Duaer

入门

在 Duaer 里查CISA 已被利用漏洞

在 Duaer 里:CISA 确认已在野利用的 CVE,可按厂商、关键词或加入日期筛选,含处置要求与整改截止日期。一次成功查询用 1 额度。

能拿到什么

Duaer 数据市场里的「CISA 已被利用漏洞」:CISA 确认已在野利用的 CVE,可按厂商、关键词或加入日期筛选,含处置要求与整改截止日期。查到结果时用 1 额度,结果交给数字组织的下一个节点。

从节点创建器选 Duaer 数据 → CISA 已被利用漏洞,或打开 数据市场。相关:NVD 漏洞库、OSV 开源漏洞。

适合做什么

  • 每周检查新增的已被利用漏洞。
  • 列出某厂商进入 KEV 目录的漏洞及修复期限。

在画布里检索

  1. 打开节点创建器,选 Duaer 数据 → CISA known exploited vulnerabilities。
  2. 填 Added in Last Days(如 30);Words、Vendor 可选。
  3. Limit 默认 10,最大 20。执行。

查到结果才扣 1 额度;没有结果、输入有误或上游失败都不扣。

用 API 调用

  • GET https://api.duaer.com/v1/data/cisa-kev?days=30
  • Authorization: Bearer <Duaer key>

下方是与数据市场「复制技能」相同的英文技能,含参数、示例与返回字段。

调用技能(英文)

与数据市场「复制技能」一致。

---
name: duaer-cisa-kev
description: >-
  Duaer CISA known exploited vulnerabilities. CVEs that CISA confirms are exploited in the wild, by vendor, words, or date added, with required action and remediation due date.
  One successful search uses 1 Duaer credit.
---

# Duaer CISA known exploited vulnerabilities

Duaer CISA known exploited vulnerabilities reads the CISA KEV catalog: CVEs with confirmed exploitation that US federal agencies must fix by a due date. Newest additions come first.

## When to use

- Prioritize patches that attackers already use.
- List new exploited CVEs for a vendor this month.

## When not to use

- Any CVE, exploited or not. Use https://skills.duaer.com/nvd.md.
- Package-level advisories. Use https://skills.duaer.com/osv.md.

## Call

`GET https://api.duaer.com/v1/data/cisa-kev?days=30`

Header: `Authorization: Bearer <Duaer key>`

Use an account key or a model API key.

Get a Duaer key: https://skills.duaer.com/keys.md

## Parameters

Provide `words`, `vendor`, or `days`.

- `words` — Words in the CVE, product, or description, such as remote code execution.
- `vendor` — Optional. Vendor, such as Microsoft or Cisco.
- `days` — Optional. Only entries added in the last N days, 1 to 3650.
- `limit` — Optional. Rows to return, from 1 to 20. Default 10.

## Examples

- `GET https://api.duaer.com/v1/data/cisa-kev?days=30` — entries added in the last 30 days.
- `GET https://api.duaer.com/v1/data/cisa-kev?vendor=Microsoft&days=90` — Microsoft CVEs exploited this quarter.

## Result

The response is `{ "items": [...] }`. Each item has `source`, `title`, `url`, and `summary`, plus:

- `cveId`, `vendor`, `product` — the vulnerability and affected product.
- `description`, `requiredAction` — what it is and what to do.
- `dateAdded`, `dueDate` — catalog date and remediation deadline.
- `ransomwareUse`, `cwe` — Known when used in ransomware campaigns; weakness ids.

Fields without a value are left out.

## Credits

A search that returns at least one row uses 1 credit.
An empty search, a search that finds nothing, or a failed search uses 0.
Wrong input returns 400 with a message and uses 0.
No remaining credits returns 402 and does not search.
A missing key returns 401.

## Related

- https://skills.duaer.com/nvd.md — Duaer NVD CVE records
- https://skills.duaer.com/osv.md — Duaer OSV vulnerabilities

常见问题

Duaer 的CISA 已被利用漏洞检索扣多少额度?

查到结果时扣 1 额度;没有结果或出错不扣。

Duaer CISA 已被利用漏洞与 NVD 有什么区别?

Duaer CISA 已被利用漏洞只收录已确认被实际利用的 CVE,并带美国联邦机构的修复期限;NVD 收录全部 CVE。

同组