{"uid":"cap_Abt4tzc5UEykGr9_lyLO5","slug":"aayat-ai-cve-vulnerability-lookup-2bd06183","name":"Aayat AI CVE Vulnerability Lookup","description":"Vulnerability lookup for agents: by id (?id=CVE-2021-44228, GHSA-..., PYSEC-..., RUSTSEC-..., GO-...) get the advisory, severity/CVSS, affected packages and fixed versions, exploit probability (EPSS) and whether CISA lists it as exploited in the wild; or by package (?ecosystem=npm&package=lodash[&version=]) list every advisory with the same enrichment.","url":"https://aayatai.com/cve?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{"id":{"type":"string","maxLength":60,"description":"Advisory id: CVE-..., GHSA-..., PYSEC-..., RUSTSEC-..., GO-..., MAL-..."},"package":{"type":"string","maxLength":214,"description":"Or: a package name, to list its advisories."},"version":{"type":"string","maxLength":64,"description":"With package: only advisories affecting this version."},"ecosystem":{"enum":["npm","pypi","crates","go"],"type":"string","default":"npm","description":"Package ecosystem: npm, pypi, crates (Rust) or go (Go modules)."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","required":["mode","sources","checkedAt"],"properties":{"mode":{"enum":["id","package"],"type":"string"},"count":{"type":"integer"},"package":{"type":"string"},"sources":{"type":"array","items":{"type":"string"}},"version":{"type":["string","null"]},"checkedAt":{"type":"string"},"vulnerability":{"type":"object","description":"id mode: the full advisory with epss and knownExploited."},"vulnerabilities":{"type":"array","items":{"type":"object"},"description":"package mode: advisories (most severe first), each with epss and knownExploited."}}}}}}},"responseSchema":{"type":"json","example":{"mode":"id","sources":["OSV.dev","FIRST EPSS","CISA KEV"],"checkedAt":"2026-09-28T12:00:00.000Z","vulnerability":{"id":"CVE-2021-44228","url":"https://osv.dev/vulnerability/CVE-2021-44228","cvss":[{"type":"CVSS_V3","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}],"epss":{"date":"2026-09-27","score":0.99999,"percentile":1},"aliases":["GHSA-jfh8-c2jp-5v3q"],"details":"Apache Log4j2 2.0-beta9 through 2.15.0 ... JNDI features ...","fixedIn":["2.15.0"],"summary":"Log4Shell: remote code execution in Apache Log4j2","affected":[{"fixedIn":["2.15.0"],"package":"org.apache.logging.log4j:log4j-core","ecosystem":"Maven"}],"modified":"2026-01-01T00:00:00Z","severity":"critical","published":"2021-12-10T10:15:09Z","withdrawn":null,"kevChecked":true,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-44228","type":"ADVISORY"}],"knownExploited":{"dueDate":"2021-12-24","dateAdded":"2021-12-10","ransomware":true,"requiredAction":"Apply updates per vendor instructions."}}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_BJ8L8yeNQuv_gFcBsVzaF","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Look up security advisories by CVE/GHSA/PYSEC/RUSTSEC/GO ID or by package name, returning severity, CVSS, affected versions, EPSS exploit probability, and CISA KEV status","exampleAgentPrompt":"Look up CVE-2021-44228 and tell me how severe it is, what packages are affected, whether it's being actively exploited in the wild, and what the EPSS score is.","exampleUseCases":[{"title":"Log4Shell severity assessment","prompt":"Can you pull up the full advisory for CVE-2021-44228 — I need the CVSS score, affected versions, fix versions, EPSS probability, and whether CISA has flagged it as exploited in the wild?"},{"title":"npm package vulnerability audit","prompt":"Check if the npm package lodash has any known security advisories and list them from most severe to least, including EPSS scores and whether any are CISA known exploited vulnerabilities."},{"title":"Version-specific vulnerability check","prompt":"I'm running PyPI package requests version 2.25.0 — does it have any known vulnerabilities? If so, tell me which ones, how severe they are, and what version I should upgrade to."}],"resultDescription":"Returns a JSON object with mode (id or package), checkedAt timestamp, and sources consulted. In id mode: a single vulnerability object with ID, summary, details, severity, CVSS vectors, affected packages, fixed versions, EPSS score and percentile, aliases, references, and CISA KEV metadata (dueDate, dateAdded, ransomware flag, requiredAction). In package mode: an array of vulnerability objects sorted by severity, each with the same enrichment fields.","failureModes":["Advisory ID not found in OSV.dev — returns empty or null vulnerability","Package not found in the specified ecosystem — returns empty vulnerabilities array","Invalid ecosystem value — request rejected with validation error","Malformed CVE/GHSA/advisory ID format — may return no results","EPSS or CISA KEV data temporarily unavailable — partial enrichment returned","Rate limiting or upstream OSV.dev outage — service error response","Missing required query parameter (neither id nor package provided) — error response"],"whenToPreferThis":"Choose this endpoint when you need comprehensive, enriched vulnerability intelligence in a single call — combining OSV.dev advisory data with FIRST EPSS exploit probability scores and CISA KEV status. Prefer it over raw NVD/OSV queries when you need to know not just what a vulnerability is but how likely it is to be exploited and whether it is actively being weaponized. Ideal for dependency audits, security triage pipelines, and agentic security workflows where cost-per-lookup matters and breadth of enrichment (CVSS + EPSS + KEV) in one response saves multiple API calls.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T04:27:02.836Z","isFirstParty":false,"canonicalSlug":"aayat-ai-cve-vulnerability-lookup-2bd06183"}