Vulnerability Intelligence and CVE Prioritization API

API ID 13270

Look up any CVE or software dependency and get a P1-P5 patch-priority verdict fusing CVSS (NVD), actively-exploited status (CISA KEV) and exploit probability (FIRST EPSS). Includes OSV dependency scanning across PyPI, npm, Go, Maven and more. Informational prioritisation only.

100% uptime 483 ms avg response

API Documentation

Endpoints

Request
Look up a single CVE and get CVSS (NVD), actively-exploited status (CISA KEV), exploit probability (FIRST EPSS) and a P1-P5 priority verdict in one response.
Endpoint ID: 27344
GET https://docs.zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27344/cve+lookup+and+priority+verdict
INPUT PARAMETERS

CVE lookup and priority verdict — Endpoint Features

Object Description
id Required Required. The CVE identifier to look up, e.g. CVE-2021-44228.

Free test requests remaining: 3 of 3.


INPUT PARAMETERS

id
API EXAMPLE RESPONSE
JSON
{
    "id": "CVE-2021-44228",
    "description": "Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.",
    "published": "2021-12-10T10:15:09.143",
    "last_modified": "2026-06-17T04:12:05.460",
    "status": "Analyzed",
    "cwe": [
        "CWE-20",
        "CWE-400",
        "CWE-502",
        "CWE-917"
    ],
    "products": [
        "siemens:6bk1602-0aa12-0tp0_firmware",
        "siemens:6bk1602-0aa12-0tp0",
        "siemens:6bk1602-0aa22-0tp0_firmware",
        "siemens:6bk1602-0aa22-0tp0",
        "siemens:6bk1602-0aa32-0tp0_firmware",
        "siemens:6bk1602-0aa32-0tp0",
        "siemens:6bk1602-0aa42-0tp0_firmware",
        "siemens:6bk1602-0aa42-0tp0",
        "siemens:6bk1602-0aa52-0tp0_firmware",
        "siemens:6bk1602-0aa52-0tp0",
        "apache:log4j",
        "siemens:sppa-t3000_ses3000_firmware",
        "siemens:sppa-t3000_ses3000",
        "siemens:capital",
        "siemens:comos",
        "siemens:desigo_cc_advanced_reports",
        "siemens:desigo_cc_info_center",
        "siemens:e-car_operation_center",
        "siemens:energy_engage",
        "siemens:energyip"
    ],
    "cpe_ranges": [
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa12-0tp0_firmware",
            "vulnerable": true,
            "versionEndExcluding": "2.7.0"
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa12-0tp0",
            "vulnerable": false
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa22-0tp0_firmware",
            "vulnerable": true,
            "versionEndExcluding": "2.7.0"
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa22-0tp0",
            "vulnerable": false
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa32-0tp0_firmware",
            "vulnerable": true,
            "versionEndExcluding": "2.7.0"
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa32-0tp0",
            "vulnerable": false
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa42-0tp0_firmware",
            "vulnerable": true,
            "versionEndExcluding": "2.7.0"
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa42-0tp0",
            "vulnerable": false
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa52-0tp0_firmware",
            "vulnerable": true,
            "versionEndExcluding": "2.7.0"
        },
        {
            "vendor": "siemens",
            "product": "6bk1602-0aa52-0tp0",
            "vulnerable": false
        },
        {
            "vendor": "apache",
            "product": "log4j",
            "vulnerable": true,
            "versionStartIncluding": "2.0.1",
            "versionEndExcluding": "2.3.1"
        },
        {
            "vendor": "apache",
            "product": "log4j",
            "vulnerable": true,
            "versionStartIncluding": "2.4.0",
            "versionEndExcluding": "2.12.2"
        },
        {
            "vendor": "apache",
            "product": "log4j",
            "vulnerable": true,
            "versionStartIncluding": "2.13.0",
            "versionEndExcluding": "2.15.0"
        },
        {
            "vendor": "apache",
            "product": "log4j",
            "vulnerable": true,
            "version": "2.0"
        },
        {
            "vendor": "apache",
            "product": "log4j",
            "vulnerable": true,
            "version": "2.0"
        },
        {
            "vendor": "apache",
            "product": "log4j",
            "vulnerable": true,
            "version": "2.0"
        },
        {
            "vendor": "apache",
            "product": "log4j",
            "vulnerable": true,
            "version": "2.0"
        },
        {
            "vendor": "siemens",
            "product": "sppa-t3000_ses3000_firmware",
            "vulnerable": true
        },
        {
            "vendor": "siemens",
            "product": "sppa-t3000_ses3000",
            "vulnerable": false
        },
        {
            "vendor": "siemens",
            "product": "capital",
            "vulnerable": true,
            "versionEndExcluding": "2019.1"
        },
        {
            "vendor": "siemens",
            "product": "capital",
            "vulnerable": true,
            "version": "2019.1"
        },
        {
            "vendor": "siemens",
            "product": "capital",
            "vulnerable": true,
            "version": "2019.1"
        },
        {
            "vendor": "siemens",
            "product": "comos",
            "vulnerable": true,
            "versionEndExcluding": "10.4.2"
        },
        {
            "vendor": "siemens",
            "product": "desigo_cc_advanced_reports",
            "vulnerable": true,
            "version": "3.0"
        },
        {
            "vendor": "siemens",
            "product": "desigo_cc_advanced_reports",
            "vulnerable": true,
            "version": "4.0"
        },
        {
            "vendor": "siemens",
            "product": "desigo_cc_advanced_reports",
            "vulnerable": true,
            "version": "4.1"
        },
        {
            "vendor": "siemens",
            "product": "desigo_cc_advanced_reports",
            "vulnerable": true,
            "version": "4.2"
        },
        {
            "vendor": "siemens",
            "product": "desigo_cc_advanced_reports",
            "vulnerable": true,
            "version": "5.0"
        },
        {
            "vendor": "siemens",
            "product": "desigo_cc_advanced_reports",
            "vulnerable": true,
            "version": "5.1"
        },
        {
            "vendor": "siemens",
            "product": "desigo_cc_info_center",
            "vulnerable": true,
            "version": "5.0"
        },
        {
            "vendor": "siemens",
            "product": "desigo_cc_info_center",
            "vulnerable": true,
            "version": "5.1"
        },
        {
            "vendor": "siemens",
            "product": "e-car_operation_center",
            "vulnerable": true,
            "versionEndExcluding": "2021-12-13"
        },
        {
            "vendor": "siemens",
            "product": "energy_engage",
            "vulnerable": true,
            "version": "3.1"
        },
        {
            "vendor": "siemens",
            "product": "energyip",
            "vulnerable": true,
            "version": "8.5"
        },
        {
            "vendor": "siemens",
            "product": "energyip",
            "vulnerable": true,
            "version": "8.6"
        },
        {
            "vendor": "siemens",
            "product": "energyip",
            "vulnerable": true,
            "version": "8.7"
        },
        {
            "vendor": "siemens",
            "product": "energyip",
            "vulnerable": true,
            "version": "9.0"
        },
        {
            "vendor": "siemens",
            "product": "energyip_prepay",
            "vulnerable": true,
            "versionEndExcluding": "3.8.0.12"
        },
        {
            "vendor": "siemens",
            "product": "gma-manager",
            "vulnerable": true,
            "versionEndExcluding": "8.6.2j-398"
        },
        {
            "vendor": "siemens",
            "product": "head-end_system_universal_device_integration_system",
            "vulnerable": true
        },
        {
            "vendor": "siemens",
            "product": "industrial_edge_management",
            "vulnerable": true
        },
        {
            "vendor": "siemens",
            "product": "industrial_edge_management_hub",
            "vulnerable": true,
            "versionEndExcluding": "2021-12-13"
        },
        {
            "vendor": "siemens",
            "product": "logo\\!_soft_comfort",
            "vulnerable": true
        },
        {
            "vendor": "siemens",
            "product": "mendix",
            "vulnerable": true
        },
        {
            "vendor": "siemens",
            "product": "mindsphere",
            "vulnerable": true,
            "versionEndExcluding": "2021-12-16"
        },
        {
            "vendor": "siemens",
            "product": "navigator",
            "vulnerable": true,
            "versionEndExcluding": "2021-12-13"
        },
        {
            "vendor": "siemens",
            "product": "nx",
            "vulnerable": true
        },
        {
            "vendor": "siemens",
            "product": "opcenter_intelligence",
            "vulnerable": true,
            "versionStartIncluding": "3.2"
        }
    ],
    "_note": "Response truncated for documentation purposes"
}
CVE lookup and priority verdict — CODE SNIPPETS

curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27344/cve+lookup+and+priority+verdict?id=CVE-2021-44228' --header 'Authorization: Bearer YOUR_API_KEY' 


    
Request
Search CVEs by keyword, CPE or severity (live NVD), each enriched with KEV, EPSS and a priority verdict. Provide at least one of q, severity or cpe.
Endpoint ID: 27345
GET https://docs.zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27345/search+cves
INPUT PARAMETERS

Search CVEs — Endpoint Features

Object Description
q Optional Optional. Keyword search over CVE text.
severity Optional Optional. Filter by LOW, MEDIUM, HIGH or CRITICAL.
cpe Optional Optional. Exact CPE name, e.g. cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
limit Optional Optional. Max results, up to 100.
weaponized Optional Boolean filtering weaponized vulnerabilities.

Free test requests remaining: 3 of 3.


INPUT PARAMETERS

q
severity
cpe
limit
weaponized
API EXAMPLE RESPONSE
JSON
{
    "total": 7,
    "count": 3,
    "weaponized": true,
    "results": [
        {
            "id": "CVE-2017-5645",
            "description": "In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.",
            "published": "2017-04-17T21:59:00.373",
            "last_modified": "2026-06-17T01:20:55.043",
            "status": "Modified",
            "cwe": [
                "CWE-502"
            ],
            "products": [
                "apache:log4j",
                "netapp:oncommand_api_services",
                "netapp:oncommand_insight",
                "netapp:oncommand_workflow_automation",
                "netapp:service_level_manager",
                "netapp:snapcenter",
                "netapp:storage_automation_store",
                "redhat:fuse",
                "redhat:enterprise_linux",
                "redhat:enterprise_linux_desktop",
                "redhat:enterprise_linux_server",
                "redhat:enterprise_linux_server_aus",
                "redhat:enterprise_linux_server_eus",
                "redhat:enterprise_linux_server_tus",
                "redhat:enterprise_linux_workstation",
                "oracle:api_gateway",
                "oracle:application_testing_suite",
                "oracle:autovue_vuelink_integration",
                "oracle:banking_platform",
                "oracle:bi_publisher"
            ],
            "cpe_ranges": [
                {
                    "vendor": "apache",
                    "product": "log4j",
                    "vulnerable": true,
                    "versionStartIncluding": "2.0",
                    "versionEndExcluding": "2.8.2"
                },
                {
                    "vendor": "netapp",
                    "product": "oncommand_api_services",
                    "vulnerable": true
                },
                {
                    "vendor": "netapp",
                    "product": "oncommand_insight",
                    "vulnerable": true
                },
                {
                    "vendor": "netapp",
                    "product": "oncommand_workflow_automation",
                    "vulnerable": true
                },
                {
                    "vendor": "netapp",
                    "product": "service_level_manager",
                    "vulnerable": true
                },
                {
                    "vendor": "netapp",
                    "product": "snapcenter",
                    "vulnerable": true
                },
                {
                    "vendor": "netapp",
                    "product": "storage_automation_store",
                    "vulnerable": true
                },
                {
                    "vendor": "redhat",
                    "product": "fuse",
                    "vulnerable": true,
                    "version": "1.0"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux",
                    "vulnerable": true,
                    "version": "6.0"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux",
                    "vulnerable": true,
                    "version": "6.7"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux",
                    "vulnerable": true,
                    "version": "7.0"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux",
                    "vulnerable": true,
                    "version": "7.3"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux",
                    "vulnerable": true,
                    "version": "7.4"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux",
                    "vulnerable": true,
                    "version": "7.5"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux",
                    "vulnerable": true,
                    "version": "7.6"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux_desktop",
                    "vulnerable": true,
                    "version": "7.0"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux_server",
                    "vulnerable": true,
                    "version": "7.0"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux_server_aus",
                    "vulnerable": true,
                    "version": "7.4"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux_server_aus",
                    "vulnerable": true,
                    "version": "7.6"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux_server_eus",
                    "vulnerable": true,
                    "version": "7.4"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux_server_eus",
                    "vulnerable": true,
                    "version": "7.5"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux_server_eus",
                    "vulnerable": true,
                    "version": "7.6"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux_server_tus",
                    "vulnerable": true,
                    "version": "7.4"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux_server_tus",
                    "vulnerable": true,
                    "version": "7.6"
                },
                {
                    "vendor": "redhat",
                    "product": "enterprise_linux_workstation",
                    "vulnerable": true,
                    "version": "7.0"
                },
                {
                    "vendor": "oracle",
                    "product": "api_gateway",
                    "vulnerable": true,
                    "version": "11.1.2.4.0"
                },
                {
                    "vendor": "oracle",
                    "product": "application_testing_suite",
                    "vulnerable": true,
                    "version": "13.3.0.1"
                },
                {
                    "vendor": "oracle",
                    "product": "autovue_vuelink_integration",
                    "vulnerable": true,
                    "version": "21.0.0"
                },
                {
                    "vendor": "oracle",
                    "product": "autovue_vuelink_integration",
                    "vulnerable": true,
                    "version": "21.0.1"
                },
                {
                    "vendor": "oracle",
                    "product": "banking_platform",
                    "vulnerable": true,
                    "version": "2.6.0"
                },
                {
                    "vendor": "oracle",
                    "product": "banking_platform",
                    "vulnerable": true,
                    "version": "2.6.1"
                },
                {
                    "vendor": "oracle",
                    "product": "banking_platform",
                    "vulnerable": true,
                    "version": "2.6.2"
                },
                {
                    "vendor": "oracle",
                    "product": "bi_publisher",
                    "vulnerable": true,
                    "version": "11.1.1.7.0"
                },
                {
                    "vendor": "oracle",
                    "product": "bi_publisher",
                    "vulnerable": true,
                    "version": "11.1.1.9.0"
                },
                {
                    "vendor": "oracle",
                    "product": "bi_publisher",
                    "vulnerable": true,
                    "version": "12.2.1.3.0"
                },
                {
                    "vendor": "oracle",
                    "product": "bi_publisher",
                    "vulnerable": true,
                    "version": "12.2.1.4.0"
                },
                {
                    "vendor": "oracle",
                    "product": "communications_converged_application_server_-_service_controller",
                    "vulnerable": true,
                    "version": "6.1"
                },
                {
                    "vendor": "oracle",
                    "product": "communications_instant_messaging_server",
                    "vulnerable": true,
                    "version": "10.0.1.3.0"
                }]}],"_note":"Response truncated for documentation purposes"}
Search CVEs — CODE SNIPPETS

curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27345/search+cves?q=log4j&severity=CRITICAL&limit=20&weaponized=true' --header 'Authorization: Bearer YOUR_API_KEY' 


    
Request
Return CVEs published within a look-back window, each enriched with the same CVSS, KEV and EPSS priority verdict. Useful for a monitoring feed.
Endpoint ID: 27346
GET https://docs.zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27346/recently+published+cves
INPUT PARAMETERS

Recently published CVEs — Endpoint Features

Object Description
days Optional Optional. Look-back window in days, up to 120 (default 7).
severity Optional Optional. Filter by LOW, MEDIUM, HIGH or CRITICAL.
limit Optional Optional. Max results, up to 100.
weaponized Optional Boolean filtering weaponized vulnerabilities.

Free test requests remaining: 3 of 3.


INPUT PARAMETERS

days
severity
limit
weaponized
API EXAMPLE RESPONSE
JSON
{
    "days": 7,
    "total": 38,
    "count": 1,
    "weaponized": true,
    "results": [
        {
            "id": "CVE-2026-44596",
            "description": "Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform unlimited password-guessing attempts against any user account, significantly increasing the risk of successful brute-force attacks. This issue is fixed in versions 5.12.7 and 5.13.0.",
            "published": "2026-07-16T17:16:55.880",
            "last_modified": "2026-07-17T18:44:26.383",
            "status": "Analyzed",
            "cwe": [
                "CWE-307"
            ],
            "products": [
                "spaceapplications:yamcs"
            ],
            "references": [
                "https://github.com/yamcs/yamcs/commit/309218c651680f79df11a8d0f8628f7033f98a83",
                "https://github.com/yamcs/yamcs/commit/64392df531fbcbc65f19ee5724c4c23d289f49fc",
                "https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7",
                "https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0",
                "https://github.com/yamcs/yamcs/security/advisories/GHSA-w5r6-mcgq-7pq4",
                "https://github.com/yamcs/yamcs/security/advisories/GHSA-w5r6-mcgq-7pq4"
            ],
            "exploit_available": true,
            "exploit_refs": [
                "https://github.com/yamcs/yamcs/security/advisories/GHSA-w5r6-mcgq-7pq4",
                "https://github.com/yamcs/yamcs/security/advisories/GHSA-w5r6-mcgq-7pq4"
            ],
            "has_patch": true,
            "has_mitigation": false,
            "cvss": 6.5,
            "severity": "MEDIUM",
            "cvss_version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "epss": 0.0177,
            "epss_percentile": 0.75706,
            "kev": false,
            "exploitation": {
                "weaponized": true,
                "metasploit": false,
                "nuclei": false,
                "exploit_db": true,
                "public_exploit": true,
                "kev": false,
                "exploitdb_ids": [
                    "52605"
                ]
            },
            "priority": {
                "tier": "P2",
                "label": "Urgent",
                "reason": "A working public exploit exists (Metasploit/Nuclei/Exploit-DB); exploit probability 2%.",
                "score": 39
            }
        }
    ]
}
Recently published CVEs — CODE SNIPPETS

curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27346/recently+published+cves?days=7&severity=CRITICAL&limit=1&weaponized=true' --header 'Authorization: Bearer YOUR_API_KEY' 


    
Request
Return known vulnerabilities affecting a software package (optionally a specific version) via OSV, each cross-enriched with EPSS and KEV and a priority verdict, plus the versions that fix it.
Endpoint ID: 27347
GET https://docs.zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27347/package+and+dependency+vulnerabilities
INPUT PARAMETERS

Package and dependency vulnerabilities — Endpoint Features

Object Description
ecosystem Required PyPI, npm, Go, Maven, RubyGems, crates.io, NuGet or Packagist.
name Required The package name.
version Optional Optional. Version to check; omit for all known vulnerabilities.

Free test requests remaining: 3 of 3.


