Live · run by Zetlyn
CVE
What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.
Its entry in the hub · take a copy →
Only one source knows: EPSS 9516 · Exploit-DB 18468 · GitHub advisories 36 · CISA Known Exploited Vulnerabilities 363 · Metasploit exploit modules 308 · NVD 13116 · Red Hat 19788 · Write-ups 4
Compared · what is held against what, and from which column of each source
| Property | CISA Known Exploited Vulnerabilities | Red Hat | NVD | GitHub advisories | Metasploit exploit modules | Exploit-DB | Write-ups | EPSS |
|---|---|---|---|---|---|---|---|---|
| Cvss | not said | cvss3_score | cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore | cvss.score | not said | not said | not said | not said |
| Cwe | cwes | CWE | cve.weaknesses[].description[].value | cwes[].cwe_id | not said | not said | not said | not said |
| Exploited | const:yes | not said | not said | not said | not said | not said | not said | not said |
| Product | product | not said | cve.affected[].affectedData[].product | not said | not said | not said | not said | not said |
| Severity | not said | severity | cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity | severity | not said | not said | not said | not said |
| Vendor | vendorProject | not said | cve.affected[].affectedData[].vendor | not said | not said | not said | not said | not said |
Everything else the sources say is shown side by side, and not compared.
Things
25 things, from 119,538 claims| Thing | Kind | Vendor | Product | Severity | Cvss | Epss | Date |
|---|---|---|---|---|---|---|---|
| Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability CVE-2026-88779 · CISA Known Exploited Vulnerabilities, NVD, GitHub advisories | vulnerability 3 | Citrix / NetScaler | ADC / NetScaler | high | 7.5 | — | 2026-10-04 |
| sssd: sssd: Denial of service via stale connection state reuse in PAM GSSAPI responder CVE-2026-104039 · Red Hat, GitHub advisories, NVD | vulnerability 3 | Red Hat | Red Hat Enterprise Linux 10 | medium | 4.7 | — | 2026-10-06 |
| HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to supply unexpected or malformed data, enabling processing errors, business logic bypasses, and unintended application behavior. CVE-2026-56596 · NVD | vulnerability 1 | HCL Software | HCL BigFix Service Management | low | 3.5 | — | 2026-10-06 |
| In AMD Versal™ Adaptive SoC devices, insufficient boundary checks in USB boot mode—when enabled... CVE-2026-0482 · GitHub advisories, NVD | vulnerability 2 | AMD | Alveo™ Accelerator Cards | medium | — | — | 2026-10-05 |
| Generic Payload Handler · Metasploit exploit modules | exploit 1 | — | — | — | — | — | 2026-10-06 |
| Ecava_ntegraXor IGX_16.0.701.10 - RCE · Exploit-DB | exploit 1 | — | — | — | — | — | 2026-10-01 |
| console: Authenticated SSRF via user-controlled towerHost in /ansibletower handler CVE-2026-66804 · Red Hat, Write-ups | vulnerability 1 article 1 | — | — | high | 7.7 | — | 2026-08-13 |
| Windows Exploitation Techniques: Dangling COM Object Registrations CVE-2026-50343 · Write-ups | article 1 | — | — | — | — | — | 2026-09-21 |
| CVE-2015-1399 CVE-2015-1399 · EPSS | vulnerability 1 | — | — | — | — | 0.10001 | 2026-10-05 |
| Zammad GmbH Zammad Session Fixation Vulnerability CVE-2026-102489 · CISA Known Exploited Vulnerabilities, NVD, GitHub advisories | vulnerability 3 | Zammad GmbH | Zammad | critical | 9.8 | — | 2026-09-30 |
| sssd: sssd: Information disclosure via OData injection in Entra ID lookups CVE-2026-104040 · Red Hat, GitHub advisories, NVD | vulnerability 3 | Red Hat | Red Hat Enterprise Linux 10 | medium | 4.4 | — | 2026-10-06 |
| A vulnerability has been found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. Impacted is the function mysql_error of the file login.php of the component Login Endpoint. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105918 · NVD | vulnerability 1 | Kusalkasilva | Learning-Management-System | high | 7.3 | — | 2026-10-06 |
| Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+... CVE-2026-0461 · GitHub advisories, NVD | vulnerability 2 | AMD | Zynq™ UltraScale+ MPSoCs | high | — | — | 2026-10-05 |
| SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CVE-2026-83548 · CISA Known Exploited Vulnerabilities, Metasploit exploit modules | vulnerability 1 exploit 1 | SonicWall | SMA1000 Appliances | — | — | — | 2026-09-01 |
| SonicWall SMA1000 Appliances OS Command Injection Vulnerability CVE-2026-83549 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules, EPSS | vulnerability 3 exploit 1 | SonicWall | SMA1000 / SMA1000 Appliances | high | 7.8 | 0.1076 | 2026-09-01 |
| WordPress Core Remote File Inclusion Vulnerability CVE-2026-87902 · CISA Known Exploited Vulnerabilities, NVD, Exploit-DB, EPSS | vulnerability 3 exploit 1 | WordPress | Core / WordPress | high | 8.1 | 0.46117 | 2026-09-22 |
| Testing race conditions with memory access tracing and stack-based delay injection · Write-ups | article 1 | — | — | — | — | — | 2026-09-08 |
| CVE-2013-0613 CVE-2013-0613 · EPSS | vulnerability 1 | — | — | — | — | 0.10004 | 2026-10-05 |
| Zammad GmbH Zammad Improper Privilege Management Vulnerability CVE-2026-102490 · CISA Known Exploited Vulnerabilities, NVD, GitHub advisories | vulnerability 3 | Zammad GmbH | Zammad | critical | 9.8 | — | 2026-09-30 |
| sssd: sssd: Denial of Service via unbounded negative cache growth CVE-2026-104041 · Red Hat, GitHub advisories, NVD | vulnerability 3 | Red Hat | Red Hat Enterprise Linux 10 | medium | 5.5 | — | 2026-10-06 |
| GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service.
This issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d which will be released in version 0.60.8.3. CVE-2026-75820 · NVD | vulnerability 1 | GNU | Aspell | — | — | — | 2026-10-06 |
| A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to... CVE-2026-105468 · GitHub advisories, NVD | vulnerability 2 | girishsaraf | Online-Appointment-Booking-System | high / medium | 7.3 | — | 2026-10-05 |
| SPIP Autosave Session Unauthenticated RCE · Metasploit exploit modules | exploit 1 | — | — | — | — | — | 2026-08-30 |
| TigerGraph_Community_Edition 4.2.4 - arbitrary file write · Exploit-DB | exploit 1 | — | — | — | — | — | 2026-10-01 |
| A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens CVE-2025-54957 · Write-ups | article 2 | — | — | — | — | — | 2026-01-14 |
Facets
Source 119538 of 119538 claims
Exploited 1734 of 119538 claims
Sources
CISA Known Exploited Vulnerabilities primary
The only source that says a vulnerability is being exploited right now.
Red Hat high
Its own severity, and the packages it tracks a vulnerability in.
NVD high
The CVSS baseline, and an anchor for CVEs the other members never reach.
GitHub advisories high
The ecosystem packages no distribution ships.
Metasploit exploit modules normal
Whether a module exists for the tool an attacker actually runs.
Exploit-DB normal
Whether working code exists at all, which is a different question from how severe it is.
Write-ups normal
The prose that explains a vulnerability after the advisories have stopped.
EPSS normal
How likely it is to be exploited next, which neither a severity nor a proof of concept says.