Vulnerability Database.

Complete coverageNo more missing CVSS, CPEs or versions.
Instant enrichmentNo more waiting weeks for analysis.
Reliable accessNo more outages, 503s or failed syncs.

Why buy now

NVD No Longer Enriches Every CVE

In April 2026, NIST changed NVD operations to a risk-based model. CVEs still enter the NVD, but many are no longer scheduled for enrichment. For teams that depend on complete coverage, this creates blind spots and slower triage unless enrichment comes from another source.

Get your free API key

The data layer your program needs

We Enrich the Ones They Don’t.

NVD’s cutback pushes enrichment onto your team, whether you’re ready to staff it or not. We take on that work for a fraction of the cost of building it in-house, so your pipeline keeps receiving reliable scoring, mapped products, and meaningful source context.

01

CVSS 3.1 and CVSS 4.0 vectors

Severity scoring that helps your team prioritize remediation quickly.
02

Dictionary-validated CPEs

Normalized product mappings so affected assets are easier to identify.
03

Categorized reference tagging

Links grouped by source type so analysts can review evidence faster.
04

Context-rich CVE descriptions

Expanded vulnerability context that makes each record more actionable.

One endpoint change.
No workflow rewrite.

Our API stays compatible with NVD 2.0 request and response formats, so your existing parsers and workflows keep working. We enrich every CVE and inject the missing context directly into that same schema, so downstream systems receive complete records in the format they already trust.

View NVD-compatible endpoint docs

01Endpoint compatible

Keep your established NVD 2.0 request patterns.

02Schema compatible

Receive enriched CVEs in familiar NVD 2.0 response shapes.

03Gap-filling enrichment

Missing fields are injected so records arrive complete for triage.

Simple production access

Choose the capacity your program needs.

All plans include the same complete enrichment coverage. Scale request volume and support as your operational needs grow.

Free

For evaluation

0

Validate your integration with real enrichment data.

  • Rate limit60 requests / min
  • Monthly requests10K / month
  • API keys1
  • Data windowFull CVE coverage
  • CVSS 3.1 and CVSS 4.0 vectors
  • Dictionary-validated CPEs
  • Categorized reference tagging
  • Context-rich CVE descriptions
Start for free

Team

For production

199 / month

For production integrations and larger security programs.

  • Rate limit1,000 requests / min
  • Monthly requests2M / month
  • API keys10
  • Data windowFull CVE coverage
  • CVSS 3.1 and CVSS 4.0 vectors
  • Dictionary-validated CPEs
  • Categorized reference tagging
  • Context-rich CVE descriptions
Get Team access

Enterprise

Custom limits, SLA, bulk feeds, OEM/redistribution, and dedicated contract support for large-scale deployments.

Contact us

API access is for internal security workflows. Commercial redistribution, white-label use, and AI training datasets require a separate agreement. Prices are excl. VAT where applicable, taxes calculated at checkout.

FAQ

Questions about NVDAPI.com

What is NVDAPI.com?

NVDAPI.com is an NVD API alternative powered by Volerion. It provides NVD 2.0-compatible access to fully enriched CVE records.

Is NVDAPI.com compatible with NVD API 2.0?

Yes. Most integrations can keep their existing requests, parsers, and workflows. You only need to change the base URL.

What CVE enrichment is included?

Records include CVSS 3.1 and 4.0 vectors, validated CPEs, affected versions, improved descriptions, and categorized references.

How quickly are new CVEs enriched?

Most new CVEs are enriched within 10 minutes. Complex or unusually large records can take up to a few hours.

Can NVDAPI.com help with NVD API downtime and 503 errors?

Yes. NVDAPI.com uses a separate production endpoint, reducing your dependency on NVD availability and helping prevent failed synchronization cycles.

What are the rate limits?

Rate limits vary by plan. We offer options for evaluation, regular ingestion, and high-volume production use.

Do I need an NVD API key?

No. NVDAPI.com uses credentials issued by Volerion instead of a NIST NVD API key.

How do you ensure CVE data quality?

We've spent over 3 years automating CVE enrichment and specializing in standards like CVSS, CPE, and SSVC. During that time, we developed a unique graph-based approach that models each vulnerability as auditable attack paths. Enrichment such as CVSS is then derived from that structured analysis. You can watch our VulnCon26 talk to learn how it works. Our public CISA Vulnrichment corrections also show real examples of us identifying and correcting problems in public vulnerability data.

NVD-compatible API by Volerion

Stop waiting for vulnerability context.

Get your free API key