CISA KEV

Compare a buyer-supplied inventory with the official CISA KEV catalog

CISA KEV Asset Remediation Report compares a bounded buyer-supplied asset inventory with the official CISA Known Exploited Vulnerabilities Catalog. It returns conservative potential matches, CISA requiredAction and dueDate evidence, deadline alerts, and review handoffs. Matches are never assertions that an asset is vulnerable or compromised. Labels are potential_match + review_required only. Version match is not_assessed_from_cisa_catalog. baseline_only and unchanged: 0 rows / 0 charge. It is not an OSV/GitHub package CVE monitor — that job is OSS Vulnerability Monitor — and it is not HTTP security headers (Security Headers Checker).

Try Input: 1 asset, emit_backfill, generateReport false, includeDeadlineAlerts false. Live Store: from $60.00 / 1,000 kev asset potential matches ($0.06) + $0.35 deadline alert + $12 report + $8 export. No Actor Start. baseline_only is free.

Try the cheapest first paid CISA KEV Asset Remediation Report run on Apify Input

Open taroyamada/cisa-kev-asset-remediation-report on the Apify Store

CISA KEV vs inventory, not OSV package CVEs or HTTP header grades

Use this page when you already hold an asset inventory (vendor + product or CPE 2.3) and want conservative joins to the official CISA KEV JSON. Use OSS Vulnerability Monitor for package-name CVE rows from OSV/GitHub. Use PyPI & npm Dependency Risk Report for pinned package upgrade risk. Use Security Headers Checker for HTTP headers.

CISA KEV Asset Remediation Report OSS Vulnerability Monitor PyPI & npm Dependency Risk Report
Intent Join buyer inventory to official CISA KEV Package CVE rows from OSV/GitHub Pinned package upgrade risk
Primary input assets[] with assetId plus vendor/product or CPE packages Pinned package lists
What it reads Official CISA KEV JSON plus the inventory you supply OSV/GitHub public APIs Registry/package metadata
Primary output kev-asset-potential-match (Store primary), optional deadline/report/export Vulnerability result rows Upgrade-risk report rows
Not this job Never asserts an asset is vulnerable or compromised. Not CISA KEV dueDate/requiredAction joins. Not CISA KEV catalog matching.

Store ID: taroyamada/cisa-kev-asset-remediation-report. Categories on the live Store card: Developer Tools. Fetch only sources you are authorized to use. Respect source terms, robots.txt, and rate limits.

Use cases

The live Store tagline (truncated on the card) is: compare a bounded buyer-supplied asset inventory with the official CISA Known Exploited Vulnerabilities Catalog; return conservative potential matches, CISA requiredAction and dueDate evidence, deadline alerts, and review handoffs. Schema default generateReport is true — turn it off on the cheapest paid path. Default dryRun is false. Default maxChargeUsd is 50.

How is CISA KEV Asset Remediation Report different from OSS Vulnerability Monitor and PyPI & npm Dependency Risk Report?

CISA KEV Asset Remediation Report (taroyamada/cisa-kev-asset-remediation-report) joins a buyer-supplied inventory to the official CISA KEV catalog. Live PPE is kev-asset-potential-match $0.06 (Store primary), kev-deadline-alert $0.35, kev-remediation-report $12, and kev-remediation-export $8. No Actor Start. OSS Vulnerability Monitor is OSV/GitHub package CVEs. PyPI & npm Dependency Risk Report is pinned upgrade risk. Security Headers Checker is HTTP headers. Use this Actor for CISA KEV inventory joins. Use OSS Vulnerability Monitor for package CVEs. Matches are never assertions that an asset is vulnerable or compromised.

What input is required?

Live required fields: assets, monitorKey, initialRunMode, generateReport, emitPotentialMatches, includeDeadlineAlerts, emitUnchanged, maxChargeUsd, dryRun. assets[] required per item: assetId. Optional per item: vendor, product, aliases (max 10), vendorAliases (max 10), versions (max 20), cpe, environment, label. Array minItems 1, maxItems 250. Default sample is Apache Log4j2. initialRunMode: baseline_only (save baseline only) or emit_backfill (emit current matches). Optional: deadlineWithinDays (default 30), emitExport (default false), requestTimeoutSeconds, rateLimitMs, maxRetries, backoffBaseMs, maxBackoffMs, delivery (dataset or webhook), webhookUrl. Schema default generateReport is true; default dryRun is false; default maxChargeUsd is 50.

