Skip to content

Data tools

CVE monitor with NVD, CISA KEV and EPSS.

Returns one row per CVE with the description, CVSS score and weakness type from the National Vulnerability Database, whether the CVE is in CISA's Known Exploited Vulnerabilities catalog, and FIRST's EPSS estimate of the probability that it will be exploited in the next 30 days.

Price

5 USD

per 1 000 CVEs. Platform usage is included.

Try it free on Apify

Try it free: Apify's free plan includes 5 USD of usage every month, enough for about 1 000 CVEs. No credit card needed.

What it does.

Search NVD by keyword or look up CVE ids, then filter by vendor, minimum CVSS score, KEV status and minimum EPSS score, within a date window on publication, last change or the date CISA added the CVE to KEV. With onlyNew a CVE comes once more on the day CISA adds it to KEV, so a CVE you saw as unexploited is reported again when it becomes exploited.

A run with empty input returns the CVEs published in the last 7 days that have a CVSS score of 7 or higher and are in KEV or have an EPSS score above 0.1; the sample below is such a run on 7 October 2026. The rows describe published vulnerabilities. Whether a CVE affects you depends on the versions and configuration you run.

Sample from a real run.

4 rows (selected fields) from run n2nazZUPgVvFDdaUF on 7 October 2026, exactly as the tool returned them.
cveIdpublishedcvssScorecvssSeveritycweaffectedVendorsaffectedProductsinKevkevDateAddedepssScore
CVE-2026-887792026-10-04T04:16:43.680Z7.5HIGHCWE-119NetScaler, citrixADC, Gateway, netscaler_application_delivery_controller, netscaler_gatewaytrue2026-10-040.00592
CVE-2026-1042862026-10-01T20:17:24.010Z9.8CRITICALCWE-22FortinetFortiMailtrue2026-10-010.02201
CVE-2026-1024902026-09-30T17:16:40.707Z9.8CRITICALCWE-269Zammad GmbH, zammadZammadtrue2026-10-020.00629
CVE-2026-1024892026-09-30T17:16:40.550Z9.8CRITICALCWE-384Zammad GmbH, zammadZammadtrue2026-10-020.01396

What people use it for.

  • Triage of new CVEs

    The CVEs for the vendors you run, with CVSS score, KEV status and EPSS side by side.
  • Ticketing and SIEM

    Feed only the CVEs that matter to a ticketing system or a SIEM.
  • Scanner reports

    Check a list of CVE ids from a scanner report against KEV and EPSS.
  • Newly exploited vulnerabilities

    A daily run for your vendors with dateField set to kevDateAdded and onlyNew set to true lists the CVEs CISA has added to KEV.

Fields.

Every row has these fields. Field names are stable between versions.
FieldWhat it holds
cveIdThe CVE id
publishedWhen the CVE was published in NVD, UTC
lastModifiedWhen NVD last changed the CVE, UTC
vulnStatusNVD's analysis status, for example Analyzed, Awaiting Analysis or Deferred
descriptionEnglish description, at most 500 characters
cvssScoreCVSS base score. Version 3.1 is used when it exists, then 3.0, 4.0 and 2.0, and NVD's own score before the issuer's
cvssSeveritySeverity of the CVSS score, for example CRITICAL
cvssVersionCVSS version of the score, for example 3.1
cvssVectorCVSS vector of the score
cweWeakness types, for example ["CWE-22"]
affectedVendorsAffected vendors from the CVE record and NVD's CPE data, up to 20
affectedProductsAffected products from the CVE record and NVD's CPE data, up to 20. A product can appear twice, by the issuer's name and by the CPE name
inKevtrue when the CVE is in the CISA KEV catalog
kevDateAddedWhen CISA added the CVE to KEV
kevDueDateRemediation deadline for US federal agencies
kevRansomwareCISA's knownRansomwareCampaignUse: Known or Unknown. null when not in KEV
epssScoreEPSS probability of exploitation in the next 30 days, 0 to 1. null when FIRST has not scored the CVE yet
epssPercentilePercentile of the EPSS score among all scored CVEs
epssDateDate of the EPSS score
referencesUp to 5 links, vendor advisories and patches first
nvdUrlThe CVE's page at NVD
sourceNames of the sources, for attribution
licenseTerms of the sources
retrievedAtTime of the run

Input example.

Paste it into the JSON tab of the actor in Apify Console, or send it to the Apify API.
{
  "kevOnly": false,
  "onlyNew": false,
  "dateField": "published",
  "maxResults": 50
}

What a run costs

A run with the default input returned 4 CVEs on 7 October 2026 in about 10 seconds, which is 0.02 USD; in a test on 4 October it read 2 571 CVEs from NVD and returned the 7 that met the default filter, 0.035 USD. maxResults caps every run (default 50), a run without matches costs nothing per CVE, and platform usage is included in the price.

Run it on a schedule.

  1. Ask for new rows only

    Set onlyNew to true. The actor remembers what it has already delivered for the same input, in a named key-value store in your own Apify account (nightwave-state-vulnerability-monitor-nvd-kev-epss).
  2. Add a schedule

    Add the actor to a schedule in Apify Console, for example with the cron expression 0 7 * * * for 07:00 every day.
  3. Get what is new

    The first run returns everything in the selection. After that, each run returns and charges only what is new. A run with nothing new finishes with 0 rows and costs nothing.

Source and license.

CVE records come from the NVD API 2.0 published by NIST, KEV status from the CISA KEV catalog and scores from the FIRST EPSS API. Without an API key NVD allows 5 requests in a rolling 30 second window, and the tool keeps under that. This product uses the NVD API but is not endorsed or certified by the NVD. The tool is not affiliated with or endorsed by NIST, CISA or FIRST.

NVD data is US government information and not subject to copyright in the United States. CISA distributes the KEV database under CC0 1.0. FIRST publishes EPSS scores freely and requests attribution when they are used in publications or products. Every row carries source and license, so you can credit the sources.

More data tools.

Try it on Apify.

Apify's free plan includes 5 USD of usage every month, so you can try the input above at no cost. Apify handles the account, the runs and the payment.