You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Software distribution method or binary type: CISA KEV JSON feed — cross-references CVE IDs found in scan findings against the CISA Known Exploited Vulnerabilities catalog (known_exploited_vulnerabilities.json)
Popularity of distribution method: The CISA KEV catalog is the authoritative, US-government-maintained list of CVEs actively exploited in the wild. As of mid-2025 it contains 1,200+ entries. Under CISA Binding Operational Directive 22-01, all US federal civilian agencies are required to remediate KEV-listed vulnerabilities on defined timelines. The catalog is freely available with no authentication and is updated multiple times per week. It is the single most actionable prioritization signal for vulnerability triage in any organization.
Any critical, emergent vulnerability associated with software from the distribution method: By definition, every entry is actively exploited. Representative entries include CVE-2021-44228 (Log4Shell), CVE-2022-22965 (Spring4Shell), CVE-2023-34362 (MOVEit SQL injection), CVE-2024-6387 (OpenSSH regreSSHion), CVE-2024-3400 (PAN-OS command injection). Current scalibr enrichers surface vulnerabilities but provide no signal distinguishing theoretical risk from confirmed active exploitation — KEV integration fills this gap directly.
known_exploited_vulnerabilities.json)cveID,vendorProject,product,vulnerabilityName,dateAdded,dueDate,requiredActionfields