https://2s.io/api/security/cve-changesGET /api/security/cve-changes · x402 API by 2s.io
CVE change feed — the CVE records MODIFIED within a time window, so an agent can incrementally maintain a vulnerability view instead of re-scanning. Pass since (YYYY-MM-DD or ISO datetime); until defaults to now (window must be ≤ 120 days, the NVD limit). Optionally narrow by keyword (product/text) or cpe (exact CPE). Returns each changed CVE with its id, published + lastModified timestamps, current vulnStatus (e.g. Modified, Analyzed, Rejected), best-available CVSS score/severity, description, and kevListed — whether it is now on the CISA Known-Exploited Vulnerabilities catalog (the high-signal flag for a poller). Newest modification first. Sourced live from NVD (NIST) + CISA KEV, free/keyless. Pair with security.cve for full per-CVE detail.
What does this x402 API do?
https://2s.io/api/security/cve-changes. This is an x402-gated GET API resource from 2s.io. TOLL·402 confirmed a protocol-valid HTTP 402 quote on 2026-07-21. No normalized USD price is recorded; the listing names Base and Solana. No settled paid call has been verified.
- Published price
- No normalized USD price is recorded
- Networks
- Base · Solana
- Latest evidence
- TOLL·402 confirmed a protocol-valid HTTP 402 quote on 2026-07-21
- Resource ID
- db5cd6058cc25792a37c694e
Start with a quote-only recipe. Payment signing stays in your project.
const response = await fetch("https://2s.io/api/security/cve-changes", {
method: "GET",
});
console.log(response.status);
console.log(Object.fromEntries(response.headers));
console.log((await response.text()).slice(0, 1000));
// A valid 402 is a quote, not a completed paid call.This sends no payment. Inspect the 402 response before adding a wallet-enabled client.
- Live 402 quote confirmed
GET returned a protocol-valid 402 quote (402). No payment was made.
- Origin reachable
HEAD https://2s.io/ returned 200.
- Observed in cdp-bazaar
The registry record was observed and retained with provenance.
- Observed in 402-index
Discovered through bazaar.
- Registry record checked
Registry health: healthy.
What evidence supports this listing?
Each record has an exact-route quote outcome. Unresolved templates and potentially mutating methods are labeled instead of being invoked without provider-specific test input. A quote is still separate from a settled paid call. Read the discovery and verification methodology →
Which networks and payment options does it accept?
The normalized listing price is No normalized USD price is recorded. Raw protocol requirements remain visible below for implementation and audit use.