INPUT PARAMETERS

ecosystem
name
version
API EXAMPLE RESPONSE
JSON
{
    "ecosystem": "PyPI",
    "package": "django",
    "version": "3.0",
    "vulnerable": true,
    "vuln_count": 31,
    "highest_priority": "P2",
    "vulnerabilities": [
        {
            "id": "GHSA-frmv-pr5f-9mcr",
            "cve": "CVE-2025-64459",
            "aliases": [
                "BIT-django-2025-64459",
                "CVE-2025-64459",
                "PYSEC-2025-108"
            ],
            "summary": "Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.",
            "published": "2025-11-05T15:31:07Z",
            "modified": "2026-06-05T14:45:52.053173828Z",
            "fixed_versions": [
                "4.2.26",
                "5.1.14",
                "5.2.8"
            ],
            "references": [
                "https://nvd.nist.gov/vuln/detail/CVE-2025-64459",
                "https://github.com/django/django/commit/06dd38324ac3d60d83d9f3adabf0dcdf423d2a85",
                "https://github.com/django/django/commit/59ae82e67053d281ff4562a24bbba21299f0a7d4",
                "https://github.com/django/django/commit/6703f364d767e949c5b0e4016433ef75063b4f9b",
                "https://github.com/django/django/commit/72d2c87431f2ae0431d65d0ec792047f078c8241",
                "https://docs.djangoproject.com/en/dev/releases/security",
                "https://github.com/django/django",
                "https://github.com/omarkurt/django-connector-CVE-2025-64459-testbed"
            ],
            "cvss": 9.1,
            "severity": "CRITICAL",
            "cvss_version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "epss": 0.19396,
            "epss_percentile": 0.9706,
            "kev": false,
            "priority": {
                "tier": "P2",
                "label": "Urgent",
                "reason": "Critical severity (CVSS 9.1); exploit probability 19%."
            }
        },
        {
            "id": "GHSA-hmr4-m2h5-33qx",
            "cve": "CVE-2020-7471",
            "aliases": [
                "BIT-django-2020-7471",
                "CVE-2020-7471",
                "PYSEC-2020-35"
            ],
            "summary": "SQL injection in Django",
            "published": "2020-02-11T21:03:20Z",
            "modified": "2025-02-21T06:12:43.981276Z",
            "fixed_versions": [
                "1.11.28",
                "2.2.10",
                "3.0.3"
            ],
            "references": [
                "https://nvd.nist.gov/vuln/detail/CVE-2020-7471",
                "https://github.com/django/django/commit/001b0634cd309e372edb6d7d95d083d02b8e37bd",
                "https://github.com/django/django/commit/505826b469b16ab36693360da9e11fd13213421b",
                "https://github.com/django/django/commit/c67a368c16e4680b324b4f385398d638db4d8147",
                "https://github.com/django/django/commit/eb31d845323618d688ad429479c6dda973056136",
                "https://www.openwall.com/lists/oss-security/2020/02/03/1",
                "https://www.djangoproject.com/weblog/2020/feb/03/security-releases",
                "https://www.debian.org/security/2020/dsa-4629"
            ],
            "cvss": 9.8,
            "severity": "CRITICAL",
            "cvss_version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "epss": 0.65336,
            "epss_percentile": 0.99173,
            "kev": false,
            "priority": {
                "tier": "P2",
                "label": "Urgent",
                "reason": "High exploit probability (65%) though not yet on KEV."
            }
        },
        {
            "id": "GHSA-vfq6-hq5r-27r6",
            "cve": "CVE-2019-19844",
            "aliases": [
                "CVE-2019-19844",
                "PYSEC-2019-16"
            ],
            "summary": "Django Potential account hijack via password reset form",
            "published": "2020-01-16T22:35:12Z",
            "modified": "2024-09-20T15:24:05.816291Z",
            "fixed_versions": [
                "1.11.27",
                "2.2.9",
                "3.0.1"
            ],
            "references": [
                "https://nvd.nist.gov/vuln/detail/CVE-2019-19844",
                "https://github.com/django/django/commit/302a4ff1e8b1c798aab97673909c7a3dfda42c26",
                "https://github.com/django/django/commit/4d334bea06cac63dc1272abcec545b85136cca0e",
                "https://github.com/django/django/commit/5b1fbcef7a8bec991ebe7b2a18b5d5a95d72cb70",
                "https://github.com/django/django/commit/f4cff43bf921fcea6a29b726eb66767f67753fa2",
                "https://www.djangoproject.com/weblog/2019/dec/18/security-releases",
                "https://www.debian.org/security/2020/dsa-4598",
                "https://usn.ubuntu.com/4224-1"
            ],
            "cvss": 9.8,
            "severity": "CRITICAL",
            "cvss_version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "epss": 0.3481,
            "epss_percentile": 0.98255,
            "kev": false,
            "priority": {
                "tier": "P2",
                "label": "Urgent",
                "reason": "Critical severity (CVSS 9.8); exploit probability 35%."
            }
        },
        {
            "id": "GHSA-xpfp-f569-q3p2",
            "cve": "CVE-2021-35042",
            "aliases": [
                "BIT-django-2021-35042",
                "CVE-2021-35042",
                "PYSEC-2021-109"
            ],
            "summary": "SQL Injection in Django",
            "published": "2021-09-22T17:34:49Z",
            "modified": "2025-02-21T05:30:56.014475Z",
            "fixed_versions": [
                "3.1.13",
                "3.2.5"
            ],
            "references": [
                "https://nvd.nist.gov/vuln/detail/CVE-2021-35042",
                "https://github.com/django/django/commit/0bd57a879a0d54920bb9038a732645fb917040e9",
                "https://github.com/django/django/commit/a34a5f724c5d5adb2109374ba3989ebb7b11f81f",
                "https://github.com/django/django/commit/dae83a24519d6f284c74414e0b81d64d9b5a0db4",
                "https://docs.djangoproject.com/en/3.2/releases/security",
                "https://github.com/advisories/GHSA-xpfp-f569-q3p2",
                "https://github.com/django/django",
                "https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2021-109.yaml"
            ],
            "cvss": 9.8,
            "severity": "CRITICAL",
            "cvss_version": "3.1",
            "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "epss": 0.44369,
            "epss_percentile": 0.98627,
            "kev": false,
            "priority": {
                "tier": "P2",
                "label": "Urgent",
                "reason": "Critical severity (CVSS 9.8); exploit probability 44%."
            }
        },
        {
            "id": "PYSEC-2020-35",
            "cve": "CVE-2020-7471",
            "aliases": [
                "BIT-django-2020-7471",
                "CVE-2020-7471",
                "GHSA-hmr4-m2h5-33qx"
            ],
            "summary": null,
            "published": "2020-02-03T12:15:00Z",
            "modified": "2023-12-06T01:00:38.606116Z",
            "fixed_versions": [
                "1.11.28",
                "2.2.10",
                "3.0.3",
                "eb31d845323618d688ad429479c6dda973056136"
            ],
            "references": [
                "https://www.openwall.com/lists/oss-security/2020/02/03/1",
                "https://docs.djangoproject.com/en/3.0/releases/security/",
                "https://groups.google.com/forum/#!topic/django-announce/X45S86X5bZI",
                "https://www.djangoproject.com/weblog/2020/feb/03/security-releases/",
                "http://www.openwall.com/lists/oss-security/2020/02/03/1",
                "https://github.com/django/django/commit/eb31d845323618d688ad429479c6dda973056136",
                "https://usn.ubuntu.com/4264-1/",
                "https://seclists.org/bugtraq/2020/Feb/30"
            ],
            "cvss": null,
            "severity": null,
            "cvss_version": null,
            "vector": null,
            "epss": 0.65336,
            "epss_percentile": 0.99173,
            "kev": false,
            "priority": {
                "tier": "P2",
                "label": "Urgent",
                "reason": "High exploit probability (65%) though not yet on KEV."
            }
        },
        {
            "id": "GHSA-3gh2-xw74-jmcw",
            "cve": "CVE-2020-9402",
            "aliases": [
                "BIT-django-2020-9402",
                "CVE-2020-9402",
                "PYSEC-2020-36"
            ],
            "summary": "SQL injection in Django",
            "published": "2020-06-05T14:52:07Z",
            "modified": "2026-07-09T16:56:16.012032693Z",
            "fixed_versions": [
                "1.11.29",
                "2.2.11",
                "3.0.4"
            ],
            "references": [
                "https://nvd.nist.gov/vuln/detail/CVE-2020-9402",
                "https://github.com/django/django/commit/6695d29b1c1ce979725816295a26ecc64ae0e927",
                "https://www.djangoproject.com/weblog/2020/mar/04/security-releases",
                "https://www.debian.org/security/2020/dsa-4705",
                "https://usn.ubuntu.com/4296-1"
            ]
        }
    ],
    "_note": "Response truncated for documentation purposes"
}
Package and dependency vulnerabilities — CODE SNIPPETS

curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27347/package+and+dependency+vulnerabilities?ecosystem=PyPI&name=django&version=3.0' --header 'Authorization: Bearer YOUR_API_KEY' 


    
Request
Return a single OSV advisory (GitHub Security Advisory, PYSEC, or a CVE) with the same EPSS and KEV enrichment and priority verdict.
Endpoint ID: 27348
GET https://docs.zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27348/osv+and+ghsa+advisory+by+id
INPUT PARAMETERS

OSV and GHSA advisory by id — Endpoint Features

Object Description
id Required Required. OSV id such as GHSA, PYSEC, or a CVE.

