Hi
I haven't work with this myself but our devops team have had some words to say about the lack of proper API sources for CVE's.
Currently I know you have an RSS feed you can subscribe to, and parse the information and in your own service do the correlation between hardware, software and the CVE's.
The RSS feed can be found on this page: Subscribe to RSS feeds
------------------------------
Best Regards
Jonas Hammarbäck
MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security
Aranya AB
If you find my answer useful, consider giving kudos and/or mark as solution
------------------------------