← All tools

vulnerability_lookup · REST + MCP

Look up a security vulnerability

Look up a security vulnerability by CVE id, or search CVEs by keyword (product, library, attack; newest first): description, CVSS score and severity, published and modified dates, affected vendors/products, CWE weaknesses, known-exploited flag and reference links. Data source: NVD. This product uses data from the NVD API but is not endorsed or certified by the NVD.

$0.002 USD per successful paid call

Free to try. A few calls a day over MCP without a key. Daily limits apply; with a key, calls use the price above.

Charged once per call that returns a result, including an empty result list. Failed calls are free.

Connect your agent

Use it in your chat

Start with no key

In Claude.ai, Claude Desktop, Claude Code, ChatGPT or Codex, add a custom connector with this URL. No API key or Authorization header is needed.

MCP URL, no key needed
https://unstuckapi.com/mcp

Try a few free calls a day with read_page, domain_check, domain_info, pdf_to_text, vulnerability_lookup, or paper_search. Each free result says how many are left and when they reset (midnight UTC).

A paid tool called without a key returns a new API key and a payment link instead of a result, and nothing is charged. In Claude, a Connect button opens the same payment page. Once credit is added, the agent can continue in the same chat with that key.

Already have a key?

If your connector cannot send headers, use this URL instead. Replace YOUR_API_KEY with your key.

Connector URL with key
https://unstuckapi.com/mcp?key=YOUR_API_KEY

Keep the completed URL private: it contains your API key.

Ask your agent to call vulnerability_lookup with these arguments:

MCP arguments
{
  "cve_id": "CVE-2021-44228"
}

Inputs

Send these fields as a JSON object to POST /v1/tools/vulnerability_lookup.

Input fields for vulnerability_lookup
FieldTypeDescription & limits
cve_idstring
Optional
Exact CVE id, e.g. "CVE-2021-44228". Give this or keyword.
keywordstring
Optional
Words to search CVE descriptions for, e.g. "log4j remote code execution".Minimum characters: 2 · Maximum characters: 200
limitinteger
Optional
Max results for a keyword search. Default 5, max 10.Minimum: 1 · Maximum: 10

Developer option: REST

Replace YOUR_API_KEY with your key. The following command makes a paid call if it succeeds.

Set your API key
export UNSTUCK_API_KEY="YOUR_API_KEY"
REST request
curl 'https://unstuckapi.com/v1/tools/vulnerability_lookup' \
  -H "Authorization: Bearer $UNSTUCK_API_KEY" \
  -H 'Content-Type: application/json' \
  --data '{"cve_id":"CVE-2021-44228"}'

The response contains result, charged_usd, and your remaining balance_usd. Invalid input and failed tool calls are not charged.

Developer option: MCP with a header

For clients that support headers, connect using Streamable HTTP and these values:

MCP URL
https://unstuckapi.com/mcp
Authorization header
Authorization: Bearer YOUR_API_KEY

Connection guide · Full JSON schemas and prices · Agent instructions