Skip to content
feed: live
0dayNews
$ kev-catalogs --compare

KEV catalog comparison

Compare CISA KEV, ENISA EUVD's EU KEV-tagged entries, and CIRCL's catalog by CVE ID. ENISA's consolidated dump is filtered to records it tags as EU KEV. Coverage analytics use matching 0dayNews records only.

External snapshots refreshed hourly. Last successful sync: 2026-10-05T21:43:36.359Z.

CISA entries
1,735
CIRCL entries
25
ENISA entries
71
Combined CVEs
1,750

Pairwise overlap

CatalogCISACIRCLENISA
CISA—2160
CIRCL21—8
ENISA608—

Overlap counts are exact CVE ID intersections. ENISA EU KEV records may also carry the CISA KEV tag; the downloadable JSON preserves both source labels, so shared entries are visible and are not independent confirmations.

Listing lead time

Days from CVE publication to source listing for CVEs with a matching local record and both dates.

SourceSamplesMedianP25–P75Before publish
CISA17300d0d–0d4
CIRCL202d1d–18d1
ENISA490d0d–0d11

Listing dates: CISA KEV date added; ENISA consolidated dump's dateAdded (which can predate an EU KEV tag); CIRCL first seen, falling back to assertion date. ENISA does not provide a separate EU KEV listing timestamp in this dump.

Risk score breakdown

Scores from locally tracked CVEs present in each catalog. “Unavailable” includes missing local records and missing scores.

SourceEPSS <1%1–10%10–50%≥50%EPSS missingCVSS 9+7–8.94–6.9<4CVSS missing
CISA603964188610615900202810
CIRCL081124154006
ENISA41312311137136015

Scores are not imputed. Counts reflect current 0dayNews CVE metadata, not every record in the upstream catalog.

Coverage timeline

Monthly counts from each source’s available date field. CISA uses its date added; ENISA uses the consolidated dump dateAdded, which is not specific to its EU KEV tag; CIRCL uses first-seen/assertion time.

