Known Exploited Vulnerabilities Not in CISA KEV

Exploited CVEs attested by KEVIntel that are not currently listed in the official CISA Known Exploited Vulnerabilities catalog.

Beyond CISA KEV

1,037

Tracked exploited CVEs not in CISA KEV

Total KEVs

2,693

All known exploited vulnerabilities in KEVIntel

In CISA KEV

1,656

Also present in the official catalog

Why This List Matters

CISA KEV is the baseline many organisations use for mandatory remediation. Exploitation does not wait for catalog updates. KEVIntel surfaces additional known exploited vulnerabilities from public reporting, vendor advisories stating active exploitation, and proprietary sensor observations — so teams can act before (or alongside) official listing.

“Not in CISA KEV” means the CVE is not currently in the CISA catalog when we last reconciled sources. Status can change when CISA adds an entry; KEVIntel continues to enrich both in-catalog and beyond-catalog KEVs.

Learn more in our CISA KEV comparison and methodology.

Browse the Live Feed

The live table of known exploited vulnerabilities not in CISA KEV is filtered on the main feed. Open it to search by vendor, product, confidence, and sensor observation.

Recently Added Beyond CISA KEV

  • CVE-2026-1623

    Totolink A7000R cstecgi.cgi setUpgradeFW command injection

    30 Jul 2026

  • CVE-2025-71334

    Flowise - Arbitrary File Access via Missing Chat Flow ID Validation

    28 Jul 2026

  • CVE-2026-58138

    Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators

    27 Jul 2026

  • CVE-2026-16723

    Remote Code Execution in fastjson 1.2.68–1.2.83

    25 Jul 2026

  • CVE-2014-2383

    dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read...

    25 Jul 2026

  • CVE-2025-4283

    SourceCodester/oretnom23 Stock Management System Login.php sql injection

    24 Jul 2026

  • CVE-2026-36356

    The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection...

    22 Jul 2026

  • CVE-2016-3081

    Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to...

    23 Jul 2026

  • CVE-2026-29059

    Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly

    22 Jul 2026

  • CVE-2025-68493

    Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component

    20 Jul 2026