MCP Server

exploitwatch

app.vercel.exploitwatch-kappa/exploitwatch
Security Public & reachable MCP 2026-07-28

What this MCP does

Checks software dependency names against CISA's Known Exploited Vulnerabilities catalog.

check_kev
Check a comma-separated list of software dependency/product names (e.g. 'lodash, openssl, apache struts') against CISA's real, public Known Exploited Vulnerabilities (KEV) catalog. Returns any current matches with the CVE ID, description, date added, and known ransomware use -- grounded in CISA's live feed, not a guess. Useful for triaging whether a project's dependencies include anything under active exploitation right now.
Input schema
{'type': 'object', 'required': ['dependencies'], 'properties': {'dependencies': {'type': 'string', 'description': "Comma-separated dependency/product names, e.g. 'express, lodash, openssl'"}}}
Added
check_kev
Sept. 17, 2026, 7:58 a.m.