curl --request GET \
--url https://api.leen.dev/v1/vms/vulnerabilities \
--header 'X-API-KEY: <api-key>' \
--header 'X-CONNECTION-ID: <api-key>'import requests
url = "https://api.leen.dev/v1/vms/vulnerabilities"
headers = {
"X-API-KEY": "<api-key>",
"X-CONNECTION-ID": "<api-key>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {'X-API-KEY': '<api-key>', 'X-CONNECTION-ID': '<api-key>'}
};
fetch('https://api.leen.dev/v1/vms/vulnerabilities', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.leen.dev/v1/vms/vulnerabilities",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-KEY: <api-key>",
"X-CONNECTION-ID: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.leen.dev/v1/vms/vulnerabilities"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-KEY", "<api-key>")
req.Header.Add("X-CONNECTION-ID", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.leen.dev/v1/vms/vulnerabilities")
.header("X-API-KEY", "<api-key>")
.header("X-CONNECTION-ID", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.leen.dev/v1/vms/vulnerabilities")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-KEY"] = '<api-key>'
request["X-CONNECTION-ID"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"count": 123,
"items": [
{
"category": "web",
"cert_id": "<string>",
"cve": [
"<string>"
],
"cvss_base_score": 123,
"cvss_temporal_score": 123,
"cvss_temporal_vector": "<string>",
"cvss_vector": "<string>",
"cvss_version": "<string>",
"description": "<string>",
"first_seen": "2023-11-07T05:31:56Z",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"last_seen": "2023-11-07T05:31:56Z",
"name": "<string>",
"patchable": true,
"port": 123,
"protocol": "<string>",
"scan_output": "<string>",
"service": "<string>",
"solution": "<string>",
"state_updated_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"vendor": "tenable",
"vendor_id": "<string>",
"vendor_scan_id": "<string>",
"vendor_severity": "<string>",
"device": {
"ad_info": {
"device_id": "<string>",
"domain": "<string>",
"org_unit": "<string>",
"site_name": "<string>"
},
"first_seen": "2023-11-07T05:31:56Z",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"installed_software": [
"<string>"
],
"last_seen": "2023-11-07T05:31:56Z",
"source_vendors": [
{
"vendor": "<string>",
"vendor_id": "<string>",
"agent_info": {
"agent_version": "<string>",
"policies": [
{}
],
"signature_version": "<string>"
}
}
],
"status": "active",
"cloud_metadata": {
"account_id": "<string>",
"availability_zone": "<string>",
"cloud_provider": "aws",
"image_id": "<string>",
"instance_id": "<string>",
"instance_type": "<string>",
"kernel_id": "<string>",
"region": "<string>",
"subnet_id": "<string>",
"vpc_id": "<string>"
},
"fqdns": [
"<string>"
],
"hostnames": [
"<string>"
],
"identities": [
{
"username": "<string>",
"user_sid": "<string>"
}
],
"ipv4s": [
"<string>"
],
"ipv6s": [
"<string>"
],
"mac_addresses": [
"<string>"
],
"os_major_version": "<string>",
"os_minor_version": "<string>",
"os_version": "<string>",
"platform": "mac",
"tags": [
{
"key": "<string>",
"source": "aws",
"value": "<string>"
}
],
"vendor_data": {}
},
"exploitable": true,
"reachability": "reachable",
"resource": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"state": "ACTIVE",
"type": "BRANCH",
"vendor": "<string>",
"vendor_attributes": {
"id": "<string>",
"data": {
"host_id": "<string>",
"vendor": "qualys",
"asset_id": "<string>",
"tracking_method": "<string>"
}
},
"cloud_metadata": {
"account_id": "<string>",
"account_name": "<string>",
"cloud_provider": "<string>",
"image_id": "<string>",
"instance_id": "<string>",
"instance_type": "<string>",
"region": "<string>",
"subnet_id": "<string>",
"vpc_id": "<string>"
},
"data": {
"hostnames": [
"<string>"
],
"image": "<string>"
},
"first_seen": "2023-11-07T05:31:56Z",
"groups": [
{
"name": "<string>",
"uid": "<string>"
}
],
"last_seen": "2023-11-07T05:31:56Z",
"tags": [
{
"key": "<string>",
"source": "wiz_vms",
"value": "<string>"
}
],
"url": "<string>"
},
"severity": "none",
"state": "open",
"vendor_data": {},
"vulnerability_url": "<string>"
}
],
"total": 123
}{
"code": "<string>",
"detail": [
{}
],
"message": "<string>",
"type": "<string>"
}List Vulnerabilities
List all the vulnerabilities for a given connection.
