mcpbeat Sign in

Exploitwatch MCP Server

by vercel-exploitwatch-kappa Your server? Claim it
answering

Exploitwatch is answering right now. Last checked 4 min ago. It exposes 1 tools.

Check dependencies against CISA's real Known Exploited Vulnerabilities feed.

Uptime history 5 days of history
5 days agonow
100.0%
Uptime 24h
92 of 92 checks
1
Tools
read from the server
247 ms
Response time
average over 24h
open, no key
Access
streamable-http

Nothing serious here today

Today is the operative word: we check Exploitwatch every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 4 min ago.

run in your terminal
claude mcp add exploitwatch --transport http https://exploitwatch-kappa.vercel.app/api/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "exploitwatch": {
      "url": "https://exploitwatch-kappa.vercel.app/api/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.exploitwatch]
url = "https://exploitwatch-kappa.vercel.app/api/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "exploitwatch": {
      "url": "https://exploitwatch-kappa.vercel.app/api/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "exploitwatch": {
      "url": "https://exploitwatch-kappa.vercel.app/api/mcp"
    }
  }
}

Available tools 1

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

kev
check_kev
Check a comma-separated list of software dependency/product names (e.g. 'lodash, openssl, apache struts') against CISA's real, public Known Exploited Vulnerabilities (KEV) catalog. Returns any current matches with the CVE ID, description, date added, and known ransomware use -- grounded in CISA's live feed, not a guess. Useful for triaging whether a project's dependencies include anything under active exploitation right now.

Endpoints

URLTransportStateLatencyChecked
https://exploitwatch-kappa.vercel.app/api/mcp streamable-http answering 234 ms 4 min ago

Alternatives to Exploitwatch

same job, measured the same way
Exploitwatch
by edgethirteen-www

Check a dependency list against CISA's live Known Exploited Vulnerabilities catalog.

1 tools answering
Cisa Kev
by pipeworx-io

CISA Known Exploited Vulnerabilities catalog

35 tools answering
Cisa Kev MCP
by csoai-org

CISA Known Exploited Vulnerabilities feed + remediation deadlines for US federal + critical infr...

138 installs/wk local only
CISA Known Exploited Vulnerabilities (kevwatch)
by a2awire

CISA KEV catalog: active-exploit alerts, hourly. Register in-session — free testnet funds.

16 tools answering
GhostFree
by shane-js

MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.

31 installs/wk local only
AgentGuard — security checks for AI agents
by shuaicongxiaomai

Secret, CVE and dependency-vulnerability scanning for AI agents (free, OSV.dev).

local only
VulnFeed
by novadyne-hq

Dependency vulnerability scanner with EPSS scoring. 9 MCP tools. Free tier + x402.

110 installs/wk local only
VulnFeed
by infai-tech

Dependency vulnerability scanner with EPSS scoring. 9 MCP tools. Free tier + x402.

local only

Exploitwatch — questions

Answers built from our own checks of this server.

What can Exploitwatch do?
It exposes 1 tools, read directly from the server on our last check. Among them: check_kev. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is Exploitwatch working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 92 of 92 checks got a reply (100.0%), average response time 247 ms. The bar chart above shows every period we have measured.
How do I connect Exploitwatch?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does Exploitwatch need an API key?
No. Exploitwatch completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 1 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is Exploitwatch?
It answers our handshake in 247 ms on average, which is faster than 57% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.