Developer API

Build custom vulnerability workflows with the OpenCVE API

Keep OpenCVE synchronized with your security stack. Import your software inventory, manage projects and subscriptions, automate CVE triage, and feed your internal workflows with enriched vulnerability intelligence.

From software inventory to actionable CVE workflows, without manual synchronization.

Read the documentation
OpenCVE API v2 workflow connecting inventory, subscriptions, CVE monitoring, and external tools

Make OpenCVE part of your security stack

Synchronize inventories

Automatically update OpenCVE project subscriptions whenever your CMDB or software inventory changes.

Automate CVE triage

Update CVE statuses and assignees from your own workflows, SOAR playbooks, or internal services.

Connect security tooling

Bring vulnerability intelligence into your ITSM, SIEM, dashboards, compliance systems, and internal applications.

Eliminate manual maintenance

Replace repetitive clicks, exports, and fragile synchronization scripts with structured API operations.

OpenCVE Developer API with Python example, endpoints, and JSON response

Replace repetitive security operations with API-driven workflows

Before

Manual vulnerability workflows

  • Add vendors and products by hand
  • Export CVEs into spreadsheets
  • Update statuses and assignees one by one
  • Maintain separate inventories and monitoring scopes
After

OpenCVE API v2

  • Synchronize subscriptions from your CMDB
  • Update CVE status and ownership programmatically
  • Feed ITSM, SIEM, SOAR, and internal dashboards
  • Configure reusable workflows across projects

Keep vulnerability monitoring aligned with your inventory

Your CMDB already knows which software your organization runs. OpenCVE API v2 lets you use that data to automatically maintain project subscriptions, so your vulnerability monitoring always reflects your real environment.

Your inventory changes. OpenCVE follows.

CMDB and inventory data flowing through OpenCVE API v2 to project subscriptions, relevant CVEs, and automations

Always up to date

Add or remove software in your inventory and update the corresponding OpenCVE project automatically.

No subscription drift

Keep vulnerability monitoring aligned with the technologies actually deployed by your teams.

Automate what happens next

Trigger triage, notifications, reports, and downstream integrations from the updated project scope.

How it works

Create a scoped organization token

Choose read-only, read-write, or granular permissions according to your integration and plan.

Call the REST API

Use standard Bearer authentication and JSON requests from any programming language or platform.

Automate your workflow

Synchronize inventories, update CVEs, manage projects, and connect OpenCVE to your operational tooling.

See OpenCVE API v2 in action

Preview real API workflows for CVE search, project management, inventory synchronization, and CVE triage.

Request
Response
200 OK 42ms

Response shortened for readability.

Explore all endpoints in Swagger

Built for teams that build with code

Platform engineers

Keep projects and software subscriptions synchronized with internal inventories and provisioning workflows.

SOC teams

Feed enriched CVE intelligence into investigation, prioritization, and response processes.

MSSPs

Automate customer onboarding, subscriptions, triage, and reporting across multiple environments.

DevSecOps

Connect vulnerability intelligence to engineering workflows, CI/CD pipelines, and internal developer tooling.

Bring OpenCVE into your security stack

Start synchronizing inventories, automating CVE triage, and building custom vulnerability workflows today.

Read the API documentation