KEV Intelligence is becoming Previdian.

Sensor-led exploitation intelligence

Your early warning for vulnerabilities moving into active exploitation.

KEV Intelligence uses proprietary sensors and private honeypots to surface active exploitation, corroborated by vendor advisories and public evidence. Inspect the evidence, prioritize with confidence, and act sooner.

Start with the free live feed, RSS, and JSON. Pro adds deeper evidence, telemetry, and integration-ready context.

Live sensor activity

Exploitation activity observed across KEV Intelligence sensors during the last 7 days.

Live telemetry

121

KEVs observed

14,320

Exploitation events

603

Attacker IPs

View exploitation signals

Earlier visibility, backed by evidence

High-confidence records
2,759
Exploitation records supported by strong, inspectable evidence
Beyond CISA KEV
1,084
Exploited vulnerabilities missing from CISA’s catalog
Observed in sensors
121
Tracked KEVs seen across proprietary sensors in the last 7 days
Actionable artifacts
1,732+
PoCs, Nuclei, Metasploit, and virtual-patch context

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.

Evidence depth

Early warning your team can verify

Every warning connects the exploitation verdict to inspectable evidence, confidence, available sensor telemetry, affected versions, and practical security artifacts.

Browse exploited CVEs

Verified vulnerability record

CVE-2026-76904

geotools SQL Injection

High confidence

To limit scope of SQL Injection the PostGIS connection pool should be configured with limited rights

Sensor telemetry

1 attempt · 1 sensor

First-party observations recorded across 1 attacker IP.

Evidence

Active exploitation observed

Independent exploitation attestation added to the KEV Intelligence record.

Actionable artifact

Proof of concept available

Public PoC material increases practical exploitability.

Evidence, telemetry, and action stay attached to the CVE.

Browse exploited CVEs →

Intelligence system

How exploitation signals become trusted warnings

KEV Intelligence observes exploitation through proprietary sensors and private honeypots, corroborates signals against vendor advisories and public evidence, and keeps the evidence chain attached as warnings move into operational workflows.

  1. 01

    Observe

    Proprietary sensors and private honeypots surface exploitation activity, supported by vendor advisories and relevant public evidence.

  2. 02

    Attest

    Evaluate source credibility, specificity, corroboration, and available first-party telemetry.

  3. 03

    Enrich

    Add EPSS, CVSS, CWE, affected-version context, PoCs, Nuclei, Metasploit, and virtual-patch context.

  4. 04

    Deliver

    Send trusted warnings through the live feed, email alerts, RSS, JSON, and Pro API.

  5. 121 KEVs observed in sensors (7d)

    Evidence remains inspectable at every stage

Built to act

Turn earlier visibility into faster security action

Explore use cases

Act on exploitation sooner

See active exploitation earlier. Prioritize it with evidence.

Start with the free live feed, then add deeper telemetry, confidence, and automation through the Pro API.