curl --request GET \
--url https://api.leen.dev/v2/vulnerability_findings \
--header 'X-API-KEY: <api-key>' \
--header 'X-CONNECTION-ID: <api-key>'import requests
url = "https://api.leen.dev/v2/vulnerability_findings"
headers = {
"X-API-KEY": "<api-key>",
"X-CONNECTION-ID": "<api-key>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {'X-API-KEY': '<api-key>', 'X-CONNECTION-ID': '<api-key>'}
};
fetch('https://api.leen.dev/v2/vulnerability_findings', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.leen.dev/v2/vulnerability_findings",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-KEY: <api-key>",
"X-CONNECTION-ID: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.leen.dev/v2/vulnerability_findings"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-KEY", "<api-key>")
req.Header.Add("X-CONNECTION-ID", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.leen.dev/v2/vulnerability_findings")
.header("X-API-KEY", "<api-key>")
.header("X-CONNECTION-ID", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.leen.dev/v2/vulnerability_findings")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-KEY"] = '<api-key>'
request["X-CONNECTION-ID"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"items": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"severity": "CRITICAL",
"state": "OPEN",
"type": "DEPENDENCY",
"vendor_attributes": {
"id": "<string>",
"severity": "<string>",
"state": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"data": {
"report_type": "SAST",
"scanner": {
"id": "<string>",
"name": "<string>",
"vendor": "<string>"
},
"vendor": "GITLAB"
},
"updated_at": "2023-11-07T05:31:56Z",
"url": "<string>",
"vulnerability_identifiers": [
{
"type": "CVE",
"value": "CVE-2021-34527"
}
]
},
"analytic": {
"name": "<string>",
"type": "<string>",
"uid": "<string>",
"url": "<string>"
},
"analytic_output": "<string>",
"description": "<string>",
"exploitable": true,
"first_seen": "2023-11-07T05:31:56Z",
"has_fix": true,
"last_seen": "2023-11-07T05:31:56Z",
"product": {
"name": "<string>",
"vendor_name": "<string>"
},
"reachability": "REACHABLE",
"remediation": "<string>",
"resource_related": [
{
"affected_code": {
"end_line_number": 123,
"file_path": "<string>",
"start_line_number": 123,
"url": "<string>"
},
"affected_image": "<string>",
"affected_os": "<string>",
"affected_package": {
"name": "<string>",
"package_manager": "<string>",
"reachability": "REACHABLE",
"version": "<string>"
},
"affected_platform": "<string>",
"port": 123,
"protocol": "<string>",
"service": "<string>"
}
],
"resources": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"state": "ACTIVE",
"type": "BRANCH",
"vendor": "<string>",
"vendor_attributes": {
"id": "<string>",
"data": {
"host_id": "<string>",
"vendor": "qualys",
"asset_id": "<string>",
"tracking_method": "<string>"
}
},
"cloud_metadata": {
"account_id": "<string>",
"account_name": "<string>",
"cloud_provider": "<string>",
"image_id": "<string>",
"instance_id": "<string>",
"instance_type": "<string>",
"region": "<string>",
"subnet_id": "<string>",
"vpc_id": "<string>"
},
"data": {
"hostnames": [
"<string>"
],
"image": "<string>"
},
"first_seen": "2023-11-07T05:31:56Z",
"groups": [
{
"name": "<string>",
"uid": "<string>"
}
],
"last_seen": "2023-11-07T05:31:56Z",
"tags": [
{
"key": "<string>",
"source": "wiz_vms",
"value": "<string>"
}
],
"url": "<string>"
}
],
"state_updated_at": "2023-11-07T05:31:56Z",
"ticket": {
"status": "<string>",
"uid": "<string>",
"url": "<string>"
},
"title": "<string>",
"vulnerabilities": [
{
"uid": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"cvss_scores": [
{
"score": 123,
"vector": "<string>",
"version": "<string>",
"severity": "<string>"
}
],
"description": "<string>",
"last_modified": "2023-11-07T05:31:56Z",
"published": "2023-11-07T05:31:56Z",
"references": [
{
"url": "<string>",
"source": "<string>",
"tags": [
"<string>"
]
}
],
"source_identifier": "<string>",
"status": "<string>",
"updated_at": "2023-11-07T05:31:56Z",
"weaknesses": [
"<string>"
]
}
]
}
],
"next_cursor": "<string>",
"previous_cursor": "<string>"
}{
"code": "<string>",
"detail": [
{}
],
"message": "<string>",
"type": "<string>"
}List Vulnerability Findings
List vulnerability findings with keyset pagination and filtering options.
