CISA KEV
Compare a buyer-supplied inventory with the official CISA KEV catalog
CISA KEV Asset Remediation Report compares a bounded buyer-supplied asset inventory with the official CISA Known Exploited Vulnerabilities Catalog. It returns conservative potential matches, CISA requiredAction and dueDate evidence, deadline alerts, and review handoffs. Matches are never assertions that an asset is vulnerable or compromised. Labels are potential_match + review_required only. Version match is not_assessed_from_cisa_catalog. baseline_only and unchanged: 0 rows / 0 charge. It is not an OSV/GitHub package CVE monitor — that job is OSS Vulnerability Monitor — and it is not HTTP security headers (Security Headers Checker).
Try Input: 1 asset, emit_backfill, generateReport false, includeDeadlineAlerts false. Live Store: from $60.00 / 1,000 kev asset potential matches ($0.06) + $0.35 deadline alert + $12 report + $8 export. No Actor Start. baseline_only is free.
Try the cheapest first paid CISA KEV Asset Remediation Report run on Apify Input
Open taroyamada/cisa-kev-asset-remediation-report on the Apify Store
CISA KEV vs inventory, not OSV package CVEs or HTTP header grades
Use this page when you already hold an asset inventory (vendor + product or CPE 2.3) and want conservative joins to the official CISA KEV JSON. Use OSS Vulnerability Monitor for package-name CVE rows from OSV/GitHub. Use PyPI & npm Dependency Risk Report for pinned package upgrade risk. Use Security Headers Checker for HTTP headers.
| CISA KEV Asset Remediation Report | OSS Vulnerability Monitor | PyPI & npm Dependency Risk Report | |
|---|---|---|---|
| Intent | Join buyer inventory to official CISA KEV | Package CVE rows from OSV/GitHub | Pinned package upgrade risk |
| Primary input | assets[] with assetId plus vendor/product or CPE |
packages |
Pinned package lists |
| What it reads | Official CISA KEV JSON plus the inventory you supply | OSV/GitHub public APIs | Registry/package metadata |
| Primary output | kev-asset-potential-match (Store primary), optional deadline/report/export | Vulnerability result rows | Upgrade-risk report rows |
| Not this job | Never asserts an asset is vulnerable or compromised. | Not CISA KEV dueDate/requiredAction joins. | Not CISA KEV catalog matching. |
Store ID: taroyamada/cisa-kev-asset-remediation-report. Categories on the live Store card: Developer Tools. Fetch only sources you are authorized to use. Respect source terms, robots.txt, and rate limits.
Use cases
- Paste one asset (vendor + product, optional versions or CPE 2.3), skip report/alerts/export, use emit_backfill for a paid try.
- Use
baseline_onlyto save the catalog snapshot with zero rows / zero charge. - Deadline window:
deadlineWithinDaysdefaults to 30 (min 0, max 3650) whenincludeDeadlineAlertsis true ($0.35 per alert).
The live Store tagline (truncated on the card) is: compare a bounded buyer-supplied asset inventory with the official CISA Known Exploited Vulnerabilities Catalog; return conservative potential matches, CISA requiredAction and dueDate evidence, deadline alerts, and review handoffs. Schema default generateReport is true — turn it off on the cheapest paid path. Default dryRun is false. Default maxChargeUsd is 50.
How is CISA KEV Asset Remediation Report different from OSS Vulnerability Monitor and PyPI & npm Dependency Risk Report?
CISA KEV Asset Remediation Report (taroyamada/cisa-kev-asset-remediation-report) joins a buyer-supplied inventory to the official CISA KEV catalog. Live PPE is kev-asset-potential-match $0.06 (Store primary), kev-deadline-alert $0.35, kev-remediation-report $12, and kev-remediation-export $8. No Actor Start. OSS Vulnerability Monitor is OSV/GitHub package CVEs. PyPI & npm Dependency Risk Report is pinned upgrade risk. Security Headers Checker is HTTP headers. Use this Actor for CISA KEV inventory joins. Use OSS Vulnerability Monitor for package CVEs. Matches are never assertions that an asset is vulnerable or compromised.
What input is required?
Live required fields: assets, monitorKey, initialRunMode, generateReport, emitPotentialMatches, includeDeadlineAlerts, emitUnchanged, maxChargeUsd, dryRun. assets[] required per item: assetId. Optional per item: vendor, product, aliases (max 10), vendorAliases (max 10), versions (max 20), cpe, environment, label. Array minItems 1, maxItems 250. Default sample is Apache Log4j2. initialRunMode: baseline_only (save baseline only) or emit_backfill (emit current matches). Optional: deadlineWithinDays (default 30), emitExport (default false), requestTimeoutSeconds, rateLimitMs, maxRetries, backoffBaseMs, maxBackoffMs, delivery (dataset or webhook), webhookUrl. Schema default generateReport is true; default dryRun is false; default maxChargeUsd is 50.
