List vulnerabilities
Returns third-party vulnerability findings for the authenticated tenant. count is 50 or 100 and defaults to 50.
vulnerabilityId is URL-encoded so it can be used as the path segment on GET and PATCH.
Default items include id, title, status, severity, source, assignees, CVE, and custom fields.
Filter with status, severity, fixAvailable, and source (comma-separated VM app ids). These filters are applied by the vulnerability service.
Request extra columns with fields (comma-separated).
Pass meta.nextCursor back as the nextCursor query parameter to fetch the next page. It is null when there are no further findings.
meta.totalCount is the number of matching findings across all pages.
Requires scope vulnerability:read or vulnerability:write.
curl -X GET "https://api.scrut.io/v1/vulnerabilities?status=open%2Cacknowledged&severity=critical%2Chigh&source=aws%2Capi&fixAvailable=yes&count=50&nextCursor=xK9m2pQ7vL4nR8wT1yU6zA3bC5dE0fG2hI4jK6lM8nO0pQ2rS4tU6vW8xY0zA2bC4dE6fG8hI0jK2lM4nO6pQ8rS0tU2vW&fields=cvssScore%2CresourcesCount%2CfirstSeen" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN (JWT)"
import requests
import json
url = "https://api.scrut.io/v1/vulnerabilities?status=open%2Cacknowledged&severity=critical%2Chigh&source=aws%2Capi&fixAvailable=yes&count=50&nextCursor=xK9m2pQ7vL4nR8wT1yU6zA3bC5dE0fG2hI4jK6lM8nO0pQ2rS4tU6vW8xY0zA2bC4dE6fG8hI0jK2lM4nO6pQ8rS0tU2vW&fields=cvssScore%2CresourcesCount%2CfirstSeen"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)"
}
response = requests.get(url, headers=headers)
print(response.json())
const response = await fetch("https://api.scrut.io/v1/vulnerabilities?status=open%2Cacknowledged&severity=critical%2Chigh&source=aws%2Capi&fixAvailable=yes&count=50&nextCursor=xK9m2pQ7vL4nR8wT1yU6zA3bC5dE0fG2hI4jK6lM8nO0pQ2rS4tU6vW8xY0zA2bC4dE6fG8hI0jK2lM4nO6pQ8rS0tU2vW&fields=cvssScore%2CresourcesCount%2CfirstSeen", {
method: "GET",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)"
}
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://api.scrut.io/v1/vulnerabilities?status=open%2Cacknowledged&severity=critical%2Chigh&source=aws%2Capi&fixAvailable=yes&count=50&nextCursor=xK9m2pQ7vL4nR8wT1yU6zA3bC5dE0fG2hI4jK6lM8nO0pQ2rS4tU6vW8xY0zA2bC4dE6fG8hI0jK2lM4nO6pQ8rS0tU2vW&fields=cvssScore%2CresourcesCount%2CfirstSeen", nil)
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN (JWT)")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://api.scrut.io/v1/vulnerabilities?status=open%2Cacknowledged&severity=critical%2Chigh&source=aws%2Capi&fixAvailable=yes&count=50&nextCursor=xK9m2pQ7vL4nR8wT1yU6zA3bC5dE0fG2hI4jK6lM8nO0pQ2rS4tU6vW8xY0zA2bC4dE6fG8hI0jK2lM4nO6pQ8rS0tU2vW&fields=cvssScore%2CresourcesCount%2CfirstSeen')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Get.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN (JWT)'
response = http.request(request)
puts response.body
{
"data": [
{
"vulnerabilityId": "import%23CVE-2024-1234",
"title": "Public S3 bucket",
"status": "open",
"severity": "high",
"source": "import",
"assignees": [
{
"name": "Alex Rivera",
"email": "alex@example.com",
"isPrimary": true
}
],
"cveId": "CVE-2024-1234",
"customFields": []
}
],
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000",
"nextCursor": "xK9m2pQ7vL4nR8wT1yU6zA3bC5dE0fG2hI4jK6lM8nO0pQ2rS4tU6vW8xY0zA2bC4dE6fG8hI0jK2lM4nO6pQ8rS0tU2vW",
"totalCount": 200
}
}
{
"error": {
"code": "validation_failed",
"message": "Request validation failed.",
"details": [
{
"field": "status",
"message": "status contains unknown value(s): unknown"
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "unauthorized",
"message": "Missing, malformed, or invalid Bearer token.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "token_revoked",
"message": "The API credential was revoked.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "token_stale",
"message": "The access token is stale; obtain a new token.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "forbidden",
"message": "Insufficient scope.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "not_found",
"message": "The requested resource was not found.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "rate_limit_exceeded",
"message": "Rate limit exceeded.",
"details": [
{
"retryAfterSec": 12
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "internal_error",
"message": "An unexpected error occurred.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "upstream_unavailable",
"message": "Upstream service is unavailable.",
"details": [
{
"dependency": "frameworks",
"issue": "Failed to process frameworks."
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
/v1/vulnerabilities
Target server for requests. Edit to use your own host.
Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.Filter by status. ignored and risk are sent as their vulnerability-service status codes. Pass a comma-separated list (no spaces required). Allowed values: open, closed, acknowledged, ignored, risk.
Filter by severity. Pass a comma-separated list (no spaces required). Allowed values: critical, high, medium, low.
Filter by VM app id. Comma-separated values are forwarded to the vulnerability service as source. Pass a comma-separated list (no spaces required). Allowed values: aws, github, snyk, sonarcloud, qualys, defender, sentinelOne, aikido, tenable, import, api.
Filter by whether a fix is available. Pass a comma-separated list (no spaces required). Allowed values: yes, no.
Page size. Defaults to 50.
Opaque cursor from the previous list response meta.nextCursor. Omit it on the first page.
Additional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: cvssScore, resourcesCount, firstSeen.
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token (JWT). Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
Query Parameters
Filter by status. ignored and risk are sent as their vulnerability-service status codes. Pass a comma-separated list (no spaces required). Allowed values: open, closed, acknowledged, ignored, risk.
open,acknowledgedFilter by severity. Pass a comma-separated list (no spaces required). Allowed values: critical, high, medium, low.
critical,highFilter by VM app id. Comma-separated values are forwarded to the vulnerability service as source. Pass a comma-separated list (no spaces required). Allowed values: aws, github, snyk, sonarcloud, qualys, defender, sentinelOne, aikido, tenable, import, api.
aws,apiFilter by whether a fix is available. Pass a comma-separated list (no spaces required). Allowed values: yes, no.
yesOpaque cursor from the previous list response meta.nextCursor. Omit it on the first page.
xK9m2pQ7vL4nR8wT1yU6zA3bC5dE0fG2hI4jK6lM8nO0pQ2rS4tU6vW8xY0zA2bC4dE6fG8hI0jK2lM4nO6pQ8rS0tU2vWAdditional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: cvssScore, resourcesCount, firstSeen.
cvssScore,resourcesCount,firstSeen