
# 1. Get vulnx
go install github.com/projectdiscovery/vulnx/v2/cmd/vulnx@latest
# 2. Explore commands
vulnx --help
vulnx search --help
# 3. Start exploring vulnerabilities (no API key required)
vulnx filters # See all available search fields
vulnx search apache # Basic search (subject to rate limits)
# 4. Set up your API key (recommended to avoid rate limits)
vulnx auth # Get free API key at https://cloud.projectdiscovery.io
# 5. Enhanced exploration with higher limits
vulnx search apache # No rate limits
vulnx id CVE-2021-44228 # Faster responses
精确搜索漏洞:
vulnx search "severity:critical && is_remote:true"
vulnx search "apache || nginx" --limit 20
vulnx search "cvss_score:>8.0 && cve_created_at:2024"
获取详细漏洞信息:
vulnx id CVE-2021-44228
vulnx id CVE-2024-1234 --json
分析漏洞模式:
vulnx analyze --fields severity
vulnx analyze --fields affected_products.vendor
| 命令 | 用途 | 示例 |
|---|---|---|
search | 使用高级过滤器查找漏洞 | vulnx search "apache && severity:high" |
id | 获取特定 CVE 的详情 | vulnx id CVE-2021-44228 |
filters | 列出所有可用的搜索字段和过滤器 | vulnx filters |
analyze | 按字段聚合数据 | vulnx analyze -f severity |
auth | 配置 API 访问 | vulnx auth |
version | 显示版本信息并检查更新 | vulnx version |
update | 将 vulnx 更新到最新版本 | vulnx update |
healthcheck | 测试连通性 | vulnx healthcheck |
输出格式:
vulnx search "apache" --json # Machine-readable JSON
vulnx search "apache" --output results.json # Save to file
vulnx search "apache" --silent # Quiet output
搜索控制:
vulnx search "apache" --limit 50 # Get 50 results
vulnx search "apache" --sort-desc cvss_score # Sort by CVSS score
vulnx search "apache" --fields cve_id,severity # Specific fields only
高级搜索:
vulnx search --term-facets severity=5,tags=10 "apache"
vulnx search --range-facets numeric:cvss_score:high:8:10 "remote"
vulnx search --highlight "apache" # Enable search highlighting
vulnx search --facet-size 20 "nginx" # More facet buckets
vulnx search --detailed "xss" # Detailed output like 'id' command
探索你可以搜索的内容:
vulnx filters # Show all available search fields
vulnx filters --json # Machine-readable field list
vulnx filters --output fields.json # Save field info to file
filters 命令显示所有可搜索字段的详细信息,包括:
示例输出:
Field: severity
Data Type: string
Description: Vulnerability severity level (e.g., critical, high, medium, low, info)
Can Sort: Yes
Facet Possible: Yes
Search Analyzer: keyword-lower
Examples: severity:critical, severity:high
Enum Values: critical, high, medium, low, info, unknown
Total: 69 filters available
使用此命令发现新的搜索可能性,并在构建复杂查询前了解字段语法。
查找高风险漏洞:
vulnx search "severity:critical && is_remote:true && is_kev:true"
vulnx search "cvss_score:>8.0 && cve_created_at:>=2024" # High CVSS from 2024
vulnx search "is_kev:true && age_in_days:<90" # Recent KEV exploits
按技术搜索:
vulnx search "apache" # Apache vulnerabilities
vulnx search "apache || nginx" # Multiple technologies
vulnx search "affected_products.vendor:microsoft" # By vendor
按严重性和分数过滤:
vulnx search "severity:high" # High severity
vulnx search "cvss_score:>7.0" # CVSS score above 7
vulnx search "epss_score:>0.8" # High EPSS score
基于时间的搜索:
vulnx search "cve_created_at:>=2024" # Published in 2024 or later
vulnx search "cve_created_at:>=2024-01-01 && cve_created_at:<2024-07-01" # First half of 2024
vulnx search "age_in_days:<30" # Recent vulnerabilities (last 30 days)
查找可利用的漏洞:
vulnx search "is_poc:true" # Has proof of concept
vulnx search "is_kev:true" # Known exploited vulns
vulnx search "is_template:true" # Has Nuclei templates
vulnx search --detailed "log4j" # Detailed analysis of specific vuln
| 标志 | 简写 | 描述 | 示例 |
|---|---|---|---|
--product | -p | 按产品过滤 | --product apache,nginx |
--vendor | 按供应商过滤 | --vendor microsoft,oracle | |
--severity | -s | 按严重性过滤 | --severity critical,high |
--tags | 按标签过滤 | --tags rce,injection | |
--cvss-score | 按 CVSS 分数过滤 | --cvss-score ">8.0" | |
--epss-score | 按 EPSS 分数过滤 | --epss-score ">0.8" | |
--vuln-age | -a | 按期限过滤 | --vuln-age "<30" |
--vuln-type | 按漏洞类型过滤 | --vuln-type sql_injection | |
--kev | 仅 KEV 漏洞 | --kev | |
--template | -t | 具有 Nuclei 模板 | --template |
--poc | 具有概念验证 | --poc | |
--hackerone | HackerOne 已报告 | --hackerone | |
--remote-exploit | 可远程利用 | --remote-exploit | |
--vuln-status | 按漏洞状态过滤 | --vuln-status confirmed |
| 标志 | 简写 | 描述 | 示例 |
|---|---|---|---|
--detailed | 详细输出,如 'id' | --detailed | |
--highlight | 启用搜索高亮 | --highlight | |
--limit | -n | 结果数量 | --limit 50 |
--offset | 分页偏移 | --offset 100 | |
--sort-asc | 升序排序 | --sort-asc cvss_score | |
--sort-desc | 降序排序 | --sort-desc cve_created_at | |
--fields | 选择特定字段 | --fields cve_id,severity | |
--term-facets | 计算词项分面 | --term-facets severity=5 | |
--range-facets | 计算范围分面 | --range-facets numeric:cvss_score:high:8:10 | |
--facet-size | 分面桶数量 | --facet-size 20 |
产品和供应商过滤:
vulnx search --product apache,nginx # Filter by products (searches both vendor and product fields)
vulnx search --vendor microsoft,oracle # Filter by vendors only
vulnx search "NOT apache" # Exclude products using query syntax
vulnx search "NOT affected_products.vendor:microsoft" # Exclude vendors using query syntax