CVE
What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.
Only one source knows: Exploit-DB 23133 · GitHub advisories 35 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12661 · Red Hat 19864 · Write-ups 5
Compared · what is held against what, and from which column of each source
| Property | CISA Known Exploited Vulnerabilities | Red Hat | NVD | GitHub advisories | Metasploit exploit modules | Exploit-DB | Write-ups |
|---|---|---|---|---|---|---|---|
| Cvss | not said | cvss3_score | cve.metrics.cvssMetricV31[].cvssData.baseScore | cvss.score | not said | not said | not said |
| Exploited | const:yes | not said | not said | not said | not said | not said | not said |
| Severity | not said | severity | not said | severity | not said | not said | not said |
Everything else the sources say is shown side by side, and not compared.
Found
51–75 of 2,298| Thing | Type | Platform | Date |
|---|---|---|---|
| Saflok - Key Derication Function Exploit · Exploit-DB | local | hardware | 2024-02-28 |
| TEM Opera Plus FM Family Transmitter 35.45 - XSRF · Exploit-DB | remote | hardware | 2024-02-27 |
| TEM Opera Plus FM Family Transmitter 35.45 - Remote Code Execution · Exploit-DB | remote | hardware | 2024-02-27 |
| DS Wireless Communication - Remote Code Execution · Exploit-DB | local | hardware | 2024-02-15 |
| VIMESA VHF/FM Transmitter Blue Plus 9.7.1 (doreboot) - Remote Denial Of Service · Exploit-DB | dos | hardware | 2024-02-13 |
| Zyxel zysh - Format string · Exploit-DB | remote | hardware | 2024-02-09 |
| Milesight Routers UR5X_ UR32L_ UR32_ UR35_ UR41 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption · Exploit-DB | remote | hardware | 2024-02-05 |
| TP-Link TL-WR740N - UnAuthenticated Directory Transversal · Exploit-DB | webapps | hardware | 2024-02-02 |
| TP-LINK TL-WR740N - Multiple HTML Injection · Exploit-DB | webapps | hardware | 2024-02-02 |
| Electrolink FM/DAB/TV Transmitter (login.htm/mail.htm) - Credentials Disclosure · Exploit-DB | webapps | hardware | 2024-02-02 |
| Electrolink FM/DAB/TV Transmitter - Remote Authentication Removal · Exploit-DB | webapps | hardware | 2024-02-02 |
| Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure · Exploit-DB | webapps | hardware | 2024-02-02 |
| Electrolink FM/DAB/TV Transmitter - Unauthenticated Remote DoS · Exploit-DB | dos | hardware | 2024-02-02 |
| Electrolink FM/DAB/TV Transmitter - Pre-Auth MPFS Image Remote Code Execution · Exploit-DB | webapps | hardware | 2024-02-02 |
| Electrolink FM/DAB/TV Transmitter (Login Cookie) - Authentication Bypass · Exploit-DB | webapps | hardware | 2024-02-02 |
| Ricoh Printer - Directory and File Exposure · Exploit-DB | remote | hardware | 2024-01-29 |
| Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Denial Of Service · Exploit-DB | dos | hardware | 2023-10-09 |
| Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Credentials Extraction · Exploit-DB | remote | hardware | 2023-10-09 |
| Ruijie Reyee Mesh Router - MITM Remote Code Execution (RCE) · Exploit-DB | remote | hardware | 2023-10-09 |
| Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Admin Password Change · Exploit-DB | remote | hardware | 2023-10-09 |
| Atcom 2.7.x.x - Authenticated Command Injection · Exploit-DB | remote | hardware | 2023-10-09 |
| Techview LA-5570 Wireless Gateway Home Automation Controller - Multiple Vulnerabilities CVE-2023-34723 · Exploit-DB | remote | hardware | 2023-09-08 |
| DLINK DPH-400SE - Exposure of Sensitive Information · Exploit-DB | webapps | hardware | 2023-09-04 |
| EuroTel ETL3100 - Transmitter Unauthenticated Config/Log Download · Exploit-DB | remote | hardware | 2023-08-21 |
| EuroTel ETL3100 - Transmitter Authorization Bypass (IDOR) · Exploit-DB | remote | hardware | 2023-08-21 |
Facets
Platform 49396 of 99440 claims
Sources
CISA Known Exploited Vulnerabilities primary
The only source that says a vulnerability is being exploited right now.
Red Hat high
Its own severity, and the packages it tracks a vulnerability in.
NVD high
The CVSS baseline, and an anchor for CVEs the other members never reach.
GitHub advisories high
The ecosystem packages no distribution ships.
Metasploit exploit modules normal
Whether a module exists for the tool an attacker actually runs.
Exploit-DB normal
Whether working code exists at all, which is a different question from how severe it is.
Write-ups normal
The prose that explains a vulnerability after the advisories have stopped.