CVE intelligencepages
Search known-exploited vulnerabilities by CVE, vendor, product, severity, and remediation status.
CVEs analysed
2,668
Listed last 30d
36
Ransomware-linked
361
Public exploit
2,064
Attributed
290
EPSS ≥ 90%
468
Every CVE on the CISA KEV catalog, enriched with exploit code, attributed groups, malware families and published detection rules. CISA lists a CVE here once it has evidence of exploitation against real targets — so the question this tab answers is not "could this be attacked" but "who is being attacked with it". No KEV chip in the Signals column: every row on this tab is on KEV.
2,668 pages · showing 1–100 · sorted by kev listed ↓
Field coverage across these 2,668 pages: KEV listing date 1,739 · CVSS base score 2,612 · publication date 2,668 · EPSS 2,485 · threat-intel signals 291. Rows with no value on the column being sorted are listed last in both directions rather than counted as zero.
Reading a row
- ransomware
- CISA records known use in ransomware campaigns. Varies across this index, which is why it is on the row.
- PoC
- Public proof-of-concept repositories this deployment found on GitHub, and how many.
- EPSS
- FIRST's estimate of the probability the CVE is exploited in the next 30 days. Present on every record here.
- CVSS
- Base score, from scored sources only. "n/a" means no source scored it — not that the score is low.
F.A.Q.
Find answers to common questions about CVEs and vulnerability intelligence
