CISA KEV Known Exploited Vulnerabilities Scraper
Pricing
from $23.25 / 1,000 results
CISA KEV Known Exploited Vulnerabilities Scraper
Scrape the CISA Known Exploited Vulnerabilities (KEV) catalog. Filter by CVE ID, vendor, product, or date added. Returns required actions, due dates, ransomware campaign use, and CWE references for every actively-exploited CVE tracked by CISA.
Pricing
from $23.25 / 1,000 results
Rating
0.0
(0)
Developer
ParseForge
Maintained by CommunityActor stats
0
Bookmarked
1
Total users
1
Monthly active users
6 days ago
Last modified
Categories
Share

๐จ CISA KEV Scraper
๐ Export the U.S. federal Known Exploited Vulnerabilities catalogue in seconds. Track every CVE actively exploited in the wild with vendor, product, due date, and ransomware-campaign tagging from the official CISA KEV catalogue. No sign-up, no token, no manual CSV wrangling.
The CISA KEV Scraper pulls every entry from the U.S. Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities catalogue and returns 14 normalised fields per record, including the CVE ID, vendor, product, vulnerability name, addition date, required action, federal due date, ransomware-campaign flag, and associated CWE weaknesses. The catalogue is the single most important U.S. government list for vulnerability prioritisation. Federal civilian agencies are bound by Binding Operational Directive 22-01 to remediate every entry by its due date.
The catalogue covers 1,500+ CVEs across 600+ vendors and projects spanning operating systems, network gear, browsers, email servers, virtualisation platforms, and SaaS products. This Actor makes that data downloadable as CSV, Excel, JSON, or XML in seconds. Filters apply locally on the full catalogue snapshot, so you skip pagination, retry handling, and JSON-to-spreadsheet plumbing entirely.
| ๐ฏ Target Audience | ๐ก Primary Use Cases |
|---|---|
| Security operations teams, vulnerability managers, federal contractors, MSSPs, threat intel analysts, compliance officers, security tool builders | BOD 22-01 compliance, patch prioritisation, ransomware risk reports, SIEM enrichment, executive dashboards, incident response triage |
๐ What the CISA KEV Scraper does
Six filtering workflows in a single run:
- ๐ Full catalogue export. Every active KEV entry in one dataset.
- ๐ข Vendor filter. Restrict to a vendor like
Microsoft,Cisco, orApache. - ๐ฆ Product filter. Drill down to a specific product line like
WindowsorLog4j. - ๐ CVE filter. Find a single CVE in the catalogue.
- ๐ Ransomware-only filter. Restrict to CVEs flagged as
Knownransomware campaign use. - ๐งฌ CWE filter. Slice by weakness type, e.g.
CWE-79,CWE-89.
Each record includes the CVE identifier, vendor and product, plain-English vulnerability name, short description, the action CISA requires, the due date federal agencies must meet, a normalised ransomware-use boolean, free-text notes, and the full CWE list.
๐ก Why it matters: the CISA KEV catalogue is the single most actionable feed for vulnerability prioritisation. Building your own ingestion means handling JSON parsing, normalising the ransomware text field, and refreshing on cadence. This Actor skips all of that and gives you a clean, downloadable dataset.
๐ Data fields
Each record includes: cveID, cwes, dateAdded, dueDate, knownRansomwareCampaignUse, knownRansomwareCampaignUseRaw, notes, product, requiredAction, scrapedAt, shortDescription, url, vendorProject, vulnerabilityName. All 14 field names come from a real production run, so what you see here is what lands in your dataset.
๐ How to use
- ๐ Sign up. Create a free account with $5 credit (takes 2 minutes).
- ๐ Open the Actor. Go to the CISA KEV Scraper page on the Apify Store.
- ๐ฏ Set input. Pick a vendor, product, date filter, or leave blank for the full catalogue, then set
maxItems. - ๐ Run it. Click Start and let the Actor collect your data.
- ๐ฅ Download. Grab your results in the Dataset tab as CSV, Excel, JSON, or XML.
โฑ๏ธ Total time from signup to downloaded dataset: 3-5 minutes. No coding required.
๐ Recommended Actors
- ๐ก๏ธ NIST NVD CVE Scraper - Official NVD catalogue with CVSS v4/v3/v2 scores
- ๐ EPSS Exploit Prediction Scraper - 30-day exploitation probability scores
- ๐ GitHub Security Advisories Scraper - GHSA + CVE advisories with patched versions
- ๐ฆ OSV Vulnerabilities Scraper - Open source vulnerabilities across 30+ ecosystems
- ๐ฌ CIRCL CVE Scraper - CIRCL Luxembourg CVE catalogue with CWE and CAPEC
๐ก Pro Tip: browse the complete ParseForge collection for more security and reference-data scrapers.
โ ๏ธ Disclaimer: this Actor is an independent tool and is not affiliated with, endorsed by, or sponsored by CISA, the U.S. Department of Homeland Security, or any other government agency. All trademarks mentioned are the property of their respective owners. Only publicly available U.S. government vulnerability data is collected.
๐ Need Help?
If you hit a bug, have questions about setup, or need a scraper we haven't built yet, open our contact form or write to parseforge@protonmail.com. We also take on paid custom data projects.
For faster answers, join our Discord. It's the best place to get support and suggest new actors.