/data/kev.json is the consolidated catalog the pages of this site read: every KEV entry joined with its EPSS score and the CVSS assessments listed by the NVD, plus the critical CVEs published in the last 7 days. The copy bundled with this build has 1,733 KEV entries, collected on 3 Oct 2026.
The file starts with a meta object: origin (build-snapshot or scheduled-collector), collectedAt, the KEV catalogVersion and the EPSS model date. Check collectedAt before trusting the content: it is the only statement of freshness.
Field of entries[]Meaning
- id
- CVE identifier.
- kev
- true when the CVE is in the CISA KEV catalog.
- vendor, product, name
- As written in the KEV catalog (vendorProject, product, vulnerabilityName). For CVEs outside KEV, vendor and product come from the first CPE in the NVD record, when there is one.
- added, due
- KEV dateAdded and dueDate, YYYY-MM-DD.
- ransomware
- true when KEV says knownRansomwareCampaignUse = "Known".
- epss, pct
- FIRST EPSS probability and percentile, 0 to 1; null when FIRST has no score. The model date is meta.epssDate.
- cvss[]
- Published assessments: source, type (NVD "Primary" or "Secondary"), version, score, severity label as published.
- published, modified
- Dates of the CVE record on the NVD, ISO 8601 UTC.
- desc, action, refs, cwes
- Only for KEV entries added in the last 30 days and for recent critical CVEs.
Example: identifiers in KEV with known ransomware use and an EPSS above 50%.