KEV Compare

Compare Known Exploited Vulnerabilities catalogs across publishers (CISA, ENISA, CIRCL, and future sources). Explore overlap, unique coverage, and who listed a vulnerability first.

Unique vulns (union)
1,684
Sources
3
Avg sources/vuln
1.03
Top overlap
CISA & ENISA34 (2.0%)

KEVs added (cumulative)

3 sources
Loading chart...

Coverage overview

CISA
1,675
1,630
Excl: 1,630 Shared: 45
ENISA
39
Excl: 5 Shared: 34
CIRCL
19
Excl: 4 Shared: 15

KEV catalogs tracked by CveMate

3 catalogs
CatalogPublisherKEVsAvg/moExclusiveSharedSinceScope
CISA
Cybersecurity and Infrastructure Security Agency (US)1,67528.881,630452021-11-03US federal / global
ENISA
European Union Agency for Cybersecurity (EU)391.955342025-01-17EU member states
CIRCL
Computer Incident Response Center Luxembourg190.954152025-01-01EU / international
Union (all catalogs) 1,684
Avg/mo: average new KEVs per month. Exclusive: listed by that source only. Shared: also in at least one other source.

Pairwise overlap

Coverage
CISAvsENISA
34
2.0%
CISA:2.0%
ENISA:87.2%
CISA:28
ENISA:4
Tie:2
CIRCLvsCISA
15
0.9%
CIRCL:78.9%
CISA:0.9%
CIRCL:1
CISA:10
Tie:4
CIRCLvsENISA
4
7.4%
CIRCL:21.1%
ENISA:10.3%
CIRCL:1
ENISA:3
Jaccard: shared / (A + B - shared) (similarity).
Coverage: % of source's KEVs that are shared with the other.
Listed first: among shared CVEs, how many each source listed before the other.

