About this dataset
Tracks the CISA Known Exploited Vulnerabilities (KEV) catalog — the authoritative US-government list of CVEs confirmed as actively exploited in the wild. Rows include CVE id, vendor/product, vulnerability name, date added, BOD 22-01 remediation due date, required action, CISA notes, and whether the flaw is used in known ransomware campaigns. Distinct from a raw CVE feed: every row is exploit-confirmed with federal remediation guidance. Content fingerprints cover the CISA-mutable fields (dueDate, requiredAction, notes) so catalog amendments surface as updates. Source is CISA's keyless official JSON feed; collected hourly and republished on change.