Skip to content

PRP: Enricher for CISA Known Exploited Vulnerabilities (KEV) Catalog #2194

Description

@Para-dox00
  • Software distribution method or binary type: CISA KEV JSON feed — cross-references CVE IDs found in scan findings against the CISA Known Exploited Vulnerabilities catalog (known_exploited_vulnerabilities.json)
  • Popularity of distribution method: The CISA KEV catalog is the authoritative, US-government-maintained list of CVEs actively exploited in the wild. As of mid-2025 it contains 1,200+ entries. Under CISA Binding Operational Directive 22-01, all US federal civilian agencies are required to remediate KEV-listed vulnerabilities on defined timelines. The catalog is freely available with no authentication and is updated multiple times per week. It is the single most actionable prioritization signal for vulnerability triage in any organization.
  • Any critical, emergent vulnerability associated with software from the distribution method: By definition, every entry is actively exploited. Representative entries include CVE-2021-44228 (Log4Shell), CVE-2022-22965 (Spring4Shell), CVE-2023-34362 (MOVEit SQL injection), CVE-2024-6387 (OpenSSH regreSSHion), CVE-2024-3400 (PAN-OS command injection). Current scalibr enrichers surface vulnerabilities but provide no signal distinguishing theoretical risk from confirmed active exploitation — KEV integration fills this gap directly.
  • Resources:

Metadata

Metadata

Assignees

Labels

PRPPatch Reward Program: This label is added to all PRP related issues for easy filteringPRP:Out of scopePatch Reward Program: This contribution request is not in scope for the PRP.PRP:RequestPatch Reward Program: This issue is a PRP contribution request and is being reviewed by the panel.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions