Known Exploited Vulnerability Feed
Evidence-backed KEV intelligence enriched with confidence scoring, exploitation status, CISA KEV status, and sensor telemetry.
2,682
Total KEVs
Known exploited vulnerabilities tracked in KEVIntel
1,031
Beyond CISA KEV
Additional exploited CVEs tracked beyond CISA KEV
55
KEVs Observed in Sensors (7d)
Tracked KEVs with live exploitation attempts in honeypots
1,831+
Artifacts Available
PoC, Nuclei, and scanner context
| CVE | Product | Vendor | Confidence | Exploitation Status | Sensors | Added | Artifacts |
|---|---|---|---|---|---|---|---|
| CVE-2022-41840 | Welcart e-Commerce (WordPress plugin) | Collne Inc. | High | Active | — | about 2 months ago |
PoC
Nuclei
|
| CVE-2022-0786 | KiviCare – Clinic & Patient Management System (EHR) | Unknown | High | Active | — | about 2 months ago |
PoC
Nuclei
|
| CVE-2020-10548 | rConfig | rConfig | High | Active | — | about 2 months ago |
PoC
Nuclei
|
| CVE-2021-30168 | P2/Z2/P3/Z3 IP camera firmware | MERIT LILIN ENT.CO.,LTD. | High | Active | — | about 2 months ago |
—
|
| CVE-2018-3810 | Smart Google Code Inserter | Oturia | High | Active | — | about 2 months ago |
PoC
Nuclei
|
| CVE-2022-0867 | Pricing Table Plugin | Unknown | High | Active | — | about 2 months ago |
PoC
Nuclei
|
| CVE-2020-36112 | Bookstore | CSE | High | Active | — | about 2 months ago |
PoC
Nuclei
|
| CVE-2018-2894 | WebLogic Server | Oracle Corporation | Confirmed | Active | Yes | about 2 months ago |
PoC
Nuclei
|
| CVE-2014-3206 | BlackArmor NAS | Seagate | High | Active | — | about 2 months ago |
PoC
Nuclei
|
| CVE-2018-10942 | Attribute Wizard addon | PrestaShop | High | Active | — | about 2 months ago |
PoC
Nuclei
|
| CVE-2023-43000 | macOS, iOS and iPadOS, Safari | Apple | Confirmed | Active | — | about 2 months ago |
—
|
| CVE-2025-31277 | Safari, iOS and iPadOS, macOS, tvOS, visionOS, watchOS | Apple | Confirmed | Active | — | about 2 months ago |
—
|
| CVE-2026-9082 | Drupal core | Drupal | Confirmed | Active | Yes | about 2 months ago |
PoC
Nuclei
VPatch
|
| CVE-2026-48172 | cPanel Plugin, WHM Plugin | LiteSpeed Technologies | Confirmed | Active | — | about 2 months ago |
PoC
|
| CVE-2026-34926 | TrendAI Apex One, TrendAI Apex One as a Service | Trend Micro, Inc. | Confirmed | Active | — | about 2 months ago |
PoC
|
| CVE-2025-34291 | Langflow | Langflow | Confirmed | Active | — | about 2 months ago |
PoC
Nuclei
|
| CVE-2026-45498 | Microsoft Defender Antimalware Platform | Microsoft | Confirmed | Active | — | about 2 months ago |
—
|
| CVE-2026-41091 | Microsoft Malware Protection Engine | Microsoft | Confirmed | Active | — | about 2 months ago |
PoC
|
| CVE-2026-34234 | panel | Ctrlpanel-gg | High | Active | — | about 2 months ago |
PoC
|
| CVE-2026-42897 | Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server Subscription Edition RTM | Microsoft | Confirmed | Active | — | about 2 months ago |
—
|
| CVE-2026-42208 | litellm | BerriAI | Confirmed | Active | — | about 2 months ago |
PoC
Nuclei
|
| CVE-2026-6973 | Endpoint Manager Mobile | Ivanti | Confirmed | Active | — | about 2 months ago |
—
|
| CVE-2026-44742 | Postorius | Postorius project | High | Active | — | about 2 months ago |
—
|
| CVE-2026-0300 | Cloud NGFW, PAN-OS, Prisma Access | Palo Alto Networks | Confirmed | Active | — | about 2 months ago |
PoC
|
| CVE-2026-31431 | Linux | Linux | Confirmed | Active | — | about 2 months ago |
PoC
|