Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
-
Updated
Aug 5, 2026 - Python
8000
Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
Streamline vulnerability patching with CVSS, EPSS, and CISA's Known Exploited Vulnerabilities. Prioritize actions based on real-time threat information, gain a competitive advantage, and stay informed about the latest trends.
Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.
A Trivy plugin that scans and outputs the results (vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more) to an interactive html file.
🛡️ VIPER: Stay ahead of threats with AI-driven vulnerability intelligence. Prioritize CVEs effectively using NVD, EPSS, CISA KEV, and Google Gemini insights, all on an interactive dashboard
Zero-touch pipeline that turns newly weaponized CVEs from the CISA Known Exploited Vulnerabilities (KEV) catalog into production-ready Sigma detection rules, automatically, every week.
Build a CVE library with aggregated CISA, EPSS and CVSS data
Open-source vulnerability prioritization engine that enriches scanner findings with vulnerability intelligence, identifies urgent risks, and automates alerts and ITSM ticketing.
DetecTI-CLI is a high-performance Python 3.11+ CLI tool designed for External Attack Surface Management (EASM), Reconnaissance, and Vulnerability Intelligence.
CVE monitoring for Magento / Adobe Commerce / Mage-OS. Polls KEV, NVD, GHSA, OSV, Packagist; filters against your composer.lock; alerts only P0/P1 to Slack.
WordPress vulnerability scanner with public exploit/POC lookup, gambling spam (judol) detection, and AI-powered analysis. Scan plugins, themes & core for known CVEs — offline or remote.
🛡️ Turnkey cybersecurity lab for Hermes Agent — 397 CVE-driven skills, 152 tools, 28 frameworks (MITRE ATT&CK, MISP, CVSS, EPSS, OWASP, NIST, Sigma, YARA). Real exploits 2015–2026.
Unified vulnerability intelligence platform - CVE data, CVSS scores, EPSS predictions, CISA KEV, exploit tracking, and risk scoring in one place.
370 standalone dependency-free Python 3 CVE exploits, each validated end-to-end against the real vulnerable software with a write-up and a screenshot of the live run.
Scraper for daily renewal of the Known Exploited Vulnerabilities Catalog by CISA
Answers "what do I patch first?" — scores an OT/ICS asset inventory against CVE + CISA KEV + EPSS and ranks remediation by real risk, not just CVSS. Runs offline.
A small, fast Rust CLI to search CVEs from vuln.mlab.sh, keyword & faceted search, latest feed, full CVE detail (CVSS, EPSS, CISA KEV, CWE, references), colored TTY output and --json for piping. Single static binary, no API key, no runtime deps.
An automated repo to track Nuclei template scanning capabilities against the CISA KEV.
Add a description, image, and links to the cisa-kev topic page so that developers can more easily learn about it.
To associate your repository with the cisa-kev topic, visit your repo's landing page and select "manage topics."