search_cves
Search the catalog. Free text (q) and/or structured filters: vendor (slug), cwe (CWE-nnn), technique (ATT&CK id, such as T1190), year ("2024,2025"), sev ("critical,high"), kev (0|1), kev_from / kev_to (ISO days, half-open CISA listing window; imply kev=1), kev_vendor (the CISA vendorProject string verbatim, such as "Microsoft"), ransomware (0|1), detect (0|1, a detection signal we track), fix (0|1; fix=0 means the fix status was computed and this dataset holds no actionable vendor fix), automatable (0|1, CISA SSVC Automatable; 1=yes, 0=CISA assessed no, unassessed CVEs match neither), sighted (7|30: a named sensor network recorded the CVE in the last 7 or 30 days, a field sighting; presence per day, apart from the exploitation claims), malware (0|1: a published source ties a named malware family, tool, campaign or ransomware group to the CVE), watch (0|1: on KEV Watch at tier 1 or 2, reported exploited by trackers other than CISA and outside CISA KEV), epss_gte (0..1), ti (total|partial: CISA SSVC Technical impact, for CVEs with a CISA assessment held), triage_flag (0|1: CISA's forensic triage flag on the KEV entry), ssvc (0|1; ssvc=0 selects rows with no CISA SSVC assessment held), bod (3df|3d|14d|60d|fsu: the BOD 26-04 Table 1 read at the stated exposure, with exposed 0|1, default 1; a mapping at that exposure, and an agency's timeline still needs its own enumeration date), eco (OSS ecosystem, such as npm or PyPI), pkg (pkg_key, such as npm/lodash; for ranges use query_package), page, limit (1..50). Filter-only queries return the /browse slice ordered KEV-first then EPSS.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| q | No | ||
| ti | No | CISA SSVC Technical impact, for CVEs with a CISA assessment held | |
| bod | No | BOD 26-04 Table 1 read at the stated exposure: a mapping of KEV status and CISA SSVC values to a timeline key at that exposure | |
| cwe | No | ||
| eco | No | ||
| fix | No | ||
| kev | No | ||
| pkg | No | ||
| sev | No | ||
| page | No | ||
| ssvc | No | Whether this dataset holds a CISA SSVC assessment for the CVE | |
| year | No | ||
| limit | No | ||
| watch | No | On KEV Watch at tier 1 or 2: reported as exploited by trackers other than CISA, outside CISA KEV | |
| detect | No | ||
| kev_to | No | ISO day, exclusive upper bound on the CISA listing date | |
| vendor | No | ||
| chained | No | In a known exploit chain: a cited source reports the CVE was used together with another CVE in one exploit chain | |
| exposed | No | The exposure branch for bod: 1 publicly exposed (default), 0 internal | |
| malware | No | A published source ties a named malware family, tool, campaign or ransomware group to the CVE | |
| sighted | No | Field sighting window in days: a named sensor network recorded the CVE within the last 7 or 30 days | |
| epss_gte | No | ||
| kev_from | No | ISO day, inclusive lower bound on the CISA listing date | |
| technique | No | ATT&CK technique id, such as T1190 or T1059.001 | |
| kev_vendor | No | CISA's vendorProject, verbatim (for example 'Palo Alto Networks') | |
| ransomware | No | ||
| automatable | No | ||
| triage_flag | No | CISA's forensic triage flag on the KEV entry (BOD 26-04) | |
| chainability | No | On KCV Watch™: the CVE carries at least one chain candidate at tier A or B, a pair whose extracted exploit capabilities connect or whose records tie the two CVEs together; a candidate is not a confirmed chain |