Rapid7 Vulnerabilities API

A Vulnerability is a resource that encapsulates any information found by any Scan over the lifetime of an App, that may identify where and how an App could be exploited. Each Vulnerability contains information about the Root Cause (location) and Variances (attack types and natures) which contribute to the evidence that the Vulnerability exists. A Vulnerability cannot be explicitly created or deleted via the API, as its life cycle is managed by the product; but, it can be implicitly created by submitting a Scan and can be implicitly deleted by deleting the App that owns it. There are a number of fields which are mutable and can help to control the workflow of the management of an App's Vulnerabilities.

Business capability
Vulnerability Management BC-620.40

Operations 9

GET /modules Get Modules #
GET /modules/{module-id} Get Module #
GET /modules/{module-id}/attacks/{attack-id} Get Attack #
GET /modules/{module-id}/attacks/{attack-id}/documentation Get Attack Documentation #
GET /vulnerabilities Get Vulnerabilities #
GET /vulnerabilities/{vuln-id} Get Vulnerability #
PUT /vulnerabilities/{vuln-id} Update Vulnerability #
GET /vulnerabilities/{vuln-id}/discoveries Get Vulnerability Discoveries #
GET /vulnerabilities/{vuln-id}/discoveries/{vuln-discovery-id} Get Vulnerability Discovery #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/rapid7-vulnerabilities-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

rapid7-vulnerabilities-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: InsightAppSec Vulnerabilities API
  description: Welcome to the reference documentation for the public APIs available for InsightAppSec.
  version: v1
servers:
- url: https://[region].api.insight.rapid7.com/ias/v1
tags:


# --- truncated at 32 KB (34 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/rapid7/refs/heads/main/openapi/rapid7-vulnerabilities-api-openapi.yml