badchars/cve-mcp
View on GitHub ↗23-tool MCP server for CVE & vulnerability intelligence. NVD, EPSS, CISA KEV, GitHub Advisory, OSV — unified in one server. Risk scoring, bulk triage, exploit search. 2 dependencies, runs with npx.
20 ★4 forksTypeScriptUpdated 23d ago
What you need to know
Unified CVE and vulnerability intelligence MCP server combining NVD, EPSS, CISA KEV, OSV, GitHub Advisory, Shodan, VulnCheck, Vulners, Nuclei, Metasploit, CIRCL, AttackerKB, and MITRE ATT&CK.
Install
Follow the README to set up API keys and run the server
Usage
- •Query CVEs, EPSS scores, KEV catalog, exploit kits, and vulnerability intel from one place
Key features
- ✓Unified CVE database across multiple sources
- ✓EPSS and KEV integration
- ✓Exploit kit and PoC intelligence
- ✓CISA KEV catalog
- ✓Nuclei and Metasploit checks
Best for
Comprehensive vulnerability research and response
Caveats
- ⚠Some sources require API keys
Platforms: PythonClients: MCP-compatible clients
Documentation ↗Reviewed 2026-08-11
Topics
ai-securitycisaclaudecvecvsscybersecurityepssghsakevmcpmodel-context-protocolnvdosvpentestingsecurityvulnerabilityvulnerability-intelligence
- Stars
- 20★
- Forks
- 4
- Language
- TypeScript
- License
- MIT
- Created
- 2026-03-15
- Last push
- 2026-08-13