cbcvebase.

Start free. Scale when you need to.

Search is free for everyone. Pay when you want your whole stack monitored — or the API in production.

Free

For individual researchers

$0forever
  • Search across 90+ sources, 1.4M+ documents
  • Full enrichment: EPSS, KEV, Priority, exploits, detection rules
  • Watchlist: track 3 products with KEV/exploit email alerts
  • 50 API calls/day (10/day anonymous)
  • MCP integration · 1 API key
  • Batch API: 10 CVEs/request · Stack matching: 10 items/request
Start searching
7-day free trial

Pro

For engineers who monitor a stack, not just look things up

$29/ month
  • Everything in Free
  • Unlimited watched products — alerts when YOUR stack gets a new KEV entry, exploit, or EPSS surge
  • Stack matching API: 100 items/request — feed it your SBOM
  • 500 API calls/day · Batch: 100 CVEs/request
  • Commercial use license
  • Email support

Team

For security teams and MSSPs

$149/ month
  • Everything in Pro
  • 5,000 API calls/day
  • Batch API: 500 CVEs/request · Stack matching: 500 items/request
  • 5 API keys
  • Priority support
  • Invoice billing
FeatureFreeProTeam
Searches / day505005,000
Watched products (stack alerts)3unlimitedunlimited
Stack matching API (items/req)10100500
Batch API10/req · 5/day100/req · 50/day500/req · 500/day
API keys115
MCP access
Detection rules + IOCs (Sigma/Nuclei/YARA)
Weekly digest + CVE alerts
Commercial use license
Priority support

Frequently asked questions

Is the data free to use?+
Yes. The vulnerability data comes from public sources (NVD, CISA KEV, MITRE, ExploitDB, Sigma repos, etc.) and is free to search on cvebase.io. Commercial use may require a Pro license (see above).
Do I need to sign up to search?+
No. Anonymous users get 10 searches per day. Sign in with GitHub or Google to bump that to 50/day.
What does MCP access mean?+
cvebase runs a remote MCP server at https://cvebase.io/mcp — add it to Claude Desktop, Claude Code, or Cursor and your AI assistant can query CVEs, exploits, and detection rules directly. Available on every tier; requests count toward your daily quota.
How do watchlist alerts work?+
Add the products you run (optionally pinned to a version) to your watchlist. When one of them gets a new CISA KEV entry, a public exploit, or an EPSS surge, you get an email with the detection coverage linked — the rule to deploy, or the gap to fill. Free accounts can track 3 products; Pro and Team are unlimited.
What enrichment data is included?+
Each CVE ships with the raw signals straight from upstream: EPSS score and percentile (FIRST.org), CISA KEV status with due dates, public exploit availability (ExploitDB, Metasploit, Nuclei), wild-exploitation flags, CWE, and MITRE ATT&CK mappings. We don't invent our own scores — plug the signals into whatever model your team already uses. Included on every tier, including the 50 searches/day Free plan.
Is there a free trial for Pro and Team?+
Yes. Both paid tiers include a 7-day free trial — no charge until it ends, and you can cancel any time from the dashboard.
Can I self-host cvebase?+
Not today. cvebase is managed only — we run the index, the embedding model, and the API for you. Self-hosting would mean shipping the fine-tuned model weights and a multi-million-document Qdrant snapshot, which we're not ready to support yet. If you have a hard on-prem requirement, email [email protected] and tell us about your setup — it helps us prioritize.

Start searching now

1.4M+ security documents across 90+ sources. No account required.

Go to search