Free test requests remaining: 3 of 3.


INPUT PARAMETERS

id
API EXAMPLE RESPONSE
JSON
{
    "id": "GHSA-jfh8-c2jp-5v3q",
    "cve": "CVE-2021-44228",
    "aliases": [
        "CVE-2021-44228"
    ],
    "summary": "Remote code injection in Log4j",
    "published": "2021-12-10T00:40:56Z",
    "modified": "2025-10-22T19:37:02.616807Z",
    "fixed_versions": [],
    "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
        "https://github.com/apache/logging-log4j2/pull/608",
        "https://github.com/github/advisory-database/pull/5501",
        "https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf",
        "https://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html",
        "https://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html",
        "https://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html",
        "https://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html"
    ],
    "cvss": 10,
    "severity": "CRITICAL",
    "cvss_version": "3.1",
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H",
    "epss": 0.99999,
    "epss_percentile": 1,
    "kev": true,
    "kev_details": {
        "date_added": "2021-12-10",
        "due_date": "2021-12-24",
        "ransomware": true,
        "required_action": "For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available."
    },
    "priority": {
        "tier": "P1",
        "label": "Patch now",
        "reason": "actively exploited in known ransomware campaigns; exploit probability 100%."
    }
}
OSV and GHSA advisory by id — CODE SNIPPETS

curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27348/osv+and+ghsa+advisory+by+id?id=GHSA-jfh8-c2jp-5v3q' --header 'Authorization: Bearer YOUR_API_KEY' 


    
Request
Return entries from the CISA Known Exploited Vulnerabilities catalog, EPSS-enriched, with optional vendor, product or ransomware filters.
Endpoint ID: 27349
GET https://docs.zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27349/cisa+kev+catalog
INPUT PARAMETERS

CISA KEV catalog — Endpoint Features

Object Description
vendor Optional Optional. Filter by vendor, e.g. Microsoft.
product Optional Optional. Filter by product.
ransomware Optional Optional. Set true to return only entries used in known ransomware campaigns.
limit Optional Optional. Max results, up to 500.

Free test requests remaining: 3 of 3.


INPUT PARAMETERS

vendor
product
ransomware
limit
API EXAMPLE RESPONSE
JSON
{
    "count": 50,
    "released": "2026-07-16",
    "total_kev": 1647,
    "results": [
        {
            "cve": "CVE-2026-35273",
            "vendor": "Oracle",
            "product": " PeopleSoft Enterprise PeopleTools",
            "name": "Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
            "date_added": "2026-06-12",
            "due_date": "2026-06-15",
            "ransomware": true,
            "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
            "short_description": "Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.",
            "epss": 0.9233,
            "epss_percentile": 0.99812
        },
        {
            "cve": "CVE-2026-50751",
            "vendor": "Check Point",
            "product": "Security Gateway",
            "name": "Check Point Security Gateway Improper Authentication Vulnerability",
            "date_added": "2026-06-08",
            "due_date": "2026-06-11",
            "ransomware": true,
            "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
            "short_description": "Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.",
            "epss": 0.70099,
            "epss_percentile": 0.99307
        },
        {
            "cve": "CVE-2026-48027",
            "vendor": "Nx",
            "product": "Nx Console",
            "name": "Nx Console Embedded Malicious Code Vulnerability",
            "date_added": "2026-05-27",
            "due_date": "2026-06-10",
            "ransomware": true,
            "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
            "short_description": "Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.",
            "epss": 0.0185,
            "epss_percentile": 0.76784
        },
        {
            "cve": "CVE-2026-45321",
            "vendor": "TanStack",
            "product": "TanStack",
            "name": "TanStack Unspecified Vulnerability",
            "date_added": "2026-05-27",
            "due_date": "2026-06-10",
            "ransomware": true,
            "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
            "short_description": "TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.",
            "epss": 0.02342,
            "epss_percentile": 0.81773
        },
        {
            "cve": "CVE-2026-41940",
            "vendor": "WebPros",
            "product": "cPanel & WHM and WP2 (WordPress Squared)",
            "name": "WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability",
            "date_added": "2026-04-30",
            "due_date": "2026-05-03",
            "ransomware": true,
            "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
            "short_description": "WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
            "epss": 0.981,
            "epss_percentile": 0.99907
        },
        {
            "cve": "CVE-2024-1708",
            "vendor": "ConnectWise",
            "product": "ScreenConnect",
            "name": "ConnectWise ScreenConnect Path Traversal Vulnerability",
            "date_added": "2026-04-28",
            "due_date": "2026-05-12",
            "ransomware": true,
            "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
            "short_description": "ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.",
            "epss": 0.87624,
            "epss_percentile": 0.99742
        },
        {
            "cve": "CVE-2024-57728",
            "vendor": "SimpleHelp ",
            "product": "SimpleHelp",
            "name": "SimpleHelp Path Traversal Vulnerability",
            "date_added": "2026-04-24",
            "due_date": "2026-05-08",
            "ransomware": true,
            "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
            "short_description": "SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.",
            "epss": 0.06982,
            "epss_percentile": 0.93433
        },
        {
            "cve": "CVE-2024-57726",
            "vendor": "SimpleHelp ",
            "product": "SimpleHelp",
            "name": "SimpleHelp Missing Authorization Vulnerability",
            "date_added": "2026-04-24",
            "due_date": "2026-05-08",
            "ransomware": true,
            "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
            "short_description": "SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.",
            "epss": 0.08632,
            "epss_percentile": 0.94514
        },
        {
            "cve": "CVE-2026-33825",
            "vendor": "Microsoft",
            "product": "Defender",
            "name": "Microsoft Defender Insufficient Granularity of Access Control Vulnerability",
            "date_added": "2026-04-22",
            "due_date": "2026-05-06",
            "ransomware": true,
            "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
            "short_description": "Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.",
            "epss": 0.06749,
            "epss_percentile": 0.93237
        },
        {
            "cve": "CVE-2023-27351",
            "vendor": "PaperCut",
            "product": "NG/MF",
            "name": "PaperCut NG/MF Improper Authentication Vulnerability",
            "date_added": "2026-04-20",
            "due_date": "2026-05-04",
            "ransomware": true,
            "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
            "short_description": "PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.",
            "epss": 0.77388,
            "epss_percentile": 0.99508
        },
        {
            "cve": "CVE-2024-27199",
            "vendor": "JetBrains",
            "product": "TeamCity",
            "name": "JetBrains TeamCity Relative Path Traversal Vulnerability",
            "date_added": "2026-04-20",
            "due_date": "2026-05-04",
            "ransomware": true,
            "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."
        }
    ],
    "_note": "Response truncated for documentation purposes"
}
CISA KEV catalog — CODE SNIPPETS

curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27349/cisa+kev+catalog?ransomware=true&limit=50' --header 'Authorization: Bearer YOUR_API_KEY' 


    
Request
Return the FIRST EPSS exploit-probability score and percentile for a single CVE.
Endpoint ID: 27350
GET https://docs.zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27350/epss+exploit-probability+score
INPUT PARAMETERS

EPSS exploit-probability score — Endpoint Features

Object Description
id Required The CVE identifier.

