CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 2h agofresh within 24h
66,595things
9,206named by two sources or more
1,122conflicts
7sources

Only one source knows: Exploit-DB 23133 · GitHub advisories 35 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12706 · Red Hat 19827 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

Try:mikrotikknown_ransomware_campaign_use=UnknownCVE-2026-67279kernel

EverythingExploited, and severearticle 10exploit 49396vulnerability 50709

Things

25 things, from 100,115 claims
ThingKindSeverityCvssDate
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
CVE-2026-88779 · CISA Known Exploited Vulnerabilities, NVD, GitHub advisories
vulnerability 3 high—2026-10-04
perl-yaml: perl-yaml: Arbitrary destructor method execution via crafted YAML document
CVE-2017-20285 · Red Hat, GitHub advisories, NVD
vulnerability 3 high / unknown7.42026-10-05
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.
CVE-2026-63277 · NVD
vulnerability 1 ——2026-10-05
A vulnerability was detected in itsourcecode Online Admission System 1.0. This affects an unknown...
CVE-2026-105185 · GitHub advisories, NVD
vulnerability 2 medium7.32026-10-05
Generic Payload Handler
· Metasploit exploit modules
exploit 1 ——2026-10-05
Ecava_ntegraXor IGX_16.0.701.10 - RCE
· Exploit-DB
exploit 1 ——2026-10-01
console: Authenticated SSRF via user-controlled towerHost in /ansibletower handler
CVE-2026-66804 · Red Hat, Write-ups
vulnerability 1 article 1 high7.72026-08-13
Windows Exploitation Techniques: Dangling COM Object Registrations
CVE-2026-50343 · Write-ups
article 1 ——2026-09-21
Zammad GmbH Zammad Session Fixation Vulnerability
CVE-2026-102489 · CISA Known Exploited Vulnerabilities, NVD, GitHub advisories
vulnerability 3 critical9.82026-09-30
perl-yaml: perl-yaml: Arbitrary code execution via unrestricted package variable assignment
CVE-2019-25777 · Red Hat, GitHub advisories, NVD
vulnerability 3 high / unknown8.12026-10-05
URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not cover every place a document can supply a URL. XForms instance data and the Calc csv and sql data providers still reached the expansion. In fixed versions these places refuse URLs with internal schemes when the URL comes from the document.
CVE-2026-63270 · NVD
vulnerability 1 ——2026-10-05
A vulnerability has been found in itsourcecode Online Admission System 1.0. Affected is an...
CVE-2026-105187 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-05
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
CVE-2026-83548 · CISA Known Exploited Vulnerabilities, Metasploit exploit modules
vulnerability 1 exploit 1 ——2026-09-01
SonicWall SMA1000 Appliances OS Command Injection Vulnerability
CVE-2026-83549 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules
vulnerability 2 exploit 1 —7.82026-09-01
WordPress Core Remote File Inclusion Vulnerability
CVE-2026-87902 · CISA Known Exploited Vulnerabilities, NVD, Exploit-DB
vulnerability 2 exploit 1 —8.12026-09-22
Testing race conditions with memory access tracing and stack-based delay injection
· Write-ups
article 1 ——2026-09-08
Zammad GmbH Zammad Improper Privilege Management Vulnerability
CVE-2026-102490 · CISA Known Exploited Vulnerabilities, NVD, GitHub advisories
vulnerability 3 critical9.82026-09-30
cockpit: Cockpit CMS: Sensitive token disclosure via disabled TLS certificate verification
CVE-2026-105217 · Red Hat, NVD, GitHub advisories
vulnerability 3 low3.1 / 3.72026-10-04
LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer. A linked media file could be an HLS playlist that made GStreamer read the local files and remote URLs it listed while the document loaded, and their contents could end up in the document. In fixed versions LibreOffice does not follow playlists that name further resources, and linked media is under link update control.
CVE-2026-63269 · NVD
vulnerability 1 ——2026-10-05
A security flaw has been discovered in osCommerce osCommerce2 up to 2.3.4.1. This vulnerability...
CVE-2026-105226 · GitHub advisories, NVD
vulnerability 2 low4.72026-10-05
SPIP Autosave Session Unauthenticated RCE
· Metasploit exploit modules
exploit 1 ——2026-08-30
TigerGraph_Community_Edition 4.2.4 - arbitrary file write
· Exploit-DB
exploit 1 ——2026-10-01
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
CVE-2025-54957 · Write-ups
article 2 ——2026-01-14
Fortinet FortiMail Path Traversal Vulnerability
CVE-2026-104286 · CISA Known Exploited Vulnerabilities, NVD, GitHub advisories
vulnerability 3 critical9.82026-10-01
ImageMagick: ImageMagick: Security policy bypass via alternate XML DOCTYPE declaration
CVE-2026-105083 · Red Hat, NVD, GitHub advisories
vulnerability 3 low3.92026-10-03
← PreviousPage 1 of 4005Next →

Facets

Kind 100115 of 100115 claims

exploit49396

Severity 26762 of 100115 claims

high7330
medium13595
low3948

Exploited 1734 of 100115 claims

yes1734

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1734

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22768

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19864

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing6343

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10