Known Exploited Vulnerabilities

Evidence-backed KEV intelligence enriched with confidence scoring, exploitation status, CISA KEV status, and sensor telemetry.

2,698

Total KEVs

Known exploited vulnerabilities tracked in KEVIntel

1,042

Beyond CISA KEV

Additional exploited CVEs tracked beyond CISA KEV

80

KEVs Observed in Sensors (7d)

Tracked KEVs with live exploitation attempts in honeypots

1,842+

Artifacts Available

PoC, Nuclei, and scanner context

Displaying vulnerabilities 51 - 75 of 2698 in total
CVE Confidence CISA KEV Sensors Added Artifacts

LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF

Confirmed Not in CISA Yes about 1 month ago
PoC Nuclei VPatch

gogs

Confirmed Not in CISA Yes about 1 month ago
PoC VPatch

Oracle Payments

Confirmed In CISA Yes about 1 month ago
PoC VPatch

SimpleHelp

Confirmed In CISA about 1 month ago
PoC

dotCMS Core

Confirmed Not in CISA Yes about 1 month ago
PoC Nuclei VPatch

LearnPress – WordPress LMS Plugin

Confirmed Not in CISA Yes about 1 month ago
PoC Nuclei

Windchill PDMLink, FlexPLM

Confirmed In CISA about 1 month ago

Cisco Unified Communications Manager

Confirmed In CISA Yes about 1 month ago
PoC VPatch

EDS5000

Confirmed In CISA about 1 month ago

Apache OFBiz

Confirmed Not in CISA Yes about 1 month ago
PoC Nuclei VPatch

Gravity SMTP

Confirmed Not in CISA Yes about 1 month ago
PoC Nuclei VPatch

TRUfusion Enterprise

High Not in CISA about 2 months ago
PoC Nuclei

Repetier Server

High Not in CISA about 2 months ago
PoC Nuclei

Restler

High Not in CISA about 2 months ago
PoC Nuclei

Boa Web Server

High Not in CISA about 2 months ago
PoC Nuclei

CyberPower PowerPanel Enterprise

High Not in CISA about 2 months ago
PoC Nuclei

CuppaCMS

High Not in CISA about 2 months ago
PoC Nuclei

E2000

High Not in CISA about 2 months ago
PoC Nuclei

datacube3

High Not in CISA about 2 months ago
PoC Nuclei

PHP-Fusion

High Not in CISA about 2 months ago
PoC Nuclei

CuppaCMS

High Not in CISA about 2 months ago
PoC Nuclei

Joomla Content Editor (JCE) extension for Joomla

Confirmed In CISA about 2 months ago
PoC Nuclei

FortiSandbox, FortiSandbox Cloud

Confirmed Not in CISA Yes about 2 months ago
PoC VPatch

WBCE CMS

High Not in CISA about 2 months ago
PoC Nuclei

Cisco Catalyst SD-WAN Manager

Confirmed In CISA about 2 months ago
PoC

About Known Exploited Vulnerabilities

This live feed lists known exploited vulnerabilities tracked by KEVIntel — including CISA KEV and additional exploited-CVE coverage beyond the official catalog. Read the full methodology, the glossary article What Is a Known Exploited Vulnerability?, or compare KEVIntel with CISA KEV.

What Is a Known Exploited Vulnerability?

A known exploited vulnerability (KEV) is a CVE with credible evidence of exploitation in the wild — not merely a high CVSS score, a public PoC, or a theoretical exploitability claim.

Security teams use KEV status to prioritise remediation: only a small fraction of published CVEs are ever exploited, so exploitation evidence is a stronger signal than severity alone.

For a deeper definition and examples of accepted evidence, see What Is a Known Exploited Vulnerability?.

How Does KEVIntel Differ from the CISA KEV Catalog?

CISA KEV is the authoritative U.S. government catalog of known exploited vulnerabilities. It is essential — and KEVIntel includes it as a baseline.

KEVIntel goes further with additional exploited-CVE attestations from public reporting, vendor advisories, RSS monitoring, and proprietary honeypot/sensor telemetry, plus confidence scoring, enrichment (EPSS, CVSS, CWE, PoCs), and automation-ready delivery via RSS and API.

Many teams also track exploited CVEs not yet listed in CISA KEV. See the full KEVIntel vs CISA KEV comparison.

What Evidence Does KEVIntel Accept?

Valid attestation sources can include:

  • KEVIntel honeypot and sensor evidence of exploitation attempts mapped to a CVE
  • Vendor advisories that explicitly state active exploitation or observed attacks
  • Official known exploited vulnerability catalogs
  • High-trust exploitation reporting and threat intelligence
  • Credible public reporting that documents exploitation in the wild

A generic patch advisory, PoC release, scanner template, or exploitability claim alone is not sufficient. Details are in the KEVIntel methodology.

How Does Confidence Scoring Work?

Confidence scoring separates strong exploitation evidence from weaker signals. Levels (Confirmed, High, Medium, Low) weigh source quality, endpoint specificity, payload fidelity, repeat observations, sensor telemetry, public corroboration, and human validation where needed.

Per-CVE evidence is always shown on the CVE detail page. Read more in the confidence scoring methodology.

What Does “Observed in Sensors” Mean?

KEVIntel operates honeypots and sensors that observe exploitation attempts targeting internet-facing services and map activity to CVEs where the signal is sufficiently specific. Counts reflect attempts — not proof that a particular organisation was compromised.

Explore live telemetry on Exploitation Signals.

How Can Teams Consume This Data (RSS and API)?

KEVIntel delivers known exploited vulnerability intelligence through:

  • Free KEV RSS Feed — registered accounts get a personal tokenized feed URL (sign up for RSS). CISA KEV itself does not provide RSS — see our CISA KEV RSS alternative.
  • Free KEV JSON Feed — summary catalog via GET /api/v2/kevs with an API token after email confirmation.
  • Pro and Enterprise APIs — enriched records, telemetry summaries, and (Enterprise) raw observations, virtual patches, and webhooks. See API & Integrations and API docs.