CISA Known Exploited Vulnerabilities
Security · 1 endpoint
Every CVE CISA has confirmed is being exploited in the wild, with the remediation deadlines federal agencies are held to — filterable by vendor, product, or CVE.
Base URL
Endpoint
Snippet
Request — cURL
v1
curl https://api.diraz.ae/v1/security/kev \
-H "Authorization: Bearer drz_live_…"Query parameters
- qstring · optional
- Free-text match against the CVE id, name, and description.
- vendorstring · optional
- Exact vendor name, e.g. `Microsoft`, `MLflow`.
- productstring · optional
- Product name substring, e.g. `Exchange`.
- limitinteger · optional
- Entries per page, `1`-`500`.Default: 50
- max_ageinteger (seconds) · optional
- Ask for data no older than this. Clamped to the product's own floor, so it can narrow the window but never force a refresh on every call.Default: 300
Example response
200 OK
v1
{
"data": {
"catalog_version": "2026.08.19",
"date_released": "2026-08-19T17:00:32.1366Z",
"catalog_total": 1671,
"total": 1671,
"items": [
{
"cve": "CVE-2026-64849",
"vendor": "MLflow",
"product": "MLflow",
"vulnerability_name": "MLflow Server-Side Request Forgery Vulnerability",
"date_added": "2026-08-19",
"due_date": "2026-09-02",
"ransomware_use": "Unknown",
"short_description": "MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.",
"required_action": "Apply mitigations in accordance with vendor instructions or discontinue use of the product if mitigations are unavailable."
}
]
},
"meta": {
"request_id": "req_7Q2fK4mZ",
"as_of": "2026-08-20T04:05:00.000Z",
"age_seconds": 3600,
"next_update_at": "2026-08-20T05:05:00.000Z"
}
}- catalog_version / date_released / catalog_total
- Which edition of the catalog this copy is.
- total
- Entries matching your filters, before `limit`.
- items[].cve / vulnerability_name
- The CVE id and its human name.
- items[].date_added / due_date
- When CISA catalogued it and when remediation is due.
- items[].ransomware_use
- `Known` when ransomware crews use it, `Unknown` otherwise.
- items[].short_description / required_action
- What it does and what CISA says to do about it.
Errors
401 Unauthorized
v1
{
"error": {
"code": "UNAUTHORIZED",
"message": "The API key is invalid, expired, or revoked."
},
"meta": {
"request_id": "req_7Q2fK4mZ"
}
}Every failure carries a stable machine-readable code before the human message, and the same meta.request_id the successful responses carry. Quote it and we can find your exact request.
Errors are free
Nothing on this page is billed. You are charged for a 2xx and nothing else — a rejected key, a bad parameter, a rate limit, or an outage on our side all cost you zero. Retry without watching the meter.
- UNAUTHORIZEDHTTP 401
- Missing, malformed, expired, or revoked API key.
- FORBIDDENHTTP 403
- The key is valid but lacks the scope this product needs.
- VALIDATION_ERRORHTTP 422
- A query parameter is the wrong type or out of range.
- RATE_LIMITEDHTTP 429
- Rate limit exhausted. `Retry-After` says how long to wait.
- SERVICE_UNAVAILABLEHTTP 503
- No data recent enough to serve. Carries `Retry-After`, and is never billed.
- Status
- Operational
- Category
- Security
- Scope
- market:read
- Rate limit
- 60 requests / 60s per key
- Pricing
- 1 credit / request
- CISA Known Exploited Vulnerabilities
1/1 passing
Every response is timestamped. as_of is when the data was published, age_seconds how old that is now, and next_update_at when newer data is expected.
Three shapes to handle:
- Up to date200
The data is inside its published window. The overwhelming majority of requests.
- Delayeddelayed: true
Newer data is late. You still get the most recent there is, flagged so you can decide whether to use it.
- Unavailable503
Nothing recent enough to serve. Carries Retry-After, and is never billed.