Empirical Security Empirical Security

Findings

GET https://app.empiricalsecurity.com/api/findings/{finding_id}

Retrieve a finding by finding_id

Provides the most up-to-date data about a finding.

Authentication: Bearer token required

Parameters

Name Type Required Description
finding_id uuid Yes The id of the finding to return, a UUID
Example: e08d933b-ddba-45b3-a5e7-b769faf4d606

Response 200

successful

{
  "finding_id": "e08d933b-ddba-45b3-a5e7-b769faf4d606",
  "asset_id": "10c7ad0e-8ee6-4899-9ec0-bd04d4e6cabf",
  "asset_display_name": "10c7ad0e-8ee6-4899-9ec0-bd04d4e6cabf",
  "source_id": "5573091f-682b-415e-a99b-c7b0d7089fc3",
  "vuln_id": "fde24752-6378-40bf-8e26-d4afe7dd7156",
  "state": "active",
  "severity": "high",
  "vendor": "example_vendor",
  "vendor_issue_id": "c2419cc2-95f5-40d2-bda8-af6847b31e79",
  "title": "Example finding",
  "description": "This finding is an example.",
  "first_seen": "2026-09-01T10:10:10.123Z",
  "last_seen": "2026-09-21T10:10:10.123Z",
  "state_updated_at": "2026-09-21T10:10:10.123Z",
  "port": 3500,
  "protocol": "tcp",
  "service": "example_service",
  "affected_package": "example package",
  "affected_file_path": "/usr/bin/example",
  "scan_output": "example package on port 3500 has a problem",
  "has_fix": false,
  "remediation": null,
  "vulnerability_url": null,
  "vendor_attributes_url": null,
  "scores": {
    "global": 0.9713943314711305
  },
  "cve_identifiers": [
    "CVE-2023-49103"
  ],
  "cve_rels": [
    "https://example.com/api/cves/CVE-2023-49103"
  ]
}

Response 404

not_found

{
  "error": {
    "code": "not_found",
    "message": "Not found"
  }
}
GET https://app.empiricalsecurity.com/api/findings/search

Retrieve findings by search query

Lists matching findings for the search query

Authentication: Bearer token required

Parameters

Name Type Required Description
q string No The query to execute, using Empirical search syntax
Example: cve_score:>90
scoring_model string No The key of the scoring/model to use for the search (e.g., epss_v5, global, etc.)

Response 200

successful

[
  {
    "finding_id": "e08d933b-ddba-45b3-a5e7-b769faf4d606",
    "asset_id": "10c7ad0e-8ee6-4899-9ec0-bd04d4e6cabf",
    "asset_display_name": "10c7ad0e-8ee6-4899-9ec0-bd04d4e6cabf",
    "source_id": "5573091f-682b-415e-a99b-c7b0d7089fc3",
    "vuln_id": "fde24752-6378-40bf-8e26-d4afe7dd7156",
    "state": "active",
    "severity": "high",
    "vendor": "example_vendor",
    "vendor_issue_id": "c2419cc2-95f5-40d2-bda8-af6847b31e79",
    "title": "Example finding",
    "description": "This finding is an example.",
    "first_seen": "2026-09-01T10:10:10.123Z",
    "last_seen": "2026-09-21T10:10:10.123Z",
    "state_updated_at": "2026-09-21T10:10:10.123Z",
    "port": 3500,
    "protocol": "tcp",
    "service": "example_service",
    "affected_package": "example package",
    "affected_file_path": "/usr/bin/example",
    "scan_output": "example package on port 3500 has a problem",
    "has_fix": false,
    "remediation": null,
    "vulnerability_url": null,
    "vendor_attributes_url": null,
    "scores": {
      "global": 0.9713943314711305
    },
    "cve_identifiers": [
      "CVE-2023-49103"
    ],
    "cve_rels": [
      "https://example.com/api/cves/CVE-2023-49103"
    ]
  }
]
GET https://app.empiricalsecurity.com/api/findings/{finding_id}/cves

Retrieve cves for a finding by finding_id

Provides the associated cves for a finding

Authentication: Bearer token required

Parameters

Name Type Required Description
finding_id uuid Yes The id of the finding to return, a UUID
Example: e08d933b-ddba-45b3-a5e7-b769faf4d606

