/cisa/vulnerabilities

POST /api/cisa/vulnerabilities

Price: 20 credits

Get a CISA Known Exploited Vulnerabilities catalog entry by CVE id

How to use it

Answers whether CISA has recorded a CVE as actively exploited in the wild, and what US federal agencies are ordered to do about it by when. Pass the CVE id in any text containing it, including a full sentence or an NVD URL. Absence from the catalog is a finding about the vulnerability, not a gap in the lookup, so read it as 'CISA has not recorded exploitation' rather than as unknown. `notes` here is a single ';'-separated string, unlike ics_advisories and CSAF vulnerabilities on this platform where `notes` is a list of structured objects — this endpoint's KEV source ships it as one string.

Parameters

Request body

Response

Errors

Response headers