Field Type Default Notes
assets object[] Apache Log4j2 sample Inventory; vendor+product or CPE 2.3. Item required: assetId. minItems 1, maxItems 250. Required.
monitorKey string production-asset-portfolio Baseline namespace. Required.
initialRunMode string baseline_only Enum: baseline_only, emit_backfill. Required.
generateReport boolean true Report when changed matches exist ($12). Required. Turn off for cheapest try.
emitPotentialMatches boolean true Per-asset match rows ($0.06). Required.
includeDeadlineAlerts boolean true Deadline alerts ($0.35). Required. Turn off for cheapest try.
deadlineWithinDays integer 30 Due-date window. min 0, max 3650.
emitUnchanged boolean false Ignored for billing; unchanged still 0 charge. Required.
emitExport boolean false Handoff export ($8).
dryRun boolean false Fixture; no network/state/charges. Required.
maxChargeUsd number 50 Plan must fit before push. min 0, max 5000. Required.
delivery string dataset Enum: dataset, webhook.
webhookUrl string — HTTPS handoff.
requestTimeoutSeconds integer 30 CISA catalog request. min 2, max 120.
rateLimitMs integer 250 min 0, max 10000.
maxRetries integer 2 min 0, max 4.
backoffBaseMs integer 250
maxBackoffMs integer 4000

Cheapest first paid input (skip $12 report, $0.35 alerts, $8 export):

{
  "assets": [
    {
      "assetId": "web-prod-01",
      "vendor": "Apache",
      "product": "Log4j2",
      "versions": [
        "2.14.1"
      ]
    }
  ],
  "monitorKey": "trial-kev-portfolio",
  "initialRunMode": "emit_backfill",
  "generateReport": false,
  "emitPotentialMatches": true,
  "includeDeadlineAlerts": false,
  "emitUnchanged": false,
  "emitExport": false,
  "dryRun": false,
  "maxChargeUsd": 3
}

Documented live PPE is $0.06 per delivered potential match.

Run this 1-asset input on Apify

What is the cheapest first paid Try Input?

baseline_only is free — not a paid try. Skip the $12 report, $0.35 alerts, and $8 export. One asset, emit_backfill, generateReport false, includeDeadlineAlerts false, emitExport false, dryRun false, maxChargeUsd 3. Unit: $0.06 per delivered potential match.

What does a result contain?

README row types include kev_remediation_report; kev_asset_potential_match (asset join, CVE, vendor/product, description, requiredAction, dueDate, source URL, review labels); kev_deadline_alert; and kev_remediation_export. There is no published output JSON schema on the Store page. Treat README samples as illustrations, not a live coverage guarantee.

How is CISA KEV Asset Remediation Report priced?

Billing is pay-per-event. The live Store card is from $60.00 / 1,000 kev asset potential matches. Live events are kev-asset-potential-match $0.06 (Store API primary), kev-deadline-alert $0.35, kev-remediation-report $12 (Store title: KEV remediation review report; README/actor.json: KEV remediation report), and kev-remediation-export $8, each charged when delivered. No Actor Start. README USD amounts match. actor.json marks kev-deadline-alert primary; prefer the Store card which marks kev-asset-potential-match primary.

Event Price Emitted when
kev-asset-potential-match (KEV asset potential match) $0.06 PAID when delivered. Store API primary.
kev-deadline-alert (KEV deadline alert) $0.35 PAID when delivered.
kev-remediation-report (KEV remediation review report) $12 PAID when delivered.
kev-remediation-export (KEV remediation export) $8 PAID when delivered.

README USD amounts match. Prefer Store primary kev-asset-potential-match. This page quotes live PPE only. Matches are never vulnerability assertions.

from $60.00 / 1,000 kev asset potential matches. No Actor Start.

See CISA KEV Asset Remediation Report pricing on Apify

How do dataset, webhook, and dry-run delivery work?

delivery defaults to dataset and also accepts webhook. dryRun is a fixture path: no network/state/charges. emitUnchanged is accepted but ignored for billing; unchanged still 0 charge. Dataset output is the billable surface when rows are written.

Limits to keep in mind

Open CISA KEV Asset Remediation Report on Apify

Related pages