CISA KEV Lookup

Check whether a CVE is in CISA's Known Exploited Vulnerabilities catalogue, with the required action, due date and whether it is known to be used in ransomware.

Uses an external data source

Your search term is sent to the public authority named on this page so the answer reflects current data.

Data source: CISA Known Exploited Vulnerabilities catalogue

Use the tool

Up to 500 at once. Checked against CISA's published catalogue.

Known exploited, not predicted

CISA adds a CVE to the Known Exploited Vulnerabilities catalogue only when there is reliable evidence of active exploitation, the CVE has an ID, and there is clear remediation guidance. That makes KEV the strongest single prioritisation signal there is. It is not a severity score or a prediction: it is a record that attackers are using the vulnerability now. For US federal civilian agencies each entry comes with a binding due date under Binding Operational Directive 22-01. Everyone else can use the same dates as a benchmark.

What each entry tells you

The vendor and product, CISA's name for the vulnerability, the date it was added, the required action (usually "apply updates per vendor instructions", sometimes mitigations or discontinuing the product), and the due date. It also says whether the vulnerability is known to have been used in ransomware campaigns. That field is "Known" or "Unknown". "Unknown" means CISA has no confirmation either way, not that ransomware has never used it.

Only CISA decides membership

This tool reads the catalogue CISA publishes, and nothing else. Other databases copy KEV fields into their own records, and those copies can lag behind. They are never used to decide whether a CVE is listed. If the catalogue cannot be downloaded and no recent copy exists, the answer is Unknown, not "not listed". The catalogue version and release date are shown with every result, so you know exactly which edition you checked against.

Frequently asked questions

Does "not listed" mean the CVE is not exploited?

No. It means CISA has not added it. Exploitation may be unobserved, unreported, or not yet confirmed to CISA's standard. Check the EPSS score for a probability estimate.

How often does the catalogue change?

CISA adds entries several times a week. This tool refreshes its copy at most every 6 hours and shows the catalogue's own release timestamp.

Can entries be removed?

Rarely, but yes. CISA has removed entries that were added in error. Re-check before closing a ticket on the basis of an old lookup.

Source and attribution

What this tool can and cannot tell you. It reports what the named source held when it was queried. Where that source has no record, the answer is unknown rather than safe - an absent entry is not evidence of absence.

Security guidance here follows current published sources - OWASP, MDN, the relevant RFCs, NIST, CISA, FIRST and MITRE - which are linked beside the specific claims they support.

Rate this tool

Was this tool useful? Your feedback helps us improve it.

No ratings yet — be the first to rate this tool.
Your rating (required)
0 / 2000

Please do not include passwords, payment details or other sensitive information.

Your feedback is sent privately to the A2Z.Tools team and will not be posted publicly.