Versions
Every version of CVE on the hub, and how to keep a copy of it on your own machine, current.
Take a copy
zetlyn tracker subscribe zetlyn/cveIts statement, and every source it names, each with its claims and their receipts. A subscriber is told of the next version and fetches only what changed.
Versions
| Version | Published | Claims | |
|---|---|---|---|
37ac2411d7c0 | 2026-10-06 | latest | |
0306108c10d4 | 2026-10-06 | ||
a7312c99a062 | 2026-10-06 | ||
5bda63e4b976 | 2026-09-29 | ||
627328feb037 | 2026-09-29 | ||
f5db1762ca45 | 2026-09-29 |
Version 37ac2411d7c0 · signed ed25519:af9ffd7b7435cdad9724db5feea1a6f55ff38ea13b860ab62260f34f59a131ab · manifest.json
Its statement
name: zetlyn/cve
title: CVE
about: What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.
sources:
- source: zetlyn/cve-kev
priority: primary
why: The only source that says a vulnerability is being exploited right now.
- source: zetlyn/cve-redhat
priority: high
why: Its own severity, and the packages it tracks a vulnerability in.
- source: zetlyn/cve-nvd
priority: high
why: The CVSS baseline, and an anchor for CVEs the other members never reach.
- source: zetlyn/cve-ghsa
priority: high
why: The ecosystem packages no distribution ships.
- source: zetlyn/cve-metasploit
why: Whether a module exists for the tool an attacker actually runs.
- source: zetlyn/cve-exploitdb
why: Whether working code exists at all, which is a different question from how severe it is.
- source: zetlyn/cve-writeups
why: The prose that explains a vulnerability after the advisories have stopped.
- source: zetlyn/cve-epss
why: How likely it is to be exploited next, which neither a severity nor a proof of concept says.
identified_by:
- cve
# What a vulnerability is to something else, where a claim states both: NVD names the CPEs of what
# it affects once it has analysed a CVE. Where it has not, the CNA's own words are offered to a
# person to confirm, and a match they confirm is theirs, signed, in matches.jsonl.
relations:
- name: affects
to: cpe
as: product
suggest_from: [vendor, product]
about: The products it affects, as vendor/product.
- name: made_by
to: cpe
as: vendor
suggest_from: [vendor]
about: The vendors whose products it affects.
align:
# The same codes from KEV, NVD, Red Hat and GitHub. Two lists that differ name different
# weaknesses, and on 2026-10-06 that was no conflict anywhere, only 71 differences in wording.
cwe: {}
# A name, not an identifier, and compared only to show it beside the others. KEV calls it
# vendorProject.
vendor:
from:
zetlyn/cve-kev: vendor_project
product: {}
# The same number from every source that scores one: NVD, Red Hat and GitHub all give a CVSS
# base score, and a difference between them is a difference of judgement.
cvss: {}
# Exploited means somebody is using it, and one source says that: CISA, by putting the row in
# its catalogue. Metasploit's rank and Exploit-DB's verified flag are about the code, not about
# the attack — a module that nobody has fired and an unverified proof of concept are both code
# that exists. That question is already answered, by a claim of kind `exploit`, and 23,444
# things carry one. Reading the two as one property makes `exploited=yes` useless for triage.
exploited:
scale:
- "yes"
- "no"
severity:
scale:
- critical
- high
- medium
- low
- unknown
zetlyn/cve-ghsa:
critical: critical
high: high
low: low
moderate: medium
zetlyn/cve-nvd:
critical: critical
high: high
medium: medium
low: low
zetlyn/cve-redhat:
critical: critical
important: high
low: low
moderate: medium
view:
columns:
- kind
- vendor
- product
- severity
- cvss
- epss
- known
facets:
- kind
- source
- severity
- exploited
- vendor
- cwe
sort: known desc
named:
- name: exploited-and-severe
title: Exploited, and severe
where: exploited=yes and severity>=high
- name: likely-next
title: Likely to be exploited next
where: epss>=0.5
sort: epss desc
exploit:
adopt: zetlyn/cve-exploitdb:verified
promise:
fresh_within: 24h
covers: Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Every CVE whose EPSS is above 0.1.
excludes: Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
# A vulnerability's page: what somebody asks first, how far exploitation has got, and by day.
thing:
summary: [severity, cvss, epss, exploited, known_ransomware_campaign_use, due_date, fixed_in, vendor, product, cwe]
ladder:
title: How far exploitation has got
steps:
- name: No public code known
- name: Proof of concept
when: has:cve-exploitdb
- name: Proof of concept, verified
when: cve-exploitdb.verified=true
- name: A Metasploit module
when: has:cve-metasploit
- name: Exploited in the wild
when: exploited=yes
- name: Used in ransomware campaigns
when: known_ransomware_campaign_use=Known
timeline: [due_date]