openapi: 3.1.0 info: title: Empirical Security CVE Groups CVEs API version: '1.0' description: The Empirical Security API provides programmatic access to real-time exploitation prediction scores for CVEs. It exposes the Foundation (global) model, hourly-updated EPSS models (epss_v3/epss_v4/epss_v5), and organization-specific Radiant models, along with CVE detail, malware-hash, critical-indicator, score-history, change-history, and saved CVE-group endpoints. Authentication is OAuth 2.0 client credentials (JWT bearer). contact: name: Empirical Security url: https://docs.empiricalsecurity.com/ x-provenance: generated: '2026-07-19' method: generated source: https://docs.empiricalsecurity.com/api_reference/cves, https://docs.empiricalsecurity.com/api_reference/search, https://docs.empiricalsecurity.com/api_reference/cve_groups, https://docs.empiricalsecurity.com/authentication, https://docs.empiricalsecurity.com/errors servers: - url: https://app.empiricalsecurity.com/api description: Production security: - oauth2: [] tags: - name: CVEs description: Retrieve CVE detail, scores, malware hashes and history. paths: /cves/{cve_id}: get: operationId: getCve summary: Retrieve a CVE by identifier description: Retrieve full detail and scores for a single CVE by its identifier. tags: - CVEs parameters: - $ref: '#/components/parameters/CveId' responses: '200': description: CVE detail content: application/json: schema: $ref: '#/components/schemas/Cve' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/ServerError' /cves/{cve_id}/malware: get: operationId: getCveMalware summary: Retrieve malware hashes for a CVE description: Retrieve MD5/SHA1/SHA256 malware hashes associated with a CVE. tags: - CVEs parameters: - $ref: '#/components/parameters/CveId' - name: accept in: query required: false description: Set to application/jsonl for JSON Lines output. schema: type: string responses: '200': description: Array of malware hash records content: application/json: schema: type: array items: $ref: '#/components/schemas/MalwareHash' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' /cves/{cve_id}/critical_indicators: get: operationId: getCveCriticalIndicators summary: Retrieve critical indicators for a CVE description: Retrieve the scoring model analysis with weighted critical indicators for a CVE. tags: - CVEs parameters: - $ref: '#/components/parameters/CveId' responses: '200': description: Critical indicator analysis content: application/json: schema: type: object '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' /cves/{cve_id}/score_history: get: operationId: getCveScoreHistory summary: Retrieve score history for a CVE description: Retrieve historical scores for a CVE for a given scoring model. tags: - CVEs parameters: - $ref: '#/components/parameters/CveId' - name: scoring_model in: query required: true description: Scoring model key. schema: type: string enum: - global - epss_v3 - epss_v4 - epss_v5 - all responses: '200': description: Score history content: application/json: schema: $ref: '#/components/schemas/ScoreHistory' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' /cves/{cve_id}/history: get: operationId: getCveHistory summary: Retrieve CVE change history description: Retrieve the array of change records (data and diff) for a CVE. tags: - CVEs parameters: - $ref: '#/components/parameters/CveId' responses: '200': description: Array of change records content: application/json: schema: type: array items: type: object '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' /cves/all: get: operationId: getAllCves summary: Retrieve all CVEs description: Retrieve the full CVE dataset. Returns a 302 redirect to a gzipped JSONL file, or 202 when the file is being generated. tags: - CVEs responses: '302': description: Redirect to gzipped JSONL export file. '202': description: Export file is being generated; retry later. '401': $ref: '#/components/responses/Unauthorized' components: responses: NotFound: description: Resource not found. content: application/json: schema: $ref: '#/components/schemas/Error' Unauthorized: description: Authentication failed (missing or invalid token). content: application/json: schema: $ref: '#/components/schemas/Error' ServerError: description: Internal server error. content: application/json: schema: $ref: '#/components/schemas/Error' schemas: Cve: type: object properties: identifier: type: string example: CVE-2023-49103 description: type: string cvss: type: array items: type: object references: type: array items: type: object has_exploitation_activity: type: boolean scores: type: object additionalProperties: $ref: '#/components/schemas/Score' MalwareHash: type: object properties: md5: type: string sha1: type: string sha256: type: string ScoreHistory: type: object properties: identifier: type: string scores: type: object additionalProperties: type: array items: $ref: '#/components/schemas/Score' Score: type: object properties: score: type: number percentile: type: number computed_at: type: string format: date-time Error: type: object properties: error: type: object properties: code: type: string description: String identifier for the error type. message: type: string description: Human-readable description of the error. parameters: CveId: name: cve_id in: path required: true description: CVE identifier in the format CVE-YYYY-NNNNN. schema: type: string pattern: ^CVE-\d{4}-\d{4,}$ example: CVE-2023-49103 securitySchemes: oauth2: type: oauth2 description: OAuth 2.0 client credentials flow via FusionAuth. Exchange client ID/secret (HTTP Basic) for a one-hour JWT access token, then send it as a Bearer token. flows: clientCredentials: tokenUrl: https://empiricalsecurity.fusionauth.io/oauth2/token scopes: target-entity:0c6d5dcc-8bf0-4cd1-bd65-066ef0422369: Access to the Empirical Security tenant/entity's CVE data.