# Fetch the list of vulnerabilities Fetches a comprehensive list of vulnerabilities detected in the system, with various filtering options for precise querying. ## Endpoint `GET /dcapi/threats/vulnerabilities` ## Request URL `https://{serverurl}/dcapi/threats/vulnerabilities` `{serverurl}`: [OAuth authentication endpoint domain](https://www.manageengine.com/products/desktop-central/help/api/cloud/oauth-authentication-endpoint-domain.html) ## Scope `DesktopCentralCloud.VulnerabilityMgmt.READ` ## Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Query Parameters | Parameter | Type | Required | Description | |---|---|---|---| | **page** | string | Optional | Displays the content of the provided page number. | | **customername** | string | Optional | | | **customerid** | long | Optional | | | **pageLimit** | string | Optional | Displays the provided number of vulnerability details per page. | | **severity** | string | Optional | Filters vulnerabilities based on the severity provided. | | **publishedtime** | string | Optional | Filters vulnerabilities based on the published time provided. | | **cvss_2_score** | float | Optional | Filters vulnerabilities based on the CVSS 2.0 score provided | | **os_platform** | string | Optional | Filters vulnerabilities based on the platform provided. | | **supportedtime** | string | Optional | Filters vulnerabilities based on the supported time provided. | | **exploit_status** | string | Optional | Filters vulnerabilities based on the exploit status provided. | | **updatedtime** | string | Optional | Filters vulnerabilities based on the approved time. | | **affected_systems** | string | Optional | | | **patchid** | string | Optional | Filters vulnerabilities based on the patch ID provided. | | **vulnerabilityid** | string | Optional | Filters vulnerabilities based on the vulnerability ID provided. | | **vulnerabilityname** | string | Optional | Filters vulnerabilities that contain the provided vulnerability name. | | **solution** | string | Optional | Filters vulnerabilities based on the provided solution. | | **reboot_required** | string | Optional | Filters vulnerabilities based on the reboot option provided. | | **cveids** | string | Optional | Filters vulnerabilities based on the CVE ID provided. | | **cvss_3_score** | float | Optional | Filters vulnerabilities based on the CVSS 3.0 score provided | | **patch_availability** | string | Optional | Filters vulnerabilities based on the patch availability provided. | ### Sample Request ```curl curl --request GET \ --url https://appdomains/dcapi/threats/vulnerabilities \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' ``` ## Response Parameters ### HTTP Code 200 Response body: `application/json` `JSON Object` ### Possible Response Codes | Code | Type | |---|---| | **200** | HTTP code | ### Sample Response: HTTP 200 ```json { "metadata": { "pageLimit": 30, "totalRecords": "2", "totalPages": 1, "links": { "next": null, "prev": null }, "page": 1 }, "response_code": 200, "message_type": "vulnerabilities", "message_response": { "vulnerabilities": [ { "severity": "Important", "publishedtime": "1557810000000", "cvss_2_0_score": 5, "os_platform": "Windows", "supportedtime": "1557810000000", "exploit_status": "not available", "updatedtime": "1557858929000", "affected_systems": 1, "patchid": "37634", "vulnerabilityid": "24480", "vulnerabilityname": "KB4499405 2019-05 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows Server 2019 for x64 (KB4495618)", "solution": "Windows10.0-kb5031990-x64-ndp48-2019.msu", "reboot_required": "may require", "cveids": "CVE-2019-0981,CVE-2019-0820,CVE-2019-0980,CVE-2019-0864", "cvss_3_0_score": 7.5, "patch_availability": "available" }, { "severity": "Critical", "publishedtime": "1562524200000", "cvss_2_0_score": 7.5, "os_platform": "Windows", "supportedtime": "1562700356687", "exploit_status": "not available", "updatedtime": "1562707959273", "affected_systems": 1, "patchid": "37634", "vulnerabilityid": "25109", "vulnerabilityname": ".NET Framework Remote Code Execution Vulnerability for .NET Framework 3.5, 4.8 on Windows Server 2019 for x64 (KB4506990)", "solution": "Windows10.0-kb5031990-x64-ndp48-2019.msu", "reboot_required": "may require", "cveids": "CVE-2019-1113,CVE-2019-1006,CVE-2019-1083", "cvss_3_0_score": 9.8, "patch_availability": "available" } ] }, "status": "success" } ``` ## API Rate Limit ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.