CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 5h agofresh within 24h
65,943things
8,553named by two sources or more
1,057conflicts
7sources

Only one source knows: Exploit-DB 23133 · GitHub advisories 30 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12654 · Red Hat 19885 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

severity=medium ✕

EverythingExploited, and severearticle 10exploit 49396vulnerability 49311

Found

1–25 of 6,291
ThingKindSeverityCvssDate
kernel: Linux kernel: ublk race condition causes kernel crash
CVE-2025-37906 · Red Hat · matched kernel
vulnerability 1 medium4.12025-05-20
kernel: Kernel: Bluetooth HCI local DoS
CVE-2024-58241 · Red Hat · matched kernel
vulnerability 1 medium4.42025-09-24
kernel: Linux kernel dpaa2-switch: Kernel memory corruption via out-of-bounds write
CVE-2026-43205 · Red Hat · matched kernel
vulnerability 1 medium6.72026-05-06
kernel: Linux kernel: Memory Corruption and Kernel Crashes via IOMMU SVA coherency issue
CVE-2025-71202 · Red Hat · matched kernel
vulnerability 1 medium6.52026-02-14
kernel: Linux kernel (erofs): Kernel stack overflow due to excessive file system stacking
CVE-2025-68361 · Red Hat · matched kernel
vulnerability 1 medium4.72025-12-24
kernel: dm-integrity: fix leaking uninitialized kernel memory
CVE-2026-72101 · Red Hat · matched kernel
vulnerability 1 medium5.52026-08-15
kernel: ieee802154: fix kernel-infoleak in dgram_recvmsg()
CVE-2026-72441 · Red Hat · matched kernel
vulnerability 1 medium5.52026-08-15
kernel: Linux kernel ath12k Wi-Fi memory leak
CVE-2025-39890 · Red Hat, NVD · matched kernel
vulnerability 2 medium4.7 / 5.52025-09-24
kernel: Linux kernel: mremap local denial of service
CVE-2025-39775 · Red Hat · matched kernel
vulnerability 1 medium5.52025-09-11
kernel: Linux kernel use-after-free in eventpoll
CVE-2025-38349 · Red Hat · matched kernel
vulnerability 1 medium72025-07-18
kernel: Linux kernel: sch_htb NULL pointer dereference
CVE-2025-37953 · Red Hat · matched kernel
vulnerability 1 medium5.52025-05-20
kernel: ibmvnic: Use kernel helpers for hex dumps
CVE-2025-22104 · Red Hat · matched kernel
vulnerability 1 medium7.12025-04-16
kernel: Kernel: Denial of Service in buffer queue driver
CVE-2024-53922 · Red Hat, NVD · matched kernel
vulnerability 2 medium5.72026-09-13
kernel: perf/x86/amd/lbr: Fix kernel address leakage
CVE-2026-80602 · Red Hat · matched kernel
vulnerability 1 medium5.52026-08-28
kernel: perf/x86/amd/brs: Fix kernel address leakage
CVE-2026-72237 · Red Hat · matched kernel
vulnerability 1 medium5.52026-08-15
kernel: RDMA/bnxt_re: Avoid displaying the kernel pointer
CVE-2026-72498 · Red Hat · matched kernel
vulnerability 1 medium5.52026-08-15
kernel: rxrpc: serialize kernel accept preallocation with socket teardown
CVE-2026-74436 · Red Hat · matched kernel
vulnerability 1 medium72026-08-15
In the Linux kernel, the following vulnerability has been resolved: bpf: Guard __get_user acesss with access_ok for uprobe_multi data As reported by sashiko [1] we need to use access_ok to check the user space data bounds before we use __get-user to get it. [1] https://lore.kernel.org/bpf/20260610145235.CB1441F00893@smtp.kernel.org/
CVE-2026-74258 · NVD, Red Hat · matched kernel
vulnerability 2 medium5.5 / 7.82026-08-15
kernel: Linux kernel: drm/imagination use-after-free vulnerability
CVE-2026-68263 · Red Hat · matched kernel
vulnerability 1 medium7.12026-08-10
kernel: kernel: Information disclosure in Thunderbolt XDomain response handling
CVE-2026-53146 · Red Hat · matched kernel
vulnerability 1 medium5.52026-06-25
kernel: Linux kernel: Denial of Service in erofs filesystem
CVE-2026-31467 · Red Hat · matched kernel
vulnerability 1 medium5.52026-04-22
kernel: s390/entry: Scrub r12 register on kernel entry
CVE-2026-31482 · Red Hat · matched kernel
vulnerability 1 medium4.72026-04-22
kernel: Kernel (iommufd): Information Disclosure via uninitialized memory padding
CVE-2023-54034 · Red Hat · matched kernel
vulnerability 1 medium3.32025-12-24
In the Linux kernel, the following vulnerability has been resolved: openrisc: fix arbitrary kernel memory access via or1k_atomic syscall sys_or1k_atomic() (syscall 244 in the "or1k" ABI) takes two user pointers, v1 and v2, and swaps the words they point to in hand-written assembly. l.lwz r29,0(r4) l.lwz r27,0(r5) l.sw 0(r4),r27 l.sw 0(r5),r29 The pointers are not checked with access_ok(). The four memory accesses also have no exception table entries. A caller passes a kernel address as either pointer, and the syscall reads from and writes to it directly. This gives an unprivileged process a kernel read/write primitive. It overwrites kernel data such as the sys_call_table, gaining code execution in kernel context. Check both pointers before entering the critical section. Add fixups for the four memory accesses so faults on valid but unmapped user addresses return -EFAULT. [shorne@gmail.com: fix comment style]
CVE-2026-89489 · NVD, Red Hat · matched kernel
vulnerability 2 medium5.5 / 7.82026-09-11
kernel: RDMA/rxe: Fix "kernel NULL pointer dereference" error
CVE-2022-50671 · Red Hat · matched kernel
vulnerability 1 medium4.72025-12-09
← PreviousPage 1 of 252Next →

Facets

Kind 98717 of 98717 claims

exploit49396

Severity 26070 of 98717 claims

medium11653

Exploited 1731 of 98717 claims

yes1731

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1731

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22689

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19161

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing5730

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10