A unified intelligence layer over four government vulnerability databases: NIST NVD for CVE details and CVSS scores, CISA KEV for actively exploited vulnerabilities, FIRST.org EPSS for exploitation probability predictions, and MITRE ATT&CK for adversary technique mappings. The standout is vuln_lookup_cve, which enriches a single CVE with all four data sources in one call. You also get search across the NVD with KEV filtering, KEV entries with approaching remediation deadlines, top EPSS scores for exploitation likelihood, and vendor specific vulnerability assessments. Reach for this when you need to triage vulnerabilities, prioritize patches based on active exploitation and probability data, or track CISA compliance deadlines. Available over streamable HTTP via Apify or stdio locally with optional NVD API key for higher rate limits.
Unified vulnerability intelligence from 4 government data sources in a single MCP server. Get enriched CVE lookups with CVSS scores, active exploitation status, exploitation probability, and ATT&CK techniques in one call.
| Source | What It Provides | Update Frequency |
|---|---|---|
| NIST NVD 2.0 | CVE details, CVSS scores, descriptions, references, CWE classifications | Continuous |
| CISA KEV | Actively exploited vulnerabilities catalog, remediation deadlines | Daily |
| FIRST.org EPSS | Exploitation probability scores (0-1) predicting likelihood of exploitation in next 30 days | Daily |
| MITRE ATT&CK | Adversary techniques mapped to CVEs | Quarterly |
vuln_lookup_cve — Enriched CVE LookupThe killer feature. Look up any CVE and get intelligence from all 4 sources in a single call.
{ cveId: "CVE-2021-44228" }vuln_search — Search CVEsSearch the NVD by keyword, severity, and date range. Optionally filter to only actively exploited (KEV) vulnerabilities.
{ keyword: "apache log4j", severity: "CRITICAL", hasKev: true, limit: 20 }vuln_kev_latest — Recently Exploited VulnerabilitiesGet vulnerabilities recently added to CISA's Known Exploited Vulnerabilities catalog.
{ days: 7, limit: 20 }vuln_kev_due_soon — Upcoming Remediation DeadlinesGet KEV entries with remediation deadlines approaching. Critical for federal compliance.
{ days: 14, limit: 20 }vuln_epss_top — Highest Exploitation ProbabilityGet CVEs most likely to be exploited in the next 30 days based on EPSS machine learning model.
{ threshold: 0.7, limit: 20 }vuln_trending — Newly Published Critical CVEsGet recently published high/critical severity CVEs from the NVD.
{ days: 3, severity: "CRITICAL", limit: 20 }vuln_by_vendor — Vendor Vulnerability AssessmentSearch CVEs for a specific vendor/product. Cross-references with CISA KEV to flag actively exploited issues.
{ vendor: "microsoft", product: "windows", limit: 20 }Install from Glama.ai.
{
"mcpServers": {
"cybersecurity": {
"url": "https://cybersecurity-vuln-mcp.apify.actor/mcp"
}
}
}
{
"mcpServers": {
"cybersecurity": {
"command": "node",
"args": ["path/to/servers/cybersecurity-vuln-mcp/dist/stdio.js"],
"env": {
"NVD_API_KEY": "your-key-here"
}
}
}
}
git clone https://github.com/martc03/gov-mcp-servers.git
cd gov-mcp-servers/servers/cybersecurity-vuln-mcp
npm install && npm run build
node dist/stdio.js
| Variable | Required | Description |
|---|---|---|
NVD_API_KEY | No | NVD API key for higher rate limits (50 req/30s vs 5 req/30s). Register here. |
| Data Source | TTL | Notes |
|---|---|---|
| NVD CVE lookups | 1 hour | Per-CVE |
| CISA KEV catalog | 2 hours | Full catalog |
| EPSS scores | 24 hours | Per-CVE |
| ATT&CK mappings | Static | Bundled with server |
This repository contains 13 MCP servers for US government data. See each server's README for details.
| Server | Tools | Data Sources |
|---|---|---|
| us-safety-recalls-mcp | 4 | NHTSA recalls, FDA recalls |
| natural-disaster-intel-mcp | 4 | FEMA disasters, NOAA weather, USGS earthquakes |
| federal-financial-intel-mcp | 4 | SEC EDGAR, CFPB complaints, BLS employment |
| immigration-travel-mcp | 3 | Visa bulletins, border wait times |
| environmental-compliance-mcp | 3 | EPA air quality, HUD foreclosures |
| gov-contracts-mcp | 4 | SAM.gov contracts, USAspending |
| court-records-mcp | 4 | PACER, federal court records |
| public-health-mcp | 4 | NIH clinical trials, FDA adverse events |
| business-entity-mcp | 4 | SEC company search, SBA resources |
| regulatory-monitor-mcp | 4 | Federal Register, regulations.gov |
| grant-finder-mcp | 4 | Grants.gov, USAspending |
| competitive-intel-mcp | 4 | SEC filings, patent data, trade data |
A REST API gateway with 45 endpoints is also available at govdata-api.netlify.app.
Need a custom MCP server for your business? Visit mcpdev.netlify.app or email codee.mcpdev@gmail.com.
MIT
com.exploit-intel/eip-mcp
dmontgomery40/pentest-mcp
pantheon-security/notebooklm-mcp-secure
cyanheads/pentest-mcp-server
io.github.akhilucky/ai-firewall-mcp