Exploitation intelligence

Know what attackers are exploiting. See the evidence.

KEV Intelligence connects exploited CVEs to source evidence, confidence, proprietary sensor telemetry, and practical artifacts so security teams can act on what matters first.

Free live feed, RSS, and JSON. Pro adds deeper evidence, telemetry, and integration-ready context.

Sensor activity

Observed exploitation events · last 7 days

Live telemetry

65

KEVs observed

4,773

Events

770

Attacker IPs

View exploitation signals →
2,721
High & confirmed KEVs

Evidence-backed exploitation records

1,059
Beyond CISA KEV

Additional exploited CVEs

65
Observed in sensors

Tracked KEVs in the last 7 days

1,862+
Artifacts available

PoC, Nuclei, Metasploit, and virtual patch context

Email Alerts

Get High-Impact KEV Alerts by Email

KEV Intelligence tracks known exploited vulnerabilities beyond CISA KEV. Subscribe for occasional, curator-picked alerts when exploitation warrants attention. For every update, use the RSS feed or API.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.

Evidence depth

Not just a KEV label

Every record connects the exploitation verdict to evidence your team can inspect, telemetry it can weigh, and artifacts it can use.

Open the full CVE report

Verified vulnerability record

CVE-2026-49049

Helix3 extension for Joomla

Confirmed confidence

Helix3 extension for Joomla

Evidence

Active exploitation observed

Independent exploitation attestation added to the KEV Intelligence record.

Sensor telemetry

2 attempts · 1 sensor

First-party observations recorded across 1 attacker IP.

Actionable artifact

Proof of concept available

Public PoC material increases practical exploitability.

Evidence, telemetry, and action stay attached to the CVE.

Browse exploited CVEs →

Intelligence system

From signal to security action

KEV Intelligence combines 60+ public sources, vendor advisories, and private honeypots—then keeps the evidence chain attached as records move into operational workflows.

  1. 01

    Observe

    Public sources, vendor advisories, private honeypots, and custom sensors.

  2. 02

    Attest

    Review source credibility, specificity, corroboration, and first-hand telemetry.

  3. 03

    Enrich

    Add EPSS, CVSS, CWE, PoCs, Nuclei, Metasploit, and affected-version context.

  4. 04

    Deliver

    Ship through the live feed, email, RSS, JSON, and Pro API.

  5. 1,059+ additional exploited CVEs beyond CISA KEV

    Evidence stays inspectable at every stage

Built to act

One evidence model, four operational workflows

Explore use cases

Evidence before urgency

Patch what matters first

Start with the free live feed, then add deeper evidence, telemetry, and automation through the Pro API.