KEVIntel
0.7%
actively
exploited

Focus on what’s exploited

Out of 351,861 known CVEs, only 0.7% show real-world exploitation signals.

Data from public sources (including CISA) plus private sensors, enriched with prioritization metadata.

2,548
Total Known exploited
110
Added this week
934
More than CISA KEV

Search

Added
Exploitability

Type to search. Filters apply instantly.

CVE Severity Title
CVE-2026-11645 8.8 High
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox...
Remote Low complexity
CVE-2026-34910 10.0 Critical
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a...
Remote Low complexity No user interaction
CVE-2026-34909 10.0 Critical
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the...
Remote Low complexity No user interaction
CVE-2026-34908 10.0 Critical
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized...
Remote Low complexity No user interaction
CVE-2026-42271 8.7 High
LiteLLM: Authenticated command execution via MCP stdio test endpoints
Remote Low complexity No user interaction
CVE-2026-50751 9.3 Critical
User Authentication Bypass in VPN Remote Access and Mobile Access
Malware Remote Low complexity No user interaction
CVE-2024-39713 8.6 High
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
Remote Low complexity No user interaction
CVE-2021-24227 7.5 High
Patreon WordPress < 1.7.0 - Unauthenticated Local File Disclosure
Remote Low complexity No user interaction
CVE-2022-34121 7.5 High
Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.
Remote Low complexity No user interaction
CVE-2023-4490 9.8 Critical
WP Job Portal < 2.0.6 - Unauthenticated SQLi
Remote Low complexity No user interaction
CVE-2021-3577 8.8 High
An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker...
Low complexity No user interaction
CVE-2024-8752 9.3 Critical
WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability
Remote Low complexity No user interaction
CVE-2022-3801 6.3 Medium
IBAX go-ibax rowsInfo sql injection
Remote Low complexity No user interaction
CVE-2021-27358 7.5 High
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API...
Remote Low complexity No user interaction
CVE-2017-10974 7.5 High
Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of...
Remote Low complexity No user interaction
CVE-2026-1405 9.8 Critical
Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload
Remote Low complexity No user interaction
CVE-2022-34753 8.8 High
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote...
Remote Low complexity No user interaction
CVE-2021-20166 8.8 High
Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin endpoint of the router...
Low complexity No user interaction
CVE-2021-41569 7.5 High
SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows...
Remote Low complexity No user interaction
CVE-2024-55457 6.5 Medium
MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by...
Remote Low complexity No user interaction
CVE-2021-21805 9.8 Critical
An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted...
Remote Low complexity No user interaction
CVE-2021-27670 9.8 Critical
Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.
Remote Low complexity No user interaction
CVE-2021-4458 5.9 Medium
Modern Events Calendar Lite <= 6.3.0 - Unauthenticated SQL Injection
Remote No user interaction
CVE-2022-29078 9.8 Critical
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view...
Remote Low complexity No user interaction
CVE-2022-1390 9.8 Critical
Admin Word Count Column <= 2.2 - Unauthenticated Arbitrary File Read
Remote Low complexity No user interaction
Displaying vulnerabilities 1 - 25 of 2548 in total

KEVIntel

Known Exploited Vulnerability Intelligence Beyond CISA KEV

Prioritize the vulnerabilities attackers are actually exploiting—before they impact your organization.

KEVIntel is known exploited vulnerability intelligence that aggregates, attests, enriches, and distributes exploited-CVE data. It is not a CISA KEV mirror alone. The service includes the official catalog as a baseline and extends coverage with additional exploited-CVE attestations, evidence links, enrichment, and automation-ready delivery through the live feed above, RSS, JSON, and the Pro API.

Aggregated & attested

Exploitation signals from 60+ public sources, vendor advisories, and private honeypots—validated against credible evidence.

Enriched for prioritization

Every CVE joined with EPSS, CVSS, CWE, proof-of-concept references, and Nuclei/Metasploit context.

Automation-ready delivery

Live feed, RSS, JSON, and Pro API for VM, CTI, SOC, and MSSP workflows.

The AI vulnerability tsunami is accelerating disclosure

Hundreds of thousands of CVEs exist in the National Vulnerability Database and vendor advisories, and AI-assisted discovery is accelerating that volume further. CVSS scores describe theoretical severity, but severity is not the same as exploitation. Many high-severity vulnerabilities are never exploited in the wild, while some actively exploited flaws may be under-prioritized if teams rely on CVSS-only prioritization.

Only a small fraction of published CVEs ever show real-world exploitation signals. Security teams cannot remediate everything at once. Exploitation-led prioritization focuses limited patching, detection, and analyst time on CVEs with evidence-backed exploitation—not on vulnerability noise.

Disclosed vulnerabilities Actively exploited
351,861+ and growing

Only 0.7% of disclosed CVEs show real-world exploitation signals — and that sliver is the operationally urgent work.

Focus on the signal, not the noise. KEVIntel helps you identify the vulnerabilities attackers are actually using—so vulnerability management, CTI, SOC, MSSP, and exposure-management teams can prioritize remediation on real exploitation, not scanner volume alone.

CISA KEV is essential. It is not the whole picture.

KEVIntel extends your visibility beyond CISA KEV. CISA KEV is authoritative and valuable; KEVIntel complements it with additional exploited-CVE coverage, RSS delivery, honeypot and sensor telemetry, enrichment, and automation-ready Pro API access. See the full KEVIntel vs CISA KEV comparison.

CISA KEV

  • No RSS feed
  • Tracks vulnerabilities in CISA KEV
  • Curated by CISA

KEVIntel

  • RSS feed for real-time updates
  • CISA KEV plus 934+ more exploited in the wild
  • Independent intelligence from global honeypots, sensors, EPSS, CVSS, CWE, PoCs, and Nuclei/Metasploit context

Use CISA KEV. Go further with KEVIntel. Complete visibility, faster prioritization, stronger defenses—with exploitation timelines, source evidence, and platform statistics to back every decision.

From global telemetry to actionable intelligence

KEVIntel follows a simple pipeline: Collect, Attest, Enrich, Deliver. Each exploited CVE links to source material so analysts can verify why it was included and move from signal to action faster.

  1. Collect

    Global honeypot and sensor networks, CISA KEV, vendor advisories, cyber RSS feeds, and public reporting observe real-world exploitation attempts around the clock.

  2. Attest

    Validate exploitation with credible evidence—CISA KEV listings, advisories documenting active exploitation, honeypot observations, and defensible references—to separate signal from noise.

  3. Enrich

    Correlate each CVE with EPSS, CVSS, CWE, proof-of-concept references, Nuclei and Metasploit scanner context, online mentions, vendor metadata, and exploitation timelines.

  4. Deliver

    Actionable intelligence via this live feed, RSS, JSON, and the Pro API—ready for vulnerability management, CTI, SOC, SIEM/SOAR, MSSP, and exposure-management workflows.

Prioritize what matters
Reduce false positives
Strengthen defenses
Stay ahead of attackers