{
  "openapi": "3.1.0",
  "info": {
    "title": "0dayNews KEV & CVE API",
    "version": "1.0.0",
    "description": "Free, keyless, read-only JSON for exploited vulnerabilities: CISA KEV with due dates and ransomware flags, ENISA EUVD and CIRCL catalog cross-reference, EPSS and CVSS, and links to 0dayNews coverage. Regenerated on every site build.",
    "contact": {
      "url": "https://0daynews.com/contact/"
    }
  },
  "externalDocs": {
    "url": "https://0daynews.com/api/"
  },
  "servers": [
    {
      "url": "https://0daynews.com/api/v1"
    }
  ],
  "paths": {
    "/cve/{cveId}.json": {
      "get": {
        "operationId": "getCve",
        "summary": "One CVE record",
        "parameters": [
          {
            "name": "cveId",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "pattern": "^CVE-\\d{4}-\\d{4,}$"
            },
            "example": "CVE-2024-3400"
          }
        ],
        "responses": {
          "200": {
            "description": "The record",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/Cve"
                }
              }
            }
          },
          "404": {
            "description": "Not a CVE we track"
          }
        }
      }
    },
    "/cves.json": {
      "get": {
        "operationId": "listCves",
        "summary": "All CVE records (compact)",
        "responses": {
          "200": {
            "description": "List",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "apiVersion": {
                      "type": "string"
                    },
                    "generatedAt": {
                      "type": "string",
                      "format": "date-time"
                    },
                    "docs": {
                      "type": "string"
                    },
                    "attribution": {
                      "type": "string"
                    },
                    "count": {
                      "type": "integer"
                    },
                    "items": {
                      "type": "array",
                      "items": {
                        "$ref": "#/components/schemas/CveRow"
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/kev.json": {
      "get": {
        "operationId": "listExploited",
        "summary": "All exploited CVEs across CISA, ENISA, CIRCL",
        "responses": {
          "200": {
            "description": "List",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "apiVersion": {
                      "type": "string"
                    },
                    "generatedAt": {
                      "type": "string",
                      "format": "date-time"
                    },
                    "docs": {
                      "type": "string"
                    },
                    "attribution": {
                      "type": "string"
                    },
                    "count": {
                      "type": "integer"
                    },
                    "items": {
                      "type": "array",
                      "items": {
                        "$ref": "#/components/schemas/CveRow"
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/kev/recent.json": {
      "get": {
        "operationId": "listRecentKev",
        "summary": "CISA KEV additions in the trailing 30 days",
        "responses": {
          "200": {
            "description": "List",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "apiVersion": {
                      "type": "string"
                    },
                    "generatedAt": {
                      "type": "string",
                      "format": "date-time"
                    },
                    "docs": {
                      "type": "string"
                    },
                    "attribution": {
                      "type": "string"
                    },
                    "windowDays": {
                      "type": "integer"
                    },
                    "since": {
                      "type": "string",
                      "format": "date"
                    },
                    "count": {
                      "type": "integer"
                    },
                    "items": {
                      "type": "array",
                      "items": {
                        "$ref": "#/components/schemas/CveRow"
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/kev/{month}.json": {
      "get": {
        "operationId": "listKevByMonth",
        "summary": "CISA KEV additions for one month",
        "parameters": [
          {
            "name": "month",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string",
              "pattern": "^\\d{4}-\\d{2}$"
            },
            "example": "2026-09"
          }
        ],
        "responses": {
          "200": {
            "description": "List",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "apiVersion": {
                      "type": "string"
                    },
                    "generatedAt": {
                      "type": "string",
                      "format": "date-time"
                    },
                    "docs": {
                      "type": "string"
                    },
                    "attribution": {
                      "type": "string"
                    },
                    "month": {
                      "type": "string"
                    },
                    "count": {
                      "type": "integer"
                    },
                    "items": {
                      "type": "array",
                      "items": {
                        "$ref": "#/components/schemas/CveRow"
                      }
                    }
                  }
                }
              }
            }
          },
          "404": {
            "description": "No KEV additions that month"
          }
        }
      }
    },
    "/vendors.json": {
      "get": {
        "operationId": "listVendors",
        "summary": "Vendor index with exposure counts",
        "responses": {
          "200": {
            "description": "List",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "apiVersion": {
                      "type": "string"
                    },
                    "generatedAt": {
                      "type": "string",
                      "format": "date-time"
                    },
                    "docs": {
                      "type": "string"
                    },
                    "attribution": {
                      "type": "string"
                    },
                    "count": {
                      "type": "integer"
                    },
                    "items": {
                      "type": "array",
                      "items": {
                        "$ref": "#/components/schemas/Vendor"
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/vendors/{slug}.json": {
      "get": {
        "operationId": "getVendor",
        "summary": "One vendor's CVEs",
        "parameters": [
          {
            "name": "slug",
            "in": "path",
            "required": true,
            "schema": {
              "type": "string"
            },
            "example": "ivanti"
          }
        ],
        "responses": {
          "200": {
            "description": "Vendor and its CVEs",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "apiVersion": {
