Hiviexd/cve-tracker

React/Express hackathon project for analyzing CVEs

★ 0Forks 0JavaScriptGitHub ↗Compare

README

CVE Tracker

A hackathon React/Vite app for analyzing CVEs and vendor risk using live NVD, EPSS, and CISA KEV data.

Architecture (frontend)

  • Vite + React with React Router (/ analyze, /overview vendor view).
  • Tailwind + shadcn-style tokens in src/index.css; dark/light handled via a useTheme hook toggling the dark class.
  • UI composed of small reusable components (src/components/ui) plus feature folders (components/analyze, components/overview).
  • Data access is via src/api/client (fetches the backend API described below).

Website functionality

  • Analyze page (/):
    • Paste one or more CVE IDs; submits to the analyze API.
    • Shows summary stats (total CVEs, KEV flagged, avg CVSS/EPSS) and per-CVE cards with CVSS/impact/exploitability/EPSS, CWE badges, and collapsible affected list.
  • Vendor Overview page (/overview):
    • Vendor + period inputs (1m/3m/6m/1y) call the overview API.
    • Displays averages (CVSS/EPSS), KEV count, most common CWE, top CVSS/EPSS lists with expandable summaries, and a CVSS trend bar chart.
  • Global layout in AppLayout with navigation and theme toggle (sun/moon).

API routes

POST /api/cve/analyze

  • Body: { "cves": ["CVE-2023-34362", "CVE-2021-44228"] }
  • Success 200:
    • results[] with id, cvss { score, impact, exploitability }, epss, cwe[], exploited (KEV), summary, affected[], and raw sources.
{
    "results": [
        {
            "id": "CVE-2023-34362",
            "cvss": { "score": 9.8, "impact": 5.9, "exploitability": 3.9 },
            "epss": 0.92,
            "cwe": ["CWE-79"],
            "exploited": true,
            "summary": "Remote code execution in ...",
            "affected": ["cpe:2.3:a:vendor:product:version:*:*:*:*:*:*:*"],
            "sources": {
                "nvd": { "...": "raw NVD payload" },
                "epss": { "...": "raw EPSS payload" },
                "kev": { "...": "raw KEV payload" }
            }
        }
    ]
}
  • Errors:
    • 400 { "error": "Invalid input", "details": "Body must include cves array" }
    • 500 { "error": "Something went wrong", "details": "<message>" }

GET /api/overview

  • Query: vendor (required), period in 1m|3m|6m|1y (default 3m).
  • Success 200:
    • vendor, period, topCvss[] { id, score, summary }, topEpss[] { id, epss, summary }, avgCvss, avgEpss, mostCommonCwe, exploitedCount, trend[] { month, avg }.
{
    "vendor": "Oracle",
    "period": "3m",
    "topCvss": [{ "id": "CVE-2024-1234", "score": 9.8, "summary": "..." }],
    "topEpss": [{ "id": "CVE-2023-9999", "epss": 0.91, "summary": "..." }],
    "avgCvss": 7.2,
    "avgEpss": 0.32,
    "mostCommonCwe": "CWE-79",
    "exploitedCount": 4,
    "trend": [
        { "month": "2025-01", "avg": 7.1 },
        { "month": "2025-02", "avg": 6.8 }
    ]
}
  • Errors:
    • 400 { "error": "Invalid input", "details": "vendor is required" } or period validation message.
    • 500 { "error": "Something went wrong", "details": "<message>" }

Contributors

Hiviexd

Issues