Known Exploited Vulnerabilities
Evidence-backed KEV intelligence enriched with confidence scoring, exploitation status, CISA KEV status, and sensor telemetry.
2,695
Total KEVs
Known exploited vulnerabilities tracked in KEVIntel
1,039
Beyond CISA KEV
Additional exploited CVEs tracked beyond CISA KEV
70
KEVs Observed in Sensors (7d)
Tracked KEVs with live exploitation attempts in honeypots
1,839+
Artifacts Available
PoC, Nuclei, and scanner context
Looking for CVEs beyond the official catalog? Browse known exploited vulnerabilities not in CISA KEV.
| CVE | Product | Vendor | Confidence | CISA KEV | Sensors | Added | Artifacts |
|---|---|---|---|---|---|---|---|
|
Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 |
Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 | High | Not in CISA | — | 21 days ago |
PoC
Nuclei
|
|
|
cacti |
cacti | High | Not in CISA | — | 21 days ago |
PoC
Nuclei
|
|
|
JoomlaCK.fr Page Builder CK extension for Joomla |
JoomlaCK.fr Page Builder CK extension for Joomla | Confirmed | In CISA | — | 23 days ago |
PoC
Nuclei
|
|
|
langflow |
langflow | Confirmed | In CISA | Yes | 23 days ago |
PoC
|
|
|
SP Page Builder extension for Joomla |
SP Page Builder extension for Joomla | Confirmed | In CISA | — | 23 days ago |
PoC
Nuclei
|
|
|
ColdFusion |
ColdFusion | Confirmed | In CISA | Yes | 28 days ago |
PoC
Nuclei
VPatch
|
|
|
ADC, Gateway |
ADC, Gateway | Confirmed | Not in CISA | Yes | 28 days ago |
PoC
|
|
|
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition |
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition | Confirmed | In CISA | — | 29 days ago |
PoC
|
|
|
LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF |
LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF | Confirmed | Not in CISA | Yes | 29 days ago |
PoC
Nuclei
VPatch
|
|
|
gogs |
gogs | Confirmed | Not in CISA | Yes | 30 days ago |
PoC
VPatch
|
About Known Exploited Vulnerabilities
This live feed lists known exploited vulnerabilities tracked by KEVIntel — including CISA KEV and additional exploited-CVE coverage beyond the official catalog. Read the full methodology, the glossary article What Is a Known Exploited Vulnerability?, or compare KEVIntel with CISA KEV.
What Is a Known Exploited Vulnerability?
A known exploited vulnerability (KEV) is a CVE with credible evidence of exploitation in the wild — not merely a high CVSS score, a public PoC, or a theoretical exploitability claim.
Security teams use KEV status to prioritise remediation: only a small fraction of published CVEs are ever exploited, so exploitation evidence is a stronger signal than severity alone.
For a deeper definition and examples of accepted evidence, see What Is a Known Exploited Vulnerability?.
How Does KEVIntel Differ from the CISA KEV Catalog?
CISA KEV is the authoritative U.S. government catalog of known exploited vulnerabilities. It is essential — and KEVIntel includes it as a baseline.
KEVIntel goes further with additional exploited-CVE attestations from public reporting, vendor advisories, RSS monitoring, and proprietary honeypot/sensor telemetry, plus confidence scoring, enrichment (EPSS, CVSS, CWE, PoCs), and automation-ready delivery via RSS and API.
Many teams also track exploited CVEs not yet listed in CISA KEV. See the full KEVIntel vs CISA KEV comparison.
What Evidence Does KEVIntel Accept?
Valid attestation sources can include:
- KEVIntel honeypot and sensor evidence of exploitation attempts mapped to a CVE
- Vendor advisories that explicitly state active exploitation or observed attacks
- Official known exploited vulnerability catalogs
- High-trust exploitation reporting and threat intelligence
- Credible public reporting that documents exploitation in the wild
A generic patch advisory, PoC release, scanner template, or exploitability claim alone is not sufficient. Details are in the KEVIntel methodology.
How Does Confidence Scoring Work?
Confidence scoring separates strong exploitation evidence from weaker signals. Levels (Confirmed, High, Medium, Low) weigh source quality, endpoint specificity, payload fidelity, repeat observations, sensor telemetry, public corroboration, and human validation where needed.
Per-CVE evidence is always shown on the CVE detail page. Read more in the confidence scoring methodology.
What Does “Observed in Sensors” Mean?
KEVIntel operates honeypots and sensors that observe exploitation attempts targeting internet-facing services and map activity to CVEs where the signal is sufficiently specific. Counts reflect attempts — not proof that a particular organisation was compromised.
Explore live telemetry on Exploitation Signals.
How Can Teams Consume This Data (RSS and API)?
KEVIntel delivers known exploited vulnerability intelligence through:
- Free KEV RSS Feed — registered accounts get a personal tokenized feed URL (sign up for RSS). CISA KEV itself does not provide RSS — see our CISA KEV RSS alternative.
-
Free KEV JSON Feed — summary catalog via
GET /api/v2/kevswith an API token after email confirmation. - Pro and Enterprise APIs — enriched records, telemetry summaries, and (Enterprise) raw observations, virtual patches, and webhooks. See API & Integrations and API docs.