CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 10h agofresh within 24h
66,378things
9,017named by two sources or more
1,118conflicts
7sources

Only one source knows: Exploit-DB 23133 · GitHub advisories 35 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12677 · Red Hat 19828 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

EverythingExploited, and severearticle 10exploit 49396vulnerability 50299

Found

25 things, from 15,973 claims
ThingKindSeverityCvssDate
Linux Kernel Integer Overflow Vulnerability
CVE-2013-2596 · CISA Known Exploited Vulnerabilities · matched kernel
vulnerability 1 ——2022-09-15
kernel: Linux kernel: ublk race condition causes kernel crash
CVE-2025-37906 · Red Hat · matched kernel
vulnerability 1 medium4.12025-05-20
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix deadlock in complain-mode change_hat The use of change_hat when in complain mode can cause a deadlock when the hat doesn't exist and a new learning profile is created for the missing profile. This is because change_hat() has taken the lock to search the hat list and creating the new learning profile needs to take the lock to add it to the list. From the bug report: Originally found in 7.0.0 in LTS ubuntu 26.04 with pam_apparmor + su in complain mode set to change hats. Then verified in newest available vanilla kernel I've compiled to see if still present: 7.2-rc7 vanilla -> affected checked also some other kernels: 6.18.44 vanilla -> affected 6.12.95 with debian patches -> unaffected On systems without bug (for example 6.12.95 debian) it just prints: aa_change_hat rc=0 On systems with bug, the executable always hangs, prints nothing and becomes unkillable. (And once stuck this way, it will cause any further hat changes to also cause the changing process to get stuck) Then in syslog you can find hint about cause: kernel: INFO: task hat:3409 blocked for more than 483 seconds. kernel: Not tainted 7.2.0-rc7 #1 kernel: "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. kernel: task:hat state:D stack:0 pid:3409 tgid:3409 ppid:2605 task_flags:0x400000 flags:0x00080800 kernel: Call Trace: kernel: <TASK> kernel: __schedule+0x48f/0xfe0 kernel: schedule+0x27/0xa0 kernel: schedule_preempt_disabled+0x15/0x30 kernel: __mutex_lock.constprop.0+0x569/0xa10 kernel: aa_new_learning_profile+0x15f/0x210 kernel: build_change_hat+0x19f/0x3b0 kernel: change_hat.isra.0+0x5dd/0xd60 kernel: aa_change_hat+0x2f3/0x710 kernel: aa_setprocattr_changehat+0x121/0x1f0 kernel: do_setattr+0x28c/0x340 kernel: apparmor_setselfattr+0x20/0x50 kernel: security_setselfattr+0xf6/0x110 kernel: __x64_sys_lsm_set_self_attr+0x53/0x90 kernel: do_syscall_64+0xdd/0x5e0 kernel: ? __mod_memcg_lruvec_state+0xfd/0x260 kernel: ? lruvec_stat_mod_folio+0x8d/0xd0 kernel: ? __folio_mod_stat+0x2d/0x90 kernel: ? map_anon_folio_pte_nopf+0xd1/0x1f0 kernel: ? do_anonymous_page+0x184/0xa10 kernel: ? __handle_mm_fault+0x805/0x870 kernel: ? count_memcg_events+0xef/0x230 kernel: ? handle_mm_fault+0x1f0/0x2f0 kernel: ? do_user_addr_fault+0x2bb/0x7b0 kernel: ? do_syscall_64+0x94/0x5e0 kernel: ? exc_page_fault+0x75/0x160 kernel: entry_SYSCALL_64_after_hwframe+0x76/0x7e kernel: RIP: 0033:0x7f815e134c8d kernel: RSP: 002b:00007fff6df94ea8 EFLAGS: 00000246 ORIG_RAX: 00000000000001cc kernel: RAX: ffffffffffffffda RBX: 0000556d8c81d040 RCX: 00007f815e134c8d kernel: RDX: 0000000000000046 RSI: 0000556d8c81d040 RDI: 0000000000000064 kernel: RBP: 00007fff6df94ef0 R08: 00007f815e212ac8 R09: 000000000000000c kernel: R10: 0000000000000000 R11: 0000000000000246 R12: 0000556d8c81d010 kernel: R13: 0000000000000026 R14: 0000000000000046 R15: 0000000000000064 kernel: </TASK> kernel: INFO: task hat:3409 is blocked on a mutex likely owned by task hat:3409. To fix the issue, lift the locking out of the core of aa_new_learning_profile(), introduce a wrapper function that takes the lock where needed, and have build_change_hat() call the core function that no longer takes the lock. In addition fix 4 other issues introduced by commit 32e92764d6f8d ("apparmor: grab ns lock and refresh when looking up changehat child profiles") - aa_get_profile_rcu() was replaced-by: aa_get_profile without the accompanying rcu_dereference_protected() - an extra aa_get_label(label) was introduced at the start of change_hat() without an accompanying aa_put_label() causing a reference count leak. - a reference count leak was introduced in the label_is_stale(label) case, where the newest profile would be leaked instead of the label passed to the function. - a potential UAF when the lookup walks up the tree with new_ns != ns the new label refere ---truncated---