| Field | Type | Default | Notes |
|---|---|---|---|
assets |
object[] | Apache Log4j2 sample | Inventory; vendor+product or CPE 2.3. Item required: assetId. minItems 1, maxItems 250. Required. |
monitorKey |
string | production-asset-portfolio |
Baseline namespace. Required. |
initialRunMode |
string | baseline_only |
Enum: baseline_only, emit_backfill. Required. |
generateReport |
boolean | true |
Report when changed matches exist ($12). Required. Turn off for cheapest try. |
emitPotentialMatches |
boolean | true |
Per-asset match rows ($0.06). Required. |
includeDeadlineAlerts |
boolean | true |
Deadline alerts ($0.35). Required. Turn off for cheapest try. |
deadlineWithinDays |
integer | 30 |
Due-date window. min 0, max 3650. |
emitUnchanged |
boolean | false |
Ignored for billing; unchanged still 0 charge. Required. |
emitExport |
boolean | false |
Handoff export ($8). |
dryRun |
boolean | false |
Fixture; no network/state/charges. Required. |
maxChargeUsd |
number | 50 |
Plan must fit before push. min 0, max 5000. Required. |
delivery |
string | dataset |
Enum: dataset, webhook. |
webhookUrl |
string | — | HTTPS handoff. |
requestTimeoutSeconds |
integer | 30 |
CISA catalog request. min 2, max 120. |
rateLimitMs |
integer | 250 |
min 0, max 10000. |
maxRetries |
integer | 2 |
min 0, max 4. |
backoffBaseMs |
integer | 250 |
|
maxBackoffMs |
integer | 4000 |
Cheapest first paid input (skip $12 report, $0.35 alerts, $8 export):
{
"assets": [
{
"assetId": "web-prod-01",
"vendor": "Apache",
"product": "Log4j2",
"versions": [
"2.14.1"
]
}
],
"monitorKey": "trial-kev-portfolio",
"initialRunMode": "emit_backfill",
"generateReport": false,
"emitPotentialMatches": true,
"includeDeadlineAlerts": false,
"emitUnchanged": false,
"emitExport": false,
"dryRun": false,
"maxChargeUsd": 3
}
Documented live PPE is $0.06 per delivered potential match.
Run this 1-asset input on Apify
What is the cheapest first paid Try Input?
baseline_only is free — not a paid try. Skip the $12 report, $0.35 alerts, and $8 export. One asset, emit_backfill, generateReport false, includeDeadlineAlerts false, emitExport false, dryRun false, maxChargeUsd 3. Unit: $0.06 per delivered potential match.
What does a result contain?
README row types include kev_remediation_report; kev_asset_potential_match (asset join, CVE, vendor/product, description, requiredAction, dueDate, source URL, review labels); kev_deadline_alert; and kev_remediation_export. There is no published output JSON schema on the Store page. Treat README samples as illustrations, not a live coverage guarantee.
How is CISA KEV Asset Remediation Report priced?
Billing is pay-per-event. The live Store card is from $60.00 / 1,000 kev asset potential matches. Live events are kev-asset-potential-match $0.06 (Store API primary), kev-deadline-alert $0.35, kev-remediation-report $12 (Store title: KEV remediation review report; README/actor.json: KEV remediation report), and kev-remediation-export $8, each charged when delivered. No Actor Start. README USD amounts match. actor.json marks kev-deadline-alert primary; prefer the Store card which marks kev-asset-potential-match primary.
| Event | Price | Emitted when |
|---|---|---|
kev-asset-potential-match (KEV asset potential match) |
$0.06 | PAID when delivered. Store API primary. |
kev-deadline-alert (KEV deadline alert) |
$0.35 | PAID when delivered. |
kev-remediation-report (KEV remediation review report) |
$12 | PAID when delivered. |
kev-remediation-export (KEV remediation export) |
$8 | PAID when delivered. |
README USD amounts match. Prefer Store primary kev-asset-potential-match. This page quotes live PPE only. Matches are never vulnerability assertions.
from $60.00 / 1,000 kev asset potential matches. No Actor Start.
See CISA KEV Asset Remediation Report pricing on Apify
How do dataset, webhook, and dry-run delivery work?
delivery defaults to dataset and also accepts webhook. dryRun is a fixture path: no network/state/charges. emitUnchanged is accepted but ignored for billing; unchanged still 0 charge. Dataset output is the billable surface when rows are written.
Limits to keep in mind
- Never asserts that an asset is vulnerable or compromised. Labels are potential_match + review_required only.
baseline_onlyand unchanged: 0 rows / 0 charge.- Schema default
generateReportis true ($12) — turn it off on the cheapest paid path. - Inventory max 250 assets. You supply the inventory; the Actor does not discover assets.
- Official CISA KEV JSON only. Not a pentest.
Open CISA KEV Asset Remediation Report on Apify
Related pages
- OSS Vulnerability Monitor — OSV/GitHub package CVEs, not CISA KEV joins.
- PyPI & npm Dependency Risk Report — Pinned upgrade risk, not KEV.
- Security Headers Checker — HTTP headers, not KEV.
- PyPI Vulnerability Scraper — PyPI + OSV rows.
- npm License & Deprecation Checker — License/deprecation, not KEV.
- Tools