CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 11h agofresh within 24h
66,378things
9,017named by two sources or more
1,118conflicts
7sources

Only one source knows: Exploit-DB 23133 · GitHub advisories 35 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12677 · Red Hat 19828 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

severity=unknown ✕

EverythingExploited, and severearticle 10exploit 49396vulnerability 50299

Found

1–25 of 630
ThingKindSeverityCvssDate
Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to...
CVE-2026-103627 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An...
CVE-2026-51893 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable...
CVE-2026-51882 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a...
CVE-2026-59265 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A...
CVE-2026-102731 · GitHub advisories, Red Hat, NVD
vulnerability 3 high / unknown7.52026-10-02
Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to...
CVE-2026-103631 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is...
CVE-2026-51883 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in...
CVE-2026-51879 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>.
CVE-2026-51892 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
In Devika v1.0, the Patcher Agent save_code_to_project function contains a path traversal...
CVE-2026-51874 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An...
CVE-2026-51876 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path...
CVE-2026-51906 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
deeptutor 1.4.0 contains code injection in ExecTool.execute. Through the live tutorbot WebSocket...
CVE-2026-51881 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password...
CVE-2026-103880 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent...
CVE-2026-51914 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute.
CVE-2026-51898 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna...
CVE-2026-51911 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to...
CVE-2026-103630 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Through the live...
CVE-2026-51880 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue...
CVE-2026-103877 · GitHub advisories, Red Hat, NVD
vulnerability 3 high / unknown8.12026-10-02
FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code.
CVE-2026-51917 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker...
CVE-2026-103623 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app)....
CVE-2026-51897 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable...
CVE-2026-51894 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller...
CVE-2026-51901 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
← PreviousPage 1 of 26Next →

Facets

Kind 99705 of 99705 claims

exploit49396

Severity 26571 of 99705 claims

Exploited 1733 of 99705 claims

yes1733

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1733

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22765

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19646

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing6155

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10