The KEV catalog answers a narrower question than most vulnerability feeds, and the narrowness is the point.
What listing means
A CVE reaches the catalog when CISA has evidence that someone is actively exploiting it. Listing carries a remediation deadline for US federal civilian agencies under BOD 22-01, which is the reason the catalog exists: it is an operational instrument first and a public dataset second.
What it does not mean
It is not a severity ranking. A vulnerability with a very high CVSS score that nobody has bothered to exploit will not be listed; a mediocre-scoring flaw in something widely deployed may be listed within days.
Absence is not evidence of safety. The catalog reflects what CISA can confirm and choose to publish, which undercounts by construction — particularly for exploitation seen only by private incident responders.
Reading the cadence
Because listing is driven by evidence rather than disclosure, the rate of additions is a rough proxy for exploitation tempo — but it is also an artefact of CISA's own capacity and process changes. Both readings are in the data; neither is the whole story.