THE HUB · TRACKER · PUBLIC

CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

7 sources99,705 claimsjoined on cvepublished 4d ago

Its sources

SourceWhat it addsClaims
CISA Known Exploited Vulnerabilitieszetlyn/cve-kevThe only source that says a vulnerability is being exploited right now.1,733
Red Hatzetlyn/cve-redhatIts own severity, and the packages it tracks a vulnerability in.22,765
NVDzetlyn/cve-nvdThe CVSS baseline, and an anchor for CVEs the other members never reach.19,646
GitHub advisorieszetlyn/cve-ghsaThe ecosystem packages no distribution ships.6,155
Metasploit exploit moduleszetlyn/cve-metasploitWhether a module exists for the tool an attacker actually runs.2,698
Exploit-DBzetlyn/cve-exploitdbWhether working code exists at all, which is a different question from how severe it is.46,698
Write-upszetlyn/cve-writeupsThe prose that explains a vulnerability after the advisories have stopped.10

What it promises

fresh within24h
coversEvery CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE.
excludesVulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.

What it compares

Each of these is held against every source that says it; a difference beyond what is allowed is a conflict. Everything else is shown side by side.

PropertyCompared
cvssexactly
exploitedon the scale yes > no
severityon the scale critical > high > medium > low > unknown

Versions

VersionPublishedClaims
5bda63e4b9762026-09-29 · 4d agolatest
627328feb0372026-09-29 · 4d ago
f5db1762ca452026-09-29 · 5d ago

A subscriber holds one of these and is told of the next; an update fetches only what changed between them.

Use it

on your own machine
$ zetlyn tracker subscribe zetlyn/cve
# the statement, and every source it names

Version 5bda63e4b97629a5ce406ca4 · signed ed25519:af9ffd7b7435cdad9724db5feea1a6f55ff38ea13b860ab62260f34f59a131ab · manifest.json

Its statement
name: zetlyn/cve
title: CVE
about: What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.
sources:
- source: zetlyn/cve-kev
  priority: primary
  why: The only source that says a vulnerability is being exploited right now.
- source: zetlyn/cve-redhat
  priority: high
  why: Its own severity, and the packages it tracks a vulnerability in.
- source: zetlyn/cve-nvd
  priority: high
  why: The CVSS baseline, and an anchor for CVEs the other members never reach.
- source: zetlyn/cve-ghsa
  priority: high
  why: The ecosystem packages no distribution ships.
- source: zetlyn/cve-metasploit
  why: Whether a module exists for the tool an attacker actually runs.
- source: zetlyn/cve-exploitdb
  why: Whether working code exists at all, which is a different question from how severe it is.
- source: zetlyn/cve-writeups
  why: The prose that explains a vulnerability after the advisories have stopped.
identified_by:
- cve
# What a vulnerability is to something else, where a claim states both: NVD names the CPEs of what
# it affects once it has analysed a CVE. Where it has not, the CNA's own words are offered to a
# person to confirm, and a match they confirm is theirs, signed, in matches.jsonl.
relations:
- name: affects
  to: cpe
  as: product
  suggest_from: [vendor, product]
  about: The products it affects, as vendor/product.
- name: made_by
  to: cpe
  as: vendor
  suggest_from: [vendor]
  about: The vendors whose products it affects.
align:
  # The same number from every source that scores one: NVD, Red Hat and GitHub all give a CVSS
  # base score, and a difference between them is a difference of judgement.
  cvss: {}
  # Exploited means somebody is using it, and one source says that: CISA, by putting the row in
  # its catalogue. Metasploit's rank and Exploit-DB's verified flag are about the code, not about
  # the attack — a module that nobody has fired and an unverified proof of concept are both code
  # that exists. That question is already answered, by a claim of kind `exploit`, and 23,444
  # things carry one. Reading the two as one property makes `exploited=yes` useless for triage.
  exploited:
    scale:
    - "yes"
    - "no"
  severity:
    scale:
    - critical
    - high
    - medium
    - low
    - unknown
    zetlyn/cve-ghsa:
      critical: critical
      high: high
      low: low
      moderate: medium
    zetlyn/cve-redhat:
      critical: critical
      important: high
      low: low
      moderate: medium
view:
  columns:
  - kind
  - severity
  - cvss
  - known
  facets:
  - kind
  - source
  - severity
  - exploited
  sort: known desc
  named:
  - name: exploited-and-severe
    title: Exploited, and severe
    where: exploited=yes and severity>=high
  exploit:
    adopt: zetlyn/cve-exploitdb:verified
promise:
  fresh_within: 24h
  covers: Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE.
  excludes: Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.