-

VulnCheck KEV Surges to Track More than 3,600 Known Exploited Vulnerabilities

Exploit Intelligence Company Now Tracking 173% More Known Exploited Vulnerabilities than CISA KEV; VulnCheck Community Surpasses 10,000 Users

LEXINGTON, Mass.--(BUSINESS WIRE)--VulnCheck, the exploit intelligence company, today announced significant growth of its Known Exploited Vulnerabilities (KEV) catalog, which now tracks over 3,600 known exploited vulnerabilities, and has surpassed over 10,000 users worldwide.

The VulnCheck KEV is available through the VulnCheck Community as a free intelligence feed for any enterprise, cybersecurity firm, government team, or managed service provider. VulnCheck launched its Community offerings in early 2024, with hundreds of cybersecurity platforms now powered with VulnCheck intelligence.

The volume of the VulnCheck KEV catalog exceeds the CISA KEV catalog by 173%. On average, the VulnCheck KEV is 27 days faster at informing users of known exploited vulnerabilities than the CISA KEV, and currently averages 125% more known exploited vulnerabilities added monthly.

The VulnCheck KEV provides security teams and detection engineers with a dashboard featuring the largest real-time collection of known exploited vulnerabilities. Through its new interface, VulnCheck KEV users have enriched CVE context, including links to exploit proof-of-concept (POC) code, making it easier to find exploitation evidence and exploits for validation and testing against VulnCheck XDB - another Community resource that provides users with exploit POC code in Git repositories, programmatically compiled with validation steps that involve human analysis and automated block lists.

“Our research shows that 28% of CVEs are exploited within the first 24 hours of disclosure to gain access to critical systems and organizations,” said Anthony Bettini, CEO and founder, VulnCheck. “As defenders struggle to keep up, getting information into their hands faster about which vulnerabilities need remediation first can help stop breaches before they occur. The VulnCheck KEV solves this issue for thousands of defenders worldwide.”

The VulnCheck KEV catalog also includes citations and evidence explaining why each vulnerability is listed, linking to known threat actors, ransomware groups, or botnet activity when available. The VulnCheck KEV helps teams better manage threats, build detections faster, and solve the vulnerability prioritization challenge.

In 2024, VulnCheck:

  • Added 717 new known exploited vulnerabilities for an average of 59.8/month compared to 170 added to the CISA KEV for an average of 14.2/month.
  • Added 410 unique vendors with one or more known exploited vulnerabilities to the VulnCheck KEV vs. 56 unique vendors in the CISA KEV.
  • Provided teams with contextual intelligence on the top 10 vendors by number of exploited vulnerabilities, including Microsoft (55), Apache (18), Ivanti (17), Apple (16), D-Link (14), Oracle (14), Google (13), Cisco (11), Progress (11) and VMware (11).
  • Provided teams with intelligence on the top 10 products with exploited vulnerabilities, including Microsoft Windows (30), Google Chrome / Chromium (11), Apple IOS products (9), Apache OFBiz (6), Ivanti Connect Secure (6), Citrix Netscaler (6), Apple Safari (5), Cisco ASA / FTD (5), QNAP QTS (5), and openSSL (5).

For more information on the VulnCheck KEV and to sign up for the VulnCheck Community, visit https://vulncheck.com/kev.

About VulnCheck
VulnCheck is the exploit intelligence company helping enterprises, government organizations, and cybersecurity vendors solve the vulnerability prioritization challenge. Trusted by some of the world's largest organizations responsible for protecting hundreds of millions of systems and people, VulnCheck helps organizations outpace adversaries by providing the most comprehensive, real-time vulnerability intelligence that is autonomously correlated with unique, proprietary exploit and threat intelligence. Follow the company on LinkedIn or X.

To learn more about VulnCheck, visit https://vulncheck.com/.

Contacts

Jason Vancura
Marketbridge for VulnCheck
vulncheck@marketbridge.com

VulnCheck


Release Versions

Contacts

Jason Vancura
Marketbridge for VulnCheck
vulncheck@marketbridge.com

More News From VulnCheck

VulnCheck Announces Cybersecurity Leaders Jen Easterly and Andrew Boyd as Keynote Speakers for THREATCON1

LEXINGTON, Mass.--(BUSINESS WIRE)--VulnCheck, the exploit intelligence company, today announced that former CISA Director Jen Easterly and former Director of the CIA’s Center for Cyber Intelligence (CCI) Andrew Boyd will keynote THREATCON1, taking place September 21-22, 2025, at Carahsoft Headquarters in Reston, Virginia. The two globally recognized cybersecurity leaders will share expert perspectives on the state of cybersecurity, the intersection of national security and next-generation techn...

VulnCheck Launches Integration with ThreatQuotient, a Securonix Company, to Help Defenders Prioritize Remediation with Powerful Threat & Exploit Intelligence Solution

LEXINGTON, Mass.--(BUSINESS WIRE)--VulnCheck, the exploit intelligence company, today announced the launch of the VulnCheck Community Data Feed (CDF) in the ThreatQuotient Marketplace. The combined solution integrates VulnCheck’s API into ThreatQuotient’s ThreatQ Platform, enabling security teams to prioritize vulnerability remediation with greater scale, speed and precision. According to VulnCheck research, threat actors now exploit over a quarter of vulnerabilities (28.3%) within a day of CVE...

VulnCheck KEV Alerts Deliver Instant Warnings on Actively Exploited Vulnerabilities with Real-Time Slack and Email Notifications

LEXINGTON, Mass.--(BUSINESS WIRE)--VulnCheck, the exploit intelligence company, today announced the launch of VulnCheck KEV (Known Exploited Vulnerabilities) Alerts, a breakthrough capability delivering real-time notifications on vulnerabilities with confirmed public exploitation evidence. This enhanced capability empowers security teams and researchers to stay ahead of active, emerging threats by receiving timely, actionable alerts generated directly through Slack and email by VulnCheck. The c...
Back to Newsroom