# Kevscope API by CyberMax > CVE priority API: for up to 20 CVEs per call, returns CISA KEV status (date added, federal due date, ransomware use), FIRST EPSS probability and percentile, CVSS from the CNA or CISA-ADP, CISA SSVC exploitation/automatable/impact and a public-rules verdict (act_now, high, medium, low) with reasons. Also recent KEV additions and a pre-KEV EPSS watchlist. REST + MCP server. > Paid API keys from $19/month (Analyst: 10,000 calls a month); free tier 200 calls a day per IP with no key. Buy: https://kevscope-api.cybermaxtools.com/buy/analyst?s=lead ยท all plans: https://kevscope-api.cybermaxtools.com/docs#pricing Send up to 20 CVE IDs and get a patch-priority verdict for each, with the evidence behind it: CISA KEV status and due date, ransomware use, FIRST EPSS, CVSS and CISA's SSVC exploitation call. For security teams, MSPs, scanners and AI agents. Free tier, no key; plans from $5 (one-time pack) or $19/month. ## API (free tier without a key; paid API keys for more) - [/api/priority](https://kevscope-api.cybermaxtools.com/api/priority?cve=CVE-2024-3400,CVE-2024-6387,CVE-2019-0001): Patch-priority verdict for up to 20 CVEs, with evidence - [/api/kev/recent](https://kevscope-api.cybermaxtools.com/api/kev/recent?days=14): CVEs added to CISA KEV in the last N days, with EPSS - [/api/watchlist](https://kevscope-api.cybermaxtools.com/api/watchlist?limit=10): Early warning: highest-EPSS CVEs that are not in CISA KEV yet - GET for simple calls, POST a JSON body for lists. Same field names as the bulk version's dataset records. - OpenAPI 3.1: https://kevscope-api.cybermaxtools.com/openapi.json ## MCP (remote, streamable HTTP, no auth) - Endpoint: https://kevscope-api.cybermaxtools.com/mcp - `cve_priority`: Patch-priority verdict for 1-20 CVE IDs with evidence: CISA KEV status (date added, due date, ransomware use), FIRST EPSS probability, CVSS (CNA or CISA-ADP), CISA SSVC exploitation/automatable/impact, vendor, product and links. Sorted most urgent first. - `kev_recent`: CVEs added to the CISA Known Exploited Vulnerabilities catalog in the last N days, newest first, with due date, ransomware use and EPSS. Optional vendor/product text filter. - `epss_watchlist`: The highest-EPSS CVEs (most likely to be exploited in 30 days) that are not in CISA KEV yet. Defaults to this year's CVE IDs. ## Limits - Up to 20 CVEs per call; 10 calls a minute per IP on the free tier. - Free tier: 200 calls a day per IP, no key. Paid keys from $5 (one-time pack) or $19/month (see Get an API key). - Sources are asked live and cached up to 1 hour: CVE Program records (incl. CISA-ADP), FIRST EPSS (updated daily) and the CISA KEV catalog. - The verdict is a transparent rule set on public data, not a guarantee; your own exposure and compensating controls still decide. ## More - Health: https://kevscope-api.cybermaxtools.com/health - All CyberMax tools: https://cybermax-tools-cybermax.static.hf.space/ - Loop over longer lists 20 CVEs at a time: a key covers thousands of calls a month. For a Monday summary instead of an API, the Exploited Vulnerabilities Brief (weekly edition) is on the CyberMax hub. ## Pricing - Free: 200 calls a day per IP, 10/min, no key. - Analyst: $19/month, 10,000 calls a month, 30/min. Buy: https://kevscope-api.cybermaxtools.com/buy/analyst?s=llms - Team: $49/month, 50,000 calls a month, 60/min. Buy: https://kevscope-api.cybermaxtools.com/buy/team?s=llms - SOC: $99/month, 150,000 calls a month, 120/min. Buy: https://kevscope-api.cybermaxtools.com/buy/soc?s=llms - Pay as you go: $5, 2,000 calls (one-time pack, no expiry), 30/min. Buy: https://kevscope-api.cybermaxtools.com/buy/payg?s=llms - Analyst yearly: $190/year, 10,000 calls a month, 30/min. Buy: https://kevscope-api.cybermaxtools.com/buy/analyst-yearly?s=llms - Team yearly: $490/year, 50,000 calls a month, 60/min. Buy: https://kevscope-api.cybermaxtools.com/buy/team-yearly?s=llms - SOC yearly: $990/year, 150,000 calls a month, 120/min. Buy: https://kevscope-api.cybermaxtools.com/buy/soc-yearly?s=llms - Using several CyberMax APIs? CyberMax API All-Access: one key for all 10 APIs (this one included, 10,000 calls a month here) for $119/month. https://api-all-access.cybermaxtools.com/ - Use the key as `x-api-key: KEY` or `Authorization: Bearer KEY` (MCP too). Usage: https://kevscope-api.cybermaxtools.com/key. Machine-readable: https://kevscope-api.cybermaxtools.com/pricing.json ## Pay per call (x402, USDC on Base): for AI agents, no key, no account - $0.003 per call, paid in USDC on Base (x402 "exact" scheme, v1 and v2). - https://kevscope-api.cybermaxtools.com/x402/api/priority: same as /api/priority, always pay-per-call (an unpaid call returns HTTP 402 with the payment requirements). - https://kevscope-api.cybermaxtools.com/x402/api/kev/recent: same as /api/kev/recent, always pay-per-call (an unpaid call returns HTTP 402 with the payment requirements). - https://kevscope-api.cybermaxtools.com/x402/api/watchlist: same as /api/watchlist, always pay-per-call (an unpaid call returns HTTP 402 with the payment requirements). - Plain endpoints keep the free tier and API keys; with no key, they also answer 402 (instead of 429) once the free daily quota is used. - Send the signed payment as X-PAYMENT (v1) or PAYMENT-SIGNATURE (v2); the receipt comes back in X-PAYMENT-RESPONSE / PAYMENT-RESPONSE. Failed calls are not charged.