~/kev-catalogs --coverage-table
1750 CVEs
CVECISACIRCLENISA0dayNews record
CVE-2025-53770●●●Microsoft / SharePoint
CVE-2026-1281●●●Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2026-1340●●●Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2026-48908●●●JoomShaper / SP Page Builder (Joomla extension)
CVE-2026-85102●●●Check Point / Check Point firewall and management products
CVE-2026-88771●●●Citrix / NetScaler ADC, NetScaler Gateway
CVE-2026-88772●●●Citrix / NetScaler ADC, NetScaler Gateway
CVE-2026-94127●●●F5 / BIG-IP APM
CVE-2010-0738●—●Red Hat / JBoss
CVE-2014-8361●●—Realtek / SDK
CVE-2017-0144●—●Microsoft / SMBv1
CVE-2017-10271●—●Oracle / WebLogic Server
CVE-2017-12149●—●Red Hat / JBoss Application Server
CVE-2020-0787●—●Microsoft / Windows
CVE-2020-1472●—●Microsoft / Netlogon
CVE-2021-35394●●—Realtek / Jungle Software Development Kit (SDK)
CVE-2021-44228●●—Apache / Log4j2
CVE-2022-26134●—●Atlassian / Confluence Server and Data Center
CVE-2023-22515●—●Atlassian / Confluence Data Center and Server
CVE-2023-27997●—●Fortinet / FortiOS and FortiProxy SSL-VPN
CVE-2023-28771●●—Zyxel / ZyWALL/USG, USG FLEX, ATP, and VPN series firewalls
CVE-2023-3519●—●Citrix / NetScaler ADC and NetScaler Gateway
CVE-2023-46604●—●Apache / ActiveMQ
CVE-2023-46747●—●F5 / BIG-IP Configuration Utility
CVE-2023-48788●—●Fortinet / FortiClient EMS
CVE-2024-42009●—●Roundcube / Roundcube Webmail (1.5.x through 1.5.7; 1.6.x through 1.6.7)
CVE-2024-55591●—●Fortinet / FortiOS and FortiProxy
CVE-2024-8190●—●Ivanti / Cloud Services Appliance
CVE-2024-8963●—●Ivanti / Cloud Services Appliance (CSA)
CVE-2024-9380●—●Ivanti / Cloud Services Appliance (CSA)
CVE-2025-22457●—●Ivanti / Connect Secure, Policy Secure, and ZTA Gateways
CVE-2025-4427●—●Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2025-4428●—●Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2025-55182●—●Meta / React Server Components
CVE-2025-59718●—●Fortinet / Multiple Products
CVE-2025-6543●—●Citrix / NetScaler ADC and Gateway
CVE-2026-0257●●—Palo Alto Networks / PAN-OS (GlobalProtect portal and gateway)
CVE-2026-102489●—●Zammad GmbH / Zammad
CVE-2026-102490●—●Zammad GmbH / Zammad
CVE-2026-104286●—●Fortinet / FortiMail
CVE-2026-10520●●—Ivanti / Sentry
CVE-2026-12569●—●PTC / Windchill PDMLink and FlexPLM (see body for affected version ranges)
CVE-2026-16232●●—Check Point / SmartConsole
CVE-2026-1731●—●BeyondTrust / Remote Support (RS) and Privileged Remote Access (PRA)
CVE-2026-20079●—●Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
CVE-2026-20245●●—Cisco / Catalyst SD-WAN Manager
CVE-2026-20316●—●Cisco / Cisco Secure Firewall Management Center (FMC)
CVE-2026-20963●—●Microsoft / SharePoint
CVE-2026-21509●●—Microsoft / Office
CVE-2026-25108●●—Soliton Systems K.K / FileZen
CVE-2026-31431●●—Linux / Kernel
CVE-2026-35616●●—Fortinet / FortiClient EMS
CVE-2026-41940●—●WebPros / cPanel & WHM and WP2 (WordPress Squared)
CVE-2026-42897●—●Microsoft / Microsoft
CVE-2026-48907●—●Widget Factory / Joomla Content Editor
CVE-2026-50751●●—Check Point / Security Gateway
CVE-2026-59310●—●Broadcom (VMware) / VMware vCenter Server
CVE-2026-60137●—●WordPress / WordPress Core (6.8.0-6.8.5, 6.9.0-6.9.4, 7.0.0-7.0.1)
CVE-2026-63030●—●WordPress / WordPress Core (6.9 and 7.0 branches per The Hacker News)
CVE-2026-65660●—●Microsoft / SharePoint
CVE-2026-67277●—●MikroTik / RouterOS
CVE-2026-67279●—●MikroTik / RouterOS
