Research

Research and Data

Stable statistics, methodology, and citation-ready reports for journalists, vendors, vulnerability-management teams, and academic researchers.

Total KEVs
2,750
Known exploited vulnerabilities tracked
Beyond CISA KEV
1,080
Additional exploited CVEs beyond CISA
In CISA KEV
1,670
Also listed in the official catalog
Sensor KEVs (7d)
92
KEVs with sensor activity in the last 7 days

Publications

Reports

Monthly known exploited vulnerability reports publish automatically after each month ends, starting June 2026. Older months stay published — we do not replace report pages in place.

Methods

Methodology

How KEV Intelligence observes, attests, scores, enriches, and delivers exploited-vulnerability intelligence — including accepted evidence sources and confidence scoring.

Citation

Attribution and Citation

Preferred attribution: “Source: KEV Intelligence (kevintel.com)”

Deep links: When discussing a specific CVE or sensor-observed exploitation, link the relevant CVE page, Exploitation Signals, or methodology rather than only the homepage.

Citation example: KEV Intelligence. (2026). Known Exploited Vulnerabilities. Retrieved 19 August 2026, from https://kevintel.com/feed

Media

Press Contact

Media and research enquiries: [email protected].

About

Founder

Ryan Dewhurst, Founder of KEV Intelligence. Cybersecurity researcher since 2009, creator of DVWA and founder of WPScan.

Live data

Embeddable Charts and Live Data

Use these stable product pages for charts and tables (link or screenshot with attribution):

Guidance

Media Link Guidance

If you already cover KEV Intelligence, prefer deep links that match the story: sensor-observed exploitation → the CVE or Exploitation Signals; catalog/list stories → the feed; methodology or “what is a KEV” → methodology or glossary; press packs and stats → this Research and Data page. Homepage-only links are fine for brand mentions, but deep links help readers and improve topical relevance.