CISA KEV Scraper - Exploited CVEs & Remediation Dates avatar

CISA KEV Scraper - Exploited CVEs & Remediation Dates

Pricing

from $2.00 / 1,000 results

Go to Apify Store
CISA KEV Scraper - Exploited CVEs & Remediation Dates

CISA KEV Scraper - Exploited CVEs & Remediation Dates

Export CISA's Known Exploited Vulnerabilities catalog. Filter actively exploited CVEs by vendor, product, date, ransomware use, keywords, and remediation deadline.

Pricing

from $2.00 / 1,000 results

Rating

0.0

(0)

Developer

Thirdwatch

Thirdwatch

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

2 days ago

Last modified

Share

CISA KEV Scraper

Export actively exploited CVEs from CISA with vendors, products, ransomware status, required actions, and remediation dates.

What you get

Turn the authoritative Known Exploited Vulnerabilities catalog into a filtered, schedulable dataset. Focus remediation work on vulnerabilities observed in the wild, monitor selected vendors or products, and retain CISA's required action and due date beside every CVE.

Output fields

FieldDescription
cve_idCVE identifier
vendor / productAffected vendor and product
vulnerability_nameCISA vulnerability title
date_addedDate added to the KEV catalog
short_descriptionPublished vulnerability summary
required_actionCISA remediation direction
due_datePublished remediation deadline
known_ransomware_useKnown or unknown ransomware-campaign use
notesAdditional CISA references or guidance
cwesRelated weakness identifiers
catalog_version / catalog_released_atFeed version metadata
source_url / sourceCISA lookup link and attribution

Example output

{
"cve_id": "CVE-2026-58644",
"vendor": "Microsoft",
"product": "SharePoint",
"vulnerability_name": "Microsoft SharePoint Deserialization Vulnerability",
"date_added": "2026-07-16",
"due_date": "2026-07-19",
"known_ransomware_use": "Unknown"
}

Input parameters

ParameterRequiredDescription
queryNoText matched across IDs, vendors, products, descriptions, actions, and notes.
vendorsNoVendor-name filters.
productsNoProduct-name filters.
ransomwareOnlyNoKeep only entries with known ransomware use.
dateAddedFromNoEarliest catalog-addition date.
dateAddedToNoLatest catalog-addition date.
sortNonewest or oldest.
maxResultsNoMaximum KEV rows. Defaults to 10.

Use cases

  • Vulnerability teams: prioritize actively exploited CVEs over unranked backlogs.
  • Managed security providers: create vendor-specific remediation feeds.
  • Compliance teams: track required actions and due dates with source evidence.
  • Security leaders: build ransomware-exposure and remediation dashboards.

Export the CISA KEV catalog without an API key

Collect the current federal catalog with vendor, product, ransomware, date, and keyword filters. Every result includes the remediation action and official catalog context needed for downstream review.

Limitations

KEV is a prioritized catalog, not a complete vulnerability database. Absence from KEV does not mean a CVE is safe or unexploited. CISA deadlines are primarily tied to federal directives; other organizations should apply their own risk process and validate vendor guidance before remediation.

Compared to alternatives

Compared with compute-edge/cisa-kev-scraper, this Actor combines keyword, vendor, product, ransomware, date, and sort filters with a low first-run cap. Compared with a broad NVD export, it focuses only on vulnerabilities CISA confirms have been exploited in the wild. Store pricing and features can change.

FAQ

What qualifies for KEV?

CISA adds vulnerabilities with evidence of active exploitation and actionable remediation guidance.

Does ransomware-only include unknown entries?

No. It keeps only records CISA explicitly marks Known.

Can this replace vulnerability management?

No. Use it as a prioritization input alongside asset exposure, vendor advisories, scanning, and incident context.

Explore more at thirdwatch.dev. Related Actors: NVD CVE Scraper, OSV Vulnerability Scraper, and OFAC Sanctions Scraper.

Last verified: 2026-07