THE Known Exploited Vulnerabilities (KEV) Catalog, maintained by the Cybersecurity and Infrastructure Security Agency (CISA), serves as a resource for cybersecurity professionals to address vulnerabilities that have been actively exploited. Organizations are encouraged to integrate the KEV catalog into their vulnerability management frameworks. The catalog is available in multiple formats, including CSV and JSON.
The page highlights a specific vulnerability, CVE-2015-3246, affecting Red Hat's libuser, which can lead to denial of service or privilege escalation. Users are advised to apply mitigations and adhere to CISA's guidelines for risk management.