Live · run by Zetlyn

CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Its entry in the hub · take a copy →

Behind8 sourcesupdated 5h agofresh within 24h
77,036things
15,437named by two sources or more
3,511conflicts
8sources

Only one source knows: EPSS 9516 · Exploit-DB 18468 · GitHub advisories 36 · CISA Known Exploited Vulnerabilities 363 · Metasploit exploit modules 308 · NVD 13116 · Red Hat 19788 · Write-ups 4

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Every CVE whose EPSS is above 0.1. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-upsEPSS
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot saidnot said
CwecwesCWEcve.weaknesses[].description[].valuecwes[].cwe_idnot saidnot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot saidnot said
Productproductnot saidcve.affected[].affectedData[].productnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritycve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverityseveritynot saidnot saidnot saidnot said
VendorvendorProjectnot saidcve.affected[].affectedData[].vendornot saidnot saidnot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

Try:mikrotikknown_ransomware_campaign_use=UnknownCVE-2026-67279kernel

EverythingExploited, and severeLikely to be exploited nextarticle 10exploit 49396vulnerability 70132

Things

25 things, from 119,538 claims
ThingKindVendorProductSeverityCvssEpssDate
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
CVE-2026-88779 · CISA Known Exploited Vulnerabilities, NVD, GitHub advisories
vulnerability 3 Citrix / NetScalerADC / NetScalerhigh7.5—2026-10-04
sssd: sssd: Denial of service via stale connection state reuse in PAM GSSAPI responder
CVE-2026-104039 · Red Hat, GitHub advisories, NVD
vulnerability 3 Red HatRed Hat Enterprise Linux 10medium4.7—2026-10-06
HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to supply unexpected or malformed data, enabling processing errors, business logic bypasses, and unintended application behavior.
CVE-2026-56596 · NVD
vulnerability 1 HCL SoftwareHCL BigFix Service Managementlow3.5—2026-10-06
In AMD Versal™ Adaptive SoC devices, insufficient boundary checks in USB boot mode—when enabled...
CVE-2026-0482 · GitHub advisories, NVD
vulnerability 2 AMDAlveo™ Accelerator Cardsmedium——2026-10-05
Generic Payload Handler
· Metasploit exploit modules
exploit 1 —————2026-10-06
Ecava_ntegraXor IGX_16.0.701.10 - RCE
· Exploit-DB
exploit 1 —————2026-10-01
console: Authenticated SSRF via user-controlled towerHost in /ansibletower handler
CVE-2026-66804 · Red Hat, Write-ups
vulnerability 1 article 1 ——high7.7—2026-08-13
Windows Exploitation Techniques: Dangling COM Object Registrations
CVE-2026-50343 · Write-ups
article 1 —————2026-09-21
CVE-2015-1399
CVE-2015-1399 · EPSS
vulnerability 1 ————0.100012026-10-05
Zammad GmbH Zammad Session Fixation Vulnerability
CVE-2026-102489 · CISA Known Exploited Vulnerabilities, NVD, GitHub advisories
vulnerability 3 Zammad GmbHZammadcritical9.8—2026-09-30
sssd: sssd: Information disclosure via OData injection in Entra ID lookups
CVE-2026-104040 · Red Hat, GitHub advisories, NVD
vulnerability 3 Red HatRed Hat Enterprise Linux 10medium4.4—2026-10-06
A vulnerability has been found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. Impacted is the function mysql_error of the file login.php of the component Login Endpoint. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-105918 · NVD
vulnerability 1 KusalkasilvaLearning-Management-Systemhigh7.3—2026-10-06
Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+...
CVE-2026-0461 · GitHub advisories, NVD
vulnerability 2 AMDZynq™ UltraScale+ MPSoCshigh——2026-10-05
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
CVE-2026-83548 · CISA Known Exploited Vulnerabilities, Metasploit exploit modules
vulnerability 1 exploit 1 SonicWallSMA1000 Appliances———2026-09-01
SonicWall SMA1000 Appliances OS Command Injection Vulnerability
CVE-2026-83549 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules, EPSS
vulnerability 3 exploit 1 SonicWallSMA1000 / SMA1000 Applianceshigh7.80.10762026-09-01
WordPress Core Remote File Inclusion Vulnerability
CVE-2026-87902 · CISA Known Exploited Vulnerabilities, NVD, Exploit-DB, EPSS
vulnerability 3 exploit 1 WordPressCore / WordPresshigh8.10.461172026-09-22
Testing race conditions with memory access tracing and stack-based delay injection
· Write-ups
article 1 —————2026-09-08
CVE-2013-0613
CVE-2013-0613 · EPSS
vulnerability 1 ————0.100042026-10-05
Zammad GmbH Zammad Improper Privilege Management Vulnerability
CVE-2026-102490 · CISA Known Exploited Vulnerabilities, NVD, GitHub advisories
vulnerability 3 Zammad GmbHZammadcritical9.8—2026-09-30
sssd: sssd: Denial of Service via unbounded negative cache growth
CVE-2026-104041 · Red Hat, GitHub advisories, NVD
vulnerability 3 Red HatRed Hat Enterprise Linux 10medium5.5—2026-10-06
GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service. This issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d which will be released in version 0.60.8.3.
CVE-2026-75820 · NVD
vulnerability 1 GNUAspell———2026-10-06
A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to...
CVE-2026-105468 · GitHub advisories, NVD
vulnerability 2 girishsarafOnline-Appointment-Booking-Systemhigh / medium7.3—2026-10-05
SPIP Autosave Session Unauthenticated RCE
· Metasploit exploit modules
exploit 1 —————2026-08-30
TigerGraph_Community_Edition 4.2.4 - arbitrary file write
· Exploit-DB
exploit 1 —————2026-10-01
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
CVE-2025-54957 · Write-ups
article 2 —————2026-01-14
← PreviousPage 1 of 4782Next →

Facets

Kind 119538 of 119538 claims

exploit49396

Severity 45163 of 119538 claims

high15426
medium20990
low4804

Exploited 1734 of 119538 claims

yes1734

Vendor 22328 of 119538 claims

Linux2367
n/a856

Cwe 45955 of 119538 claims

CWE-792811
CWE-221251

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1734

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current23701

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current20772

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing6630

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10

EPSS normal

How likely it is to be exploited next, which neither a severity nor a proof of concept says.

vulnerability · current17295