Not in CISA KEV

Known Exploited Vulnerabilities Not in CISA KEV

Exploited vulnerabilities tracked by Previdian that are not currently listed in CISA's Known Exploited Vulnerabilities catalog.

Beyond CISA KEV
1,240
Exploited vulnerabilities not currently in CISA KEV
In CISA KEV
1,739
Also present in the official catalog
Total
2,979
Known exploited vulnerabilities tracked by Previdian

Recent

Recently Identified Outside CISA KEV

Newest exploited vulnerabilities tracked by Previdian that are not currently in CISA KEV.

  • CVE-2025-34469

    Cowrie < 2.9.0 Unrestricted wget/curl Emulation Enables SSRF-Based DDoS Amplification

    08 Oct 2026

  • CVE-2026-26216

    Crawl4AI < 0.8.0 Docker API Unauthenticated Remote Code Execution via Hooks Parameter

    07 Oct 2026

  • CVE-2025-41243

    Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux

    06 Oct 2026

  • CVE-2026-94504

    Ninja Forms – The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting

    07 Oct 2026

  • CVE-2026-93836

    WPC Product Bundles for WooCommerce <= 8.6.6 - Unauthenticated Stored Cross-Site Scripting via 'qty' Parameter

    07 Oct 2026

  • CVE-2026-21589

    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo...

    06 Oct 2026

  • CVE-2023-7102

    Remote Code Execution (RCE) Vulnerability

    06 Oct 2026

  • CVE-2026-51886

    langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is:...

    06 Oct 2026

  • CVE-2025-49002

    Dataease H2 Database Remote Code Execution (RCE) Bypass Vulnerability

    05 Oct 2026

  • CVE-2025-29306

    An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.

    05 Oct 2026

Status

Why are these not in CISA KEV?

CISA KEV is an official remediation baseline. A vulnerability can be exploited, and tracked here, before it appears in that catalog.

“Not in CISA KEV” means the vulnerability is not in the CISA Known Exploited Vulnerabilities catalog at the last time Previdian reconciled that catalog. The status can change when CISA adds an entry.

CISA KEV has its own evidence standards and update cadence. Exploitation does not wait for that listing. Teams that rely only on the official catalog can miss vulnerabilities that already have credible exploitation evidence.

Previdian records these vulnerabilities from honeypot and sensor evidence of exploitation attempts, vendor advisories that state active exploitation or observed attacks, official known exploited vulnerability catalogs, and credible public reporting. A generic patch advisory, a proof-of-concept release, or a scanner template is not enough on its own.

Browse all vulnerabilities not in CISA KEV

Want to understand how Previdian differs from CISA KEV? Read the comparison.