Cisa Kev
liveSecurityGovernmentCISA Known Exploited Vulnerabilities (KEV) catalog — query CVE entries, vendors, and recently added exploited vulnerability records.
4tools
0msauth
free tier50 calls/day
Tools
catalogFull KEV catalog (metadata + entries).
No parameters required.
Try it
Response
entrySingle KEV entry by CVE id.
No parameters required.
Try it
Response
vendorsDistinct vendors with entries.
No parameters required.
Try it
Response
recentEntries added in the last N days.
No parameters required.
Try it
Response
Test with curl
The gateway speaks JSON-RPC 2.0 over HTTP POST. You can test any pack directly from the terminal.
List available tools
bash
curl -X POST https://gateway.pipeworx.io/cisa-kev/mcp \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'Call a tool
bash
curl -X POST https://gateway.pipeworx.io/cisa-kev/mcp \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"catalog","arguments":{}}}'Use with the SDK
Install @pipeworx/sdk to call tools from any TypeScript/Node project.
TypeScript
import { Pipeworx } from '@pipeworx/sdk';
const px = new Pipeworx();
const result = await px.call("catalog", {});ask_pipeworx
// Or ask in plain English:
const answer = await px.ask("cisa known exploited vulnerabilities (kev) catalog — query cve entries, vendors, and recently added exploited vulnerability records");