- all Every CVE in CISA KEV
- 2025 Red Hat, from 2025-01-01
- 2026 NVD, from 2026-08-01
- 2026 GitHub advisories, from 2026-09-01
- all Every Exploit-DB thing naming a CVE
- all Every Metasploit module naming a CVE
Two are running here. Yours is one file away.
A tracker is a list of sources, what joins them, and what it promises. It is a small file, and the two below are only the ones this workspace happens to hold. Both answer at hub.zetlyn.com, so you can ask one before you take it. Every number here is one the tracker itself will show you, through the same calls a reader uses.
Each one names its thing: the kind of thing it holds one of per thing. Below, a security flaw and an AI model. Those are not words Zetlyn knows — there are two of those, a source and a tracker — they are what these two happen to be about, and yours will be about something else.
ZETLYN/CVE · SUBJECT: A SECURITY FLAW
What each publisher says
about one security flaw.
A thing here is one flaw in one piece of software, named by the number
the whole industry already uses for it: a CVE number, like CVE-2021-44228. Seven
sources publish about those, each knowing one part.
THE SEVEN MEMBERS, AND WHY EACH IS THERE · COUNTED 2026-09-27
zetlyn/cve-kevThe only source that says a vulnerability is being exploited right now. 1,728 claims, asked hourlyzetlyn/cve-redhatIts own severity, and the packages it tracks a vulnerability in. 22,388 claimszetlyn/cve-nvdThe CVSS baseline, and an anchor for CVEs the other sources never reach. 14,738 claimszetlyn/cve-ghsaThe ecosystem packages no distribution ships. 3,813 claimszetlyn/cve-metasploitWhether a module exists for the tool an attacker actually runs. 2,698 claimszetlyn/cve-exploitdbWhether working code exists at all, which is a different question from how severe it is. 46,688 claimszetlyn/cve-writeupsThe prose that explains a vulnerability after the advisories have stopped. 10 claims
A count is a measurement and it has a date on it. These came out of the running tracker through the same calls a reader can make, and they move every time a source publishes.
- — Vulnerabilities with no CVE number
- — Ubuntu 20 claims per 30s
Ubuntu was measured and dropped, not assumed away: its list endpoint answers twenty claims in between twenty-three and forty seconds, which is about thirty-four hours for one pass. It is a source the day that changes.
Promise: every source has finished an update within 24 hours, or the front page says the promise does not hold and names the source that is behind.
1,685 things are
being exploited right now.
Twenty-nine of those are also rated high or critical by a publisher who ships the package. No source answers that on its own. CISA has never heard of the severity and Red Hat has never heard of the exploitation, and putting the two together in one place is what a tracker is for.
ZETLYN/LOCAL-MODELS · SUBJECT: A LANGUAGE MODEL
Which AI models will run
on the machine you have.
A second topic, to show that the shape is not about security. Here a thing is one AI language model: the kind somebody downloads and runs on their own computer instead of sending their text to somebody else's. Two sources publish about them and neither holds what the other does.
TWO MEMBERS, 2,717 THINGS · COUNTED 2026-09-27
zetlyn/models-hfThe model itself: who made it, what licence it carries, what it is for, how many people fetch it. 1,496 claimszetlyn/models-ggufThe shrunk-down copies other people have made of it. A model in its original form needs a machine most people do not have; a shrunk copy is what decides whether it runs on the one they do. 10,271 claims
The join is the model's name on Hugging Face, which is where both sources already put it. Without that there would be no tracker here, only two lists.
This one is not finished, and it is here because the reason is worth reading. The things are the 2,788 models the shrunk copies name, and without a Hugging Face token the update is throttled off after roughly six to seven hundred of them. Measured twice on 26 September: 734, then 578, both ended by the source after the retries ran out. The tracker says partial on its own face and the promise it makes is the one it keeps.
It has no cadence of its own. It asks about the models the other source names, so it runs when that one finds something and not on a clock.
COMPOSE YOUR OWN
Sources, a key,
and a sentence each.
Which sources are in it, what number joins them, and what each one contributes that the others do not. The sentence is not documentation: the format requires it, the form that adds a source requires it, and a source nobody can justify in a sentence is one somebody added and nobody removed.
Where two sources use different words for the same thing, a scale says which words mean which. The raw word is kept and shown beside the translation, so a reader can always see what the publisher actually wrote.
name: zetlyn/cve
title: CVE
sources:
- source: zetlyn/cve-kev
priority: primary
why: The only source that says a vulnerability is being
exploited right now.
- source: zetlyn/cve-exploitdb
why: Whether working code exists at all, which is a
different question from how severe it is.
identified_by:
- cve
align:
# The same number from every source that scores one, and a
# difference between them is a difference of judgement.
cvss: {}
severity:
scale: [critical, high, medium, low, unknown]
zetlyn/cve-redhat:
important: high
moderate: medium
zetlyn/cve-ghsa:
moderate: medium
promise:
fresh_within: 24h
covers: Every CVE in CISA KEV. Red Hat since 2025-01-01…
excludes: Vulnerabilities with no CVE number…
BEFORE PROMISING ONE TO OTHER PEOPLE
Five questions,
and all five have to answer yes.
THE FILTER
a shared keySeveral bodies publish about the same thing and at least one states the other's identifier. Where they do not, a tracker is a download with extra stepspermissionThe sources may be fetched, indexed and republished. Checked per source before a line of codeit changesA subject that is finished has no currency to sella buyerSomebody already pays for this, to a consultancy, a vendor or an analystwhat changedEach source can be asked, by a watermark, a modification date or a commit. A source that can only be read whole is affordable at a thousand claims and is not at four hundred thousand
Four of the five drop away for a topic you keep to yourself: nobody needs permission to index their own documents and nobody has to be sold anything. The first one does not. Measure the key in the real data before promising the topic. A sanctions tracker was proposed on the belief that the EU, OFSI and OFAC lists share one; the measurement found 86 of 6,241 EU things carrying a UN reference, 1.4%, against zero on the OFAC list. A week, and the right answer.
ZETLYN