KEVIntel

Known Exploited Vulnerabilities

Focus on What Matters

There are 297,489 vulnerabilities in the CVE database. Whilst only 0.6% are ever actively exploited.

This list contains the vulnerabilities that are actively exploited by malware and threat actors that you should prioritize first.

0.6% Exploited

This table displays known exploited vulnerabilities (KEVs) that have been cataloged from over 60 public sources, including CISA, and our own private sensors. Each entry links to a CVE identifier, where the CVE details are enriched with EPSS scores, online mentions, scanner inclusion, exploitation, tags, and other metadata. The goal is to be an early warning system, even before being published by CISA. More data and features coming soon!

CVE ID Vendor Source
CVE-2024-1708 ConnectWise TheHackerNews
CVE-2024-56145 craftcms TrendMicro
CVE-2024-9047 nickboss TrendMicro
CVE-2022-1952 Syntactics, Inc. The Shadowserver (via CIRCL)
CVE-2023-2648 Weaver The Shadowserver (via CIRCL)
CVE-2020-29597 IncomCMS The Shadowserver (via CIRCL)
CVE-2025-48930 TeleMessage CVE
CVE-2025-48929 TeleMessage CVE
CVE-2025-48928 TeleMessage CVE
CVE-2025-48927 TeleMessage CVE
CVE-2025-48926 TeleMessage CVE
CVE-2025-48925 TeleMessage CVE
CVE-2020-13117 Wavlink The Shadowserver (via CIRCL)
CVE-2020-35713 Belkin The Shadowserver (via CIRCL)
CVE-2023-39780 ASUS GreyNoise
CVE-2019-18818 Strapi The Shadowserver (via CIRCL)
CVE-2023-47248 Apache Software Foundation The Shadowserver (via CIRCL)
CVE-2023-51467 Apache Software Foundation The Shadowserver (via CIRCL)
CVE-2023-49070 Apache Software Foundation The Shadowserver (via CIRCL)
CVE-2025-48827 vBulletin KEVIntel
CVE-2025-48828 vBulletin KEVIntel
CVE-2023-40000 LiteSpeed Technologies WPScan
CVE-2021-36356 KRAMER The Shadowserver (via CIRCL)
CVE-2023-1454 jeecg The Shadowserver (via CIRCL)
CVE-2023-34960 Chamilo The Shadowserver (via CIRCL)
Displaying vulnerabilities 51 - 75 of 1850 in total