Noroxi CVE API
JSON endpoints with a personal key: single record, bulk lookup, stack matching and search. For CLI and CI.
Authentication
Every request carries a Bearer key in the Authorization header. 1,000 calls per key per day; the remaining quota is returned in X-RateLimit-Remaining.
export NOROXI_KEY=nrx_… curl -s https://noroxi.com/api/v1/cve/CVE-2021-44228 -H "Authorization: Bearer $NOROXI_KEY"
Endpoints
Examples below use curl and jq; call it the same way from any language.
GET/api/v1/cve/{id}
Single record
Everything on the detail page: scores, KEV, SSVC, CNA version ranges, fixes, packages, aliases, changes, ATT&CK context. No exploit links.
curl -s https://noroxi.com/api/v1/cve/CVE-2024-3400 -H "Authorization: Bearer $NOROXI_KEY" | jq '{severity, kev, ssvc, fixes: .fixes[:3]}'POST/api/v1/cve/bulk
Bulk lookup
Up to 500 ids; GHSA/EUVD/BDU aliases are resolved. Returns list-row fields.
curl -s https://noroxi.com/api/v1/cve/bulk -H "Authorization: Bearer $NOROXI_KEY" -H "Content-Type: application/json" \
-d '{"ids":["CVE-2024-3400","CVE-2023-4966","GHSA-9c4x-8p9h-8m4m"]}' | jq '.items[] | [.id, .severity, .kev, .fix_available]'POST/api/v1/match
Stack matching
Matching records for entries like "nginx@1.24.0", "p:apache:tomcat@9.0.50", "k:npm:lodash@4.17.20" (version-aware).
curl -s https://noroxi.com/api/v1/match -H "Authorization: Bearer $NOROXI_KEY" -H "Content-Type: application/json" \
-d '{"entries":["nginx@1.24.0","p:openbsd:openssh@9.6","k:npm:lodash@4.17.20"],"kev":false,"days":90}' | jq '.summary'GET/api/v1/search
Search
Same parameters as the list page: q, sev, mat, kev, epss, vendor, product, year, cwe, fix, sort, page.
curl -s "https://noroxi.com/api/v1/search?q=openssh&sev=critical&sev=high&fix=1&sort=published&size=20" -H "Authorization: Bearer $NOROXI_KEY" | jq '.items[].id'
Fields
id, title, published, updated, severity, cvss, epss, epss_percentile, kev, exploit_maturity (none|poc|weaponized), action_score (0–100), vendor, product, cwe, fix_available, tags[] (pre-auth, rce, auth-bypass …)
+ summary, cvss_vector, cvss_source, cvss_cna, cna, ssvc {exploitation, automatable, impact}, sources {nvd, cna, adp, kev, epss, osv, msrc …}, exploit_counts, exploit_refs {metasploit[], nuclei[]}, credits, patches, related {variants, chains}, bug_bounty, products, affected_nvd, affected_cna, packages, fixes, aliases, changes, attack {capec, techniques}, references
The API never returns exploit code or links. exploit_refs carries Metasploit module names and Nuclei template ids (names only); Exploit-DB entries and PoC repositories are counts.