Glossary

KEV (CISA Known Exploited Vulnerabilities catalog)

A catalog maintained by the U.S. CISA listing vulnerabilities that are being actively exploited in the wild (Known Exploited Vulnerabilities). Adding a CVE to the KEV means the threat is no longer theoretical: real attacks are underway. The KEV serves as a de facto patch-priority list, including for organizations outside the United States.

Related Pages

Other Terms

Need an external review of your HR SaaS?

Share your product, stack, and client context. We will come back with the right review scope.

Discuss your audit