Beyond CISA KEV
Known Exploited Vulnerabilities Not in CISA KEV
Exploited CVEs attested by KEV Intelligence that are not currently listed in the official CISA Known Exploited Vulnerabilities catalog — with confidence scoring and sensor telemetry.
- Beyond CISA KEV
- 1,073
- Tracked exploited CVEs not in CISA KEV
- Total KEVs
- 2,738
- All known exploited vulnerabilities in KEV Intelligence
- In CISA KEV
- 1,665
- Also present in the official catalog
Why it matters
Why This List Matters
CISA KEV is the baseline many organisations use for mandatory remediation. Exploitation does not wait for catalog updates.
KEV Intelligence surfaces additional known exploited vulnerabilities from public reporting, vendor advisories stating active exploitation, and proprietary sensor observations — so teams can act before (or alongside) official listing.
“Not in CISA KEV” means the CVE is not currently in the CISA catalog when we last reconciled sources. Status can change when CISA adds an entry; KEV Intelligence continues to enrich both in-catalog and beyond-catalog KEVs.
Learn more in our CISA KEV comparison and methodology.
Live data
Browse the Live Feed
The live table of known exploited vulnerabilities not in CISA KEV is filtered on the main feed. Open it to search by vendor, product, confidence, and sensor observation.
Recent
Recently Added Beyond CISA KEV
Newest known exploited vulnerabilities tracked by KEV Intelligence that are not currently in CISA KEV.
-
CVE-2016-20097
Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad
14 Aug 2026
-
CVE-2026-73533
Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build
14 Aug 2026
-
CVE-2026-73532
Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build
14 Aug 2026
-
CVE-2026-67595
VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
14 Aug 2026
-
CVE-2022-50997
Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp
14 Aug 2026
-
CVE-2022-4995
Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp
14 Aug 2026
-
CVE-2019-25765
ASP-CMS SQL Injection via commentList.asp id Parameter
14 Aug 2026
-
CVE-2026-58231
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
14 Aug 2026
-
CVE-2021-30120
2FA bypass in Kaseya VSA <= v9.5.6
14 Aug 2026
-
CVE-2021-30119
Authenticated Authenticated reflective XSS in Kaseya VSA <= v9.5.6
14 Aug 2026
Beyond CISA KEV
Prioritize What Attackers Are Exploiting
CISA KEV is essential baseline. Open the live feed filter for exploited CVEs not currently in the official catalog — with evidence, confidence, and sensor context where available.