KEVIntel

Known Exploited Vulnerabilities

Focus on What Matters

There are 303,822 vulnerabilities in the CVE database. Whilst only 0.7% are ever actively exploited.

This list contains the vulnerabilities that are actively exploited by malware and threat actors that you should prioritize first.

0.7% Exploited

This table displays known exploited vulnerabilities (KEVs) that have been cataloged from over 60 public sources, including CISA, and our own private sensors. Each entry links to a CVE identifier, where the CVE details are enriched with EPSS scores, online mentions, scanner inclusion, exploitation, tags, and other metadata. The goal is to be an early warning system, even before being published by CISA. More data and features coming soon!

CVE ID Vendor Source
CVE-2024-11120 GeoVision CVE
CVE-2020-35131 n/a The Shadowserver (via CIRCL)
CVE-2023-52163 n/a The Shadowserver (via CIRCL)
CVE-2016-5700 F5 The Shadowserver (via CIRCL)
CVE-2024-7399 Samsung Electronics CyberInsider
CVE-2013-7091 Zimbra The Shadowserver (via CIRCL)
CVE-2025-24016 wazuh The Shadowserver (via CIRCL)
CVE-2022-38130 n/a The Shadowserver (via CIRCL)
CVE-2021-27931 n/a The Shadowserver (via CIRCL)
CVE-2022-3801 IBAX The Shadowserver (via CIRCL)
CVE-2017-7921 Hikvision The Shadowserver (via CIRCL)
CVE-2001-0537 Cisco The Shadowserver (via CIRCL)
CVE-2024-36991 Splunk The Shadowserver (via CIRCL)
CVE-2020-21650 GrandStream The Shadowserver (via CIRCL)
CVE-2023-6114 Snap Creek LLC The Shadowserver (via CIRCL)
CVE-2021-37291 KevinLAB Inc The Shadowserver (via CIRCL)
CVE-2023-31478 GL.iNet The Shadowserver (via CIRCL)
CVE-2022-31126 hap-wi The Shadowserver (via CIRCL)
CVE-2022-29078 fleegix The Shadowserver (via CIRCL)
CVE-2022-26833 Open Automation Software The Shadowserver (via CIRCL)
CVE-2023-53086 Linux CVE
CVE-2025-34028 Commvault CISA
CVE-2017-9844 SAP SE Tenable Blog
CVE-2024-38475 Apache Software Foundation TheHackerNews
CVE-2023-44221 SonicWall TheHackerNews
Displaying vulnerabilities 351 - 375 of 2004 in total