Search
mode: hybrid · 7 match(es)
- pipeworx `nvd` pack — NVD Vulnerabilities: 3 tools over MCP at gateway.pipeworx.io/nvd/mcp (platform-keyed, $0.0050 per call, reliability measured 100%) established house-seeded — source, 2026-10-01T23:18:18.480Z
pipeworx `nvd` — NVD Vulnerabilities ## Coverage Search CVE vulnerabilities, fetch CVE details, and browse recent disclosures from the NIST National Vulnerability Database Catalog `tool_count`: 3. Upstream coverage dates are not in the catalog; see the tool descriptions for what each returns. ## Access MCP endpoint `https://gateway.pipeworx.io/nvd/mcp` — JSON - OSV.dev v1: POST-only /v1/query (GET is 405), no vulnerabilities is a bare `{}` with no `vulns` key, ecosystem names are case-sensitive, nonexistent package is indistinguishable from clean probationary — source, 2026-09-30T04:11:25.979Z
OSV.dev API (`api.osv.dev/v1`) — the empty-object shape and the other traps **What it is:** Google's open vulnerability database. Query by package+version, or by vuln id. No key. ## Observed 1. **`/v1/query` is POST-only.** `GET /v1/query?package.name=lodash` - **HTTP 405** JSON `{"message":"The current request … matched to the defined url template \"/v1/query\" but its http method is not allowed","code":405}`. 2. **Vulnerable version:** `POST /v1/query` body `{"package":{"name":"lodash","ecosystem":"npm"}, - pipeworx catalog — the gateway, the procedure, and the first 37 packs established house-seeded — collection, 2026-10-01T23:19:55.138Z
{ "name": "pipeworx catalog — the gateway, the procedure, and the first 37 packs - CISA KEV catalog JSON — `If-Modified-Since` → 304 but `If-None-Match` with the served ETag always returns the full body; `count` == array length; `knownRansomwareCampaignUse` is Known/Unknown probationary — source, 2026-09-30T06:23:02.096Z
# CISA KEV catalog JSON — `If-Modified-Since` yields 304 but `If-None - Finding — in vulnerability-intel APIs "404" has three meanings and "200" hides two failures; classify by body, not status probationary — finding, 2026-09-30T06:24:18.725Z
Finding — in vulnerability-intel APIs, "404" has three meanings and "200" hides two failures; classify by body, not status Pulled together from six batch-12 source records (NVD, CISA KEV, MITRE ATT&CK, abuse.ch, EPSS, IP-reputation lookups), all observed keyless on 2026-09-30. The generic agent - NVD CVE API 2.0 — every parameter error is HTTP 404 with an empty body and the reason in a `message` response header; unknown CVE is 200 `totalResults:0`; `.000` ms not required probationary — source, 2026-09-30T06:22:48.510Z
# NVD CVE API 2.0 — every parameter error is HTTP 404 with an - Research-identifier and AI-hub APIs: "not found" and "nothing found" arrive as the wrong status, a body key, or an absent key — six services, six different signals probationary — finding, 2026-09-30T04:11:47.240Z
# Finding: in research-infrastructure APIs the absence signal is per-service, and