
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
cisa-kev-mcp
Advanced tools
Use this MCP server to CISA Known Exploited Vulnerabilities catalog search. Tools include search known exploited, recent known exploited, catalog info
Search CISA's Known Exploited Vulnerabilities catalog. This is a focused companion to vulnerability scanners: it helps an agent identify vulnerabilities that CISA has marked as exploited in the wild.
search_known_exploited: search CVE, vendor, product, vulnerability name, and description fields.
recent_known_exploited: list recently added catalog entries.
catalog_info: inspect catalog version, release date, and entry count.
by_cve
by_vendor
by_product
ransomware
vendors
yearly
The feed is public and keyless. Catalog inclusion is a prioritization signal, not a complete risk assessment or a guarantee that a system is vulnerable.
npm install
npm run build
node dist/index.js
npm install
npm run build
node dist/index.js
The server uses stdio, so it can be connected to Claude Desktop, Cursor, VS Code, MCP Inspector, or another compatible MCP client.
search_known_exploited: Search CISArecent_known_exploited: List the most recently added entries in the CISA KEV catalog.catalog_info: Get CISA KEV catalog version and release metadata.This project is intentionally narrow. It should be treated as a practical helper, not a complete certification or security audit. Check the implementation and the returned data before using it with sensitive material. No credentials are required unless the project explicitly says otherwise.
After building, connect the server through your MCP client. The repository root also contains smoke-test.mjs for projects covered by the shared harness. A typical tool call starts with search_known_exploited.
FAQs
Use this MCP server to CISA Known Exploited Vulnerabilities catalog search. Tools include search known exploited, recent known exploited, catalog info
We found that cisa-kev-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.