Free test requests remaining: 3 of 3.


INPUT PARAMETERS

id
API EXAMPLE RESPONSE
JSON
{
    "id": "CVE-2021-44228",
    "epss": 0.99999,
    "epss_percentile": 1,
    "score_date": "2026-07-21"
}
EPSS exploit-probability score — CODE SNIPPETS

curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27350/epss+exploit-probability+score?id=CVE-2021-44228' --header 'Authorization: Bearer YOUR_API_KEY' 


    
Request
Enrich and prioritise up to 100 CVEs in one call, returned sorted by the 0-100 fix-first score with a per-tier summary. Ideal for triaging scanner output or a CVE feed.
Endpoint ID: 27354
GET https://docs.zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27354/rank+a+list+of+cves+fix-first
INPUT PARAMETERS

Rank a list of CVEs fix-first — Endpoint Features

Object Description
ids Required Comma-separated CVE ids, up to 100. Results come back sorted by the fix-first score (highest first).
weaponized Optional Boolean to filter weaponized vulnerabilities.

Free test requests remaining: 3 of 3.


INPUT PARAMETERS

ids
weaponized
API EXAMPLE RESPONSE
JSON
{
    "requested": 3,
    "resolved": 3,
    "highest_priority": "P1",
    "by_tier": {
        "P1": 2,
        "P2": 1
    },
    "results": [
        {
            "id": "CVE-2021-44228",
            "description": "Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.",
            "published": "2021-12-10T10:15:09.143",
            "last_modified": "2026-06-17T04:12:05.460",
            "status": "Analyzed",
            "cwe": [
                "CWE-20",
                "CWE-400",
                "CWE-502",
                "CWE-917"
            ],
            "products": [
                "siemens:6bk1602-0aa12-0tp0_firmware",
                "siemens:6bk1602-0aa12-0tp0",
                "siemens:6bk1602-0aa22-0tp0_firmware",
                "siemens:6bk1602-0aa22-0tp0",
                "siemens:6bk1602-0aa32-0tp0_firmware",
                "siemens:6bk1602-0aa32-0tp0",
                "siemens:6bk1602-0aa42-0tp0_firmware",
                "siemens:6bk1602-0aa42-0tp0",
                "siemens:6bk1602-0aa52-0tp0_firmware",
                "siemens:6bk1602-0aa52-0tp0",
                "apache:log4j",
                "siemens:sppa-t3000_ses3000_firmware",
                "siemens:sppa-t3000_ses3000",
                "siemens:capital",
                "siemens:comos",
                "siemens:desigo_cc_advanced_reports",
                "siemens:desigo_cc_info_center",
                "siemens:e-car_operation_center",
                "siemens:energy_engage",
                "siemens:energyip"
            ],
            "cpe_ranges": [
                {
                    "vendor": "siemens",
                    "product": "6bk1602-0aa12-0tp0_firmware",
                    "vulnerable": true,
                    "versionEndExcluding": "2.7.0"
                },
                {
                    "vendor": "siemens",
                    "product": "6bk1602-0aa12-0tp0",
                    "vulnerable": false
                },
                {
                    "vendor": "siemens",
                    "product": "6bk1602-0aa22-0tp0_firmware",
                    "vulnerable": true,
                    "versionEndExcluding": "2.7.0"
                },
                {
                    "vendor": "siemens",
                    "product": "6bk1602-0aa22-0tp0",
                    "vulnerable": false
                },
                {
                    "vendor": "siemens",
                    "product": "6bk1602-0aa32-0tp0_firmware",
                    "vulnerable": true,
                    "versionEndExcluding": "2.7.0"
                },
                {
                    "vendor": "siemens",
                    "product": "6bk1602-0aa32-0tp0",
                    "vulnerable": false
                },
                {
                    "vendor": "siemens",
                    "product": "6bk1602-0aa42-0tp0_firmware",
                    "vulnerable": true,
                    "versionEndExcluding": "2.7.0"
                },
                {
                    "vendor": "siemens",
                    "product": "6bk1602-0aa42-0tp0",
                    "vulnerable": false
                },
                {
                    "vendor": "siemens",
                    "product": "6bk1602-0aa52-0tp0_firmware",
                    "vulnerable": true,
                    "versionEndExcluding": "2.7.0"
                },
                {
                    "vendor": "siemens",
                    "product": "6bk1602-0aa52-0tp0",
                    "vulnerable": false
                },
                {
                    "vendor": "apache",
                    "product": "log4j",
                    "vulnerable": true,
                    "versionStartIncluding": "2.0.1",
                    "versionEndExcluding": "2.3.1"
                },
                {
                    "vendor": "apache",
                    "product": "log4j",
                    "vulnerable": true,
                    "versionStartIncluding": "2.4.0",
                    "versionEndExcluding": "2.12.2"
                },
                {
                    "vendor": "apache",
                    "product": "log4j",
                    "vulnerable": true,
                    "versionStartIncluding": "2.13.0",
                    "versionEndExcluding": "2.15.0"
                },
                {
                    "vendor": "apache",
                    "product": "log4j",
                    "vulnerable": true,
                    "version": "2.0"
                },
                {
                    "vendor": "apache",
                    "product": "log4j",
                    "vulnerable": true,
                    "version": "2.0"
                },
                {
                    "vendor": "apache",
                    "product": "log4j",
                    "vulnerable": true,
                    "version": "2.0"
                },
                {
                    "vendor": "apache",
                    "product": "log4j",
                    "vulnerable": true,
                    "version": "2.0"
                },
                {
                    "vendor": "siemens",
                    "product": "sppa-t3000_ses3000_firmware",
                    "vulnerable": true
                },
                {
                    "vendor": "siemens",
                    "product": "sppa-t3000_ses3000",
                    "vulnerable": false
                },
                {
                    "vendor": "siemens",
                    "product": "capital",
                    "vulnerable": true,
                    "versionEndExcluding": "2019.1"
                },
                {
                    "vendor": "siemens",
                    "product": "capital",
                    "vulnerable": true,
                    "version": "2019.1"
                },
                {
                    "vendor": "siemens",
                    "product": "capital",
                    "vulnerable": true,
                    "version": "2019.1"
                },
                {
                    "vendor": "siemens",
                    "product": "comos",
                    "vulnerable": true,
                    "versionEndExcluding": "10.4.2"
                },
                {
                    "vendor": "siemens",
                    "product": "desigo_cc_advanced_reports",
                    "vulnerable": true,
                    "version": "3.0"
                },
                {
                    "vendor": "siemens",
                    "product": "desigo_cc_advanced_reports",
                    "vulnerable": true,
                    "version": "4.0"
                },
                {
                    "vendor": "siemens",
                    "product": "desigo_cc_advanced_reports",
                    "vulnerable": true,
                    "version": "4.1"
                },
                {
                    "vendor": "siemens",
                    "product": "desigo_cc_advanced_reports",
                    "vulnerable": true,
                    "version": "4.2"
                },
                {
                    "vendor": "siemens",
                    "product": "desigo_cc_advanced_reports",
                    "vulnerable": true,
                    "version": "5.0"
                },
                {
                    "vendor": "siemens",
                    "product": "desigo_cc_advanced_reports",
                    "vulnerable": true,
                    "version": "5.1"
                },
                {
                    "vendor": "siemens",
                    "product": "desigo_cc_info_center",
                    "vulnerable": true,
                    "version": "5.0"
                },
                {
                    "vendor": "siemens",
                    "product": "desigo_cc_info_center",
                    "vulnerable": true,
                    "version": "5.1"
                },
                {
                    "vendor": "siemens",
                    "product": "e-car_operation_center",
                    "vulnerable": true,
                    "versionEndExcluding": "2021-12-13"
                },
                {
                    "vendor": "siemens",
                    "product": "energy_engage",
                    "vulnerable": true,
                    "version": "3.1"
                },
                {
                    "vendor": "siemens",
                    "product": "energyip",
                    "vulnerable": true,
                    "version": "8.5"
                },
                {
                    "vendor": "siemens",
                    "product": "energyip",
                    "vulnerable": true
                }
            ]
        }
    ],
    "_note": "Response truncated for documentation purposes"
}
Rank a list of CVEs fix-first — CODE SNIPPETS

curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27354/rank+a+list+of+cves+fix-first?ids=CVE-2021-44228,CVE-2019-19844,CVE-2014-0160&weaponized=true' --header 'Authorization: Bearer YOUR_API_KEY' 


    
Request
CVEs newly added to the CISA KEV catalog within a look-back window, newest first, EPSS-enriched. A daily what-just-became-actively-exploited feed.
Endpoint ID: 27355
GET https://docs.zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27355/newly+exploited+cves+kev+feed
INPUT PARAMETERS

Newly exploited CVEs KEV feed — Endpoint Features

Object Description
days Optional Look-back window in days.
limit Optional Max results ( up to 500)

Free test requests remaining: 3 of 3.


INPUT PARAMETERS

days
limit
API EXAMPLE RESPONSE
JSON
{
    "days": 7,
    "cutoff": "2026-07-15",
    "count": 9,
    "results": [
        {
            "cve": "CVE-2026-60137",
            "vendor": "WordPress",
            "product": "Core",
            "name": "WordPress Core SQL Injection Vulnerability",
            "date_added": "2026-07-21",
            "due_date": "2026-08-04",
            "ransomware": false,
            "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
            "short_description": "WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.",
            "epss": 0.20395,
            "epss_percentile": 0.97219
        },
        {
            "cve": "CVE-2026-63030",
            "vendor": "WordPress",
            "product": "Core",
            "name": "WordPress Core Interpretation Conflict Vulnerability",
            "date_added": "2026-07-21",
            "due_date": "2026-07-24",
            "ransomware": false,
            "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
            "short_description": "WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.",
            "epss": 0.38599,
            "epss_percentile": 0.98425
        },
        {
            "cve": "CVE-2026-0770",
            "vendor": "Langflow",
            "product": "Langflow",
            "name": "Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability",
            "date_added": "2026-07-21",
            "due_date": "2026-07-24",
            "ransomware": false,
            "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
            "short_description": "Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. ",
            "epss": 0.54503,
            "epss_percentile": 0.98911
        },
        {
            "cve": "CVE-2021-27137",
            "vendor": "DD-WRT",
            "product": "DD-WRT",
            "name": "DD-WRT Stack-Based Buffer Overflow Vulnerability",
            "date_added": "2026-07-21",
            "due_date": "2026-07-24",
            "ransomware": false,
            "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
            "short_description": "DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.",
            "epss": 0.10809,
            "epss_percentile": 0.95377
        },
        {
            "cve": "CVE-2026-58644",
            "vendor": "Microsoft",
            "product": "SharePoint",
            "name": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
            "date_added": "2026-07-16",
            "due_date": "2026-07-19",
            "ransomware": false,
            "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
            "short_description": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.",
            "epss": 0.01465,
            "epss_percentile": 0.709
        },
        {
            "cve": "CVE-2026-25089",
            "vendor": "Fortinet",
            "product": "FortiSandbox",
            "name": "Fortinet FortiSandbox OS Command Injection Vulnerability",
            "date_added": "2026-07-16",
            "due_date": "2026-07-19",
            "ransomware": false,
            "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
            "short_description": "Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.",
            "epss": 0.36135,
            "epss_percentile": 0.98317
        },
        {
            "cve": "CVE-2026-39808",
            "vendor": "Fortinet",
            "product": "FortiSandbox",
            "name": "Fortinet FortiSandbox OS Command Injection Vulnerability",
            "date_added": "2026-07-16",
            "due_date": "2026-07-19",
            "ransomware": false,
            "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
            "short_description": "Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.",
            "epss": 0.84158,
            "epss_percentile": 0.99669
        },
        {
            "cve": "CVE-2026-46817",
            "vendor": "Oracle",
            "product": "E-Business Suite",
            "name": "Oracle E-Business Suite Improper Privilege Management Vulnerability",
            "date_added": "2026-07-15",
            "due_date": "2026-07-18",
            "ransomware": false,
            "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
            "short_description": "Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.",
            "epss": 0.01045,
            "epss_percentile": 0.6053
        },
        {
            "cve": "CVE-2023-4346",
            "vendor": "KNX Association",
            "product": "KNX Protocol Connection Authorization Option 1",
            "name": "KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability",
            "date_added": "2026-07-15",
            "due_date": "2026-07-29",
            "ransomware": false
        }
    ],
    "_note": "Response truncated for documentation purposes"
}
Newly exploited CVEs KEV feed — CODE SNIPPETS

curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27355/newly+exploited+cves+kev+feed?days=7&limit=100' --header 'Authorization: Bearer YOUR_API_KEY' 


    

API Access Key & Authentication

After signing up, every developer is assigned a personal API access key, a unique combination of letters and digits provided to access to our API endpoint. To authenticate with the Vulnerability Intelligence and CVE Prioritization API simply include your bearer token in the Authorization header.

Headers
Header Description
Authorization Required Should be Bearer access_key. See "Your API Access Key" above when you are subscribed.

No long-term commitment. Upgrade, downgrade, or cancel anytime. Free Trial includes up to 50 requests.

