Skip to content

Data collected

CVEs Live

CVE feeds: KEV additions as RSS and JSON

Follow new exploited vulnerabilities in a feed reader or a script, filtered by your vendors, without creating an account.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

Comma-separated. Leave empty for every KEV addition.

The feed lists the 50 most recent matching KEV entries, with EPSS and due date in each item. The filter is applied when the feed is requested from the live site.

The whole catalog as one JSON file

/data/kev.json is the consolidated catalog the pages of this site read: every KEV entry joined with its EPSS score and the CVSS assessments listed by the NVD, plus the critical CVEs published in the last 7 days. The copy bundled with this build has 1,733 KEV entries, collected on 3 Oct 2026.

The file starts with a meta object: origin (build-snapshot or scheduled-collector), collectedAt, the KEV catalogVersion and the EPSS model date. Check collectedAt before trusting the content: it is the only statement of freshness.

id
CVE identifier.
kev
true when the CVE is in the CISA KEV catalog.
vendor, product, name
As written in the KEV catalog (vendorProject, product, vulnerabilityName). For CVEs outside KEV, vendor and product come from the first CPE in the NVD record, when there is one.
added, due
KEV dateAdded and dueDate, YYYY-MM-DD.
ransomware
true when KEV says knownRansomwareCampaignUse = "Known".
epss, pct
FIRST EPSS probability and percentile, 0 to 1; null when FIRST has no score. The model date is meta.epssDate.
cvss[]
Published assessments: source, type (NVD "Primary" or "Secondary"), version, score, severity label as published.
published, modified
Dates of the CVE record on the NVD, ISO 8601 UTC.
desc, action, refs, cwes
Only for KEV entries added in the last 30 days and for recent critical CVEs.
curl -s https://cves.live/data/kev.json \
  | jq '.entries[] | select(.kev and .ransomware and .epss > 0.5) | .id'

Example: identifiers in KEV with known ransomware use and an EPSS above 50%.

Using the feed

  1. Type the vendors or products you operate in the field above. A term matches when it is part of the vendor or product name, so “exchange” matches “Exchange Server”.
  2. Copy the RSS address into your feed reader, or the JSON Feed address into your script or chat integration.
  3. Each item links to the page of the CVE on this site, where the required action, the affected versions and the primary sources are.

Items are KEV additions only. A feed of every new CVE would carry dozens of items a day; the point of this one is that each item is a vulnerability someone is already using.

Questions

How do I get only the vendors I care about?

Add a stack parameter with comma-separated terms, for example /feed/kev.xml?stack=fortinet,ivanti. An entry is included when its vendor or product contains any of the terms. The filter is applied by the site’s edge worker when the feed is requested.

How often does the feed change?

The collector reads the KEV catalog every eight hours and the feed is rebuilt from the catalog it keeps. CISA usually adds entries on US business days, so several days can pass with no new items.

May I reuse the data?

The KEV catalog is a work of the US government and is in the public domain. EPSS scores are free to use with attribution to FIRST.org. NVD data is public; products that use the NVD API must state that they are not endorsed or certified by the NVD. Keep the source names next to the numbers, as this site does.

Related sections