Start free. Scale when you need to.
Search is free for everyone. Pay when you want your whole stack monitored — or the API in production.
Free
For individual researchers
$0forever
- ✓Search across 90+ sources, 1.4M+ documents
- ✓Full enrichment: EPSS, KEV, Priority, exploits, detection rules
- ✓Watchlist: track 3 products with KEV/exploit email alerts
- ✓50 API calls/day (10/day anonymous)
- ✓MCP integration · 1 API key
- ✓Batch API: 10 CVEs/request · Stack matching: 10 items/request
7-day free trial
Pro
For engineers who monitor a stack, not just look things up
$29/ month
- ✓Everything in Free
- ✓Unlimited watched products — alerts when YOUR stack gets a new KEV entry, exploit, or EPSS surge
- ✓Stack matching API: 100 items/request — feed it your SBOM
- ✓500 API calls/day · Batch: 100 CVEs/request
- ✓Commercial use license
- ✓Email support
Team
For security teams and MSSPs
$149/ month
- ✓Everything in Pro
- ✓5,000 API calls/day
- ✓Batch API: 500 CVEs/request · Stack matching: 500 items/request
- ✓5 API keys
- ✓Priority support
- ✓Invoice billing
| Feature | Free | Pro | Team |
|---|---|---|---|
| Searches / day | 50 | 500 | 5,000 |
| Watched products (stack alerts) | 3 | unlimited | unlimited |
| Stack matching API (items/req) | 10 | 100 | 500 |
| Batch API | 10/req · 5/day | 100/req · 50/day | 500/req · 500/day |
| API keys | 1 | 1 | 5 |
| MCP access | ✓ | ✓ | ✓ |
| Detection rules + IOCs (Sigma/Nuclei/YARA) | ✓ | ✓ | ✓ |
| Weekly digest + CVE alerts | ✓ | ✓ | ✓ |
| Commercial use license | — | ✓ | ✓ |
| Priority support | — | — | ✓ |
Frequently asked questions
Is the data free to use?+
Yes. The vulnerability data comes from public sources (NVD, CISA KEV, MITRE, ExploitDB, Sigma repos, etc.) and is free to search on cvebase.io. Commercial use may require a Pro license (see above).
Do I need to sign up to search?+
No. Anonymous users get 10 searches per day. Sign in with GitHub or Google to bump that to 50/day.
What does MCP access mean?+
cvebase runs a remote MCP server at https://cvebase.io/mcp — add it to Claude Desktop, Claude Code, or Cursor and your AI assistant can query CVEs, exploits, and detection rules directly. Available on every tier; requests count toward your daily quota.
How do watchlist alerts work?+
Add the products you run (optionally pinned to a version) to your watchlist. When one of them gets a new CISA KEV entry, a public exploit, or an EPSS surge, you get an email with the detection coverage linked — the rule to deploy, or the gap to fill. Free accounts can track 3 products; Pro and Team are unlimited.
What enrichment data is included?+
Each CVE ships with the raw signals straight from upstream: EPSS score and percentile (FIRST.org), CISA KEV status with due dates, public exploit availability (ExploitDB, Metasploit, Nuclei), wild-exploitation flags, CWE, and MITRE ATT&CK mappings. We don't invent our own scores — plug the signals into whatever model your team already uses. Included on every tier, including the 50 searches/day Free plan.
Is there a free trial for Pro and Team?+
Yes. Both paid tiers include a 7-day free trial — no charge until it ends, and you can cancel any time from the dashboard.
Can I self-host cvebase?+
Not today. cvebase is managed only — we run the index, the embedding model, and the API for you. Self-hosting would mean shipping the fine-tuned model weights and a multi-million-document Qdrant snapshot, which we're not ready to support yet. If you have a hard on-prem requirement, email [email protected] and tell us about your setup — it helps us prioritize.
Start searching now
1.4M+ security documents across 90+ sources. No account required.
Go to search