开发者参考

漏洞情报

通过 DomScan API,发现公开网站上暴露的软件、高风险配置和已知受影响版本。每项结果都会说明检查了什么、为何匹配以及证据的可信程度。

漏洞情报

发现公开网站上暴露的软件、高风险配置和已知受影响版本。每项结果都会说明检查了什么、为何匹配以及证据的可信程度。

GET /v1/vulnerabilities

查询参数

参数类型说明
url 可选 string 要分析的完整公开 HTTP(S) URL。如果同时提供 URL 和域名,URL 优先。
domain 可选 string 要分析的公开域名或 HTTP(S) URL。请提供 URL 或域名之一。
mode 可选 string standard | deep 扫描模式: standard 是默认值,消耗 8 个积分,deep 添加隔离的 JavaScript 渲染,消耗 12 个积分。不接受其他值。

咨询来源和覆盖范围

将经过验证的公开技术版本与权威软件包安全公告、已知在野利用信息和利用概率相关联。DomScan会区分受影响版本、安全配置错误和未知覆盖范围,让团队优先修复证据最充分的问题。

字段说明
checked来源已被查询,结果反映在调查结果中。
not_requested没有要查询来源的内容。没有检测到的组件具有映射到已审查包的版本,因此未查询任何建议,也没有 CVE 到达利用来源。这是覆盖范围的限制,不是目标未受影响的证明。
partial / failed来源已被查询但响应不完整或完全无响应。受影响的组件保持未知,永远不会报告为安全。

请求示例

curl -H "X-API-Key: your-api-key" "https://domscan.net/v1/vulnerabilities?domain=example.com&mode=standard"   -H "x-api-key: YOUR_API_KEY"
import requests

domscan = requests.Session()
domscan.headers.update({"X-API-Key": "your-api-key"})

response = domscan.get(
    "https://domscan.net/v1/vulnerabilities",
    params={"domain": "example.com", "mode": "deep"},
    headers={"x-api-key": "YOUR_API_KEY"},
)
result = response.json()

print(result["summary"]["posture"])
print(result["coverage"]["package_advisories"])

响应字段

字段 类型
target object
target.requested_url string
target.final_url string
target.hostname string
scan object
scan.mode string
scan.status string
scan.checked_at string
scan.duration_ms integer
scan.disclaimer string
summary object
summary.posture string
summary.risk_level string
summary.finding_count integer
summary.version_affected_count integer
summary.misconfiguration_count integer
summary.urgent_count integer
summary.severity_counts object
findings[] object[]
findings[] object
findings[].fingerprint string
findings[].classification string
findings[].severity string
findings[].priority string
findings[].title string
findings[].summary string
findings[].component object
findings[].component.technology_id string
findings[].component.name string
findings[].component.detected_version string
findings[].component.version_kind string
findings[].component.confidence string
findings[].component.confidence_score integer
findings[].component.ecosystem string
findings[].component.package string
findings[].component.purl string
findings[].advisory object
findings[].advisory.id string
findings[].advisory.aliases[] string[]
findings[].advisory.cves[] string[]
findings[].advisory.published_at string | null
findings[].advisory.modified_at string | null
findings[].advisory.cvss[] object[]
findings[].advisory.cvss[] object
findings[].advisory.cvss[].type string
findings[].advisory.cvss[].vector string
findings[].advisory.fixed_versions[] string[]
findings[].advisory.affected_ranges[] object[]
findings[].advisory.affected_ranges[] object
findings[].advisory.references[] string[]
findings[].exploitation object
findings[].exploitation.cisa_kev boolean | null
findings[].exploitation.kev_added_at string | null
findings[].exploitation.kev_required_action string | null
findings[].exploitation.known_ransomware_use string | null
findings[].exploitation.epss_probability number | null
findings[].exploitation.epss_percentile number | null
findings[].exploitation.epss_date string | null
findings[].evidence object
findings[].evidence.confidence string
findings[].evidence.observed[] string[]
findings[].evidence.limitations[] string[]
findings[].remediation object
findings[].remediation.summary string
findings[].remediation.fixed_versions[] string[]
findings[].sources[] string[]
components[] object[]
components[] object
components[].technology_id string
components[].name string
components[].detected_version string | null
components[].version_kind string | null
components[].confidence string
components[].advisory_status string
components[].matched_advisories integer
coverage object
coverage.target_response string
coverage.technology_detection string
coverage.package_advisories string
coverage.known_exploitation string
coverage.exploitation_probability string
coverage.detected_components integer
coverage.versioned_components integer
coverage.advisory_eligible_components integer
coverage.advisory_checked_components integer
coverage.advisory_deferred_components integer
coverage.advisory_query_limit integer
coverage.relay_used boolean
coverage.limitations[] string[]
sources[] object[]
sources[] object
sources[].id string
sources[].name string
sources[].owner string
sources[].url string
sources[].status string
sources[].retrieved_at string | null
sources[].cache_hit boolean
sources[].expected_freshness string
sources[].fallback_behavior string
sources[].cost string
_meta object

