Research

Statistics

Comprehensive overview of known exploited vulnerabilities and their characteristics — catalog growth, Beyond CISA KEV coverage, sensor telemetry, and enrichment distributions.

Total KEVs
2,979
Known exploited vulnerabilities tracked
KEVs (Last 30 Days)
295
Recently added to Previdian
CISA KEVs
1,739
Also listed in the official catalog
Beyond CISA KEV
1,240
Additional exploited vulnerabilities beyond CISA
Total Tags
32
Tags applied across the catalog
Total Vendors
995
Distinct affected vendors

Weekly

Intelligence Highlights

Rolling last 7 days by KEV added date. “Ahead of CISA” is by CISA listing date and uses operational sources only (excludes CVE metadata ingest). Sensor counts reflect observed exploitation attempts in the honeypot and sensor network (90-day aggregate history; lifetime first/last observed preserved).

Last 7 Days

29
New KEVs
24
Beyond CISA KEV
5
In CISA
4
Ahead of CISA
489h
Avg Faster
48h
Median Faster

Sensor Telemetry

230
KEVs in Sensors
177
Active (7d)
71,979
Exploitation Events (7d)
1,839
Unique Attackers (7d)

Ahead of CISA This Week

CVE Vendor / Product Lead
CVE-2026-88779 NetScaler / ADC, Gateway Recorded 12 hours before CISA KEV
CVE-2016-3081 Apache / Struts Recorded 77 days before CISA KEV
CVE-2026-102489 Zammad / Zammad Recorded 2 days before CISA KEV
CVE-2026-102490 Zammad / Zammad Recorded 2 days before CISA KEV

Vendors

Distribution

Top 10 Vendors by KEV Count

Loading...

Top 10 Vendors with Edge KEVs

Vendors with the most KEVs tagged as 'edge' (edge computing, edge devices, etc.)

Loading...

Severity

CVSS Score Distribution

Scores among known exploited vulnerabilities. A high score is potential damage if exploited, separate from whether attackers are using it. Only vulnerabilities with a score for that version are included.

CVSS v4.0

Loading...

Access

Authentication

Whether an attacker needs an account, from the best available CVSS vector. Unauthenticated means no privileges required. Vulnerabilities with no privileges metric are left out.

Loading...

EPSS

30-Day Exploitation Probability

EPSS estimates the chance of exploitation in the next 30 days. It is not evidence that exploitation has happened.

EPSS Score Distribution (Last 30 Days)

Loading...

Top 10 KEVs by EPSS Score

Loading...

Activity

Mentions and PoCs

Top 10 KEVs by News Mentions

Based on mentions in security news articles and advisories

Loading...

Top 10 KEVs by Proof of Concepts

Public exploit code is not the same as exploitation in the wild.

Loading...

Timing

Time to KEV Listing

Time Between CVE Publication and KEV Listing

Note: This shows the time between CVE publication and KEV listing, not necessarily when exploitation began

Loading...

Median Days to Listing

Median days from CVE publication to listing, by the month it was listed. Same-day publication and listing are left out, including when a vendor released both together. A listing dated before publication is left out too. This is not when exploitation began. A month with only a few listings can move the line a lot.

Loading...