Beyond CISA KEV

Known Exploited Vulnerabilities Not in CISA KEV

Exploited CVEs attested by KEV Intelligence that are not currently listed in the official CISA Known Exploited Vulnerabilities catalog — with confidence scoring and sensor telemetry.

Beyond CISA KEV
1,080
Tracked exploited CVEs not in CISA KEV
Total KEVs
2,750
All known exploited vulnerabilities in KEV Intelligence
In CISA KEV
1,670
Also present in the official catalog

Why it matters

Why This List Matters

CISA KEV is the baseline many organisations use for mandatory remediation. Exploitation does not wait for catalog updates.

KEV Intelligence surfaces additional known exploited vulnerabilities from public reporting, vendor advisories stating active exploitation, and proprietary sensor observations — so teams can act before (or alongside) official listing.

“Not in CISA KEV” means the CVE is not currently in the CISA catalog when we last reconciled sources. Status can change when CISA adds an entry; KEV Intelligence continues to enrich both in-catalog and beyond-catalog KEVs.

Learn more in our CISA KEV comparison and methodology.

Live data

Browse the Live Feed

The live table of known exploited vulnerabilities not in CISA KEV is filtered on the main feed. Open it to search by vendor, product, confidence, and sensor observation.

Recent

Recently Added Beyond CISA KEV

Newest known exploited vulnerabilities tracked by KEV Intelligence that are not currently in CISA KEV.

  • CVE-2026-64849

    MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

    18 Aug 2026

  • CVE-2022-50973

    Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet

    17 Aug 2026

  • CVE-2025-52907

    TOTOLINK X6000R Security Bypass Vulnerability

    17 Aug 2026

  • CVE-2026-52806

    Gogs: RCE via git rebase --exec argument injection in pull request merge

    17 Aug 2026

  • CVE-2026-56270

    Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint

    17 Aug 2026

  • CVE-2026-8452

    Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service

    17 Aug 2026

  • CVE-2016-5312

    Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read...

    16 Aug 2026

  • CVE-2021-2109

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...

    15 Aug 2026

  • CVE-2026-45298

    Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)

    16 Aug 2026

  • CVE-2016-20097

    Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad

    14 Aug 2026

Beyond CISA KEV

Prioritize What Attackers Are Exploiting

CISA KEV is essential baseline. Open the live feed filter for exploited CVEs not currently in the official catalog — with evidence, confidence, and sensor context where available.