Exploitation intelligence

Know what attackers are exploiting. See the evidence.

KEVIntel connects exploited CVEs to source evidence, confidence, proprietary sensor telemetry, and practical artifacts so security teams can act on what matters first.

Free live feed, RSS, and JSON. Pro adds deeper evidence, telemetry, and integration-ready context.

Sensor activity

Observed exploitation events · last 7 days

Live telemetry

57

KEVs observed

5,388

Events

732

Attacker IPs

View exploitation signals →
2,715
High & confirmed KEVs

Evidence-backed exploitation records

1,053
Beyond CISA KEV

Additional exploited CVEs

57
Observed in sensors

Tracked KEVs in the last 7 days

1,855+
Artifacts available

PoC, Nuclei, Metasploit, and virtual patch context

Email Alerts

Get High-Impact KEV Alerts by Email

KEVIntel tracks known exploited vulnerabilities beyond CISA KEV. Subscribe for occasional, curator-picked alerts when exploitation warrants attention. For every update, use the RSS feed or API.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.

Evidence depth

Not just a KEV label

Every record connects the exploitation verdict to evidence your team can inspect, telemetry it can weigh, and artifacts it can use.

Open the full CVE report

Verified vulnerability record

CVE-2013-3821

PeopleSoft Products

Confirmed confidence

PeopleSoft Products

Evidence

Active exploitation observed

Independent exploitation attestation added to the KEVIntel record.

Sensor telemetry

82 attempts · 1 sensor

First-party observations recorded across 9 attacker IPs.

Actionable artifact

Enrichment available

CVSS, EPSS, and related context help prioritize remediation.

Evidence, telemetry, and action stay attached to the CVE.

Browse exploited CVEs →

Intelligence system

From signal to security action

KEVIntel combines 60+ public sources, vendor advisories, and private honeypots—then keeps the evidence chain attached as records move into operational workflows.

  1. 01

    Observe

    Public sources, vendor advisories, private honeypots, and custom sensors.

  2. 02

    Attest

    Review source credibility, specificity, corroboration, and first-hand telemetry.

  3. 03

    Enrich

    Add EPSS, CVSS, CWE, PoCs, Nuclei, Metasploit, and affected-version context.

  4. 04

    Deliver

    Ship through the live feed, email, RSS, JSON, and Pro API.

  5. 1,053+ additional exploited CVEs beyond CISA KEV

    Evidence stays inspectable at every stage

Built to act

One evidence model, four operational workflows

Explore use cases

Evidence before urgency

Patch what matters first

Start with the free live feed, then add deeper evidence, telemetry, and automation through the Pro API.