Cover image for project: NEXUS NVD CVE Enrichment IN PROGRESS

Technical summary

NEXUS plugin that automatically enriches CVEs detected in tasks and comments with official NVD/NIST metadata — CVSS score and severity, vector, CWE and references. Data is cached locally for instant response, and the Intelligence Hub enricher returns structured signals to the Intel panel, with manual lookup and configurable parameters through the plugin tab.

Executed scope

  • Registration: plugin.json v1.0.0, icon_bg #3b82f6, lucide shield-alert icon and custom icon.svg (no is_core — additional plugin); registerTab('nvd','NVD Intelligence','shield-alert',tab.php,'Threat Intel') and registerDoc('nvd','NVD Intelligence','shield-alert',doc.md).
  • nvd_cves table via nvd_install(): cve_id VARCHAR(50) PK, cvss_score DECIMAL(3,1), severity VARCHAR(20), vector VARCHAR(120), description TEXT, cwe VARCHAR(100), references_urls TEXT, published_at/updated_at/created_at DATETIME (InnoDB, utf8mb4).
  • NVD API v2 lookup (https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=): CVE-\d{4}-\d{4,7} validation, custom User-Agent, optional apiKey header (5 → 50 req/30s), 2s connect / 4s response timeouts, IPv4 and configurable SSL_VERIFY.
  • Metadata mapping: English description, CVSS metrics with v3.1 → v3.0 → v4.0 → v2 precedence, score-derived severity when missing, deduplicated CWEs and up to 5 references as JSON.
  • Resilient local cache: nvd_query() checks the cache (source: cache) before the remote call (source: remote), INSERTing on miss — instant response in the Core and less traffic to NIST.
  • 4 API actions: nvd_stats (cache total + last 20 + api_online pulse via HEAD on a test CVE), nvd_query (manual, cache→remote), nvd_delete (removes one record) and nvd_settings_save (API key + auto_enrich via DB::setConfig).
  • Intelligence Hub enricher: nx_intel_register_enricher('nvd', ['cve'], 'nvd_intel_enrich', 46) — emits ok/error/skipped signals with CVSS x.x · SEVERITY summary, 0–100 severity (score × 10 or label match), respects the max_live_lookups budget (default 12, slice ≤ 5) and flags cached.
  • Fast Responses: fastr.json manifest with /nvd (required CVE argument), action nvd_query — direct slash lookup.
  • On demand: cronjob.json with jobs: [] (no periodic routine needed); no CLI.
  • UI: Alpine.js tab (tab.php, 393 lines) with pulsing "API Online/Offline" badge, stats cards (Cached CVEs, Response Speed < 1ms, NVD/NIST Source), manual lookup with quick tests (OpenSSH CVE-2023-38408 and Log4j CVE-2021-44228), parameters (optional password API key + auto-enrich toggle), color-coded severity result badge and cache table with search and cleanup.
  • Legacy: nvd_filter_task_read/nvd_filter_comment_read disabled (commented out) — automatic enrichment moved to the Intelligence Hub (core/intel.php).

Stack and tools

  • PHP 8 backend (no framework) + MySQL 8 (nvd_cves table)
  • NVD API v2 (NIST) via cURL (services.nvd.nist.gov/rest/json/cves/2.0)
  • Alpine.js + Tailwind CSS (panel tab) + internal Plugin API (tabs/actions + fastr.json + Intel Hub)

Tags

NVD, NIST, CVE, CVSS, Threat Intelligence, Intelligence Hub, NEXUS Plugin

Operational result

  • Automatic enrichment: CVEs mentioned in tasks and comments become Intelligence Hub signals with official NIST data.
  • Resilient local cache: misses hit the remote API and persist; hits respond in < 1ms without traffic to NVD.
  • Standardized severity: CVSS score with color-coded badge (CRITICAL/HIGH/MEDIUM/LOW/UNKNOWN) in the tab and Intel signals.
  • Optional API key: without a key the limit is 5 requests/30s; with a key it rises to 50 — password-configured in the tab.
  • Manual lookup: CVE search with detailed result (score, CWE, vector, summary and update date) plus cache cleanup from the table.
  • No routines: purely on-demand plugin — no cron or CLI.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS plugin that automatically enriches CVEs detected in tasks and comments with official NVD/NIST metadata — CVSS score and severity, vector, CWE and references. Data is cached locally for instant response, and the Intelligence Hub enricher returns structured signals to the Intel panel, with manual lookup and configurable parameters through the plugin tab.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.