响应示例

{
  "target": {
    "requested_url": "https://example.com",
    "final_url": "https://example.com",
    "hostname": "example.com"
  },
  "scan": {
    "mode": "standard",
    "status": "complete",
    "checked_at": "2026-08-27T12:00:00Z",
    "duration_ms": 1,
    "disclaimer": "example"
  },
  "summary": {
    "posture": "action_required",
    "risk_level": "critical",
    "finding_count": 1,
    "version_affected_count": 1,
    "misconfiguration_count": 1,
    "urgent_count": 1,
    "severity_counts": {}
  },
  "findings": [
    {
      "fingerprint": "example",
      "classification": "version_affected",
      "severity": "critical",
      "priority": "urgent",
      "title": "example",
      "summary": "example",
      "evidence": {
        "confidence": "high",
        "observed": [
          "example"
        ],
        "limitations": [
          "example"
        ]
      },
      "remediation": {
        "summary": "example",
        "fixed_versions": [
          "example"
        ]
      },
      "sources": [
        "osv"
      ],
      "component": {
        "technology_id": "example",
        "name": "example",
        "detected_version": "example",
        "version_kind": "product",
        "confidence": "high",
        "confidence_score": 85,
        "ecosystem": "example",
        "package": "example",
        "purl": "https://example.com"
      },
      "advisory": {
        "id": "example-id",
        "aliases": [
          "example"
        ],
        "cves": [
          "example"
        ],
        "published_at": "2026-08-27T12:00:00Z",
        "modified_at": "2026-08-27T12:00:00Z",
        "cvss": [
          {
            "type": "domain",
            "vector": "example"
          }
        ],
        "fixed_versions": [
          "example"
        ],
        "affected_ranges": [
          {}
        ],
        "references": [
          "https://example.com"
        ]
      },
      "exploitation": {
        "cisa_kev": false,
        "kev_added_at": "2026-08-27",
        "kev_required_action": "example",
        "known_ransomware_use": "example",
        "epss_probability": 0.85,
        "epss_percentile": 0.5,
        "epss_date": "2026-08-27"
      }
    }
  ],
  "components": [
    {
      "technology_id": "example",
      "name": "example",
      "detected_version": "example",
      "version_kind": "example",
      "confidence": "high",
      "advisory_status": "checked",
      "matched_advisories": 1
    }
  ],
  "coverage": {
    "target_response": "example",
    "technology_detection": "example",
    "package_advisories": "example",
    "known_exploitation": "example",
    "exploitation_probability": "example",
    "detected_components": 1,
    "versioned_components": 1,
    "advisory_eligible_components": 1,
    "advisory_checked_components": 1,
    "advisory_deferred_components": 1,
    "advisory_query_limit": 1,
    "relay_used": false,
    "limitations": [
      "example"
    ]
  },
  "sources": [
    {
      "id": "example-id",
      "name": "example",
      "owner": "example",
      "url": "https://example.com",
      "status": "available",
      "retrieved_at": "2026-08-27T12:00:00Z",
      "cache_hit": false,
      "expected_freshness": "example",
      "fallback_behavior": "example",
      "cost": "none"
    }
  ],
  "_meta": {}
}
覆盖范围和数据源: 未发现问题的结果无法证明应用不存在漏洞,也不能替代经授权的渗透测试。

被出色公司的人们使用

InstantOutseerMongoDBRespondentSage Expense ManagementInstantlyD.R. HortonWhatConvertsAdobeMotionElementsLLM Pulse