Not in CISA KEV
Known Exploited Vulnerabilities Not in CISA KEV
Exploited vulnerabilities tracked by Previdian that are not currently listed in CISA's Known Exploited Vulnerabilities catalog.
- Beyond CISA KEV
- 1,240
- Exploited vulnerabilities not currently in CISA KEV
- In CISA KEV
- 1,739
- Also present in the official catalog
- Total
- 2,979
- Known exploited vulnerabilities tracked by Previdian
Recent
Recently Identified Outside CISA KEV
Newest exploited vulnerabilities tracked by Previdian that are not currently in CISA KEV.
-
CVE-2025-34469
Cowrie < 2.9.0 Unrestricted wget/curl Emulation Enables SSRF-Based DDoS Amplification
08 Oct 2026
-
CVE-2026-26216
Crawl4AI < 0.8.0 Docker API Unauthenticated Remote Code Execution via Hooks Parameter
07 Oct 2026
-
CVE-2025-41243
Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux
06 Oct 2026
-
CVE-2026-94504
Ninja Forms – The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting
07 Oct 2026
-
CVE-2026-93836
WPC Product Bundles for WooCommerce <= 8.6.6 - Unauthenticated Stored Cross-Site Scripting via 'qty' Parameter
07 Oct 2026
-
CVE-2026-21589
This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo...
06 Oct 2026
-
CVE-2023-7102
Remote Code Execution (RCE) Vulnerability
06 Oct 2026
-
CVE-2026-51886
langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is:...
06 Oct 2026
-
CVE-2025-49002
Dataease H2 Database Remote Code Execution (RCE) Bypass Vulnerability
05 Oct 2026
-
CVE-2025-29306
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.
05 Oct 2026
Status
Why are these not in CISA KEV?
CISA KEV is an official remediation baseline. A vulnerability can be exploited, and tracked here, before it appears in that catalog.
“Not in CISA KEV” means the vulnerability is not in the CISA Known Exploited Vulnerabilities catalog at the last time Previdian reconciled that catalog. The status can change when CISA adds an entry.
CISA KEV has its own evidence standards and update cadence. Exploitation does not wait for that listing. Teams that rely only on the official catalog can miss vulnerabilities that already have credible exploitation evidence.
Previdian records these vulnerabilities from honeypot and sensor evidence of exploitation attempts, vendor advisories that state active exploitation or observed attacks, official known exploited vulnerability catalogs, and credible public reporting. A generic patch advisory, a proof-of-concept release, or a scanner template is not enough on its own.
Want to understand how Previdian differs from CISA KEV? Read the comparison.