CISA Known Exploited Vulnerabilities
LiveCheck CISA's recorded known exploitation by CVE.
Check an exact CVE against CISA's Known Exploited Vulnerabilities catalogue, or research filtered vendor and product additions. Keep recorded exploitation, ransomware uncertainty and federal remediation context attached to a dated source snapshot.
Connect / 2 tools
Server URL
https://toolcargo.com/mcp/cisa-kevClaude Code
claude mcp add --transport http --scope user toolcargo-cisa-kev https://toolcargo.com/mcp/cisa-kev \
--header "Authorization: Bearer YOUR_API_KEY"Create a key in your dashboard. Other clients: setup guides.
What it helps you do
- Recorded known-exploitation lookup
- Filtered vendor and product research
- Dated federal source context
Built for: Developer and security research agents reviewing public vulnerability records.
Example requests
Add recorded exploitation context to an advisory
“Look up CVE-2021-44228 in CISA KEV, then research Apache records with known ransomware campaign use. Inspect two explicit pages with the same snapshot and report source dates and federal due-date context. Do not treat absence as safety or give personalized patch instructions.”
Source-linked recorded exploitation context alongside general advisory research.
Tools
| Tool | What it does | Access |
|---|---|---|
cisa_kev_lookupLook up CISA known exploitation by CVE | Look up one exact CVE in CISA's validated Known Exploited Vulnerabilities snapshot. Returns dated membership, bounded source descriptions/actions, federal due-date context, ransomware/forensic-triage status and provenance. Not listed does not mean safe or not exploited. One shared-plan call. | Read-only |
cisa_kev_catalogueResearch a filtered CISA KEV page | Filter CISA KEV by literal vendor/product, inclusive added dates or known/unknown ransomware status. At least one filter; AND combined. Up to 20 records with explicit snapshot-bound nextCursor, newest added first. No automatic paging, exploit code, scanning or personalized patch/compliance decisions. One shared-plan call. | Read-only |
Requirements
- • A ToolCargo account with Site Audit activated (free). No CISA account, API key, usage form or paid provider.
Limitations
- • CISA supplies a public JSON catalogue under CC0. Linked third-party content has separate terms. CISA/DHS logos, seals and endorsement are not included; upstream availability is not guaranteed.
- • A validated snapshot can be cached across instances for at most 30 minutes and remaining source max-age minus Age; fallback 30 minutes when valid max-age is unavailable. Source no-store/no-cache prevents reusable caching. Snapshot SHA256 identifies the bounded projection, not original source bytes.
- • Not listed means absent from that validated catalogue snapshot only; it does not prove no exploitation, vulnerability or risk. Failed or expired source reads never produce a stale negative.
- • Due dates and required actions retain federal remediation context under BOD 26-04, which superseded BOD 22-01. No asset assessment, legal/compliance guarantee or personalized patch instructions.
- • Ransomware Unknown means lacks confirmation, not no. Optional ransomware and forensic-triage strings retain missing/unrecognized states.
- • At least one literal vendor/product, added-date or ransomware filter; up to 20 records per explicit snapshot-bound cursor page. Pages cannot mix snapshots. Text and reference links are bounded with truncation signals.
- • One fixed HTTPS feed, 4 MB/15-second transport bound, at most 10,000 validated records and shared refresh lease/cooldown. No redirects, retries, mirrors, user data, code, exploits, scanning, installs or followed links. Successful cache hits also use one shared-plan call.
Supported clients
“Tested” means we connected that client to this endpoint and ran a tool call ourselves. Recorded client-specific tests currently cover Site Audit. Other connectors use the documented setup until tested in that client.
| Claude Code | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| Claude (claude.ai) | OAuth sign-in | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| Cursor | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| VS Code (Copilot agent mode) | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| ChatGPT (developer mode) | OAuth sign-in | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| MCP Inspector | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
Practical workflows
More in Developer tools
- Hugging Face Hub Research LiveFind models and datasets, then review their public metadata.
- npm Package Intelligence LiveCompare dependencies before adding them to a project.
- OSV Vulnerability Lookup LiveCheck package versions against public vulnerability advisories.
- PyPI Package Intelligence LiveCompare Python packages before choosing a dependency.
Pricing
Included with Site Audit. Each successful exact lookup or filtered page uses one shared-plan call.
Free
$0Try hosted tools with a shared monthly allowance.
50 shared calls/month
Pro
$12/moProposed larger shared allowance; see checkout status on the pricing page.
2,000 shared calls/month
Proposed test price. See the pricing page for checkout status.