{"uid":"cap_BGwp58imsh7iwO5Rsq2a5","slug":"synergy-cve-risk-brief-aa4d468e","name":"Synergy CVE Risk Brief","description":"Vulnerability risk brief: exact CVE id (or product-name search over the NVD keyword index). Attested NVD 2.0 record (description, CVSS v2/v3.x/v4.0 metrics, CWE weaknesses, vulnerable CPE surface, references) + CISA KEV catalog status + FIRST EPSS score/percentile, then a machine-formatted risk brief from those attested facts only. Keyless public sources (NVD/CISA/FIRST); $1.00 (moat product #4).","url":"https://api.exo-trust.com/execute/cve_brief","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"cve":{"type":"string","description":"CVE id, e.g. CVE-2021-44228 (CVE-YYYY-NNNN)."},"product":{"type":"string","description":"Vendor/product name search over the NVD keyword index, e.g. log4j — surfaces the most recently published matches; use 'cve' for the full risk brief."}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_kRvWV0ScqhvGLeEUJh3bH","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches a full NVD 2.0 CVE record (CVSS metrics, CWE weaknesses, CPE surface, references) enriched with CISA KEV catalog status and FIRST EPSS exploit probability score, then synthesizes a machine-formatted risk brief.","exampleAgentPrompt":"Pull the full risk brief for CVE-2021-44228 — I need the CVSS scores, CWE weaknesses, whether it's in the CISA KEV catalog, and the EPSS exploit probability.","exampleUseCases":[{"title":"Log4Shell severity triage","prompt":"I need a complete risk brief for CVE-2021-44228 — give me the CVSS v3 score, the EPSS percentile, whether it's in the CISA Known Exploited Vulnerabilities list, and a summary of the vulnerable CPE surface."},{"title":"Product vulnerability discovery","prompt":"Search NVD for the most recent vulnerabilities related to OpenSSL and give me the CVE IDs and their severity scores so I can triage which ones to patch first."},{"title":"Security report enrichment","prompt":"I'm writing a security advisory and need the full NVD record for CVE-2023-44487 — CVSS metrics across all versions, the CWE classification, CISA KEV status, and EPSS score with percentile."}],"resultDescription":"Returns the attested NVD 2.0 record (description, CVSS v2/v3.x/v4.0 base scores and vectors, CWE weakness identifiers, vulnerable CPE configurations, and reference links), the CISA KEV catalog membership status, the FIRST EPSS probability score and percentile, and a machine-formatted risk brief synthesized from those sources only.","failureModes":["CVE ID not found in NVD — returns empty or not-found response","Malformed CVE ID format — input validation error","Product name search returns no matches — empty results","NVD/CISA/FIRST upstream APIs unavailable — service error","Payment not confirmed — 402 Payment Required before processing"],"whenToPreferThis":"Choose this endpoint when you need a single, consolidated vulnerability risk brief that combines NVD authoritative data, CISA active exploitation status, and EPSS statistical exploit likelihood in one call. It is ideal for security triage workflows, compliance reporting, and agent-driven patch prioritization where you need attestable, multi-source enrichment rather than raw NVD data alone.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:34:08.177Z","isFirstParty":false}