Skip to main content
GET
List Vulnerability Findings
reachability and exploitable are tri-state: a finding for which the vendor gave no signal carries null, and null matches neither filter value, so filtering a vendor that never reports the field returns an empty page. Use the capabilities block on List Integration Details to see which integrations populate these filters and which values they emit.

Authorizations

X-API-KEY
string
header
required
X-CONNECTION-ID
string
header
required

Query Parameters

sort
string | null

Sort by a field, written as field, field:asc or field:desc. Which fields can be sorted on differs per endpoint.

Pattern: ^severity$|^severity\:asc$|^severity\:desc$|^updated_at$|^updated_at\:asc$|^updated_at\:desc$|^state_updated_at$|^state_updated_at\:asc$|^state_updated_at\:desc$
severity
string | null

Filter by severity (comma-separated list, e.g., 'CRITICAL,HIGH')

state
string | null

Filter by state (comma-separated list, e.g., 'OPEN,REOPENED')

has_fix
boolean | null

Filter by whether a fix is available

reachability
string | null

Filter by reachability rollup (comma-separated list, e.g., 'REACHABLE,POTENTIALLY_REACHABLE'). Findings with no vendor signal match no value.

exploitable
boolean | null

Filter by exploitability: true returns findings the vendor marked exploitable (typically a known exploit exists); false returns findings the vendor explicitly marked not exploitable. Findings with no vendor signal match neither true nor false.

firstSeenSince
string<date-time> | null

Filter by findings first seen after this date

lastSeenSince
string<date-time> | null

Filter by findings last seen after this date

stateUpdatedSince
string<date-time> | null

Filter by findings with state updated after this date

resourceId
string | null

Filter by resource ID (comma-separated list)

ids
string | null

Filter by finding IDs (comma-separated list of UUIDs, max 100)

updatedSince
string<date-time> | null

Only records whose updated_at is at or after this time. Leen bumps updated_at whenever any field on a record changes, so this is the filter for an incremental sync: it returns records that are new and records that changed, and nothing that has stood still. Example: 2021-01-01T00:00:00+00:00.

Example:

"2021-01-01T00:00:00+00:00"

cursor
string | null

Opaque position of the next page, taken from the previous response. Ignore its contents; it encodes where the walk had reached.

limit
integer
default:100

How many records to return per page. The walk is the same either way; a larger page means fewer round trips and more memory per response.

Required range: 1 <= x <= 500

Response

Successful Response

items
VulnerabilityFindingV2 · object[]
required

The records on this page.

next_cursor
string | null

Opaque position of the next page. Pass it back as cursor to continue; null when this is the last page.

previous_cursor
string | null

Opaque position of the previous page, for walking backwards. Null on the first page.