(Save 2 months with annual billing 🎉)

🚀 Enterprise Plan

Starts at
$ 10,000/Year


  • Custom Volume
  • Custom Rate Limit
  • Specialized Customer Support
  • Real-Time API Monitoring
zeiss-logo amazon-logo zoom-logo decathlon-logo

Trusted by leading companies

Overview

Look up any CVE or software dependency and get a P1-P5 patch-priority verdict fusing CVSS (NVD), actively-exploited status (CISA KEV) and exploit probability (FIRST EPSS). Includes OSV dependency scanning across PyPI, npm, Go, Maven and more. Informational prioritisation only.

Vulnerability Intelligence and CVE Prioritization API FAQs

Each endpoint returns detailed information about CVEs, including descriptions, published dates, CVSS scores, exploit probabilities, and priority verdicts. For example, the CVE lookup endpoint provides a comprehensive view of a specific CVE, while the package vulnerabilities endpoint lists known vulnerabilities for software packages.

Key fields include "id" (CVE identifier), "description" (vulnerability details), "published" (publication date), "status" (analysis status), "cwe" (Common Weakness Enumeration), and "priority" (P1-P5 verdict). These fields help assess the severity and relevance of vulnerabilities.

Parameters vary by endpoint. For the CVE search endpoint, you can use "q" (keyword), "severity" (severity level), or "cpe" (Common Platform Enumeration). The package vulnerabilities endpoint allows specifying a "package" and "version" to narrow results.

Response data is structured in JSON format, with top-level fields indicating the total count of results and an array of "results" containing individual CVE entries. Each entry includes detailed attributes like "description," "published," and "fixed_versions."

The API aggregates data from multiple trusted sources, including the National Vulnerability Database (NVD), CISA's Known Exploited Vulnerabilities (KEV) catalog, and FIRST's Exploit Prediction Scoring System (EPSS). This ensures comprehensive and reliable vulnerability information.

Typical use cases include vulnerability management, risk assessment, and prioritization of patching efforts. Security teams can use the API to identify critical vulnerabilities in their software dependencies and make informed decisions on remediation.

Users can analyze the returned data to prioritize vulnerabilities based on their severity and exploitability. For instance, by focusing on P1-P2 vulnerabilities with high EPSS scores, organizations can allocate resources efficiently to mitigate risks.

Data accuracy is maintained through regular updates from authoritative sources and automated checks for consistency. The API integrates multiple datasets, cross-referencing information to ensure that users receive the most accurate and up-to-date vulnerability data.

General FAQs

To obtain your API key, first sign in to your account and navigate to the API you want to use. From the API's Pricing section, choose a plan and complete the subscription process. Once subscribed, return to the API page and you will see your API Access Key displayed at the top of the documentation page. You can use this key to authenticate your requests.

You can’t switch APIs during the free trial. If you subscribe to a different API, your trial will end and the new subscription will start as a paid plan.

The free trial lasts for 7 days and allows you to make up to 50 API requests.

No, the free trial is available only once, so we recommend using it on the API that interests you the most. Most of our APIs offer a free trial, but some may not include this option.

Yes. If the API offers a free trial, you will see a "Free 7-Day Trial" option in its Pricing section. The trial lasts for 7 days and allows up to 50 API requests, enabling you to evaluate the API before subscribing to a paid plan.

Zyla API Hub is like a big store for APIs, where you can find thousands of them all in one place. We also offer dedicated support and real-time monitoring of all APIs. Once you sign up, you can pick and choose which APIs you want to use. Just remember, each API needs its own subscription. But if you subscribe to multiple ones, you'll use the same key for all of them, making things easier for you.

Prices are listed in USD (United States Dollar), EUR (Euro), CAD (Canadian Dollar), AUD (Australian Dollar), and GBP (British Pound). We accept all major debit and credit cards. Our payment system uses the latest security technology and is powered by Stripe, one of the world's most reliable payment companies. If you have any trouble paying by card, just contact us at [email protected]

Additionally, if you already have an active subscription in any of these currencies (USD, EUR, CAD, AUD, GBP), that currency will remain for subsequent subscriptions. You can change the currency at any time as long as you don't have any active subscriptions.
The local currency shown on the pricing page is based on the country of your IP address and is provided for reference only. The actual prices are in USD (United States Dollar). When you make a payment, the charge will appear on your card statement in USD, even if you see the equivalent amount in your local currency on our website. This means you cannot pay directly with your local currency.
Occasionally, a bank may decline the charge due to its fraud protection settings. We suggest reaching out to your bank initially to check if they are blocking our charges. Also, you can access the Billing Portal and change the card associated to make the payment. If these does not work and you need further assistance, please contact our team at [email protected]
Prices are determined by a recurring monthly or yearly subscription, depending on the chosen plan.
API calls are deducted from your plan based on successful requests. Each plan comes with a specific number of calls that you can make per month. Only successful calls, indicated by a Status 200 response, will be counted against your total. This ensures that failed or incomplete requests do not impact your monthly quota.
Zyla API Hub works on a recurring monthly subscription system. Your billing cycle will start the day you purchase one of the paid plans, and it will renew the same day of the next month. So be aware to cancel your subscription beforehand if you want to avoid future charges.
To upgrade your current subscription plan, simply go to the pricing page of the API and select the plan you want to upgrade to. The upgrade will be instant, allowing you to immediately enjoy the features of the new plan. Please note that any remaining calls from your previous plan will not be carried over to the new plan, so be aware of this when upgrading. You will be charged the full amount of the new plan.
To check how many API calls you have left for the current month, refer to the 'X-Zyla-API-Calls-Monthly-Remaining' field in the response header. For example, if your plan allows 1,000 requests per month and you've used 100, this field in the response header will indicate 900 remaining calls.

You can monitor your API usage through the response headers included with every request:

x-zyla-api-calls-monthly-used: Shows the total number of API requests you have used during the current billing period.
x-zyla-api-calls-monthly-remaining: Shows the number of API requests you have remaining for the current billing period.

The 'X-Zyla-RateLimit-Reset' header shows the number of seconds until your rate limit resets. This tells you when your request count will start fresh. For example, if it displays 3,600, it means 3,600 seconds are left until the limit resets.

Yes, you can cancel your subscription at any time. Simply go to the Pricing section of the API you're subscribed to and click the "Unsubscribe" button.

Please note that upgrades, downgrades, and cancellations take effect immediately. Once your subscription is canceled, access to the service will end immediately, regardless of any remaining API calls in your quota.

After 7 days, you will be charged the full amount for the plan you were subscribed to during the trial. Therefore, it's important to cancel before the trial period ends. Refund requests for forgetting to cancel on time are not accepted.
When you subscribe to an API free trial, you can make up to 50 API calls. If you wish to make additional API calls beyond this limit, the API will prompt you to perform an "Start Your Paid Plan." You can find the "Start Your Paid Plan" button in your profile under Subscription -> Choose the API you are subscribed to -> Pricing tab.
You can contact us through our chat channel to receive immediate assistance. We are always online from 8 am to 5 pm (EST). If you reach us after that time, we will get back to you as soon as possible. Additionally, you can contact us via email at [email protected]

Please have a look at our Refund Policy: https://zylalabs.com/terms#refund


Related APIs


You might also like