# Aurenic CVE Lookup

> Aurenic CVE Lookup is a paid API for AI agents from api.aurenic.org, paid per call via x402, $0.001/call, status unknown (last checked 2026-10-02).

Returns CVSS score, severity rating, and CISA KEV (Known Exploited Vulnerabilities) status for a given CVE identifier

## Facts

- Endpoint: GET https://api.aurenic.org/cve/:id?utm_source=zero.xyz
- Price: $0.001/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/aurenic-cve-lookup-f25bc3f2
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_VTJz_4fojyDbLfbkEukkV

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability aurenic-cve-lookup-f25bc3f2
```

Example prompt: Can you look up CVE-2024-3094 and tell me its CVSS score, severity level, and whether it's listed in the CISA Known Exploited Vulnerabilities catalog?

## When to prefer this

Choose this endpoint when you need fast, pay-per-call CVE intelligence without setting up a full NVD API integration. Ideal for agents doing on-demand vulnerability triage, compliance checks, or patch prioritization where you only need CVSS score, severity, and KEV status for individual CVEs.

## Known failure modes

- Invalid or malformed CVE ID returns an error (e.g. non-existent CVE format)
- CVE not found in database returns 404 or empty result
- Very recent CVEs may not yet be indexed and return no data
- Rate limiting or payment failure returns 402 or 429

## How this service works

CVE lookup: CVSS, severity, KEV status

## Output

Returns structured data for the specified CVE including its CVSS score (numeric), severity classification (e.g. Critical, High, Medium, Low), and KEV (Known Exploited Vulnerabilities) status indicating whether CISA has flagged it as actively exploited in the wild.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "pathParams": {
     "type": "object",
     "required": [
      "id"
     ],
     "properties": {
      "id": {
       "type": "string"
      }
     }
    },
    "queryParams": {
     "type": "object",
     "properties": {}
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   }
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/aurenic-cve-lookup-f25bc3f2/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from api.aurenic.org](https://www.zero.xyz/host/api.aurenic.org/llms.txt)