curl --request GET \
--url https://api.leen.dev/v1/vms/vulnerabilities \
--header 'X-API-KEY: <api-key>' \
--header 'X-CONNECTION-ID: <api-key>'import requests
url = "https://api.leen.dev/v1/vms/vulnerabilities"
headers = {
"X-API-KEY": "<api-key>",
"X-CONNECTION-ID": "<api-key>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {
method: 'GET',
headers: {'X-API-KEY': '<api-key>', 'X-CONNECTION-ID': '<api-key>'}
};
fetch('https://api.leen.dev/v1/vms/vulnerabilities', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.leen.dev/v1/vms/vulnerabilities",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-KEY: <api-key>",
"X-CONNECTION-ID: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.leen.dev/v1/vms/vulnerabilities"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-KEY", "<api-key>")
req.Header.Add("X-CONNECTION-ID", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.leen.dev/v1/vms/vulnerabilities")
.header("X-API-KEY", "<api-key>")
.header("X-CONNECTION-ID", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.leen.dev/v1/vms/vulnerabilities")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-KEY"] = '<api-key>'
request["X-CONNECTION-ID"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"count": 123,
"items": [
{
"category": "web",
"cert_id": "<string>",
"cve": [
"<string>"
],
"cvss_base_score": 123,
"cvss_temporal_score": 123,
"cvss_temporal_vector": "<string>",
"cvss_vector": "<string>",
"cvss_version": "<string>",
"description": "<string>",
"first_seen": "2023-11-07T05:31:56Z",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"last_seen": "2023-11-07T05:31:56Z",
"name": "<string>",
"patchable": true,
"port": 123,
"protocol": "<string>",
"scan_output": "<string>",
"service": "<string>",
"solution": "<string>",
"state_updated_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"vendor": "tenable",
"vendor_id": "<string>",
"vendor_scan_id": "<string>",
"vendor_severity": "<string>",
"device": {
"ad_info": {
"device_id": "<string>",
"domain": "<string>",
"org_unit": "<string>",
"site_name": "<string>"
},
"first_seen": "2023-11-07T05:31:56Z",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"installed_software": [
"<string>"
],
"last_seen": "2023-11-07T05:31:56Z",
"source_vendors": [
{
"vendor": "<string>",
"vendor_id": "<string>",
"agent_info": {
"agent_version": "<string>",
"policies": [
{}
],
"signature_version": "<string>"
}
}
],
"status": "active",
"cloud_metadata": {
"account_id": "<string>",
"availability_zone": "<string>",
"cloud_provider": "aws",
"image_id": "<string>",
"instance_id": "<string>",
"instance_type": "<string>",
"kernel_id": "<string>",
"region": "<string>",
"subnet_id": "<string>",
"vpc_id": "<string>"
},
"fqdns": [
"<string>"
],
"hostnames": [
"<string>"
],
"identities": [
{
"username": "<string>",
"user_sid": "<string>"
}
],
"ipv4s": [
"<string>"
],
"ipv6s": [
"<string>"
],
"mac_addresses": [
"<string>"
],
"os_major_version": "<string>",
"os_minor_version": "<string>",
"os_version": "<string>",
"platform": "mac",
"tags": [
{
"key": "<string>",
"source": "aws",
"value": "<string>"
}
],
"vendor_data": {}
},
"exploitable": true,
"reachability": "reachable",
"resource": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"state": "ACTIVE",
"type": "BRANCH",
"vendor": "<string>",
"vendor_attributes": {
"id": "<string>",
"data": {
"host_id": "<string>",
"vendor": "qualys",
"asset_id": "<string>",
"tracking_method": "<string>"
}
},
"cloud_metadata": {
"account_id": "<string>",
"account_name": "<string>",
"cloud_provider": "<string>",
"image_id": "<string>",
"instance_id": "<string>",
"instance_type": "<string>",
"region": "<string>",
"subnet_id": "<string>",
"vpc_id": "<string>"
},
"data": {
"hostnames": [
"<string>"
],
"image": "<string>"
},
"first_seen": "2023-11-07T05:31:56Z",
"groups": [
{
"name": "<string>",
"uid": "<string>"
}
],
"last_seen": "2023-11-07T05:31:56Z",
"tags": [
{
"key": "<string>",
"source": "wiz_vms",
"value": "<string>"
}
],
"url": "<string>"
},
"severity": "none",
"state": "open",
"vendor_data": {},
"vulnerability_url": "<string>"
}
],
"total": 123
}{
"code": "<string>",
"detail": [
{}
],
"message": "<string>",
"type": "<string>"
}reachability and exploitable are tri-state: a vulnerability for which the vendor gave no signal carries null, and null matches neither filter value, so filtering a vendor that never reports the field returns an empty page. Use the capabilities block on List Integration Details to see which integrations populate these filters, and severity, state, category, port, protocol and cve, and which values they emit. protocol is matched case-sensitively and vendors differ in case; the block’s notes say which each emits.Query Parameters
Sort by a field, written as field, field:asc or field:desc. Which fields can be sorted on differs per endpoint.