Response 200

successful

[
  {
    "identifier": "CVE-2023-49103",
    "description": "An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo).",
    "cvss": [
      {
        "version": "3.1",
        "score": 10.0,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "metrics": {
          "attack_vector": "Network",
          "attack_complexity": "Low",
          "privileges_required": "None",
          "user_interaction": "None",
          "scope": "Changed",
          "confidentiality": "High",
          "integrity": "High",
          "availability": "High"
        },
        "sources": [
          "cve@mitre.org",
          "mitre"
        ]
      },
      {
        "version": "3.1",
        "score": 7.5,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
        "metrics": {
          "attack_vector": "Network",
          "attack_complexity": "Low",
          "privileges_required": "None",
          "user_interaction": "None",
          "scope": "Unchanged",
          "confidentiality": "High",
          "integrity": "None",
          "availability": "None"
        },
        "sources": [
          "nvd@nist.gov"
        ]
      }
    ],
    "references": [
      "https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/",
      "https://owncloud.org/security"
    ],
    "has_exploitation_activity": true,
    "exploitation_activity": {
      "0_to_7_days": true,
      "8_to_30_days": true,
      "31_to_90_days": true,
      "91_to_365_days": true,
      "alltime": true
    },
    "tags": {
      "actor": [],
      "actor_action": [],
      "attack_vector": [],
      "component": [
        "mail server credentials",
        "license key",
        "ownCloud admin password"
      ],
      "keywords": [
        "information disclosure",
        "web",
        "configuration"
      ],
      "outcome": [
        "credential disclosure",
        "gather information"
      ],
      "prerequisite": [
        "URL is accessed"
      ],
      "stride": [
        "tampering",
        "information disclosure",
        "denial of service"
      ],
      "weakness": [
        "reveals the configuration details of the PHP environment",
        "exposes various other potentially sensitive configuration details"
      ]
    },
    "cwes": [
      {
        "identifier": "CWE-200",
        "name": "Exposure of Sensitive Information to an Unauthorized Actor",
        "description": "The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.",
        "category_name": "SFP Secondary Cluster: Exposed Data",
        "category_id": "CWE-963"
      }
    ],
    "reserved_at": "2023-11-21T00:00:00.000Z",
    "published_at": "2023-11-21T00:00:00.000Z",
    "last_updated_at": "2025-01-27T22:24:27.772Z",
    "cisa_kev_added_at": "2023-11-30T00:00:00.000Z",
    "shodan_vulnerability_count": null,
    "google_project_zero": {
      "present": false,
      "patched_at": null
    },
    "exploits": {
      "metasploit": [
        {
          "name": "ownCloud Phpinfo Reader",
          "fullname": "auxiliary/gather/owncloud_phpinfo_reader",
          "description": "Docker containers of ownCloud compiled after February 2023, which have version 0.2.0 before 0.2.1 or 0.3.0 before 0.3.1 of the app `graph` installed\n          contain a test file which prints `phpinfo()` to an unauthenticated user. A post file name must be appended to the URL to bypass the login filter.\n          Docker may export sensitive environment variables including ownCloud, DB, redis, SMTP, and S3 credentials, as well as other host information.",
          "disclosure_date": "2023-11-21",
          "mod_time": "2023-12-04T20:09:56.000Z",
          "url": "https://github.com/rapid7/metasploit-framework/tree/master/modules/auxiliary/gather/owncloud_phpinfo_reader.rb"
        }
      ],
      "exploitdb": [],
      "github": [
        {
          "repo": "d0rb/CVE-2023-49103",
          "prediction": 0.8660581707954407,
          "predicted_at": "2025-03-10T16:40:29.000Z",
          "repo_created_at": "2025-03-10T20:11:29.004Z",
          "url": "https://github.com/d0rb/CVE-2023-49103"
        }
      ]
    },
    "hackerone_reports_submitted": 4,
    "scores": {
      "global": {
        "score": 0.9713943314711305,
        "percentile": 0.9998484036161284,
        "computed_at": "2025-03-16T07:27:24.000Z"
      },
      "epss_v3": {
        "score": 0.92099,
        "percentile": 0.99238,
        "computed_at": "2025-03-16T15:46:16.000Z"
      },
      "epss_v4": {
        "score": 0.9091291982186883,
        "percentile": 0.996181146025878,
        "computed_at": "2025-03-16T18:47:04.000Z"
      },
      "epss_v5": {
        "score": 0.9341291982186883,
        "percentile": 0.997181146025878,
        "computed_at": "2025-03-16T18:47:04.000Z"
      }
    },
    "platforms": [
      {
        "product": "product",
        "vendor": "vendor"
      }
    ],
    "most_recent_exploitation_activity_date": "2025-07-20",
    "exploitation_activity_source_count": 1,
    "replacement_cve": null
  }
]