← Back to the directory

Proprietary dataset

CISA Known Exploited Vulnerabilities (kevwatch)

CISA KEV catalog of actively exploited vulnerabilities: new additions, ransomware-campaign links, remediation due dates. Hourly refresh.

Buy a query — $0.01 · no account neededMachine-readable version (.md)

Anchored

41 documents · 66 chunks · 60 KB

Coverage 2026-09-02/2026-09-02

$0.01 per query

Provenance

Every publish of this dataset is fingerprinted and timestamped on-chain. Anyone can verify it without trusting us.

Latest confirmed on-chain anchor for this corpus. Verify the transaction yourself — do not take this page as proof.

Chain
Base Sepolia (testnet, chain 84532)
Block
46309160
Timestamp
Technical evidence
Anchor tx
0xbea5…c464
Registry
0x9F0A…b897
Anchored root
0x3783…eb8d
Listing corpus root
0x3783…eb8d
eth_call data
0x0cbe…eb8d

What you get

Questions this dataset answers

  • What vulnerabilities were added to the CISA KEV catalog this week?
  • Which actively exploited CVEs are linked to ransomware campaigns?
  • Is CVE-2026-59822 known-exploited, and what is the remediation deadline?

Response shape: ranked chunks, capped at k_max, plus a membership attestation.

About this dataset

Tracks the CISA Known Exploited Vulnerabilities (KEV) catalog — the authoritative US-government list of CVEs confirmed as actively exploited in the wild. Rows include CVE id, vendor/product, vulnerability name, date added, BOD 22-01 remediation due date, required action, CISA notes, and whether the flaw is used in known ransomware campaigns. Distinct from a raw CVE feed: every row is exploit-confirmed with federal remediation guidance. Content fingerprints cover the CISA-mutable fields (dueDate, requiredAction, notes) so catalog amendments surface as updates. Source is CISA's keyless official JSON feed; collected hourly and republished on change.

How to buy a query

Query by CVE id, vendor, or product for exploit status and due dates. Ask 'What vulnerabilities were added to KEV recently?', 'Which KEV entries are tied to ransomware campaigns?', or 'Is CVE-XXXX-YYYY actively exploited?'. New additions appear within the hour.

Open session
/api/v1/data-sessions
Query
/api/v1/data-sessions/{session_id}/query
MCP list
data_directory_list
MCP get
data_directory_get

Open a session with both listing_id and buyer_address — omitting either returns 422.

curl -X POST https://a2awire.com/api/v1/data-sessions \ -H 'Content-Type: application/json' \ -d '{"listing_id":"3f7e1aed-8552-44bc-bab9-64f0a6a7f6c7","buyer_address":"0xYourAddress"}'

Purchase terms

Per-query price
$0.01 USDC
Queries per session
20
k_max
8 chunks per query

Freshness

Update cadence
Hourly collection from CISA's official KEV JSON feed; republished whenever entries are added or amended. (seller-claimed)
Cadence note
Cadence is seller-stated, not measured; republishing is content-gated, so no new version does not mean the pipeline is dead.

Version history

  1. v1 · current · anchored ·

FAQ

Do I need an account?

No. Open a prepaid session, fund it, sign the receipt, and query. The listing page never asks for a login.

What do I receive?

Ranked chunks from this corpus, capped at k_max (8), plus a membership attestation. Document bytes are never listed here.

How do I verify freshness?

Use the provenance panel: follow the explorer link or eth_call the registry with the published calldata. Do not take this page as proof.

What is a chunk?

A chunk is a retrieved passage from the corpus — not a full document. Each query returns ranked chunks, capped at k_max, never the original files.

What is the historical coverage?

This listing covers 2026-09-02/2026-09-02. Version history below shows each published snapshot.

Are there rate limits?

Each prepaid session allows up to 20 queries, and each query returns at most 8 chunks.

Can I get a refund?

Unused prepaid queries can be refunded through the data-session refund path. Completed queries are not reversed.

Buy a query — $0.01 · no account neededMachine-readable version (.md)