Zetlyn

CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 55m agofresh within 24h

freeSign in20878 claims are newer than 30 days and need a subscription

65,940things
8,540named by two sources or more
960conflicts
7sources

Only one source knows: Exploit-DB 23131 · GitHub advisories 30 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12667 · Red Hat 19884 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

platform=asp ✕

EverythingExploited, and severearticle 10exploit 49396vulnerability 49311

Found

1–25 of 1,449
ThingTypePlatformDate
InnovaStudio WYSIWYG Editor 5.4 - Unrestricted File Upload / Directory Traversal
· Exploit-DB
webappsasp2023-04-14
ENTAB ERP 1.0 - Username PII leak
CVE-2022-30076 · Exploit-DB
webappsasp2023-04-08
Snitz Forum v1.0 - Blind SQL Injection
· Exploit-DB
webappsasp2023-04-07
EQ Enterprise management system v2.2.0 - SQL Injection
CVE-2022-45297 · Exploit-DB
webappsasp2023-03-31
Password Manager for IIS v2.0 - XSS
CVE-2022-36664 · Exploit-DB
webappsasp2023-03-25
wkhtmltopdf 0.12.6 - Server Side Request Forgery
CVE-2022-35583 · Exploit-DB
webappsasp2023-03-23
Build Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated)
· Exploit-DB
webappsasp2021-10-25
HelloWeb 2.0 - Arbitrary File Download
· Exploit-DB
webappsasp2020-07-10
Enhanced Multimedia Router 3.0.4.27 - Cross-Site Request Forgery (Add Admin)
· Exploit-DB
webappsasp2020-03-16
OLK Web Store 2020 - Cross-Site Request Forgery
· Exploit-DB
webappsasp2020-01-24
Rumpus FTP Web File Manager 8.2.9.1 - Reflected Cross-Site Scripting
CVE-2019-19368 · Exploit-DB
webappsasp2019-12-18
Crystal Live HTTP Server 6.01 - Directory Traversal
· Exploit-DB
webappsasp2019-11-18
Web Wiz Forums 12.01 - 'PF' SQL Injection
· Exploit-DB
webappsasp2019-08-16
microASP (Portal+) CMS - 'pagina.phtml?explode_tree' SQL Injection
· Exploit-DB
webappsasp2019-05-06
Skyworth GPON HomeGateways and Optical Network Terminals - Stack Overflow
CVE-2018-19524 · Exploit-DB
dosasp2019-02-12
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
CVE-2018-15707 · Exploit-DB
webappsasp2018-11-05
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
CVE-2018-15705 · Exploit-DB
webappsasp2018-11-05
IssueTrak 7.0 - SQL Injection
· Exploit-DB
webappsasp2018-05-29
ASP.NET jVideo Kit - 'query' SQL Injection
· Exploit-DB
webappsasp2018-05-24
totemomail Encryption Gateway 6.0.0 Build 371 - Cross-Site Request Forgery
CVE-2018-6563 · Exploit-DB
webappsasp2018-05-16
Tenda FH303/A300 Firmware v5.07.68_EN - Remote DNS Change
· Exploit-DB
webappsasp2018-03-30
Tenda W316R Wireless Router 5.07.50 - Remote DNS Change
· Exploit-DB
webappsasp2018-03-30
Tenda W308R v2 Wireless Router 5.07.48 - (Cookie Session) Remote DNS Change
· Exploit-DB
webappsasp2018-03-30
Tenda W3002R/A302/w309r Wireless Router v5.07.64_en - Remote DNS Change (PoC)
· Exploit-DB
webappsasp2018-03-30
EPIC MyChart - X-Path Injection
CVE-2016-6272 · Exploit-DB
webappsasp2018-02-16
← PreviousPage 1 of 58Next →

Facets

Type 46698 of 98717 claims

Platform 49396 of 98717 claims

asp1548

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1731

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22689

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19161

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing5730

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10