IN PROGRESS
Technical summary
NEXUS plugin that automatically enriches CVEs detected in tasks and comments with official NVD/NIST metadata — CVSS score and severity, vector, CWE and references. Data is cached locally for instant response, and the Intelligence Hub enricher returns structured signals to the Intel panel, with manual lookup and configurable parameters through the plugin tab.
Executed scope
- Registration:
plugin.jsonv1.0.0,icon_bg #3b82f6, lucideshield-alerticon and customicon.svg(nois_core— additional plugin);registerTab('nvd','NVD Intelligence','shield-alert',tab.php,'Threat Intel')andregisterDoc('nvd','NVD Intelligence','shield-alert',doc.md). nvd_cvestable vianvd_install():cve_id VARCHAR(50)PK,cvss_score DECIMAL(3,1),severity VARCHAR(20),vector VARCHAR(120),description TEXT,cwe VARCHAR(100),references_urls TEXT,published_at/updated_at/created_at DATETIME(InnoDB, utf8mb4).- NVD API v2 lookup (
https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=):CVE-\d{4}-\d{4,7}validation, custom User-Agent, optionalapiKeyheader (5 → 50 req/30s), 2s connect / 4s response timeouts, IPv4 and configurableSSL_VERIFY. - Metadata mapping: English description, CVSS metrics with v3.1 → v3.0 → v4.0 → v2 precedence, score-derived severity when missing, deduplicated CWEs and up to 5 references as JSON.
- Resilient local cache:
nvd_query()checks the cache (source: cache) before the remote call (source: remote), INSERTing on miss — instant response in the Core and less traffic to NIST. - 4 API actions:
nvd_stats(cache total + last 20 +api_onlinepulse via HEAD on a test CVE),nvd_query(manual, cache→remote),nvd_delete(removes one record) andnvd_settings_save(API key +auto_enrichviaDB::setConfig). - Intelligence Hub enricher:
nx_intel_register_enricher('nvd', ['cve'], 'nvd_intel_enrich', 46)— emitsok/error/skippedsignals withCVSS x.x · SEVERITYsummary, 0–100 severity (score × 10 or label match), respects themax_live_lookupsbudget (default 12, slice ≤ 5) and flagscached. - Fast Responses:
fastr.jsonmanifest with/nvd(required CVE argument), actionnvd_query— direct slash lookup. - On demand:
cronjob.jsonwithjobs: [](no periodic routine needed); no CLI. - UI: Alpine.js tab (
tab.php, 393 lines) with pulsing "API Online/Offline" badge, stats cards (Cached CVEs, Response Speed < 1ms, NVD/NIST Source), manual lookup with quick tests (OpenSSHCVE-2023-38408and Log4jCVE-2021-44228), parameters (optional password API key + auto-enrich toggle), color-coded severity result badge and cache table with search and cleanup. - Legacy:
nvd_filter_task_read/nvd_filter_comment_readdisabled (commented out) — automatic enrichment moved to the Intelligence Hub (core/intel.php).
Stack and tools
- PHP 8 backend (no framework) + MySQL 8 (
nvd_cvestable) - NVD API v2 (NIST) via cURL (
services.nvd.nist.gov/rest/json/cves/2.0) - Alpine.js + Tailwind CSS (panel tab) + internal Plugin API (tabs/actions +
fastr.json+ Intel Hub)
Tags
NVD, NIST, CVE, CVSS, Threat Intelligence, Intelligence Hub, NEXUS Plugin
Operational result
- Automatic enrichment: CVEs mentioned in tasks and comments become Intelligence Hub signals with official NIST data.
- Resilient local cache: misses hit the remote API and persist; hits respond in < 1ms without traffic to NVD.
- Standardized severity: CVSS score with color-coded badge (CRITICAL/HIGH/MEDIUM/LOW/UNKNOWN) in the tab and Intel signals.
- Optional API key: without a key the limit is 5 requests/30s; with a key it rises to 50 — password-configured in the tab.
- Manual lookup: CVE search with detailed result (score, CWE, vector, summary and update date) plus cache cleanup from the table.
- No routines: purely on-demand plugin — no cron or CLI.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS plugin that automatically enriches CVEs detected in tasks and comments with official NVD/NIST metadata — CVSS score and severity, vector, CWE and references. Data is cached locally for instant response, and the Intelligence Hub enricher returns structured signals to the Intel panel, with manual lookup and configurable parameters through the plugin tab.
Architecture and organization
- PHP 8
- MySQL 8
- cURL
- NVD API
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.