KEV Intelligence is becoming Previdian.

Beyond CISA KEV

Known Exploited Vulnerabilities Not in CISA KEV

Exploited vulnerabilities attested by Previdian that are not currently listed in the official CISA Known Exploited Vulnerabilities catalog — with confidence scoring and sensor telemetry.

Beyond CISA KEV
1,090
Tracked exploited vulnerabilities not in CISA KEV
Total KEVs
2,765
All known exploited vulnerabilities in Previdian
In CISA KEV
1,675
Also present in the official catalog

Why it matters

Why This List Matters

CISA KEV is the baseline many organisations use for mandatory remediation. Exploitation does not wait for catalog updates.

Previdian surfaces additional known exploited vulnerabilities from public reporting, vendor advisories stating active exploitation, and proprietary sensor observations — so teams can act before (or alongside) official listing.

“Not in CISA KEV” means the CVE is not currently in the CISA catalog when we last reconciled sources. Status can change when CISA adds an entry; Previdian continues to enrich both in-catalog and beyond-catalog KEVs.

Learn more in our CISA KEV comparison and methodology.

Live data

Browse the Live Feed

The live table of known exploited vulnerabilities not in CISA KEV is filtered on the main feed. Open it to search by vendor, product, confidence, and sensor observation.

Recent

Recently Added Beyond CISA KEV

Newest known exploited vulnerabilities tracked by Previdian that are not currently in CISA KEV.

  • CVE-2025-10164

    lmsys sglang update_weights_from_tensor main deserialization

    22 Aug 2026

  • CVE-2019-12725

    Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few...

    22 Aug 2026

  • CVE-2021-27691

    Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with...

    22 Aug 2026

  • CVE-2026-57739

    WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - SQL Injection vulnerability

    22 Aug 2026

  • CVE-2026-27971

    Qwik affected by unauthenticated RCE via server$ Deserialization

    22 Aug 2026

  • CVE-2026-19598

    Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router

    22 Aug 2026

  • CVE-2026-77806

    SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to...

    21 Aug 2026

  • CVE-2026-19478

    Improper Control of Generation of Code ('Code Injection') in GitLab

    21 Aug 2026

  • CVE-2026-77647

    SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to...

    20 Aug 2026

  • CVE-2023-25158

    Unfiltered SQL Injection in Geotools

    19 Aug 2026

Beyond CISA KEV

Prioritize What Attackers Are Exploiting

CISA KEV is essential baseline. Open the live feed filter for exploited vulnerabilities not currently in the official catalog — with evidence, confidence, and sensor context where available.