{"uid":"cap_NnWgcJBGf3CssVHGhvXWj","slug":"tech-stack-cve-risk-checker-cisa-kev-epss-5cdd5495","name":"Tech Stack CVE Risk Checker (CISA KEV & EPSS)","description":"Check a declared technology stack (e.g. nginx, WordPress, Cisco IOS) against actively-exploited CVEs (CISA KEV) and high-EPSS-score vulnerabilities. Call before deploying or continuing to run a given technology stack in production.","url":"https://atq6wtkp6k.execute-api.us-east-1.amazonaws.com/prod/v1/payg/tech-stack-cve","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"domain":{"type":"string","description":"Alternative: pull tech_stack from a stored user profile by domain"},"tech_stack":{"type":"array","items":{"type":"string"},"description":"Declared technology product names"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.2","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.2/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_I9FUHKYAnJYYZ0YgBt2DN","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.2","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks a declared technology stack against actively-exploited CVEs from CISA's Known Exploited Vulnerabilities (KEV) catalog and high-EPSS-score vulnerabilities to surface critical security risks.","exampleAgentPrompt":"Before we deploy this stack to production, check it for actively exploited CVEs and high-EPSS vulnerabilities — we're running nginx 1.24, WordPress 6.4, and PHP 8.2.","exampleUseCases":[{"title":"Pre-deployment security gate check","prompt":"We're about to push to production. Can you check our stack — nginx 1.24, Node.js 20, and Redis 7 — against CISA's known exploited vulnerabilities list and flag anything with a high EPSS score?"},{"title":"Legacy system risk assessment","prompt":"We still have some servers running Apache 2.2 and WordPress 5.6 — can you check whether any of those have active exploits in the CISA KEV catalog that we should be urgently patching?"},{"title":"Third-party vendor technology audit","prompt":"A vendor told us they're running Cisco IOS XE and VMware ESXi 7 — can you check those technologies for any known actively-exploited CVEs before we let them connect to our network?"}],"resultDescription":"Returns a list of CVEs matching the declared technology stack, indicating which appear on the CISA Known Exploited Vulnerabilities (KEV) catalog and providing EPSS scores that reflect the probability of active exploitation, along with severity details and remediation context.","failureModes":["Unrecognized or misspelled technology names may return empty results rather than an error","Very new CVEs may not yet appear in CISA KEV or EPSS data if feeds haven't refreshed","Highly generic technology names without version numbers may produce overly broad or noisy results","Rate limiting or payment authorization failure returns 402 or 429 error","Internal server error (500) if the upstream CVE/EPSS data source is unavailable"],"whenToPreferThis":"Choose this endpoint when you need to cross-reference a specific technology stack against actively-exploited CVEs — particularly the CISA KEV list and EPSS probability scores — rather than doing a broad CVE database dump. Ideal for pre-deployment gates, vendor risk assessments, or incident triage where you need to know if your components are being actively exploited in the wild right now, not just theoretically vulnerable.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-16T06:41:05.317Z","isFirstParty":false}