Skip to main content

Live catalogue

Every CISA Known Exploited Vulnerability

The complete KEV catalogue — not just the industrial slice. Filter by OT relevance, search any vendor, product or CVE, expand a row for CVSS from NVD and jump straight to the advisory.

Catalogue

CISA version loading

OT relevant

Kept by the industrial filter

Enterprise IT

Excluded from the OT view

Matching filter

Page 1 of 1

Loading the KEV catalogue…

Page 1 of 1

Filter audit

What the OT filter keeps and what it drops

The classifier only reads the vendor, product and vulnerability title — never the description, which mentions industrial words in unrelated IT advisories. Whole-word matching stops 'rtu' matching 'virtual'.

Why should I care?

Mainstream IT products such as Joomla, Citrix, Fortinet, Microsoft Exchange and Chrome are excluded by design: they dominate the catalogue and would bury the handful of entries that touch a controller. They still matter on the business network — this filter is about which entries belong on an OT triage list, not which entries are unimportant.

Largest excluded vendors ( entries total)

Vendors kept as OT relevant ( entries total)

How an entry qualifies as OT

  • Unambiguous product token in the vendor or product name: scada, codesys, simatic, modbus, profinet, openplc
  • A known industrial vendor — Siemens, Rockwell, ABB, Schneider Electric, Unitronics, Hitachi Energy and around fifty more
  • A whole-word industrial keyword in the product or title: PLC, HMI, RTU, DNP3, IEC 61850, building automation, safety instrumented

Deliberate edge cases

  • Cisco IOS is kept for one entry only — a PROFINET parsing flaw that reaches industrial traffic
  • IP camera and physical-security vendors (Hikvision, Dahua) are kept: they usually sit on the same plant network
  • The description field is never matched, so an IT advisory that merely mentions 'industrial customers' stays excluded
  • Nothing is dropped silently — switch scope to 'Excluded' and search to confirm any product's verdict