CVE-2026-68820●—●Microsoft / Windows (multiple versions)
CVE-2026-72898●—●Metabase / Metabase
CVE-2026-73570●—●Synacor / Zimbra Collaboration Suite (ZCS)
CVE-2026-81578●—●PaperCut Software / PaperCut NG and PaperCut MF (versions 24, 25, 26)
CVE-2026-82078●—●PaperCut Software / PaperCut NG and PaperCut MF (versions 24, 25, 26)
CVE-2026-82329●—●JFrog / Artifactory
CVE-2026-86060●—●MikroTik / RouterOS
CVE-2026-87902●—●WordPress / WordPress Core
CVE-2026-88779●—●Citrix / NetScaler ADC, NetScaler Gateway
CVE-2026-93616●—●Check Point / Security Management Server, Multi-Domain Management Server, Log Server, SmartEvent
CVE-2026-93952●—●Arista / VeloCloud Orchestrator
CVE-2002-0367●——Microsoft / Windows
CVE-2004-0210●——Microsoft / Windows
CVE-2004-1464●——Cisco / IOS
CVE-2005-2773●——Hewlett Packard (HP) / OpenView Network Node Manager
CVE-2006-1547●——Apache / Struts 1
CVE-2006-2492●——Microsoft / Word
CVE-2007-0671●——Microsoft / Office
CVE-2007-3010●——Alcatel / OmniPCX Enterprise
CVE-2007-5659●——Adobe / Acrobat and Reader
CVE-2008-0015●——Microsoft / Windows
CVE-2008-0655●——Adobe / Acrobat and Reader
CVE-2008-2992●——Adobe / Acrobat and Reader
CVE-2008-3431●——Oracle / VirtualBox
CVE-2008-4128●——Cisco / IOS 12.4 mainline (Cisco 871 Integrated Services Router)
CVE-2008-4250●——Microsoft / Windows
CVE-2009-0238●——Microsoft / Office
CVE-2009-0556●——Microsoft / Office
CVE-2009-0557●——Microsoft / Office
CVE-2009-0563●——Microsoft / Office
CVE-2009-0927●——Adobe / Reader and Acrobat
CVE-2009-1123●——Microsoft / Windows
CVE-2009-1151●——phpMyAdmin / phpMyAdmin
CVE-2009-1537●——Microsoft / DirectX
CVE-2009-1862●——Adobe / Acrobat and Reader, Flash Player
CVE-2009-2055●——Cisco / IOS XR
CVE-2009-3129●——Microsoft / Excel
CVE-2009-3459●——Adobe / Acrobat and Reader
CVE-2009-3953●——Adobe / Acrobat and Reader
CVE-2009-3960●——Adobe / BlazeDS
CVE-2009-4324●——Adobe / Acrobat and Reader
CVE-2010-0188●——Adobe / Reader and Acrobat
CVE-2010-0232●——Microsoft / Windows
CVE-2010-0249●——Microsoft / Internet Explorer
CVE-2010-0806●——Microsoft / Internet Explorer
CVE-2010-0840●——Oracle / Java Runtime Environment (JRE)
CVE-2010-1297●——Adobe / Flash Player
CVE-2010-1428●——Red Hat / JBoss
CVE-2010-1871●——Red Hat / JBoss Seam 2
CVE-2010-2568●——Microsoft / Windows
CVE-2010-2572●——Microsoft / PowerPoint
CVE-2010-2861●——Adobe / ColdFusion
CVE-2010-2883●——Adobe / Acrobat and Reader
CVE-2010-3035●——Cisco / IOS XR
CVE-2010-3333●——Microsoft / Office
CVE-2010-3765●——Mozilla / Multiple Products
CVE-2010-3904●——Linux / Kernel
CVE-2010-3962●——Microsoft / Internet Explorer
CVE-2010-4344●——Exim / Exim
CVE-2010-4345●——Exim / Exim
CVE-2010-4398●——Microsoft / Windows
CVE-2010-5326●——SAP / NetWeaver
CVE-2010-5330●——Ubiquiti / AirOS
CVE-2011-0609●——Adobe / Flash Player
CVE-2011-0611●——Adobe / Flash Player
CVE-2011-1823●——Android / Android OS
CVE-2011-1889●——Microsoft / Forefront Threat Management Gateway (TMG)
CVE-2011-2005●——Microsoft / Ancillary Function Driver (afd.sys)
CVE-2011-2462●——Adobe / Reader and Acrobat
CVE-2011-3402●——Microsoft / Windows
CVE-2011-3544●——Oracle / Java SE JDK and JRE
CVE-2011-4085——●—
CVE-2011-4723●——D-Link / DIR-300 Router
CVE-2012-0151●——Microsoft / Windows
CVE-2012-0158●——Microsoft / MSCOMCTL.OCX
CVE-2012-0391●——Apache / Struts 2
CVE-2012-0507●——Oracle / Java SE
CVE-2012-0518●——Oracle / Fusion Middleware
CVE-2012-0754●——Adobe / Flash Player
