CVE intelligencepages
Search known-exploited vulnerabilities by CVE, vendor, product, severity, and remediation status.
CVEs analysed
1,959
Listed last 30d
9
Ransomware-linked
338
Public exploit
528
Attributed
2
EPSS ≥ 90%
454
Every CVE on the CISA KEV catalog, enriched with exploit code, attributed groups, malware families and published detection rules. CISA lists a CVE here once it has evidence of exploitation against real targets — so the question this tab answers is not "could this be attacked" but "who is being attacked with it". No KEV chip in the Signals column: every row on this tab is on KEV.
1,959 pages · showing 1–100 · sorted by kev listed ↓
Field coverage across these 1,959 pages: KEV listing date 1,662 · CVSS base score 1,917 · publication date 1,959 · EPSS 1,959 · threat-intel signals 2. Rows with no value on the column being sorted are listed last in both directions rather than counted as zero.
Reading a row
- ransomware
- CISA records known use in ransomware campaigns. Varies across this index, which is why it is on the row.
- PoC
- Public proof-of-concept repositories this deployment found on GitHub, and how many.
- EPSS
- FIRST's estimate of the probability the CVE is exploited in the next 30 days. Present on every record here.
- CVSS
- Base score, from scored sources only. "n/a" means no source scored it — not that the score is low.
F.A.Q.
Find answers to common questions about CVEs and vulnerability intelligence