Beyond CISA KEV
Known Exploited Vulnerabilities Not in CISA KEV
Exploited vulnerabilities attested by Previdian that are not currently listed in the official CISA Known Exploited Vulnerabilities catalog — with confidence scoring and sensor telemetry.
- Beyond CISA KEV
- 1,090
- Tracked exploited vulnerabilities not in CISA KEV
- Total KEVs
- 2,765
- All known exploited vulnerabilities in Previdian
- In CISA KEV
- 1,675
- Also present in the official catalog
Why it matters
Why This List Matters
CISA KEV is the baseline many organisations use for mandatory remediation. Exploitation does not wait for catalog updates.
Previdian surfaces additional known exploited vulnerabilities from public reporting, vendor advisories stating active exploitation, and proprietary sensor observations — so teams can act before (or alongside) official listing.
“Not in CISA KEV” means the CVE is not currently in the CISA catalog when we last reconciled sources. Status can change when CISA adds an entry; Previdian continues to enrich both in-catalog and beyond-catalog KEVs.
Learn more in our CISA KEV comparison and methodology.
Live data
Browse the Live Feed
The live table of known exploited vulnerabilities not in CISA KEV is filtered on the main feed. Open it to search by vendor, product, confidence, and sensor observation.
Recent
Recently Added Beyond CISA KEV
Newest known exploited vulnerabilities tracked by Previdian that are not currently in CISA KEV.
-
CVE-2025-10164
lmsys sglang update_weights_from_tensor main deserialization
22 Aug 2026
-
CVE-2019-12725
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few...
22 Aug 2026
-
CVE-2021-27691
Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with...
22 Aug 2026
-
CVE-2026-57739
WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - SQL Injection vulnerability
22 Aug 2026
-
CVE-2026-27971
Qwik affected by unauthenticated RCE via server$ Deserialization
22 Aug 2026
-
CVE-2026-19598
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
22 Aug 2026
-
CVE-2026-77806
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to...
21 Aug 2026
-
CVE-2026-19478
Improper Control of Generation of Code ('Code Injection') in GitLab
21 Aug 2026
-
CVE-2026-77647
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to...
20 Aug 2026
-
CVE-2023-25158
Unfiltered SQL Injection in Geotools
19 Aug 2026
Beyond CISA KEV
Prioritize What Attackers Are Exploiting
CISA KEV is essential baseline. Open the live feed filter for exploited vulnerabilities not currently in the official catalog — with evidence, confidence, and sensor context where available.