Exploitation intelligence

Know what attackers are exploiting. See the evidence.

KEVIntel connects exploited CVEs to source evidence, confidence, proprietary sensor telemetry, and practical artifacts so security teams can act on what matters first.

Free live feed, RSS, and JSON. Pro adds deeper evidence, telemetry, and integration-ready context.

Sensor activity

Observed exploitation events · last 7 days

Live telemetry

50

KEVs observed

5,044

Events

622

Attacker IPs

View exploitation signals →
2,712
High & confirmed KEVs

Evidence-backed exploitation records

1,051
Beyond CISA KEV

Additional exploited CVEs

50
Observed in sensors

Tracked KEVs in the last 7 days

1,852+
Artifacts available

PoC, Nuclei, Metasploit, and virtual patch context

Email Alerts

Get High-Impact KEV Alerts by Email

KEVIntel tracks known exploited vulnerabilities beyond CISA KEV. Subscribe for occasional, curator-picked alerts when exploitation warrants attention. For every update, use the RSS feed or API.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.

Evidence depth

Not just a KEV label

Every record connects the exploitation verdict to evidence your team can inspect, telemetry it can weigh, and artifacts it can use.

Open the full CVE report

Verified vulnerability record

CVE-2025-8943

Flowise Remote Code Execution · affected before 3.0.1

Confirmed confidence

Flowise Remote Code Execution

Evidence

Active exploitation observed

Independent exploitation attestation added to the KEVIntel record.

Sensor telemetry

49 attempts · 5 sensors

First-party observations recorded across 26 attacker IPs.

Actionable artifact

Nuclei template available

Public scanner coverage helps validate exposed systems.

Evidence, telemetry, and action stay attached to the CVE.

Browse exploited CVEs →

Intelligence system

From signal to security action

KEVIntel combines 60+ public sources, vendor advisories, and private honeypots—then keeps the evidence chain attached as records move into operational workflows.

  1. 01

    Observe

    Public sources, vendor advisories, private honeypots, and custom sensors.

  2. 02

    Attest

    Review source credibility, specificity, corroboration, and first-hand telemetry.

  3. 03

    Enrich

    Add EPSS, CVSS, CWE, PoCs, Nuclei, Metasploit, and affected-version context.

  4. 04

    Deliver

    Ship through the live feed, email, RSS, JSON, and Pro API.

  5. 1,051+ additional exploited CVEs beyond CISA KEV

    Evidence stays inspectable at every stage

Built to act

One evidence model, four operational workflows

Explore use cases

Evidence before urgency

Patch what matters first

Start with the free live feed, then add deeper evidence, telemetry, and automation through the Pro API.