CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 10h agofresh within 24h
66,378things
9,017named by two sources or more
1,118conflicts
7sources

Only one source knows: Exploit-DB 23133 · GitHub advisories 35 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12677 · Red Hat 19828 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

Try:mikrotikknown_ransomware_campaign_use=UnknownCVE-2026-67279kernel

EverythingExploited, and severearticle 10exploit 49396vulnerability 50299

Things

25 things, from 99,705 claims
ThingKindSeverityCvssDate
Zammad GmbH Zammad Session Fixation Vulnerability
CVE-2026-102489 · CISA Known Exploited Vulnerabilities, NVD, GitHub advisories
vulnerability 3 critical9.82026-09-30
ImageMagick: ImageMagick: Security policy bypass via alternate XML DOCTYPE declaration
CVE-2026-105083 · Red Hat, NVD, GitHub advisories
vulnerability 3 low3.92026-10-03
A weakness has been identified in Omega Solution CoinEx Crypto 2025. Affected by this vulnerability is an unknown functionality of the file /user/ticket of the component Ticket Attachment Upload. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-105099 · NVD
vulnerability 1 —3.52026-10-04
W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that...
CVE-2026-105123 · GitHub advisories, NVD
vulnerability 2 high8.82026-10-04
Generic Payload Handler
· Metasploit exploit modules
exploit 1 ——2026-10-04
Ecava_ntegraXor IGX_16.0.701.10 - RCE
· Exploit-DB
exploit 1 ——2026-10-01
console: Authenticated SSRF via user-controlled towerHost in /ansibletower handler
CVE-2026-66804 · Red Hat, Write-ups
vulnerability 1 article 1 high7.72026-08-13
Windows Exploitation Techniques: Dangling COM Object Registrations
CVE-2026-50343 · Write-ups
article 1 ——2026-09-21
Zammad GmbH Zammad Improper Privilege Management Vulnerability
CVE-2026-102490 · CISA Known Exploited Vulnerabilities, NVD, GitHub advisories
vulnerability 3 critical9.82026-09-30
org.apache.directory.api/api-asn1-ber: Apache Directory LDAP API: Denial of Service via excessive memory allocation
CVE-2026-102731 · Red Hat, NVD, GitHub advisories
vulnerability 3 high / unknown7.52026-10-02
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
CVE-2026-88779 · NVD
vulnerability 1 ——2026-10-04
LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated...
CVE-2026-105125 · GitHub advisories, NVD
vulnerability 2 medium3.72026-10-04
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
CVE-2026-83548 · CISA Known Exploited Vulnerabilities, Metasploit exploit modules
vulnerability 1 exploit 1 ——2026-09-01
SonicWall SMA1000 Appliances OS Command Injection Vulnerability
CVE-2026-83549 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules
vulnerability 2 exploit 1 —7.82026-09-01
WordPress Core Remote File Inclusion Vulnerability
CVE-2026-87902 · CISA Known Exploited Vulnerabilities, NVD, Exploit-DB
vulnerability 2 exploit 1 —8.12026-09-22
Testing race conditions with memory access tracing and stack-based delay injection
· Write-ups
article 1 ——2026-09-08
Fortinet FortiMail Path Traversal Vulnerability
CVE-2026-104286 · CISA Known Exploited Vulnerabilities, NVD, GitHub advisories
vulnerability 3 critical9.82026-10-01
org.apache.directory.api/api-ldap-codec-core: Apache Directory LDAP API: Denial of Service via deeply nested search filter
CVE-2026-103552 · Red Hat, NVD, GitHub advisories
vulnerability 3 high7.3 / 7.52026-10-02
A security flaw has been discovered in Omega Solution CoinEx Crypto 2025. Affected is an unknown function of the file /ticket/customer of the component Support Ticket API. The manipulation of the argument status/page/count results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-105098 · NVD
vulnerability 1 —4.32026-10-04
LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows...
CVE-2026-105129 · GitHub advisories, NVD
vulnerability 2 high6.52026-10-04
SPIP Autosave Session Unauthenticated RCE
· Metasploit exploit modules
exploit 1 ——2026-08-30
TigerGraph_Community_Edition 4.2.4 - arbitrary file write
· Exploit-DB
exploit 1 ——2026-10-01
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
CVE-2025-54957 · Write-ups
article 2 ——2026-01-14
Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
CVE-2026-76504 · CISA Known Exploited Vulnerabilities, NVD, GitHub advisories
vulnerability 3 critical9.82026-09-30
org.apache.directory.api/api-ldap-client-api: Apache Directory LDAP API: Remote code execution via untrusted Java object deserialization
CVE-2026-103877 · Red Hat, NVD, GitHub advisories
vulnerability 3 high / unknown8.12026-10-02
← PreviousPage 1 of 3989Next →

Facets

Kind 99705 of 99705 claims

exploit49396

Severity 26571 of 99705 claims

high7305
medium13523
low3917

Exploited 1733 of 99705 claims

yes1733

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1733

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22765

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19646

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing6155

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10