{"uid":"cap_3X7bfkcJI_yMcxH6sbufW","slug":"cisa-known-exploited-vulnerabilities-kev-catalog-a4767e82","name":"CISA Known Exploited Vulnerabilities (KEV) Catalog","description":"The full CISA Known Exploited Vulnerabilities catalog, the US government list of CVEs confirmed exploited in the wild: CVE id, vendor, product, name, date added, due date. For AI agents prioritizing patching by real exploitation and enforcing deadlines.","url":"https://proxy.suverse.io/v1/data/suverse-cisa-kev","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","bodyType","body"],"properties":{"body":{"properties":{}},"type":{"type":"string","const":"http"},"method":{"enum":["POST","PUT","PATCH"],"type":"string"},"bodyType":{"enum":["json","form-data","text"],"type":"string"}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.004","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.004/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_9YouNQIxkASu9Rhwdocuz","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns the full CISA KEV catalog of CVEs confirmed exploited in the wild, including CVE ID, vendor, product, name, date added, and remediation due date.","exampleAgentPrompt":"Pull the full CISA Known Exploited Vulnerabilities catalog so I can see every CVE that's been confirmed exploited in the wild along with the vendor, product, and remediation due date.","exampleUseCases":[{"title":"Patch prioritization by real exploitation","prompt":"Give me the complete CISA KEV list so I can cross-reference it against our installed software and flag which vulnerabilities we need to patch first because they're actively being exploited."},{"title":"Compliance deadline enforcement","prompt":"Fetch the CISA Known Exploited Vulnerabilities catalog — I need to check which CVEs have upcoming remediation due dates so we don't miss any federal patching deadlines."},{"title":"Threat intelligence enrichment","prompt":"Pull the full CISA KEV catalog and tell me which CVEs were added in the last 30 days so my team can update our threat intelligence feeds with the latest confirmed-in-the-wild exploits."}],"resultDescription":"A catalog of CVE records that CISA has confirmed are actively exploited in the wild. Each entry includes the CVE identifier, the affected vendor, product name, vulnerability name, the date CISA added it to the KEV list, and the remediation due date by which federal agencies are required to patch.","failureModes":["Payment failure (x402) if USDC balance is insufficient","Upstream CISA data source unavailability causing empty or stale response","Malformed POST body causing a 400 error","Network timeout if the full catalog response is large"],"whenToPreferThis":"Choose this endpoint when you need authoritative, government-confirmed exploitation data rather than theoretical CVSS scores or researcher-reported vulnerabilities. It is ideal for compliance workflows requiring CISA KEV adherence, patch prioritization based on proven real-world exploitation, or enriching internal vulnerability scanners with must-patch deadlines. Prefer this over raw NVD or CVE feeds when you specifically need the 'confirmed exploited in the wild' signal and associated remediation due dates.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T00:57:29.515Z","isFirstParty":false}