CVE-2012-0767●——Adobe / Flash Player
CVE-2012-1535●——Adobe / Flash Player
CVE-2012-1710●——Oracle / Fusion Middleware
CVE-2012-1723●——Oracle / Java SE
CVE-2012-1823●——PHP / PHP
CVE-2012-1854●——Microsoft / Visual Basic for Applications (VBA)
CVE-2012-1856●——Microsoft / Office
CVE-2012-1889●——Microsoft / XML Core Services
CVE-2012-2034●——Adobe / Flash Player
CVE-2012-2539●——Microsoft / Word
CVE-2012-3152●——Oracle / Fusion Middleware
CVE-2012-4681●——Oracle / Java SE
CVE-2012-4792●——Microsoft / Internet Explorer
CVE-2012-4969●——Microsoft / Internet Explorer
CVE-2012-5054●——Adobe / Flash Player
CVE-2012-5076●——Oracle / Java SE
CVE-2013-0074●——Microsoft / Silverlight
CVE-2013-0422●——Oracle / Java Runtime Environment (JRE)
CVE-2013-0431●——Oracle / Java Runtime Environment (JRE)
CVE-2013-0625●——Adobe / ColdFusion
CVE-2013-0629●——Adobe / ColdFusion
CVE-2013-0631●——Adobe / ColdFusion
CVE-2013-0632●——Adobe / ColdFusion
CVE-2013-0640●——Adobe / Reader and Acrobat
CVE-2013-0641●——Adobe / Reader
CVE-2013-0643●——Adobe / Flash Player
CVE-2013-0648●——Adobe / Flash Player
CVE-2013-1331●——Microsoft / Office
CVE-2013-1347●——Microsoft / Internet Explorer
CVE-2013-1675●——Mozilla / Firefox
CVE-2013-1690●——Mozilla / Firefox and Thunderbird
CVE-2013-2094●——Linux / Kernel
CVE-2013-2251●——Apache / Struts
CVE-2013-2423●——Oracle / Java Runtime Environment (JRE)
CVE-2013-2465●——Oracle / Java SE
CVE-2013-2551●——Microsoft / Internet Explorer
CVE-2013-2596●——Linux / Kernel
CVE-2013-2597●——Code Aurora / ACDB Audio Driver
CVE-2013-2729●——Adobe / Reader and Acrobat
CVE-2013-3163●——Microsoft / Internet Explorer
CVE-2013-3346●——Adobe / Reader and Acrobat
CVE-2013-3660●——Microsoft / Win32k
CVE-2013-3893●——Microsoft / Internet Explorer
CVE-2013-3896●——Microsoft / Silverlight
CVE-2013-3897●——Microsoft / Internet Explorer
CVE-2013-3900●——Microsoft / WinVerifyTrust function
CVE-2013-3906●——Microsoft / Graphics Component
CVE-2013-3918●——Microsoft / Windows
CVE-2013-3993●——IBM / InfoSphere BigInsights
CVE-2013-4810●——Hewlett Packard (HP) / ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management
CVE-2013-5065●——Microsoft / Windows
CVE-2013-5223●——D-Link / DSL-2760U
CVE-2013-6282●——Linux / Kernel
CVE-2013-7331●——Microsoft / Internet Explorer
CVE-2014-0130●——Rails / Ruby on Rails
CVE-2014-0160●——OpenSSL / OpenSSL
CVE-2014-0196●——Linux / Kernel
CVE-2014-0322●——Microsoft / Internet Explorer
CVE-2014-0496●——Adobe / Reader and Acrobat
CVE-2014-0497●——Adobe / Flash Player
CVE-2014-0502●——Adobe / Flash Player
CVE-2014-0546●——Adobe / Reader and Acrobat
CVE-2014-0780●——InduSoft / Web Studio
CVE-2014-100005●——D-Link / DIR-600 Router
CVE-2014-1761●——Microsoft / Word
CVE-2014-1776●——Microsoft / Internet Explorer
CVE-2014-1812●——Microsoft / Windows
CVE-2014-2120●——Cisco / Adaptive Security Appliance (ASA)
CVE-2014-2817●——Microsoft / Internet Explorer
CVE-2014-3120●——Elastic / Elasticsearch
CVE-2014-3153●——Linux / Kernel
CVE-2014-3931●——Looking Glass / Multi-Router Looking Glass (MRLG)
CVE-2014-4077●——Microsoft / Input Method Editor (IME) Japanese
CVE-2014-4113●——Microsoft / Win32k
CVE-2014-4114●——Microsoft / Windows
CVE-2014-4123●——Microsoft / Internet Explorer
CVE-2014-4148●——Microsoft / Windows
CVE-2014-4404●——Apple / OS X
CVE-2014-6271●——GNU / Bourne-Again Shell (Bash)
CVE-2014-6278●——GNU / GNU Bash
CVE-2014-6287●——Rejetto / HTTP File Server (HFS)
CVE-2014-6324●——Microsoft / Kerberos Key Distribution Center (KDC)
