cisa-kev
backlog row · status planned · category SEC (Security advisories & identifiers) · lane B · refresh daily
What an agent uses it for
an agent triaging findings queries this for whether a CVE is known-exploited in the wild, with ransomware-use and due-date fields
Use it
xerj corpus add --from https://raw.githubusercontent.com/xerj-org/xerj/corpus-hub/tools/xerj-code/hub/cisa-kev.jsonxerj corpus index cisa-kev → xerj code cisa-kev "your question"Sources & pins
| source | pin | licence | size | review note |
|---|---|---|---|---|
| https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json | recipe | ? | curated pack | public domain (US gov); intake decides fetch mechanism (#1110 Part A owns this pack — coordinate, do not duplicate) |
— across — · added —
Rights
? — see per-source review blocks . The review block records a human opening each licence file at the pin; detector output is a hint, never the verdict.
Retrieval spot-check (G7)
not yet spot-checked; queries are pre-registered in the registry before grading.