Versions

Every version of CVE on the hub, and how to keep a copy of it on your own machine, current.

Take a copy

zetlyn tracker subscribe zetlyn/cve

Its statement, and every source it names, each with its claims and their receipts. A subscriber is told of the next version and fetches only what changed.

Versions

VersionPublishedClaims
37ac2411d7c02026-10-06latest
0306108c10d42026-10-06
a7312c99a0622026-10-06
5bda63e4b9762026-09-29
627328feb0372026-09-29
f5db1762ca452026-09-29

Version 37ac2411d7c0 · signed ed25519:af9ffd7b7435cdad9724db5feea1a6f55ff38ea13b860ab62260f34f59a131ab · manifest.json

Its statement
name: zetlyn/cve
title: CVE
about: What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.
sources:
- source: zetlyn/cve-kev
  priority: primary
  why: The only source that says a vulnerability is being exploited right now.
- source: zetlyn/cve-redhat
  priority: high
  why: Its own severity, and the packages it tracks a vulnerability in.
- source: zetlyn/cve-nvd
  priority: high
  why: The CVSS baseline, and an anchor for CVEs the other members never reach.
- source: zetlyn/cve-ghsa
  priority: high
  why: The ecosystem packages no distribution ships.
- source: zetlyn/cve-metasploit
  why: Whether a module exists for the tool an attacker actually runs.
- source: zetlyn/cve-exploitdb
  why: Whether working code exists at all, which is a different question from how severe it is.
- source: zetlyn/cve-writeups
  why: The prose that explains a vulnerability after the advisories have stopped.
- source: zetlyn/cve-epss
  why: How likely it is to be exploited next, which neither a severity nor a proof of concept says.
identified_by:
- cve
# What a vulnerability is to something else, where a claim states both: NVD names the CPEs of what
# it affects once it has analysed a CVE. Where it has not, the CNA's own words are offered to a
# person to confirm, and a match they confirm is theirs, signed, in matches.jsonl.
relations:
- name: affects
  to: cpe
  as: product
  suggest_from: [vendor, product]
  about: The products it affects, as vendor/product.
- name: made_by
  to: cpe
  as: vendor
  suggest_from: [vendor]
  about: The vendors whose products it affects.
align:
  # The same codes from KEV, NVD, Red Hat and GitHub. Two lists that differ name different
  # weaknesses, and on 2026-10-06 that was no conflict anywhere, only 71 differences in wording.
  cwe: {}
  # A name, not an identifier, and compared only to show it beside the others. KEV calls it
  # vendorProject.
  vendor:
    from:
      zetlyn/cve-kev: vendor_project
  product: {}
  # The same number from every source that scores one: NVD, Red Hat and GitHub all give a CVSS
  # base score, and a difference between them is a difference of judgement.
  cvss: {}
  # Exploited means somebody is using it, and one source says that: CISA, by putting the row in
  # its catalogue. Metasploit's rank and Exploit-DB's verified flag are about the code, not about
  # the attack — a module that nobody has fired and an unverified proof of concept are both code
  # that exists. That question is already answered, by a claim of kind `exploit`, and 23,444
  # things carry one. Reading the two as one property makes `exploited=yes` useless for triage.
  exploited:
    scale:
    - "yes"
    - "no"
  severity:
    scale:
    - critical
    - high
    - medium
    - low
    - unknown
    zetlyn/cve-ghsa:
      critical: critical
      high: high
      low: low
      moderate: medium
    zetlyn/cve-nvd:
      critical: critical
      high: high
      medium: medium
      low: low
    zetlyn/cve-redhat:
      critical: critical
      important: high
      low: low
      moderate: medium
view:
  columns:
  - kind
  - vendor
  - product
  - severity
  - cvss
  - epss
  - known
  facets:
  - kind
  - source
  - severity
  - exploited
  - vendor
  - cwe
  sort: known desc
  named:
  - name: exploited-and-severe
    title: Exploited, and severe
    where: exploited=yes and severity>=high
  - name: likely-next
    title: Likely to be exploited next
    where: epss>=0.5
    sort: epss desc
  exploit:
    adopt: zetlyn/cve-exploitdb:verified
promise:
  fresh_within: 24h
  covers: Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Every CVE whose EPSS is above 0.1.
  excludes: Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
# A vulnerability's page: what somebody asks first, how far exploitation has got, and by day.
thing:
  summary: [severity, cvss, epss, exploited, known_ransomware_campaign_use, due_date, fixed_in, vendor, product, cwe]
  ladder:
    title: How far exploitation has got
    steps:
    - name: No public code known
    - name: Proof of concept
      when: has:cve-exploitdb
    - name: Proof of concept, verified
      when: cve-exploitdb.verified=true
    - name: A Metasploit module
      when: has:cve-metasploit
    - name: Exploited in the wild
      when: exploited=yes
    - name: Used in ransomware campaigns
      when: known_ransomware_campaign_use=Known
  timeline: [due_date]