Skip to main content
GET
List Vulnerability Findings

Authorizations

X-API-KEY
string
header
required
X-CONNECTION-ID
string
header
required

Query Parameters

sort
string | null

Sort by a field, written as field, field:asc or field:desc. Which fields can be sorted on differs per endpoint.

Pattern: ^severity$|^severity\:asc$|^severity\:desc$|^updated_at$|^updated_at\:asc$|^updated_at\:desc$|^state_updated_at$|^state_updated_at\:asc$|^state_updated_at\:desc$
severity
string | null

Filter by severity (comma-separated list, e.g., 'CRITICAL,HIGH')

state
string | null

Filter by state (comma-separated list, e.g., 'OPEN,REOPENED')

has_fix
boolean | null

Filter by whether a fix is available

reachability
string | null

Filter by reachability rollup (comma-separated list, e.g., 'REACHABLE,POTENTIALLY_REACHABLE'). Findings with no vendor signal match no value.

exploitable
boolean | null

Filter by exploitability: true returns findings the vendor marked exploitable (typically a known exploit exists); false returns findings the vendor explicitly marked not exploitable. Findings with no vendor signal match neither true nor false.

firstSeenSince
string<date-time> | null

Filter by findings first seen after this date

lastSeenSince
string<date-time> | null

Filter by findings last seen after this date

stateUpdatedSince
string<date-time> | null

Filter by findings with state updated after this date

resourceId
string | null

Filter by resource ID (comma-separated list)

ids
string | null

Filter by finding IDs (comma-separated list of UUIDs, max 100)

updatedSince
string<date-time> | null

Only records whose updated_at is at or after this time. Leen bumps updated_at whenever any field on a record changes, so this is the filter for an incremental sync: it returns records that are new and records that changed, and nothing that has stood still. Example: 2021-01-01T00:00:00+00:00.

Example:

"2021-01-01T00:00:00+00:00"

cursor
string | null

Opaque position of the next page, taken from the previous response. Ignore its contents; it encodes where the walk had reached.

limit
integer
default:100

How many records to return per page. The walk is the same either way; a larger page means fewer round trips and more memory per response.

Required range: 1 <= x <= 500

Response

Successful Response

items
VulnerabilityFindingV2 · object[]
required

The records on this page.

next_cursor
string | null

Opaque position of the next page. Pass it back as cursor to continue; null when this is the last page.

previous_cursor
string | null

Opaque position of the previous page, for walking backwards. Null on the first page.