CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 11h agofresh within 24h
66,378things
9,017named by two sources or more
1,118conflicts
7sources

Only one source knows: Exploit-DB 23133 · GitHub advisories 35 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12677 · Red Hat 19828 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

severity=high ✕

EverythingExploited, and severearticle 10exploit 49396vulnerability 50299

Found

1–25 of 6,537
ThingKindSeverityCvssDate
thrift: thrift: Denial of Service via improper exception handling in TNonblockingServer
CVE-2026-90440 · Red Hat, GitHub advisories, NVD
vulnerability 3 high7.52026-10-02
LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows...
CVE-2026-105129 · GitHub advisories, NVD
vulnerability 2 high6.52026-10-04
pki-core: dogtag-pki: redhat-pki: pki: EST fullcmc authentication bypass allows certificate mis-issuance with arbitrary subject
CVE-2026-104988 · Red Hat, GitHub advisories, NVD
vulnerability 3 high8.12026-10-02
W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that...
CVE-2026-105123 · GitHub advisories, NVD
vulnerability 2 high8.82026-10-04
thrift: thrift: Denial of Service via prototype pollution in Node.js bindings
CVE-2026-94646 · Red Hat, GitHub advisories, NVD
vulnerability 3 high7.52026-10-02
LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows...
CVE-2026-105126 · GitHub advisories, NVD
vulnerability 2 high7.22026-10-04
org.apache.directory.api/api-ldap-model: Apache Directory LDAP API: Denial of Service via crafted telephone numbers
CVE-2026-103885 · Red Hat, NVD, GitHub advisories
vulnerability 3 high / unknown7.52026-10-02
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the...
CVE-2026-88783 · GitHub advisories, NVD
vulnerability 2 high8.82026-10-03
github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of compressed data
CVE-2026-94637 · Red Hat, GitHub advisories, NVD
vulnerability 3 high7.52026-10-02
The Transliterator – Multilingual and Multi-script Text Conversion plugin for WordPress is...
CVE-2026-96575 · GitHub advisories, NVD
vulnerability 2 high7.22026-10-03
org.apache.directory.api/api-ldap-codec-core: Apache Directory LDAP API: Denial of Service via deeply nested search filter
CVE-2026-103552 · Red Hat, GitHub advisories, NVD
vulnerability 3 high7.3 / 7.52026-10-02
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &...
CVE-2026-96270 · GitHub advisories, NVD
vulnerability 2 high7.22026-10-03
org.apache.thrift/libthrift: Apache Thrift: Denial of Service via unbounded resource allocation in TSaslNonblockingServer
CVE-2026-61373 · Red Hat, GitHub advisories, NVD
vulnerability 3 high—2026-10-02
In Bouncy Castle for Java LTS before 2.73.13, the one-shot native packet ciphers for AES-CBC, CCM...
CVE-2026-71883 · GitHub advisories, NVD
vulnerability 2 high—2026-10-03
thrift: thrift: Denial of Service via improper handling of compressed data
CVE-2026-66054 · Red Hat, NVD, GitHub advisories
vulnerability 3 high / medium7.52026-10-02
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a...
CVE-2026-105050 · GitHub advisories, NVD
vulnerability 2 high—2026-10-02
uv: uv: Arbitrary code execution via malicious package extraction on Windows
CVE-2026-104843 · Red Hat, NVD
vulnerability 2 high7.82026-10-02
The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape...
CVE-2026-101159 · GitHub advisories, NVD
vulnerability 2 high7.52026-10-03
langgraph-sdk: langgraph-sdk: Authorization bypass via improper resource handler registration
CVE-2026-104873 · Red Hat, NVD
vulnerability 2 high8.12026-10-02
Armatura One stores database and message-broker credentials in an install configuration file,...
CVE-2026-94591 · GitHub advisories, NVD
vulnerability 2 high8.42026-10-02
org.apache.directory.api/api-ldap-client-api: Apache Directory LDAP API: Remote code execution via untrusted Java object deserialization
CVE-2026-103877 · Red Hat, NVD, GitHub advisories
vulnerability 3 high / unknown8.12026-10-02
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member...
CVE-2026-96451 · GitHub advisories, NVD
vulnerability 2 high8.82026-10-03
thrift: thrift: Denial of Service via uninitialized pointer access in c_glib bindings
CVE-2026-66081 · Red Hat, GitHub advisories, NVD
vulnerability 3 high—2026-10-02
The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL...
CVE-2026-96267 · GitHub advisories, NVD
vulnerability 2 high7.52026-10-03
thrift: thrift: Denial of Service via uncaught exception in Ruby bindings
CVE-2026-96277 · Red Hat, GitHub advisories, NVD
vulnerability 3 high—2026-10-02
← PreviousPage 1 of 262Next →

Facets

Kind 99705 of 99705 claims

exploit49396

Severity 26571 of 99705 claims

high7305

Exploited 1733 of 99705 claims

yes1733

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1733

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22765

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19646

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing6155

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10