- severity: Filter by severity (comma-separated list, e.g., ‘CRITICAL,HIGH’)
- state: Filter by state (comma-separated list, e.g., ‘OPEN,REOPENED’)
- has_fix: Filter by whether a fix is available
- reachability: Filter by reachability rollup (comma-separated list, e.g., ‘REACHABLE,POTENTIALLY_REACHABLE’)
- exploitable: Filter by exploitability (true/false); findings with no vendor signal match neither
- first_seen_since: Filter by findings first seen after this date
- last_seen_since: Filter by findings last seen after this date
- state_updated_since: Filter by findings with state updated after this date
- resourceId: Filter by resource ID (comma-separated list)
- ids: Filter by finding IDs (comma-separated list of UUIDs, max 100)
curl --request GET \
--url https://api.leen.dev/v2/vulnerability_findings \
--header 'X-API-KEY: <api-key>' \
--header 'X-CONNECTION-ID: <api-key>'import requests
url = "https://api.leen.dev/v2/vulnerability_findings"
headers = {
"X-API-KEY": "<api-key>",
"X-CONNECTION-ID": "<api-key>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {'X-API-KEY': '<api-key>', 'X-CONNECTION-ID': '<api-key>'}
};
fetch('https://api.leen.dev/v2/vulnerability_findings', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.leen.dev/v2/vulnerability_findings",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-KEY: <api-key>",
"X-CONNECTION-ID: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.leen.dev/v2/vulnerability_findings"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-KEY", "<api-key>")
req.Header.Add("X-CONNECTION-ID", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.leen.dev/v2/vulnerability_findings")
.header("X-API-KEY", "<api-key>")
.header("X-CONNECTION-ID", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.leen.dev/v2/vulnerability_findings")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-KEY"] = '<api-key>'
request["X-CONNECTION-ID"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"items": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"severity": "CRITICAL",
"state": "OPEN",
"type": "DEPENDENCY",
"vendor_attributes": {
"id": "<string>",
"severity": "<string>",
"state": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"data": {
"report_type": "SAST",
"scanner": {
"id": "<string>",
"name": "<string>",
"vendor": "<string>"
},
"vendor": "GITLAB"
},
"updated_at": "2023-11-07T05:31:56Z",
"url": "<string>",
"vulnerability_identifiers": [
{
"type": "CVE",
"value": "CVE-2021-34527"
}
]
},
"analytic": {
"name": "<string>",
"type": "<string>",
"uid": "<string>",
"url": "<string>"
},
"analytic_output": "<string>",
"description": "<string>",
"exploitable": true,
"first_seen": "2023-11-07T05:31:56Z",
"has_fix": true,
"last_seen": "2023-11-07T05:31:56Z",
"product": {
"name": "<string>",
"vendor_name": "<string>"
},
"reachability": "REACHABLE",
"remediation": "<string>",
"resource_related": [
{
"affected_code": {
"end_line_number": 123,
"file_path": "<string>",
"start_line_number": 123,
"url": "<string>"
},
"affected_image": "<string>",
"affected_os": "<string>",
"affected_package": {
"name": "<string>",
"package_manager": "<string>",
"reachability": "REACHABLE",
"version": "<string>"
},
"affected_platform": "<string>",
"port": 123,
"protocol": "<string>",
"service": "<string>"
}
],
"resources": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"state": "ACTIVE",
"type": "BRANCH",
"vendor": "<string>",
"vendor_attributes": {
"id": "<string>",
