VulnerabilitiesList vulnerabilities

List vulnerabilities

Returns third-party vulnerability findings for the authenticated tenant. count is 50 or 100 and defaults to 50. vulnerabilityId is URL-encoded so it can be used as the path segment on GET and PATCH. Default items include id, title, status, severity, source, assignees, CVE, and custom fields. Filter with status, severity, fixAvailable, and source (comma-separated VM app ids). These filters are applied by the vulnerability service. Request extra columns with fields (comma-separated). Pass meta.nextCursor back as the nextCursor query parameter to fetch the next page. It is null when there are no further findings. meta.totalCount is the number of matching findings across all pages. Requires scope vulnerability:read or vulnerability:write.

curl -X GET "https://api.scrut.io/v1/vulnerabilities?status=open%2Cacknowledged&severity=critical%2Chigh&source=aws%2Capi&fixAvailable=yes&count=50&nextCursor=xK9m2pQ7vL4nR8wT1yU6zA3bC5dE0fG2hI4jK6lM8nO0pQ2rS4tU6vW8xY0zA2bC4dE6fG8hI0jK2lM4nO6pQ8rS0tU2vW&fields=cvssScore%2CresourcesCount%2CfirstSeen" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN (JWT)"
{
  "data": [
    {
      "vulnerabilityId": "import%23CVE-2024-1234",
      "title": "Public S3 bucket",
      "status": "open",
      "severity": "high",
      "source": "import",
      "assignees": [
        {
          "name": "Alex Rivera",
          "email": "alex@example.com",
          "isPrimary": true
        }
      ],
      "cveId": "CVE-2024-1234",
      "customFields": []
    }
  ],
  "meta": {
    "requestId": "550e8400-e29b-41d4-a716-446655440000",
    "nextCursor": "xK9m2pQ7vL4nR8wT1yU6zA3bC5dE0fG2hI4jK6lM8nO0pQ2rS4tU6vW8xY0zA2bC4dE6fG8hI0jK2lM4nO6pQ8rS0tU2vW",
    "totalCount": 200
  }
}
GET
/v1/vulnerabilities
GET
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token (JWT)
Bearer Tokenstring
Required

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
query
statusstring

Filter by status. ignored and risk are sent as their vulnerability-service status codes. Pass a comma-separated list (no spaces required). Allowed values: open, closed, acknowledged, ignored, risk.

query
severitystring

Filter by severity. Pass a comma-separated list (no spaces required). Allowed values: critical, high, medium, low.

query
sourcestring

Filter by VM app id. Comma-separated values are forwarded to the vulnerability service as source. Pass a comma-separated list (no spaces required). Allowed values: aws, github, snyk, sonarcloud, qualys, defender, sentinelOne, aikido, tenable, import, api.

query
fixAvailablestring

Filter by whether a fix is available. Pass a comma-separated list (no spaces required). Allowed values: yes, no.

query
countinteger

Page size. Defaults to 50.

Options: 50, 100
query
nextCursorstring

Opaque cursor from the previous list response meta.nextCursor. Omit it on the first page.

query
fieldsstring

Additional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: cvssScore, resourcesCount, firstSeen.

Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token (JWT). Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Query Parameters

statusstring

Filter by status. ignored and risk are sent as their vulnerability-service status codes. Pass a comma-separated list (no spaces required). Allowed values: open, closed, acknowledged, ignored, risk.

Example:
open,acknowledged
severitystring

Filter by severity. Pass a comma-separated list (no spaces required). Allowed values: critical, high, medium, low.

Example:
critical,high
sourcestring

Filter by VM app id. Comma-separated values are forwarded to the vulnerability service as source. Pass a comma-separated list (no spaces required). Allowed values: aws, github, snyk, sonarcloud, qualys, defender, sentinelOne, aikido, tenable, import, api.

Example:
aws,api
fixAvailablestring

Filter by whether a fix is available. Pass a comma-separated list (no spaces required). Allowed values: yes, no.

Example:
yes
countinteger

Page size. Defaults to 50.

Allowed values:50100
nextCursorstring

Opaque cursor from the previous list response meta.nextCursor. Omit it on the first page.

Example:
xK9m2pQ7vL4nR8wT1yU6zA3bC5dE0fG2hI4jK6lM8nO0pQ2rS4tU6vW8xY0zA2bC4dE6fG8hI0jK2lM4nO6pQ8rS0tU2vW
fieldsstring

Additional list columns. Default list items omit these keys until requested. Pass a comma-separated list (no spaces required). Allowed values: cvssScore, resourcesCount, firstSeen.

Example:
cvssScore,resourcesCount,firstSeen

Responses

dataarray
Required
metastring
Required