CVE-2026-90179 · NVD · matched kernel
vulnerability 1 ——2026-09-17
In the Linux kernel, the following vulnerability has been resolved: drm/xe: don't WARN on kernel...
CVE-2026-93248 · GitHub advisories, NVD · matched kernel
vulnerability 3 unknown—2026-09-24
Linux BPF Sign Extension Local Privilege Escalation
CVE-2017-16995 · Metasploit exploit modules, Exploit-DB · matched kernel
exploit 4 ——2017-11-12
Linux Kernel - 'mincore()' Uninitialized Kernel Heap Page Disclosure
CVE-2017-16994 · Exploit-DB · matched kernel
exploit 3 ——2017-11-24
A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave
· Write-ups · matched kernel
article 1 ——2026-01-14
Linux Kernel Improper Input Validation Vulnerability
CVE-2013-6282 · CISA Known Exploited Vulnerabilities, Metasploit exploit modules, Exploit-DB · matched kernel
vulnerability 1 exploit 3 ——2013-09-06
Linux Kernel Unspecified Vulnerability
CVE-2026-53362 · CISA Known Exploited Vulnerabilities, Red Hat · matched kernel
vulnerability 2 high7.82026-06-21
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel Driver: from r49p3 through r49p5, r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r49p3 through r49p5, from r51p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r49p3 through r49p5, from r51p0 through r54p3, r55p0.
CVE-2026-7476 · NVD · matched kernel
vulnerability 1 —7.82026-09-08
Linux Kernel Privilege Escalation Vulnerability
CVE-2014-3153 · CISA Known Exploited Vulnerabilities, Metasploit exploit modules, Exploit-DB · matched kernel
vulnerability 1 exploit 2 ——2014-05-03
Linux Kernel 4.13 - 'compat_get_timex()' Leak Kernel Pointer
CVE-2018-11508 · Exploit-DB · matched kernel
exploit 1 ——2019-01-21
Testing race conditions with memory access tracing and stack-based delay injection
· Write-ups · matched kernel
article 1 ——2026-09-08
Linux Kernel Privilege Escalation Vulnerability
CVE-2021-3493 · CISA Known Exploited Vulnerabilities, Metasploit exploit modules · matched kernel
vulnerability 1 exploit 1 ——2021-04-12
kernel: Linux kernel: IMA memory leak
CVE-2022-50577 · Red Hat · matched kernel
vulnerability 1 low5.52025-10-22
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel Driver: from r44p0 through r49p4, from r50p0 through r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r44p0 through r49p5, from r50p0 through r54p3; Arm 5th Gen GPU Architecture Kernel Driver: from r44p0 through r49p5, from r50p0 through r54p3, r55p0.
CVE-2026-7477 · NVD · matched kernel
vulnerability 1 —7.82026-09-08
In the Linux kernel, the following vulnerability has been resolved: arm64: entry: Avoid...
CVE-2026-93254 · GitHub advisories, NVD · matched kernel
vulnerability 3 unknown—2026-09-24
Linux Nested User Namespace idmap Limit Local Privilege Escalation
CVE-2018-18955 · Metasploit exploit modules, Exploit-DB · matched kernel
exploit 7 ——2018-11-15
Grsecurity Kernel Patch 1.9.4 (Linux Kernel) - Memory Protection
CVE-2002-1826 · Exploit-DB · matched kernel
exploit 1 ——2002-05-17
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
CVE-2025-54957 · Write-ups
article 2 ——2026-01-14
Linux Kernel Improper Privilege Management Vulnerability
CVE-2019-13272 · CISA Known Exploited Vulnerabilities, Metasploit exploit modules, Exploit-DB · matched kernel
vulnerability 1 exploit 5 ——2019-07-04
kernel: Kernel: Bluetooth HCI local DoS
CVE-2024-58241 · Red Hat · matched kernel
vulnerability 1 medium4.42025-09-24
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0.
CVE-2026-12285 · NVD · matched kernel
vulnerability 1 —42026-09-08
Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation
CVE-2018-5333 · Metasploit exploit modules · matched kernel
exploit 1 ——2018-11-01
Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation
CVE-2019-9213 · Metasploit exploit modules, Exploit-DB · matched kernel
exploit 3 ——2018-11-01
← PreviousPage 1 of 639Next →

Facets

Kind 99705 of 99705 claims

exploit49396

Severity 26571 of 99705 claims

high7305
medium13523
low3917

Exploited 1733 of 99705 claims

yes1733

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1733

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22765

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19646

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing6155

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10