Free defensive cyber tools
CISA Known Exploited Vulnerabilities Catalog
Track vulnerabilities with confirmed exploitation using CISA's authoritative KEV data, with a current bundled catalog available when upstream feeds are temporarily unavailable.
- Filter by CVE, vendor, product, remediation due date, and ransomware association.
- Review required actions and prioritize overdue remediation.
- Export matching KEV records to CSV for analyst and vulnerability-management workflows.
SurfaceVector cybersecurity tools
Authoritative cybersecurity sources
SurfaceVector connects defensive workflows with resources from CISA, the CVE Program, FIRST, NIST, and DISA STIGs.