Known exploited vulnerabilities, as JSON. No key.
The data behind the KEV tracker and catalog diff: CISA KEV dates and due dates, ENISA and CIRCL listings, CVSS, EPSS, and links to our write-ups. Static files on Cloudflare's edge, rebuilt with the site several times a day. CORS is open; call it from a browser, a cron job, a SOAR playbook or an agent.
- CVE records
- 1,930
- Known exploited
- 1,751
- Vendors
- 361
- KEV adds, 30d
- 39
catalog snapshot: 2026-10-05T21:43:36.359278+00:00 · base: https://0daynews.com/api/v1/ · index.json
Endpoints
All GET, all JSON, all under https://0daynews.com. Unknown IDs return 404. Paths are versioned; fields get added, never renamed or removed within v1.
- /api/v1/cve/{CVE-ID}.json
One record: CVSS, EPSS, CISA KEV dates and due date, ENISA/CIRCL listing, our coverage. 1,930 files.
- /api/v1/kev/recent.json
CISA KEV additions in the trailing 30 days (39 right now). The one to poll.
- /api/v1/kev/{YYYY-MM}.json
CISA KEV additions by month added, 2021-11 to 2026-10. Closed months don't change.
- /api/v1/kev.json
Every exploited CVE we track across CISA, ENISA and CIRCL (1,751).
- /api/v1/vendors.json
361 vendors with CVE, KEV, critical and ransomware counts.
- /api/v1/vendors/{slug}.json
One vendor: exposure summary plus every CVE we hold for it.
- /api/v1/cves.json
Bulk download: every record in compact form.
- /api/kev-comparison.json
CISA vs ENISA vs CIRCL catalog overlap and lead-time analytics.
- /api/v1/openapi.json
OpenAPI 3.1 spec — feed it to codegen or an agent framework as tools.
Quick start
What CISA added in the last 30 days, with due dates:
curl -s https://0daynews.com/api/v1/kev/recent.json \
| jq -r '.items[] | "\(.kevDateAdded) \(.cveId) \(.vendor) \(.product) due \(.kevDueDate)"'One vendor's exposure at a glance:
curl -s https://0daynews.com/api/v1/vendors/ivanti.json \
| jq '.vendor | {name, cves, kev, knownRansomwareUse, latestKevDateAdded}'From JavaScript, no proxy needed:
const res = await fetch('https://0daynews.com/api/v1/cve/CVE-2024-3400.json');
if (res.ok) {
const cve = await res.json();
console.log(cve.cveId, cve.catalogs, cve.kev?.dueDate, cve.epss);
}Watch your stack
Drop this in a daily cron to list KEV entries for the vendors you run that come due in the next two weeks. Vendor slugs are in vendors.json.
# KEV entries for the vendors you run, due in the next 14 days
for v in microsoft fortinet ivanti; do
curl -s https://0daynews.com/api/v1/vendors/$v.json
done | jq -r --arg cutoff "$(date -d '+14 days' +%F)" \
'.items[] | select(.kevDueDate != null and .kevDueDate >= (now|strftime("%Y-%m-%d")) and .kevDueDate <= $cutoff)
| "\(.kevDueDate) \(.cveId) \(.vendor) \(.product)"'Prefer feeds? Every vendor page has its own RSS, and /kev.xml carries the whole exploited list.
Record shape
Real output for CVE-2024-3400 from this build (summary trimmed). List endpoints return the compact row on the right inside an envelope with count and items.
{
"cveId": "CVE-2024-3400",
"title": "Palo Alto Networks PAN-OS GlobalProtect Command Injection Zero-Day",
"summary": "A command-injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS allows an unauthenticated attacker to execute arbitrary code with...",
"severity": "critical",
"cvss": 10,
"epss": 0.99999,
"epssDate": "2026-10-05",
"vendor": "Palo Alto Networks",
"vendorSlug": "palo-alto-networks",
"product": "PAN-OS (GlobalProtect gateway/portal)",
"status": "kev",
"exploited": true,
"catalogs": {
"CISA": true,
"ENISA": false,
"CIRCL": false
},
"publishedDate": "2024-04-12",
"dateModified": "2026-10-05",
"kev": {
"dateAdded": "2024-04-12",
"dueDate": "2024-04-19",
"knownRansomwareUse": true,
"daysPublishedToKev": 0
},
"hasWriteup": true,
"url": "https://0daynews.com/cve/cve-2024-3400/",
"apiUrl": "https://0daynews.com/api/v1/cve/CVE-2024-3400.json",
"sourceUrl": "https://nvd.nist.gov/vuln/detail/CVE-2024-3400",
"coverage": []
}{
"cveId": "CVE-2024-3400",
"title": "Palo Alto Networks PAN-OS GlobalProtect Command Injection Zero-Day",
"severity": "critical",
"cvss": 10,
"epss": 0.99999,
"vendor": "Palo Alto Networks",
"vendorSlug": "palo-alto-networks",
"product": "PAN-OS (GlobalProtect gateway/portal)",
"status": "kev",
"catalogs": {
"CISA": true,
"ENISA": false,
"CIRCL": false
},
"publishedDate": "2024-04-12",
"kevDateAdded": "2024-04-12",
"kevDueDate": "2024-04-19",
"knownRansomwareUse": true,
"hasWriteup": true,
"url": "https://0daynews.com/cve/cve-2024-3400/",
"apiUrl": "https://0daynews.com/api/v1/cve/CVE-2024-3400.json"
}Fields
| cveId | Upper-case CVE ID. |
|---|---|
| severity / cvss | As stated by NVD or the vendor. Never our own estimate. cvss is null when unscored. |
| epss / epssDate | FIRST EPSS probability (0–1) of exploitation in the next 30 days, and the day it was scored. |
| status | kev | exploited-in-wild | patched | unpatched. |
| exploited | true if any catalog (CISA, ENISA, CIRCL) lists it or we have confirmed in-the-wild exploitation. |
| catalogs | { CISA, ENISA, CIRCL } booleans. ENISA = entries ENISA tags EU KEV. |
| kev.dateAdded / kev.dueDate | CISA KEV date added and BOD 22-01 remediation due date. |
| kev.knownRansomwareUse | true when CISA marks ransomware use Known. null when CISA says Unknown. Never false: CISA's flag has no 'no' value. |
| kev.daysPublishedToKev | Days from CVE publication to CISA listing. Can be zero or negative. |
| hasWriteup | false = auto-synced catalog record without a 0dayNews write-up yet. |
| coverage[] | Our articles that cover this CVE, newest first. |
| url / apiUrl / sourceUrl | Human page, this JSON, and the primary source (NVD or vendor advisory). |
KEV by month
42 earlier months back to 2021-11 follow the same pattern.
Most-tracked vendors
Number = CISA KEV entries for that vendor.
Terms of use, plainly
Free, no signup, no key. Cache what you fetch; files change at most a few times a day and Cloudflare serves them from the edge. If you're pulling every per-CVE file, use cves.json instead.
Please credit 0dayNews (https://0daynews.com). Upstream sources: CISA KEV, ENISA EUVD, CIRCL KEV (CC-BY-4.0), FIRST EPSS, NVD.
Severity and CVSS follow the source (NVD or vendor), never our own estimate. Records with hasWriteup: false are synced straight from the catalogs and haven't been reviewed by an editor. Wrong data? corrections@0daynews.com — fixes land in the next build. See also our corrections policy.
This API describes vulnerabilities and links to vendor and government advisories. It contains no exploit code and never will.