^severity$|^severity\:asc$|^severity\:desc$|^updated_at$|^updated_at\:asc$|^updated_at\:desc$|^state_updated_at$|^state_updated_at\:asc$|^state_updated_at\:desc$Datetime filter, only return vulnerabilities where the state was updated since this datetime. Example format: 2021-01-01T00:00:00+00:00
"2021-01-01T00:00:00+00:00"
Datetime filter, only return vulnerabilities where the first seen since this datetime. Example format: 2021-01-01T00:00:00+00:00
"2021-01-01T00:00:00+00:00"
Datetime filter, only return vulnerabilities where the last seen since this datetime. Example format: 2021-01-01T00:00:00+00:00
"2021-01-01T00:00:00+00:00"
Device ID Filter, comma separated
"123e4567-e89b-12d3-a456-426614174000, 123e4567-e89b-12d3-a456-426614174001"
Resource ID Filter, comma separated
"123e4567-e89b-12d3-a456-426614174000, 123e4567-e89b-12d3-a456-426614174001"
Vulnerability severity filter, comma separated
"critical,high"
Vulnerability state filter, comma separated
"open,closed"
Filter by whether the vendor asserts the vulnerability is exploitable — a known exploit exists, or it is actively exploited. Vulnerabilities where the vendor reported no signal match neither true nor false.
true
Reachability filter, comma separated. One or more of reachable, potentially_reachable, unreachable, unknown -- matching the values this endpoint returns; either case is accepted. unknown means the vendor analyzed the vulnerability without reaching a conclusion; vulnerabilities from vendors with no reachability analysis at all are excluded by any value.
"reachable,potentially_reachable"
Port number filter, comma separated
"80,443"
Protocol filter, comma separated
"tcp,udp"
Vulnerability category filter, comma separated
"web,network"
CVE ID filter, comma separated
"CVE-2021-1234,CVE-2021-5678"
Include device groups in the devices attached to the vulnerability
Device group ID filter, comma separated
"123e4567-e89b-12d3-a456-426614174002, 123e4567-e89b-12d3-a456-426614174003"
Vulnerability ID filter, comma separated. Need to be valid UUIDs. Max 100 IDs
"123e4567-e89b-12d3-a456-426614174004,123e4567-e89b-12d3-a456-426614174005"
Enable cursor based pagination instead of default offset-based pagination
Only records whose updated_at is at or after this time. Leen bumps updated_at whenever any field on a record changes, so this is the filter for an incremental sync: it returns records that are new and records that changed, and nothing that has stood still. Example: 2021-01-01T00:00:00+00:00.
"2021-01-01T00:00:00+00:00"
How many records to return per page. The walk is the same either way; a larger page means fewer round trips and more memory per response.
1 <= x <= 500Where to start, counted in records. Offset paging is stable only while the underlying data is; prefer the cursor for anything long-running.
x >= 0Skip counting the total. Counting is the expensive half of a large query, so set this when you are walking every page anyway and never read total. total comes back null.
Opaque position of the next page, taken from the previous response. Ignore its contents; it encodes where the walk had reached.
Response
Successful Response