badchars/cve-mcp

View on GitHub ↗

23-tool MCP server for CVE & vulnerability intelligence. NVD, EPSS, CISA KEV, GitHub Advisory, OSV — unified in one server. Risk scoring, bulk triage, exploit search. 2 dependencies, runs with npx.

20 ★4 forksTypeScriptUpdated 23d ago

What you need to know

Unified CVE and vulnerability intelligence MCP server combining NVD, EPSS, CISA KEV, OSV, GitHub Advisory, Shodan, VulnCheck, Vulners, Nuclei, Metasploit, CIRCL, AttackerKB, and MITRE ATT&CK.

Install

Follow the README to set up API keys and run the server

Usage

  • Query CVEs, EPSS scores, KEV catalog, exploit kits, and vulnerability intel from one place

Key features

  • Unified CVE database across multiple sources
  • EPSS and KEV integration
  • Exploit kit and PoC intelligence
  • CISA KEV catalog
  • Nuclei and Metasploit checks

Best for

Comprehensive vulnerability research and response

Caveats

  • Some sources require API keys
Platforms: PythonClients: MCP-compatible clients
Documentation ↗

Reviewed 2026-08-11

Topics

ai-securitycisaclaudecvecvsscybersecurityepssghsakevmcpmodel-context-protocolnvdosvpentestingsecurityvulnerabilityvulnerability-intelligence
Stars
20★
Forks
4
Language
TypeScript
License
MIT
Created
2026-03-15
Last push
2026-08-13