THE HUB · TRACKER · PUBLIC
CVE
What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.
7 sources99,705 claimsjoined on cvepublished 4d ago
Its sources
| Source | What it adds | Claims |
|---|---|---|
| CISA Known Exploited Vulnerabilitieszetlyn/cve-kev | The only source that says a vulnerability is being exploited right now. | 1,733 |
| Red Hatzetlyn/cve-redhat | Its own severity, and the packages it tracks a vulnerability in. | 22,765 |
| NVDzetlyn/cve-nvd | The CVSS baseline, and an anchor for CVEs the other members never reach. | 19,646 |
| GitHub advisorieszetlyn/cve-ghsa | The ecosystem packages no distribution ships. | 6,155 |
| Metasploit exploit moduleszetlyn/cve-metasploit | Whether a module exists for the tool an attacker actually runs. | 2,698 |
| Exploit-DBzetlyn/cve-exploitdb | Whether working code exists at all, which is a different question from how severe it is. | 46,698 |
| Write-upszetlyn/cve-writeups | The prose that explains a vulnerability after the advisories have stopped. | 10 |
What it promises
| fresh within | 24h |
| covers | Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. |
| excludes | Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate. |
What it compares
Each of these is held against every source that says it; a difference beyond what is allowed is a conflict. Everything else is shown side by side.
| Property | Compared |
|---|---|
cvss | exactly |
exploited | on the scale yes > no |
severity | on the scale critical > high > medium > low > unknown |
Versions
| Version | Published | Claims | |
|---|---|---|---|
5bda63e4b976 | 2026-09-29 · 4d ago | latest | |
627328feb037 | 2026-09-29 · 4d ago | ||
f5db1762ca45 | 2026-09-29 · 5d ago |
A subscriber holds one of these and is told of the next; an update fetches only what changed between them.
Use it
on your own machine
$ zetlyn tracker subscribe zetlyn/cve # the statement, and every source it names
Version 5bda63e4b97629a5ce406ca4 · signed ed25519:af9ffd7b7435cdad9724db5feea1a6f55ff38ea13b860ab62260f34f59a131ab · manifest.json
Its statement
name: zetlyn/cve
title: CVE
about: What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.
sources:
- source: zetlyn/cve-kev
priority: primary
why: The only source that says a vulnerability is being exploited right now.
- source: zetlyn/cve-redhat
priority: high
why: Its own severity, and the packages it tracks a vulnerability in.
- source: zetlyn/cve-nvd
priority: high
why: The CVSS baseline, and an anchor for CVEs the other members never reach.
- source: zetlyn/cve-ghsa
priority: high
why: The ecosystem packages no distribution ships.
- source: zetlyn/cve-metasploit
why: Whether a module exists for the tool an attacker actually runs.
- source: zetlyn/cve-exploitdb
why: Whether working code exists at all, which is a different question from how severe it is.
- source: zetlyn/cve-writeups
why: The prose that explains a vulnerability after the advisories have stopped.
identified_by:
- cve
# What a vulnerability is to something else, where a claim states both: NVD names the CPEs of what
# it affects once it has analysed a CVE. Where it has not, the CNA's own words are offered to a
# person to confirm, and a match they confirm is theirs, signed, in matches.jsonl.
relations:
- name: affects
to: cpe
as: product
suggest_from: [vendor, product]
about: The products it affects, as vendor/product.
- name: made_by
to: cpe
as: vendor
suggest_from: [vendor]
about: The vendors whose products it affects.
align:
# The same number from every source that scores one: NVD, Red Hat and GitHub all give a CVSS
# base score, and a difference between them is a difference of judgement.
cvss: {}
# Exploited means somebody is using it, and one source says that: CISA, by putting the row in
# its catalogue. Metasploit's rank and Exploit-DB's verified flag are about the code, not about
# the attack — a module that nobody has fired and an unverified proof of concept are both code
# that exists. That question is already answered, by a claim of kind `exploit`, and 23,444
# things carry one. Reading the two as one property makes `exploited=yes` useless for triage.
exploited:
scale:
- "yes"
- "no"
severity:
scale:
- critical
- high
- medium
- low
- unknown
zetlyn/cve-ghsa:
critical: critical
high: high
low: low
moderate: medium
zetlyn/cve-redhat:
critical: critical
important: high
low: low
moderate: medium
view:
columns:
- kind
- severity
- cvss
- known
facets:
- kind
- source
- severity
- exploited
sort: known desc
named:
- name: exploited-and-severe
title: Exploited, and severe
where: exploited=yes and severity>=high
exploit:
adopt: zetlyn/cve-exploitdb:verified
promise:
fresh_within: 24h
covers: Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE.
excludes: Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
