CISA KEV Gaps — Exploited CVEs Missing from KEV

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,361 CVEs tracked 53,621 with exploits 4,857 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,840 researchers
607 results Clear all
CVE-2009-2055 5.9 MEDIUM KEV EPSS 0.01
Cisco IOS XR <3.8.1 - DoS
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.
CWE-20 Aug 19, 2009
CVE-2009-1123 7.8 HIGH KEV EPSS 0.05
Microsoft Windows - Privilege Escalation
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."
Jun 10, 2009
CVE-2008-0655 8.8 HIGH KEV EPSS 0.67
Adobe Acrobat < 8.1.2 - Information Disclosure
Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.
CWE-200 Feb 07, 2008
CVE-2007-0671 8.8 HIGH KEV EPSS 0.55
Microsoft Excel < - RCE
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
Feb 03, 2007
CVE-2006-2492 8.8 HIGH KEV EPSS 0.74
Microsoft Office < 2006 - Buffer Overflow
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
CWE-120 May 20, 2006
CVE-2006-1547 7.5 HIGH KEV EPSS 0.22
Apache Struts <1.2.9 - DoS
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.
CWE-749 Mar 30, 2006
CVE-2004-1464 5.9 MEDIUM KEV EPSS 0.02
Cisco Ios < 12.2\(15\)zj3 - Denial of Service
Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.
CWE-400 Dec 31, 2004