"data": {
"host_id": "<string>",
"vendor": "qualys",
"asset_id": "<string>",
"tracking_method": "<string>"
}
},
"cloud_metadata": {
"account_id": "<string>",
"account_name": "<string>",
"cloud_provider": "<string>",
"image_id": "<string>",
"instance_id": "<string>",
"instance_type": "<string>",
"region": "<string>",
"subnet_id": "<string>",
"vpc_id": "<string>"
},
"data": {
"hostnames": [
"<string>"
],
"image": "<string>"
},
"first_seen": "2023-11-07T05:31:56Z",
"groups": [
{
"name": "<string>",
"uid": "<string>"
}
],
"last_seen": "2023-11-07T05:31:56Z",
"tags": [
{
"key": "<string>",
"source": "wiz_vms",
"value": "<string>"
}
],
"url": "<string>"
}
],
"state_updated_at": "2023-11-07T05:31:56Z",
"ticket": {
"status": "<string>",
"uid": "<string>",
"url": "<string>"
},
"title": "<string>",
"vulnerabilities": [
{
"uid": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"cvss_scores": [
{
"score": 123,
"vector": "<string>",
"version": "<string>",
"severity": "<string>"
}
],
"description": "<string>",
"last_modified": "2023-11-07T05:31:56Z",
"published": "2023-11-07T05:31:56Z",
"references": [
{
"url": "<string>",
"source": "<string>",
"tags": [
"<string>"
]
}
],
"source_identifier": "<string>",
"status": "<string>",
"updated_at": "2023-11-07T05:31:56Z",
"weaknesses": [
"<string>"
]
}
]
}
],
"next_cursor": "<string>",
"previous_cursor": "<string>"
}{
"code": "<string>",
"detail": [
{}
],
"message": "<string>",
"type": "<string>"
}Query Parameters
Sort by a field, written as field, field:asc or field:desc. Which fields can be sorted on differs per endpoint.
^severity$|^severity\:asc$|^severity\:desc$|^updated_at$|^updated_at\:asc$|^updated_at\:desc$|^state_updated_at$|^state_updated_at\:asc$|^state_updated_at\:desc$Filter by severity (comma-separated list, e.g., 'CRITICAL,HIGH')
Filter by state (comma-separated list, e.g., 'OPEN,REOPENED')
Filter by whether a fix is available
Filter by reachability rollup (comma-separated list, e.g., 'REACHABLE,POTENTIALLY_REACHABLE'). Findings with no vendor signal match no value.
Filter by exploitability: true returns findings the vendor marked exploitable (typically a known exploit exists); false returns findings the vendor explicitly marked not exploitable. Findings with no vendor signal match neither true nor false.
Filter by findings first seen after this date
Filter by findings last seen after this date
Filter by findings with state updated after this date
Filter by resource ID (comma-separated list)
Filter by finding IDs (comma-separated list of UUIDs, max 100)
Only records whose updated_at is at or after this time. Leen bumps updated_at whenever any field on a record changes, so this is the filter for an incremental sync: it returns records that are new and records that changed, and nothing that has stood still. Example: 2021-01-01T00:00:00+00:00.
"2021-01-01T00:00:00+00:00"
Opaque position of the next page, taken from the previous response. Ignore its contents; it encodes where the walk had reached.
How many records to return per page. The walk is the same either way; a larger page means fewer round trips and more memory per response.
1 <= x <= 500Response
Successful Response
The records on this page.
Show child attributes
Show child attributes
Opaque position of the next page. Pass it back as cursor to continue; null when this is the last page.
Opaque position of the previous page, for walking backwards. Null on the first page.