                      "type": "string"
                    },
                    "generatedAt": {
                      "type": "string",
                      "format": "date-time"
                    },
                    "docs": {
                      "type": "string"
                    },
                    "attribution": {
                      "type": "string"
                    },
                    "vendor": {
                      "$ref": "#/components/schemas/Vendor"
                    },
                    "count": {
                      "type": "integer"
                    },
                    "items": {
                      "type": "array",
                      "items": {
                        "$ref": "#/components/schemas/CveRow"
                      }
                    }
                  }
                }
              }
            }
          },
          "404": {
            "description": "Unknown vendor slug"
          }
        }
      }
    }
  },
  "components": {
    "schemas": {
      "CveRow": {
        "type": "object",
        "properties": {
          "cveId": {
            "type": "string"
          },
          "title": {
            "type": "string"
          },
          "severity": {
            "type": "string",
            "enum": [
              "critical",
              "high",
              "medium",
              "low"
            ]
          },
          "cvss": {
            "type": [
              "number",
              "null"
            ]
          },
          "epss": {
            "type": [
              "number",
              "null"
            ],
            "description": "FIRST EPSS probability, 0–1"
          },
          "vendor": {
            "type": "string"
          },
          "vendorSlug": {
            "type": "string"
          },
          "product": {
            "type": "string"
          },
          "status": {
            "type": "string",
            "enum": [
              "unpatched",
              "patched",
              "exploited-in-wild",
              "kev"
            ]
          },
          "catalogs": {
            "type": "object",
            "properties": {
              "CISA": {
                "type": "boolean"
              },
              "ENISA": {
                "type": "boolean"
              },
              "CIRCL": {
                "type": "boolean"
              }
            }
          },
          "publishedDate": {
            "type": "string",
            "format": "date"
          },
          "kevDateAdded": {
            "type": [
              "string",
              "null"
            ]
          },
          "kevDueDate": {
            "type": [
              "string",
              "null"
            ],
            "description": "CISA BOD 22-01 remediation due date"
          },
          "knownRansomwareUse": {
            "type": [
              "boolean",
              "null"
            ],
            "enum": [
              true,
              null
            ],
            "description": "true when CISA marks ransomware use Known; null when CISA says Unknown or the CVE isn't on CISA KEV. Never false."
          },
          "hasWriteup": {
            "type": "boolean",
            "description": "false = auto-synced catalog record without a 0dayNews write-up"
          },
          "url": {
            "type": "string"
          },
          "apiUrl": {
            "type": "string"
          }
        }
      },
      "Cve": {
        "type": "object",
        "properties": {
          "cveId": {
            "type": "string"
          },
          "title": {
            "type": "string"
          },
          "summary": {
            "type": "string"
          },
          "severity": {
            "type": "string"
          },
          "cvss": {
            "type": [
              "number",
              "null"
            ]
          },
          "epss": {
            "type": [
              "number",
              "null"
            ]
          },
          "epssDate": {
            "type": [
              "string",
              "null"
            ]
          },
          "vendor": {
            "type": "string"
          },
          "vendorSlug": {
            "type": "string"
          },
          "product": {
            "type": "string"
          },
          "status": {
            "type": "string"
          },
          "exploited": {
            "type": "boolean"
          },
          "catalogs": {
            "type": "object",
            "properties": {
              "CISA": {
                "type": "boolean"
              },
              "ENISA": {
                "type": "boolean"
              },
              "CIRCL": {
                "type": "boolean"
              }
            }
          },
          "publishedDate": {
            "type": "string"
          },
          "dateModified": {
            "type": [
              "string",
              "null"
            ]
          },
          "kev": {
            "type": [
              "object",
              "null"
            ],
            "properties": {
              "dateAdded": {
                "type": [
                  "string",
                  "null"
                ]
              },
              "dueDate": {
                "type": [
                  "string",
                  "null"
                ]
              },
              "knownRansomwareUse": {
                "type": [
                  "boolean",
                  "null"
                ],
                "enum": [
                  true,
                  null
                ],
                "description": "true when CISA marks ransomware use Known; null when CISA says Unknown or the CVE isn't on CISA KEV. Never false."
              },
              "daysPublishedToKev": {
                "type": [
                  "integer",
                  "null"
                ]
              }
            }
          },
          "hasWriteup": {
            "type": "boolean"
          },
          "url": {
            "type": "string"
          },
          "apiUrl": {
            "type": "string"
          },
          "sourceUrl": {
            "type": "string"
          },
          "coverage": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "title": {
                  "type": "string"
                },
                "url": {
                  "type": "string"
                },
                "published": {
                  "type": "string"
                }
              }
            }
          }
        }
      },
      "Vendor": {
        "type": "object",
        "properties": {
          "slug": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "cves": {
            "type": "integer"
          },
          "kev": {
            "type": "integer"
          },
          "critical": {
            "type": "integer"
          },
          "knownRansomwareUse": {
            "type": "integer"
          },
          "latestKevDateAdded": {
            "type": [
              "string",
              "null"
            ]
          },
          "products": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "apiUrl": {
            "type": "string"
          },
          "url": {
            "type": [
              "string",
              "null"
            ]
          }
        }
      }
    }
  }
}