exploitwatch

Check dependencies against CISA's real Known Exploited Vulnerabilities feed.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
100%
Naming quality
100%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~149Tokens (tool definitions)
~549 BTypical response size
Minimal attention impact (0.12% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "exploitwatch": {
      "url": "https://exploitwatch-kappa.vercel.app/api/mcp"
    }
  }
}

Remote endpoints

https://exploitwatch-kappa.vercel.app/api/mcpstreamable-http

What it can do

Tool inventory

Tools (1)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢check_kev(dependencies)

Check a comma-separated list of software dependency/product names (e.g. 'lodash, openssl, apache struts') against CISA's real, public Known Exploited Vulnerabilities (KEV) catalog. Returns any current matches with the CVE ID, description, date added, and known ransomware use -- grounded in CISA's live feed, not a guess. Useful for triaging whether a project's dependencies include anything under active exploitation right now.

Input Schema

{
  "type": "object",
  "properties": {
    "dependencies": {
      "type": "string",
      "description": "Comma-separated dependency/product names, e.g. 'express, lodash, openssl'"
    }
  },
  "required": [
    "dependencies"
  ]
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded1 tools
verifiedversion not recorded1 tools