tooloracle.io · cve_lookup
tooloracle.io · https://tooloracle.io/v2/cve_lookup
CVE lookup + vulnerability check + threat intelligence — search NIST NVD + CISA KEV (Known Exploited Vulnerabilities) by keyword, vendor, product, or CVE ID. Returns CVSS score, severity rating, exploitability, MITRE ATT&CK technique mapping. For security agents, threat intelligence, EU DORA ICT risk assessment, NIS2 vendor due diligence, supply chain security audit, SOC2 evidence, ISO 27001 gap analysis.
This endpoint speaks x402: an unpaid request returns
HTTP 402 with machine-readable payment
terms, your agent pays the $0.005 USDC in USDC on-chain, and retries automatically. Pays to 0x11f591C3496C0632e7B173184f5Bc71dC941125D.Call it in 30 seconds
JavaScriptPythoncurl
// npm i x402-fetch viem
import { wrapFetchWithPayment } from "x402-fetch";
import { createWalletClient, http } from "viem";
import { privateKeyToAccount } from "viem/accounts";
import { base } from "viem/chains";
const account = privateKeyToAccount(process.env.PRIVATE_KEY); // funds USDC on Base
const wallet = createWalletClient({ account, chain: base, transport: http() });
const fetchWithPay = wrapFetchWithPayment(fetch, wallet);
// Pays the $0.005 USDC automatically on the 402, then returns the real response:
const res = await fetchWithPay("https://tooloracle.io/v2/cve_lookup", { method: "POST" });
console.log(await res.json());
# pip install x402 eth-account httpx
import os, asyncio
from eth_account import Account
from x402.clients.httpx import x402HttpxClient
account = Account.from_key(os.environ["PRIVATE_KEY"]) # funds USDC on Base
async def main():
async with x402HttpxClient(account=account) as client:
# x402 handles the 402 -> pay ($0.005 USDC) -> retry automatically
r = await client.get("https://tooloracle.io/v2/cve_lookup")
print((await r.aread()).decode())
asyncio.run(main())
# 1) An unpaid request returns HTTP 402 with the exact payment terms:
curl -i -X POST "https://tooloracle.io/v2/cve_lookup" \
-H 'content-type: application/json' \
-d '{"keyword": {"description": "Search keyword, vendor, or product name", "required": true, "type": "string"}, "limit": {"description": "Max results (default 10, max 50)", "required": false, "type": "integer"}}'
# 2) Paying + retrying requires an x402 client that can sign the USDC
# authorization (curl alone cannot). See the JS / Python tabs below.
New to x402? Read the 5-minute quickstart →
ad slot · a crypto-native, no-tracking ad loads here in production
Query this registry programmatically. Every service here is searchable through the
x402hub API, an x402-payable endpoint your agents call and pay per request in USDC.
https://api-service-sandy.vercel.app · GET /api/search?q=... · $0.002 / call
Prefer to just support the project? Tip USDC on Base to
0x40BbeB1BEd1D4ba6f1d4C0eE0C9D93e2dA3347C6. This hub is free and ad-light.