CVE intelligencepages
Search known-exploited vulnerabilities by CVE, vendor, product, severity, and remediation status.
CVEs analysed
2,000
Listed last 30d
9
Ransomware-linked
338
Public exploit
566
Attributed
2
EPSS ≥ 90%
454
Every CVE on the CISA KEV catalog, enriched with exploit code, attributed groups, malware families and published detection rules. CISA lists a CVE here once it has evidence of exploitation against real targets — so the question this tab answers is not "could this be attacked" but "who is being attacked with it". No KEV chip in the Signals column: every row on this tab is on KEV.
2,000 pages · showing 1–100 · sorted by kev listed ↓
Field coverage across these 2,000 pages: KEV listing date 1,662 · CVSS base score 1,955 · publication date 2,000 · EPSS 2,000 · threat-intel signals 2. Rows with no value on the column being sorted are listed last in both directions rather than counted as zero.
Reading a row
- ransomware
- CISA records known use in ransomware campaigns. Varies across this index, which is why it is on the row.
- PoC
- Public proof-of-concept repositories this deployment found on GitHub, and how many.
- EPSS
- FIRST's estimate of the probability the CVE is exploited in the next 30 days. Present on every record here.
- CVSS
- Base score, from scored sources only. "n/a" means no source scored it — not that the score is low.
F.A.Q.
Find answers to common questions about CVEs and vulnerability intelligence