Technical and passive OSINT · Hosted free and open-data sources
CISA KEV
Licence or access: free JSON/CSV
- status access
- free JSON/CSV
- i o and fit
- CVE → known-exploited status/dates
- current limitations and safe interpretation
- exploitation observed somewhere, not evidence target is affected/exploited
- official source
- Catalog
Official sources
- Catalog https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Catalogued at the 2026-09-01 research baseline. Verify the licence, free-tier limits, API schema and source terms again before deployment, and record a version-pinned registry entry for whatever you select.