CISA KEV Scraper - Exploited CVEs & Remediation Dates
Pricing
from $2.00 / 1,000 results
CISA KEV Scraper - Exploited CVEs & Remediation Dates
Export CISA's Known Exploited Vulnerabilities catalog. Filter actively exploited CVEs by vendor, product, date, ransomware use, keywords, and remediation deadline.
Pricing
from $2.00 / 1,000 results
Rating
0.0
(0)
Developer
Thirdwatch
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
2 days ago
Last modified
Categories
Share
CISA KEV Scraper
Export actively exploited CVEs from CISA with vendors, products, ransomware status, required actions, and remediation dates.
What you get
Turn the authoritative Known Exploited Vulnerabilities catalog into a filtered, schedulable dataset. Focus remediation work on vulnerabilities observed in the wild, monitor selected vendors or products, and retain CISA's required action and due date beside every CVE.
Output fields
| Field | Description |
|---|---|
cve_id | CVE identifier |
vendor / product | Affected vendor and product |
vulnerability_name | CISA vulnerability title |
date_added | Date added to the KEV catalog |
short_description | Published vulnerability summary |
required_action | CISA remediation direction |
due_date | Published remediation deadline |
known_ransomware_use | Known or unknown ransomware-campaign use |
notes | Additional CISA references or guidance |
cwes | Related weakness identifiers |
catalog_version / catalog_released_at | Feed version metadata |
source_url / source | CISA lookup link and attribution |
Example output
{"cve_id": "CVE-2026-58644","vendor": "Microsoft","product": "SharePoint","vulnerability_name": "Microsoft SharePoint Deserialization Vulnerability","date_added": "2026-07-16","due_date": "2026-07-19","known_ransomware_use": "Unknown"}
Input parameters
| Parameter | Required | Description |
|---|---|---|
query | No | Text matched across IDs, vendors, products, descriptions, actions, and notes. |
vendors | No | Vendor-name filters. |
products | No | Product-name filters. |
ransomwareOnly | No | Keep only entries with known ransomware use. |
dateAddedFrom | No | Earliest catalog-addition date. |
dateAddedTo | No | Latest catalog-addition date. |
sort | No | newest or oldest. |
maxResults | No | Maximum KEV rows. Defaults to 10. |
Use cases
- Vulnerability teams: prioritize actively exploited CVEs over unranked backlogs.
- Managed security providers: create vendor-specific remediation feeds.
- Compliance teams: track required actions and due dates with source evidence.
- Security leaders: build ransomware-exposure and remediation dashboards.
Export the CISA KEV catalog without an API key
Collect the current federal catalog with vendor, product, ransomware, date, and keyword filters. Every result includes the remediation action and official catalog context needed for downstream review.
Limitations
KEV is a prioritized catalog, not a complete vulnerability database. Absence from KEV does not mean a CVE is safe or unexploited. CISA deadlines are primarily tied to federal directives; other organizations should apply their own risk process and validate vendor guidance before remediation.
Compared to alternatives
Compared with compute-edge/cisa-kev-scraper, this Actor combines keyword, vendor, product, ransomware, date, and sort filters with a low first-run cap. Compared with a broad NVD export, it focuses only on vulnerabilities CISA confirms have been exploited in the wild. Store pricing and features can change.
FAQ
What qualifies for KEV?
CISA adds vulnerabilities with evidence of active exploitation and actionable remediation guidance.
Does ransomware-only include unknown entries?
No. It keeps only records CISA explicitly marks Known.
Can this replace vulnerability management?
No. Use it as a prioritization input alongside asset exposure, vendor advisories, scanning, and incident context.
Explore more at thirdwatch.dev. Related Actors: NVD CVE Scraper, OSV Vulnerability Scraper, and OFAC Sanctions Scraper.
Last verified: 2026-07