Known Exploited Vulnerabilities
Evidence-backed KEV intelligence enriched with confidence scoring, exploitation status, CISA KEV status, and sensor telemetry.
2,695
Total KEVs
Known exploited vulnerabilities tracked in KEVIntel
1,039
Beyond CISA KEV
Additional exploited CVEs tracked beyond CISA KEV
72
KEVs Observed in Sensors (7d)
Tracked KEVs with live exploitation attempts in honeypots
1,839+
Artifacts Available
PoC, Nuclei, and scanner context
Looking for CVEs beyond the official catalog? Browse known exploited vulnerabilities not in CISA KEV.
| CVE | Product | Vendor | Confidence | CISA KEV | Sensors | Added | Artifacts |
|---|---|---|---|---|---|---|---|
|
ShareFile Storage Zones Controller |
ShareFile Storage Zones Controller | High | Not in CISA | — | 19 days ago |
PoC
Nuclei
VPatch
|
|
|
LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF |
LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF | Confirmed | Not in CISA | Yes | 29 days ago |
PoC
Nuclei
VPatch
|
|
|
WhatsUp Gold |
WhatsUp Gold | High | Not in CISA | — | about 2 months ago |
PoC
Nuclei
|
|
|
Chef Automate |
Chef Automate | High | Not in CISA | — | about 2 months ago |
PoC
Nuclei
|
|
|
Flowmon |
Flowmon | High | Not in CISA | — | about 2 months ago |
PoC
Nuclei
|
|
|
MOVEit Transfer |
MOVEit Transfer | High | Not in CISA | — | about 2 months ago |
PoC
Nuclei
|
|
|
Telerik UI for ASP.NET AJAX |
Telerik UI for ASP.NET AJAX | Confirmed | In CISA | — | over 1 year ago |
PoC
|
|
|
Telerik UI for ASP.NET AJAX |
Telerik UI for ASP.NET AJAX | Confirmed | In CISA | — | over 1 year ago |
PoC
|
|
|
Telerik UI for ASP.NET AJAX |
Telerik UI for ASP.NET AJAX | Confirmed | In CISA | — | over 1 year ago |
PoC
|
|
|
Telerik UI for ASP.NET AJAX |
Telerik UI for ASP.NET AJAX | Confirmed | In CISA | — | over 1 year ago |
Nessus
|
|
|
MOVEit Transfer |
MOVEit Transfer | Confirmed | In CISA | — | over 1 year ago |
PoC
Nuclei
|
|
|
WS_FTP Server |
WS_FTP Server | Confirmed | In CISA | — | over 1 year ago |
PoC
Nuclei
|
|
|
Telerik Report Server |
Telerik Report Server | Confirmed | In CISA | — | over 1 year ago |
PoC
Nuclei
Nessus
|
|
|
WhatsUp Gold |
WhatsUp Gold | Confirmed | In CISA | — | over 1 year ago |
PoC
Nuclei
Nessus
|
|
|
LoadMaster |
LoadMaster | Confirmed | In CISA | — | over 1 year ago |
PoC
Nuclei
|
|
|
WhatsUp Gold |
WhatsUp Gold | Confirmed | In CISA | — | over 1 year ago |
PoC
Nuclei
Nessus
|
|
|
MOVEit Transfer |
MOVEit Transfer | High | Not in CISA | — | about 2 years ago |
PoC
|
About Known Exploited Vulnerabilities
This live feed lists known exploited vulnerabilities tracked by KEVIntel — including CISA KEV and additional exploited-CVE coverage beyond the official catalog. Read the full methodology, the glossary article What Is a Known Exploited Vulnerability?, or compare KEVIntel with CISA KEV.
What Is a Known Exploited Vulnerability?
A known exploited vulnerability (KEV) is a CVE with credible evidence of exploitation in the wild — not merely a high CVSS score, a public PoC, or a theoretical exploitability claim.
Security teams use KEV status to prioritise remediation: only a small fraction of published CVEs are ever exploited, so exploitation evidence is a stronger signal than severity alone.
For a deeper definition and examples of accepted evidence, see What Is a Known Exploited Vulnerability?.
How Does KEVIntel Differ from the CISA KEV Catalog?
CISA KEV is the authoritative U.S. government catalog of known exploited vulnerabilities. It is essential — and KEVIntel includes it as a baseline.
KEVIntel goes further with additional exploited-CVE attestations from public reporting, vendor advisories, RSS monitoring, and proprietary honeypot/sensor telemetry, plus confidence scoring, enrichment (EPSS, CVSS, CWE, PoCs), and automation-ready delivery via RSS and API.
Many teams also track exploited CVEs not yet listed in CISA KEV. See the full KEVIntel vs CISA KEV comparison.
What Evidence Does KEVIntel Accept?
Valid attestation sources can include:
- KEVIntel honeypot and sensor evidence of exploitation attempts mapped to a CVE
- Vendor advisories that explicitly state active exploitation or observed attacks
- Official known exploited vulnerability catalogs
- High-trust exploitation reporting and threat intelligence
- Credible public reporting that documents exploitation in the wild
A generic patch advisory, PoC release, scanner template, or exploitability claim alone is not sufficient. Details are in the KEVIntel methodology.
How Does Confidence Scoring Work?
Confidence scoring separates strong exploitation evidence from weaker signals. Levels (Confirmed, High, Medium, Low) weigh source quality, endpoint specificity, payload fidelity, repeat observations, sensor telemetry, public corroboration, and human validation where needed.
Per-CVE evidence is always shown on the CVE detail page. Read more in the confidence scoring methodology.
What Does “Observed in Sensors” Mean?
KEVIntel operates honeypots and sensors that observe exploitation attempts targeting internet-facing services and map activity to CVEs where the signal is sufficiently specific. Counts reflect attempts — not proof that a particular organisation was compromised.
Explore live telemetry on Exploitation Signals.
How Can Teams Consume This Data (RSS and API)?
KEVIntel delivers known exploited vulnerability intelligence through:
- Free KEV RSS Feed — registered accounts get a personal tokenized feed URL (sign up for RSS). CISA KEV itself does not provide RSS — see our CISA KEV RSS alternative.
-
Free KEV JSON Feed — summary catalog via
GET /api/v2/kevswith an API token after email confirmation. - Pro and Enterprise APIs — enriched records, telemetry summaries, and (Enterprise) raw observations, virtual patches, and webhooks. See API & Integrations and API docs.