A hackathon React/Vite app for analyzing CVEs and vendor risk using live NVD, EPSS, and CISA KEV data.
- Vite + React with React Router (
/analyze,/overviewvendor view). - Tailwind + shadcn-style tokens in
src/index.css; dark/light handled via auseThemehook toggling thedarkclass. - UI composed of small reusable components (
src/components/ui) plus feature folders (components/analyze,components/overview). - Data access is via
src/api/client(fetches the backend API described below).
- Analyze page (
/):- Paste one or more CVE IDs; submits to the analyze API.
- Shows summary stats (total CVEs, KEV flagged, avg CVSS/EPSS) and per-CVE cards with CVSS/impact/exploitability/EPSS, CWE badges, and collapsible affected list.
- Vendor Overview page (
/overview):- Vendor + period inputs (1m/3m/6m/1y) call the overview API.
- Displays averages (CVSS/EPSS), KEV count, most common CWE, top CVSS/EPSS lists with expandable summaries, and a CVSS trend bar chart.
- Global layout in
AppLayoutwith navigation and theme toggle (sun/moon).
- Body:
{ "cves": ["CVE-2023-34362", "CVE-2021-44228"] } - Success 200:
results[]withid,cvss { score, impact, exploitability },epss,cwe[],exploited(KEV),summary,affected[], and rawsources.
{
"results": [
{
"id": "CVE-2023-34362",
"cvss": { "score": 9.8, "impact": 5.9, "exploitability": 3.9 },
"epss": 0.92,
"cwe": ["CWE-79"],
"exploited": true,
"summary": "Remote code execution in ...",
"affected": ["cpe:2.3:a:vendor:product:version:*:*:*:*:*:*:*"],
"sources": {
"nvd": { "...": "raw NVD payload" },
"epss": { "...": "raw EPSS payload" },
"kev": { "...": "raw KEV payload" }
}
}
]
}- Errors:
- 400
{ "error": "Invalid input", "details": "Body must include cves array" } - 500
{ "error": "Something went wrong", "details": "<message>" }
- 400
- Query:
vendor(required),periodin1m|3m|6m|1y(default 3m). - Success 200:
vendor,period,topCvss[] { id, score, summary },topEpss[] { id, epss, summary },avgCvss,avgEpss,mostCommonCwe,exploitedCount,trend[] { month, avg }.
{
"vendor": "Oracle",
"period": "3m",
"topCvss": [{ "id": "CVE-2024-1234", "score": 9.8, "summary": "..." }],
"topEpss": [{ "id": "CVE-2023-9999", "epss": 0.91, "summary": "..." }],
"avgCvss": 7.2,
"avgEpss": 0.32,
"mostCommonCwe": "CWE-79",
"exploitedCount": 4,
"trend": [
{ "month": "2025-01", "avg": 7.1 },
{ "month": "2025-02", "avg": 6.8 }
]
}- Errors:
- 400
{ "error": "Invalid input", "details": "vendor is required" }or period validation message. - 500
{ "error": "Something went wrong", "details": "<message>" }
- 400