Vulnerability scanners want cpe:2.3:a:7-zip:7-zip. Your fleet reports “7-Zip 24.08 (x64 edition)”. Evil-DB closes that gap — then tells you exactly which version fixes it.
Every fleet scanner reimplements these badly. We do them once, in the API, so your client stays thin.
A hand-maintained regex CPE map is wrong in a different way in every client. Post a DisplayName and publisher, get ranked cpe candidates with confidence scores.
POST /api/v1/cve/resolve
{ "displayName": "7-Zip 24.08",
"publisher": "Igor Pavlov" }
→ 7-zip:7-zip (1.00)An empty result means one of two very different things. We tell you which — so a typo'd product name is never silently reported as clean.
GET /cve/match?vendor=openssl
&product=openssl&version=1.0.1
→ productKnown: true
matches: 75A finding is a report. A finding with a target version is a work order. We surface the version that closes the range, straight from the CPE config.
CVE-2014-0160 critical 7.5
fixedVersion → 1.0.1g
CVE-2014-0224 high
fixedVersion → 1.0.1hA raw CVSS list is noise. Evil-DB ships the three signals that actually decide what you patch first — on every match, no extra call.
Synced daily from the authoritative catalog, not derived second-hand. If it's being exploited in the wild, you know on the same response.
FIRST.org's exploit-probability score, refreshed daily, so you can rank by likelihood instead of theoretical severity.
Whether a weaponised exploit or detection template exists in the open — sourced from nuclei-templates. A medium-CVSS bug with a public exploit outranks a critical without one.
{
"productKnown": true,
"versionParsed": true,
"matches": [
{
"cveId": "CVE-2021-44228",
"severity": "critical",
"cvssScore": 10.0,
"isKev": true,
"epssScore": 0.944,
"fixedVersion": "2.15.0",
"exploit": {
"source": "nuclei-templates",
"url": "https://github.com/..."
}
}
]
}Bulk endpoints for fleet-wide scans, server-side severity filters so you aren't shipping megabytes of noise, and a plain-text API reference an LLM can read in one request.
# the whole API, as plain text
curl https://evil-db.io/llms.txt
# 100 products, critical-only, one call
curl -X POST https://evil-db.io/api/v1/cve/match \
-H 'x-api-key: ...' \
-d '{"items":[...],"minCvss":9,"kev":true}' Free tier: 1,000 lookups/day. No card required.