Latest 50 vulnerabilities added to KEV catalogs

1,684 total
Vuln IDSeverityVendor / ProductFixCVE PublishedKEV SourcesKEV Added
CVE-2026-735708.9 HIGHsynacor/zimbra_collaboration_suite2026-08-13
CISA
2026-08-21
CVE-2026-6983610 CRITICALmicrosoft/microsoft entra2026-08-20
CISA
2026-08-21
CVE-2026-194789.4 CRITICALgitlab/gitlab2026-08-17
CIRCL
2026-08-21
CVE-2026-725299.8 CRITICALtrueconf/trueconf_server2026-08-19
CISA
2026-08-20
CVE-2026-725309.5 CRITICALtrueconf/trueconf_server2026-08-19
CISA
2026-08-20
CVE-2026-648499.3 CRITICALlfprojects/mlflow2026-08-17
CISA
2026-08-19
CVE-2026-338249.8 CRITICALmicrosoft/windows_10_16072026-04-14
CISA
2026-08-18
CVE-2026-593109.8 CRITICALvmware/cloud foundation2026-07-30
ENISA
CISA
2026-08-10
CVE-2026-550409.1 CRITICALmicrosoft/microsoft sharepoint enterprise server 20162026-07-14
CISA
2026-08-18
CVE-2026-654009.8 CRITICALapple/macos2026-08-06
CISA
2026-08-18
CVE-2025-625939.4 CRITICALanyscale/ray2025-11-26
CISA
2026-08-17
CVE-2026-203498.6 HIGHcisco/adaptive_security_appliance_software2026-08-11
CISA
2026-08-11
CVE-2026-7289810 CRITICALmetabase/metabase2026-08-10
CISA
2026-08-11
CVE-2026-688207 HIGHmicrosoft/windows_10_16072026-08-11
ENISA
CISA
2026-08-11
CVE-2017-102717.5 HIGHoracle corporation/weblogic server2017-10-19
ENISA
CISA
2022-02-10
CVE-2026-80379.8 CRITICALprogress software/ecs connections manager2026-06-04
CISA
2026-08-07
CVE-2026-630779.8 CRITICALjetbrains/teamcity2026-07-27
CISA
2026-08-05
CVE-2026-91989.8 CRITICALibm/langflow oss2026-07-17
CISA
2026-08-04
CVE-2026-344867.5 HIGHapache software foundation/apache tomcat2026-04-09
CISA
2026-08-04
CVE-2026-185568.2 HIGHn-able/n-central2026-08-01
CISA
2026-08-04
CVE-2026-185778.2 HIGHn-able/n-central2026-08-02
CISA
2026-08-03
CVE-2022-261349.8 CRITICALatlassian/confluence data center2022-06-03
ENISA
CISA
2022-06-02
CVE-2026-203165.3 MEDIUMcisco/cisco secure firewall management center (fmc)2026-07-29
CISA
2026-07-29
CVE-2026-162329.8 CRITICALcheckpoint/multi-domain_security_management2026-07-22
CIRCL
CISA
2026-07-22
CVE-2026-1681210 CRITICALarista networks/velocloud orchestrator on-prem2026-07-27
CISA
2026-07-27
CVE-2025-686865.9 MEDIUMfortinet/fortios2026-02-10
CISA
2026-07-27
CVE-2026-505229.8 CRITICALmicrosoft/microsoft sharepoint enterprise server 20162026-07-14
CISA
2026-07-22
CVE-2021-271378.1 HIGHdd-wrt/dd-wrt2026-07-16
CISA
2026-07-21
CVE-2026-07709.8 CRITICALlangflow/langflow2026-01-23
CISA
2026-07-21
CVE-2026-601375.9 MEDIUMdebian/wordpress2026-07-17
CISA
2026-07-21
CVE-2026-630309.8 CRITICALdebian/wordpress2026-07-17
CISA
2026-07-21
CVE-2026-586449.8 CRITICALmicrosoft/microsoft sharepoint enterprise server 20162026-07-14
CISA
2026-07-16
CVE-2026-398089.8 CRITICALfortinet/fortisandbox2026-04-14
CISA
2026-07-16
CVE-2026-250899.8 CRITICALfortinet/fortisandbox2026-06-09
CISA
2026-07-16
CVE-2026-468179.8 CRITICALoracle corporation/oracle payments2026-05-28
CISA
2026-07-15
CVE-2023-43467.5 HIGHknx association/knx protocol connection authorization option 12023-08-29
CISA
2026-07-15
CVE-2026-561557.8 HIGHmicrosoft/windows_10_16072026-07-14
CISA
2026-07-14
CVE-2026-1540910 CRITICALsonicwall/sma1000_firmware2026-07-14
CISA
2026-07-14
CVE-2026-154107.2 HIGHsonicwall/sma1000_firmware2026-07-14
CISA
2026-07-14
CVE-2026-561649.8 CRITICALmicrosoft/microsoft sharepoint enterprise server 20162026-07-14
CISA
2026-07-14
CVE-2008-41289.3 HIGHcisco/ios2008-09-18
CISA
2026-07-13
CVE-2026-5629110 CRITICALbalbooa/forms2026-07-09
CISA
2026-07-10
CVE-2026-490497.5 HIGHjoomshaper.com/helix3 extension for joomla2026-06-29
ENISA
2026-07-10
CVE-2026-4893910 CRITICALicagenda.com/icagenda extension for joomla2026-06-20
CISA
2026-07-10
CVE-2026-4890810 CRITICALjoomshaper.net/sp page builder extension for joomla2026-06-20
CIRCL
ENISA
CISA
2026-07-06
CVE-2026-552558.4 HIGHlangflow-ai/langflow2026-06-23
CISA
2026-07-07
CVE-2026-5629010 CRITICALjoomlack/page_builder_ck2026-06-29
CISA
2026-07-07
CVE-2026-4828210 CRITICALadobe/coldfusion2026-06-30
CISA
2026-07-07
CVE-2026-4890710 CRITICALjoomlacontenteditor.net/joomla content editor (jce) extension for joomla2026-06-05
ENISA
CISA
2026-06-16
CVE-2026-456598.8 HIGHmicrosoft/microsoft sharepoint enterprise server 20162026-05-22
CISA
2026-07-01

What are Known Exploited Vulnerabilities (KEV) catalogs?

Known Exploited Vulnerabilities (KEV) catalogs are curated lists of CVEs that have been observed being actively exploited in the wild. Unlike the full NVD database, which contains over 250,000 vulnerabilities, KEV catalogs focus exclusively on threats that pose a real, demonstrated risk to organizations. This makes them essential for vulnerability prioritization and patch management.

Who publishes KEV catalogs?

Several organizations maintain their own KEV catalogs, each with different criteria, geographic focus, and update cadence:

  • CISA (Cybersecurity and Infrastructure Security Agency) — the original and most widely adopted KEV catalog, mandated for US federal agencies under BOD 22-01.
  • ENISA (European Union Agency for Cybersecurity) — the EU equivalent, contributing a European perspective on actively exploited vulnerabilities.
  • CIRCL (Computer Incident Response Center Luxembourg) — a CERT-based catalog with a focus on European and international threat intelligence.

Why compare KEV catalogs?

No single catalog captures every actively exploited vulnerability. Each publisher has different intelligence sources, geographic priorities, and inclusion criteria. By comparing catalogs side-by-side, security teams can identify coverage gaps, discover which source lists a CVE first, and build a more comprehensive view of the threat landscape. The overlap analysis (Jaccard similarity and pairwise coverage) quantifies how much agreement exists between publishers, while the "listed first" metric reveals which source tends to react fastest to emerging threats.

How is this data computed?

CveMate aggregates KEV entries from all supported publishers into a unified graph database. Each vulnerability is linked to every catalog that lists it, along with the date it was added. Statistics such as exclusive counts, overlap intersections, Jaccard similarity scores, and first-lister analysis are computed in real time from this unified dataset. The cumulative chart tracks how each catalog has grown over time, providing a historical view of their respective coverage trajectories.