CVE-2014-6332●——Microsoft / Windows
CVE-2014-6352●——Microsoft / Windows
CVE-2014-7169●——GNU / Bourne-Again Shell (Bash)
CVE-2014-8439●——Adobe / Flash Player
CVE-2014-9163●——Adobe / Flash Player
CVE-2015-0016●——Microsoft / Windows
CVE-2015-0071●——Microsoft / Internet Explorer
CVE-2015-0310●——Adobe / Flash Player
CVE-2015-0311●——Adobe / Flash Player
CVE-2015-0313●——Adobe / Flash Player
CVE-2015-0666●——Cisco / Prime Data Center Network Manager (DCNM)
CVE-2015-1130●——Apple / OS X
CVE-2015-1187●——D-Link and TRENDnet / Multiple Devices
CVE-2015-1427●——Elastic / Elasticsearch
CVE-2015-1635●——Microsoft / HTTP.sys
CVE-2015-1641●——Microsoft / Office
CVE-2015-1642●——Microsoft / Office
CVE-2015-1671●——Microsoft / Windows
CVE-2015-1701●——Microsoft / Win32k
CVE-2015-1769●——Microsoft / Windows
CVE-2015-1770●——Microsoft / Office
CVE-2015-2051●——D-Link / DIR-645 Router
CVE-2015-2291●——Intel / Ethernet Diagnostics Driver for Windows
CVE-2015-2360●——Microsoft / Win32k
CVE-2015-2387●——Microsoft / ATM Font Driver
CVE-2015-2419●——Microsoft / Internet Explorer
CVE-2015-2424●——Microsoft / PowerPoint
CVE-2015-2425●——Microsoft / Internet Explorer
CVE-2015-2426●——Microsoft / Windows
CVE-2015-2502●——Microsoft / Internet Explorer
CVE-2015-2545●——Microsoft / Office
CVE-2015-2546●——Microsoft / Win32k
CVE-2015-2590●——Oracle / Java SE
CVE-2015-3035●——TP-Link / Multiple Archer Devices
CVE-2015-3043●——Adobe / Flash Player
CVE-2015-3113●——Adobe / Flash Player
CVE-2015-3246●——Red Hat / Libuser
CVE-2015-4068●——Arcserve / Unified Data Protection (UDP)
CVE-2015-4495●——Mozilla / Firefox
CVE-2015-4852●——Oracle / WebLogic Server
CVE-2015-4902●——Oracle / Java SE
CVE-2015-5119●——Adobe / Flash Player
CVE-2015-5122●——Adobe / Flash Player
CVE-2015-5123●——Adobe / Flash Player
CVE-2015-5287●——Red Hat / Automatic Bug Reporting Tool
CVE-2015-5317●——Jenkins / Jenkins User Interface (UI)
CVE-2015-6175●——Microsoft / Windows
CVE-2015-7450●——IBM / WebSphere Application Server and Server Hypervisor Edition
CVE-2015-7501——●—
CVE-2015-7645●——Adobe / Flash Player
CVE-2015-7755●——Juniper / ScreenOS
CVE-2015-8651●——Adobe / Flash Player
CVE-2016-0034●——Microsoft / Silverlight
CVE-2016-0040●——Microsoft / Windows
CVE-2016-0099●——Microsoft / Windows
CVE-2016-0151●——Microsoft / Client-Server Run-time Subsystem (CSRSS)
CVE-2016-0162●——Microsoft / Internet Explorer
CVE-2016-0165●——Microsoft / Win32k
CVE-2016-0167●——Microsoft / Win32k
CVE-2016-0185●——Microsoft / Windows
CVE-2016-0189●——Microsoft / Internet Explorer
CVE-2016-0752●——Rails / Ruby on Rails
CVE-2016-0984●——Adobe / Flash Player and AIR
CVE-2016-10033●——PHP / PHPMailer
CVE-2016-1010●——Adobe / Flash Player and AIR
CVE-2016-10174●——NETGEAR / WNR2000v5 Router
CVE-2016-1019●——Adobe / Flash Player
CVE-2016-11021●——D-Link / DCS-930L Devices
CVE-2016-1555●——NETGEAR / Wireless Access Point (WAP) Devices
CVE-2016-1646●——Google / Chromium V8
CVE-2016-20017●——D-Link / DSL-2750B Devices
CVE-2016-2386●——SAP / NetWeaver
CVE-2016-2388●——SAP / NetWeaver
CVE-2016-3088●——Apache / ActiveMQ
CVE-2016-3235●——Microsoft / Office
CVE-2016-3298●——Microsoft / Internet Explorer
CVE-2016-3309●——Microsoft / Windows

Showing up to 300 combined catalog entries. Download the comparison JSON for the complete dataset.

Sources: CISA KEV; ENISA EUVD; CIRCL KEV. Informational comparison; catalog membership and risk scores retain source attribution.