Skip to content
All APIs

CISA Known Exploited Vulnerabilities

Security · 1 endpoint

Every CVE CISA has confirmed is being exploited in the wild, with the remediation deadlines federal agencies are held to — filterable by vendor, product, or CVE.

Base URL

https://api.diraz.ae
0 requests1h cache1 credit / request

Endpoint

GET/v1/security/kev

Snippet

Request — cURL

v1

curl https://api.diraz.ae/v1/security/kev \
  -H "Authorization: Bearer drz_live_…"

Query parameters

qstring · optional
Free-text match against the CVE id, name, and description.
vendorstring · optional
Exact vendor name, e.g. `Microsoft`, `MLflow`.
productstring · optional
Product name substring, e.g. `Exchange`.
limitinteger · optional
Entries per page, `1`-`500`.Default: 50
max_ageinteger (seconds) · optional
Ask for data no older than this. Clamped to the product's own floor, so it can narrow the window but never force a refresh on every call.Default: 300

Example response

200 OK

v1

{
  "data": {
    "catalog_version": "2026.08.19",
    "date_released": "2026-08-19T17:00:32.1366Z",
    "catalog_total": 1671,
    "total": 1671,
    "items": [
      {
        "cve": "CVE-2026-64849",
        "vendor": "MLflow",
        "product": "MLflow",
        "vulnerability_name": "MLflow Server-Side Request Forgery Vulnerability",
        "date_added": "2026-08-19",
        "due_date": "2026-09-02",
        "ransomware_use": "Unknown",
        "short_description": "MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.",
        "required_action": "Apply mitigations in accordance with vendor instructions or discontinue use of the product if mitigations are unavailable."
      }
    ]
  },
  "meta": {
    "request_id": "req_7Q2fK4mZ",
    "as_of": "2026-08-20T04:05:00.000Z",
    "age_seconds": 3600,
    "next_update_at": "2026-08-20T05:05:00.000Z"
  }
}
catalog_version / date_released / catalog_total
Which edition of the catalog this copy is.
total
Entries matching your filters, before `limit`.
items[].cve / vulnerability_name
The CVE id and its human name.
items[].date_added / due_date
When CISA catalogued it and when remediation is due.
items[].ransomware_use
`Known` when ransomware crews use it, `Unknown` otherwise.
items[].short_description / required_action
What it does and what CISA says to do about it.

Errors

401 Unauthorized

v1

{
  "error": {
    "code": "UNAUTHORIZED",
    "message": "The API key is invalid, expired, or revoked."
  },
  "meta": {
    "request_id": "req_7Q2fK4mZ"
  }
}

Every failure carries a stable machine-readable code before the human message, and the same meta.request_id the successful responses carry. Quote it and we can find your exact request.

Errors are free

Nothing on this page is billed. You are charged for a 2xx and nothing else — a rejected key, a bad parameter, a rate limit, or an outage on our side all cost you zero. Retry without watching the meter.

UNAUTHORIZEDHTTP 401
Missing, malformed, expired, or revoked API key.
FORBIDDENHTTP 403
The key is valid but lacks the scope this product needs.
VALIDATION_ERRORHTTP 422
A query parameter is the wrong type or out of range.
RATE_LIMITEDHTTP 429
Rate limit exhausted. `Retry-After` says how long to wait.
SERVICE_UNAVAILABLEHTTP 503
No data recent enough to serve. Carries `Retry-After`, and is never billed.
Total requests0
Cache1h
Status
Operational
Category
Security
Scope
market:read
Rate limit
60 requests / 60s per key
Pricing
1 credit / request
Request a keyView as Markdown
  • CISA Known Exploited Vulnerabilities

1/1 passing

Every response is timestamped. as_of is when the data was published, age_seconds how old that is now, and next_update_at when newer data is expected.

Three shapes to handle:

  • Up to date200

    The data is inside its published window. The overwhelming majority of requests.

  • Delayeddelayed: true

    Newer data is late. You still get the most recent there is, flagged so you can decide whether to use it.

  • Unavailable503

    Nothing recent enough to serve. Carries Retry-After, and is never billed.