Skip to content
feed: live
0dayNews
$ curl 0daynews.com/api/v1

Known exploited vulnerabilities, as JSON. No key.

The data behind the KEV tracker and catalog diff: CISA KEV dates and due dates, ENISA and CIRCL listings, CVSS, EPSS, and links to our write-ups. Static files on Cloudflare's edge, rebuilt with the site several times a day. CORS is open; call it from a browser, a cron job, a SOAR playbook or an agent.

CVE records
1,930
Known exploited
1,751
Vendors
361
KEV adds, 30d
39

catalog snapshot: 2026-10-05T21:43:36.359278+00:00 · base: https://0daynews.com/api/v1/ · index.json

Endpoints

All GET, all JSON, all under https://0daynews.com. Unknown IDs return 404. Paths are versioned; fields get added, never renamed or removed within v1.

ls /api/v1

Quick start

What CISA added in the last 30 days, with due dates:

curl -s https://0daynews.com/api/v1/kev/recent.json \
  | jq -r '.items[] | "\(.kevDateAdded)  \(.cveId)  \(.vendor) \(.product)  due \(.kevDueDate)"'

One vendor's exposure at a glance:

curl -s https://0daynews.com/api/v1/vendors/ivanti.json \
  | jq '.vendor | {name, cves, kev, knownRansomwareUse, latestKevDateAdded}'

From JavaScript, no proxy needed:

const res = await fetch('https://0daynews.com/api/v1/cve/CVE-2024-3400.json');
if (res.ok) {
  const cve = await res.json();
  console.log(cve.cveId, cve.catalogs, cve.kev?.dueDate, cve.epss);
}

Watch your stack

Drop this in a daily cron to list KEV entries for the vendors you run that come due in the next two weeks. Vendor slugs are in vendors.json.

# KEV entries for the vendors you run, due in the next 14 days
for v in microsoft fortinet ivanti; do
  curl -s https://0daynews.com/api/v1/vendors/$v.json
done | jq -r --arg cutoff "$(date -d '+14 days' +%F)" \
  '.items[] | select(.kevDueDate != null and .kevDueDate >= (now|strftime("%Y-%m-%d")) and .kevDueDate <= $cutoff)
   | "\(.kevDueDate)  \(.cveId)  \(.vendor) \(.product)"'

Prefer feeds? Every vendor page has its own RSS, and /kev.xml carries the whole exploited list.

Record shape

Real output for CVE-2024-3400 from this build (summary trimmed). List endpoints return the compact row on the right inside an envelope with count and items.

{
  "cveId": "CVE-2024-3400",
  "title": "Palo Alto Networks PAN-OS GlobalProtect Command Injection Zero-Day",
  "summary": "A command-injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS allows an unauthenticated attacker to execute arbitrary code with...",
  "severity": "critical",
  "cvss": 10,
  "epss": 0.99999,
  "epssDate": "2026-10-05",
  "vendor": "Palo Alto Networks",
  "vendorSlug": "palo-alto-networks",
  "product": "PAN-OS (GlobalProtect gateway/portal)",
  "status": "kev",
  "exploited": true,
  "catalogs": {
    "CISA": true,
    "ENISA": false,
    "CIRCL": false
  },
  "publishedDate": "2024-04-12",
  "dateModified": "2026-10-05",
  "kev": {
    "dateAdded": "2024-04-12",
    "dueDate": "2024-04-19",
    "knownRansomwareUse": true,
    "daysPublishedToKev": 0
  },
  "hasWriteup": true,
  "url": "https://0daynews.com/cve/cve-2024-3400/",
  "apiUrl": "https://0daynews.com/api/v1/cve/CVE-2024-3400.json",
  "sourceUrl": "https://nvd.nist.gov/vuln/detail/CVE-2024-3400",
  "coverage": []
}
{
  "cveId": "CVE-2024-3400",
  "title": "Palo Alto Networks PAN-OS GlobalProtect Command Injection Zero-Day",
  "severity": "critical",
  "cvss": 10,
  "epss": 0.99999,
  "vendor": "Palo Alto Networks",
  "vendorSlug": "palo-alto-networks",
  "product": "PAN-OS (GlobalProtect gateway/portal)",
  "status": "kev",
  "catalogs": {
    "CISA": true,
    "ENISA": false,
    "CIRCL": false
  },
  "publishedDate": "2024-04-12",
  "kevDateAdded": "2024-04-12",
  "kevDueDate": "2024-04-19",
  "knownRansomwareUse": true,
  "hasWriteup": true,
  "url": "https://0daynews.com/cve/cve-2024-3400/",
  "apiUrl": "https://0daynews.com/api/v1/cve/CVE-2024-3400.json"
}

Fields

cveIdUpper-case CVE ID.
severity / cvssAs stated by NVD or the vendor. Never our own estimate. cvss is null when unscored.
epss / epssDateFIRST EPSS probability (0–1) of exploitation in the next 30 days, and the day it was scored.
statuskev | exploited-in-wild | patched | unpatched.
exploitedtrue if any catalog (CISA, ENISA, CIRCL) lists it or we have confirmed in-the-wild exploitation.
catalogs{ CISA, ENISA, CIRCL } booleans. ENISA = entries ENISA tags EU KEV.
kev.dateAdded / kev.dueDateCISA KEV date added and BOD 22-01 remediation due date.
kev.knownRansomwareUsetrue when CISA marks ransomware use Known. null when CISA says Unknown. Never false: CISA's flag has no 'no' value.
kev.daysPublishedToKevDays from CVE publication to CISA listing. Can be zero or negative.
hasWriteupfalse = auto-synced catalog record without a 0dayNews write-up yet.
coverage[]Our articles that cover this CVE, newest first.
url / apiUrl / sourceUrlHuman page, this JSON, and the primary source (NVD or vendor advisory).

Terms of use, plainly

Free, no signup, no key. Cache what you fetch; files change at most a few times a day and Cloudflare serves them from the edge. If you're pulling every per-CVE file, use cves.json instead.

Please credit 0dayNews (https://0daynews.com). Upstream sources: CISA KEV, ENISA EUVD, CIRCL KEV (CC-BY-4.0), FIRST EPSS, NVD.

Severity and CVSS follow the source (NVD or vendor), never our own estimate. Records with hasWriteup: false are synced straight from the catalogs and haven't been reviewed by an editor. Wrong data? corrections@0daynews.com — fixes land in the next build. See also our corrections policy.

This API describes vulnerabilities and links to vendor and government advisories. It contains no exploit code and never will.