Knowing which CVEs are worth chasing before you point a scanner at anything is the difference between efficient recon and wasted time. These tools serve different purposes, and most hunters use only one or two when they should be using all of them together.

Here’s a practical comparison of what each gives you.

NVD API (free)

The National Vulnerability Database API is the authoritative source for CVE metadata. It’s free, rate-limited, and covers everything that’s been formally assigned a CVE ID.

# Search for critical CVEs for a specific vendor/product
curl "https://services.nvd.nist.gov/rest/json/cves/2.0?keywordSearch=nginx&cvssV3Severity=CRITICAL" \
  -H "apiKey: YOUR_KEY"

Without an API key you get 5 requests per 30 seconds. With a free key (takes minutes to register), you get 50 per 30 seconds. That’s enough for programmatic queries.

What NVD gives you: CVSS scores, CWE classifications, CPE data (what products are affected), and links to references. What it doesn’t give you: exploit code, proof-of-concept details, or any signal about whether something is actually being exploited in the wild.

NVD is best for building an initial list of CVEs matching a vendor or product. It’s the starting point, not the destination.

Shodan CVE filter

Shodan’s CVE search shows you which internet-facing systems are actually running vulnerable software. This is the key upgrade from NVD — you go from “this CVE exists” to “these specific IP addresses are running the affected version right now.”

vuln:CVE-2026-1234

Or using the API:

import shodan
api = shodan.Shodan("YOUR_API_KEY")
results = api.search("vuln:CVE-2026-1234")

Shodan Pro plans are required for CVE search — the free tier doesn’t include it. At $49/month, it’s one of the better tool investments for hunters doing volume recon. The combination of seeing affected systems by country, ASN, and org makes targeting significantly more efficient.

The limitation is freshness. Shodan scans the internet on a rolling schedule, so CVE data for a given IP might be weeks old. For newly disclosed CVEs, you’re often working with stale scan data.

Exploit-DB

Exploit-DB (exploit-db.com) is a public archive of exploit code and proof-of-concept scripts. It’s searchable by CVE ID, product name, and type.

# Using searchsploit (local mirror of Exploit-DB)
searchsploit nginx 1.18
searchsploit --cve 2026-1234

The real value of Exploit-DB for bug bounty is the quality signal it provides. If something has a working PoC on Exploit-DB, it’s been weaponized. If it hasn’t made it to Exploit-DB yet, you might be dealing with a newly disclosed vuln where you need to write your own test.

Exploit-DB is free. searchsploit as a local tool is fast and works offline. Every hunter should have it installed.

VulnDB

VulnDB (vulndb.flashpoint.io) is a commercial vulnerability intelligence feed that often has CVE data before NVD does. NVD has historically been slow to process new CVEs — the backlog problem is real. VulnDB covers that gap and also includes vulnerabilities that haven’t been assigned CVE IDs at all.

Pricing is enterprise-tier and not aimed at individual hunters. If you’re on a red team with a security budget, it’s worth evaluating. For solo bug bounty work, the cost-benefit rarely makes sense compared to combining NVD + Shodan + Exploit-DB.

CIRCL CVE search (free)

The CIRCL CVE Search API (cve.circl.lu) is an alternative to NVD’s API that’s faster and easier to query, with no rate-limit headaches for reasonable use.

curl https://cve.circl.lu/api/cve/CVE-2026-1234
curl "https://cve.circl.lu/api/search/apache/httpd"

For quick command-line lookups, CIRCL is often faster than NVD. The data comes from NVD so coverage is the same, but the API design is more usable for scripting. It also enriches CVE records with CAPEC (attack pattern) data and additional references.

SecurityClaw CVE Intelligence Module

SecurityClaw’s CVE module automates the aggregation step across all of these sources. You give it a target domain or technology stack, and it identifies which CVEs apply, cross-references against Shodan to find affected hosts in scope, and prioritizes by exploitability.

The workflow shift this enables is notable. Instead of manually querying NVD, cross-referencing Shodan, checking Exploit-DB for PoCs, and then triaging by hand, you get a prioritized list of CVEs with affected hosts already mapped. For hunters running multiple targets simultaneously, that time saving compounds.

The module also flags CVEs that have PoC code available (pulling from Exploit-DB and GitHub) versus those that are theoretical. This matters for triaging what to actually test versus what to note for later.

Putting it together

For practical bug bounty use, the workflow looks like this:

  1. Identify the tech stack on your target (Wappalyzer, HTTP headers, Shodan banner data).
  2. Query NVD or CIRCL for CVEs matching those components.
  3. Cross-reference against Exploit-DB with searchsploit to find anything with working PoC.
  4. Use Shodan’s CVE filter to see which hosts are actually exposing the vulnerable version.
  5. Prioritize CVEs where there’s a PoC and the target is confirmed running the affected version.

The gap in this workflow is the manual aggregation step between tools. That’s where SecurityClaw’s module adds real time savings, particularly when you’re working across multiple scope domains.

For hunters starting out, the free tier of NVD API + CIRCL + Exploit-DB/searchsploit gets you surprisingly far without spending anything.

For a practical walkthrough of turning CVE intelligence into actual findings, see CVE intelligence for bug bounty: NVD API and prioritization. The CVE opportunity analysis for June 2026 shows what this process looks like applied to real recent disclosures.