The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Vuln Intel listing page.
Most CVE tools hand your agent raw data. This one ranks it by what's actually being exploited, finds bugs by mechanism, catches the CVEs your agent invents — and transfers attack mechanics from ~14,000 disclosed bug-bounty reports.
A curated, hosted MCP corpus: ~364,000 CVEs, fused from NVD + CISA KEV + FIRST EPSS + OSV/GHSA + CISA Vulnrichment (SSVC), plus a mechanic layer distilled from ~14,000 disclosed, paid bug-bounty reports — refreshed daily. Not another live-API wrapper.
Free. Get a key: enter your email and your personal key is sent over. Tell me what you are hunting.
Most CVE MCP servers are thin wrappers: at query time they fan out to the same free public APIs and hand back whatever comes out. This is different in five concrete ways.
verify_cve_claim catches invented CVEs and wrong attributes. This is the one that matters most right now, with hallucinated AI bug reports flooding triage, and effectively no other CVE MCP does it.resolved: false with suggestions, never a silent 0 that reads as "not affected." A false zero is the worst answer a security tool can give.The hard part of AI-assisted security is not finding CVEs. It is triage, prioritization, and false positives. That is what this targets.
Everything below is real output from the live server, trimmed only for length.
The differentiator that matters most. Your agent cites CVE-2025-99999:
Or it gets the details wrong. Claim: "CVE-2021-44228 is a medium-severity Apache Struts bug, and it is not exploited."
The other feeds hand your agent data. This one tells you when the agent is wrong, before it reaches a report.
check_technology("GitLab") returns 792 CVEs for the product, de-duped and ranked so the exploited ones float to the top:
Names that map to more than one vendor are flagged ambiguous (here, gitlab vs a jenkins plugin) and kept separate, never silently merged. enrich_cve then gives you the full SSVC picture for any one of them:
hunt_plan(["craftcms 4.4", "nginx", "keycloak"]) ranks your stack by its most-exploitable bug and names where each component historically bleeds:
It does not just list CVEs. It names the bug class a product family keeps failing at, ranked by real exploitation, and tells you whether your version is in range. Where to look, and what shape to expect.
find_similar_vulns(cve_id="CVE-2021-44228"), "what else works like Log4Shell":
The same JNDI-injection mechanism, surfaced across different products. A keyword search for "log4j" never finds Karaf or Flume. Or search a concept directly, search_vulns("SAML SSO authentication bypass"):
find_recent_high_risk(days=7), run live today:
Median time from disclosure to in-the-wild exploitation is now days, not months. The Ivanti bug above carried a CISA remediation deadline in the same week it landed. corpus_stats right now: ~364,800 CVEs, ~1,630 KEV entries, data under a day old — these figures are point-in-time and drift daily, so call corpus_stats yourself for the live count rather than trusting the numbers on this page.
Beyond CVEs, the corpus distills ~14,000 disclosed, paid HackerOne reports into product-agnostic attack mechanics — each bug's source → sink → trigger → preconditions, de-anchored from the product it was filed against. The premise: a vulnerability is a transferable mechanism, not a property of one product — so a move that paid on one stack is a checklist item on the next.
find_attack_approaches(query="ssrf reaching cloud metadata") — the human moves that transferred, novelty-ranked, each tagged with live program-actionability:
find_continuations(position=...) — matches your accumulated attacker position mid-hunt to the next moves real reports played from a similar spot. Every move is status: UNVERIFIED with a decisive_check to run on the target — a legal move, never a confirmed bug.assist_submission(finding=...) — a grounded submission brief from the closest paid precedents (validity, what's novel, an escalation playbook), with every cited report validated against the corpus (citations_grounded) so it can't smuggle a fabricated precedent.program_outcome_prior("hackerone:gitlab") — the bug classes that historically landed on a program, with lift over base rate (GitLab: SSRF 3.4×, SQLi ~never).Honest about what this is: it primes and grounds a human hunter — it surfaces the move and the precedent. It does not find the bug for you; the target decides whether the move survives, and that's a step you still run.
The moat is three things a stateless model cannot self-generate, and this corpus holds all three:
observe recovers a host's real backend from its JS bundles and joins it to the corpus on the spot.The cardinal sin is treating it as a severity-number checker. The job is to transfer a proven mechanic onto your target and run it — or read a fix to falsify an option before you spend a probe on it.
Left alone, an agent answers from training data: stale, and it invents CVE ids under pressure. Paste this operating loop into your agent's rules (CLAUDE.md, Cursor/Windsurf, a system prompt):
It surfaces the move and the precedent; the target decides what survives. That last rule is the product's whole ethos — every tool ships its own kill-check (verify_cve_claim refutations, UNVERIFIED + a decisive_check, ambiguous, citations_grounded), so an agent can never read a narrow signal as a green light.
Or any MCP client (mcp.json):
You just need a key, free. See Get a key below.
CVE intelligence:
| Tool | Input | Returns |
|---|---|---|
check_technology | a product (+ version, vendor) | ranked CVEs de-duped across NVD CPE + OSV, ambiguity-flagged |
hunt_plan | a recon'd stack | per-component dig-order + the recurring bug-class (CWE) loci |
enrich_cve | a CVE id | full dossier: CVSS, KEV, EPSS, SSVC, affected, Metasploit + live PoC repos |
verify_cve_claim | a CVE + asserted attributes | per-claim supported / refuted / unverifiable + evidence |
find_recent_high_risk | a window (+ product) | newly dangerous KEV / high-EPSS CVEs |
find_similar_vulns | a concept or seed CVE | mechanism-siblings across products, with cosine similarity |
search_vulns | free text (+ CWE) | ranked full-text matches + total coverage |
search_public_code | an exact code string | public repos where it appears (repo / file / url) |
corpus_stats | — | corpus size and data freshness |
Bug-bounty mechanic transfer (from ~14k disclosed reports):
| Tool | Input | Returns |
|---|---|---|
find_attack_approaches | a target / CVE / bug-class | transferable attack mechanics, novelty-ranked + live program-actionability |
find_continuations | your mid-hunt attacker position | the next moves real reports played from there, each UNVERIFIED + a decisive check |
assist_submission | a draft finding | grounded submission brief + escalation playbook, citation-guarded (citations_grounded) |
program_outcome_prior | a bug-bounty program | the bug classes that historically landed on it + lift over base rate |
It lays out facts, ranked context, and transferable precedent — never an exploit or a payload. Your agent does the reasoning; the target decides what survives.
Full reference — every argument, response field, and a live example per tool — in TOOLS.md.
Two MIT-licensed companion docs turn the corpus into landed findings, not CVE lookups: a self-contained
Claude bug-bounty-hunting skill (drop the folder into ~/.claude/skills/
and it loads on "hunt for bugs" / "is this exploitable") and the deeper on-demand
MCP playbook (per-tool gotchas, the ideation loop, the verification
patterns). Both stand alone: see bug-bounty-hunting/.
Not a scanner, not an exploit tool, not an SBOM / SCA replacement. A grounding, prioritization and fact-check layer for AI-assisted security work.
It is free. Go to vulntel.com/signup, enter your email, and your personal key is sent over. Prefer to ask directly? Email rozetyp@gmail.com with what you are working on (bounty, pentest, research). Keys are per-user, attributable and revocable.
For authorized, defensive security research and bug-bounty triage. Not for exploitation. Output is decision support, not a substitute for your own verification.
© 2026 rozetyp. All rights reserved. This is not open source; see LICENSE.