Zetlyn

CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 56m agofresh within 24h

freeSign in20878 claims are newer than 30 days and need a subscription

65,940things
8,540named by two sources or more
960conflicts
7sources

Only one source knows: Exploit-DB 23131 · GitHub advisories 30 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12667 · Red Hat 19884 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

severity=high ✕

EverythingExploited, and severearticle 10exploit 49396vulnerability 49311

Found

26–50 of 4,384
ThingKindSeverityCvssDate
@xmldom/xmldom: xmldom: Markup injection via embedded line terminators in XML names
CVE-2026-83609 · Red Hat
vulnerability 1 high7.52026-09-01
github.com/kyverno/kyverno: Kyverno: Server-Side Request Forgery via apiCall.service.url allows information disclosure.
CVE-2026-84196 · Red Hat, NVD
vulnerability 2 high7.72026-09-01
thunderbird: Thunderbird: Arbitrary code execution via malicious calendar invitation attachments
CVE-2026-84637 · Red Hat
vulnerability 1 high8.82026-09-01
chromium-browser: chromium-browser: Improper input validation in Omnibox
CVE-2026-84357 · Red Hat
vulnerability 1 high8.12026-09-01
chromium-browser: chromium-browser: Uninitialized resource in V8
CVE-2026-84326 · Red Hat
vulnerability 1 high8.82026-09-01
xmldom: @xmldom/xmldom: xmldom: Denial of Service due to quadratic-time attribute processing
CVE-2026-83613 · Red Hat
vulnerability 1 high7.52026-09-01
firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: WebGPU component
CVE-2026-84123 · Red Hat
vulnerability 1 high7.52026-09-01
inets: httpd: otp: inets httpd: Denial of Service due to memory exhaustion via unenforced body-size limit
CVE-2026-74835 · Red Hat
vulnerability 1 high7.52026-09-01
github.com/kyverno/kyverno: Kyverno: Credential leak via apiCall leads to unauthorized cluster resource control
CVE-2026-84195 · Red Hat, NVD
vulnerability 2 high7.72026-09-01
xmldom: xmldom: Cross-site scripting via unvalidated element name injection
CVE-2026-83607 · Red Hat
vulnerability 1 high8.12026-09-01
firefox: Firefox: Arbitrary code execution via use-after-free in DOM: Core & HTML
CVE-2026-84125 · Red Hat
vulnerability 1 high8.82026-09-01
firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
CVE-2026-84145 · Red Hat
vulnerability 1 high7.52026-09-01
xmldom: @xmldom/xmldom: xmldom: Denial of Service via regular expression backtracking in processing instructions
CVE-2026-83606 · Red Hat
vulnerability 1 high7.52026-09-01
@xmldom/xmldom: xmldom: XML injection via embedded line terminator in element/attribute names
CVE-2026-83617 · Red Hat
vulnerability 1 high7.52026-09-01
xmldom: @xmldom/xmldom: xmldom: Denial of Service via quadratic-time XML parsing
CVE-2026-83614 · Red Hat
vulnerability 1 high7.52026-09-01
inets: inets: Denial of Service via unenforced connection limit
CVE-2026-70399 · Red Hat
vulnerability 1 high7.52026-09-01
xmldom: xmldom: Denial of Service via crafted HTML with mixed-case tags
CVE-2026-83612 · Red Hat
vulnerability 1 high7.52026-09-01
chromium-browser: chromium-browser: Use after free in Proxy
CVE-2026-84324 · Red Hat
vulnerability 1 high102026-09-01
thunderbird: Uninitialized memory in MIME parsing
CVE-2026-84639 · Red Hat
vulnerability 1 high7.52026-09-01
xmldom: @xmldom/xmldom: xmldom: DocumentType injection bypass via embedded line terminators
CVE-2026-83618 · Red Hat
vulnerability 1 high7.52026-09-01
firefox: thunderbird: Incorrect boundary conditions in the Layout: Grid component
CVE-2026-84126 · Red Hat
vulnerability 1 high7.52026-09-01
@xmldom/xmldom: xmldom: Denial of Service via crafted XML input
CVE-2026-83619 · Red Hat
vulnerability 1 high7.52026-09-01
firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15
CVE-2026-84143 · Red Hat
vulnerability 1 high7.52026-09-01
firefox: Sandbox escape due to use-after-free in the DOM: Security component
CVE-2026-84121 · Red Hat
vulnerability 1 high7.52026-09-01
firefox: Sandbox escape due to use-after-free in the DOM: Navigation component
CVE-2026-84119 · Red Hat
vulnerability 1 high7.52026-09-01
← PreviousPage 2 of 176Next →

Facets

Kind 98717 of 98717 claims

exploit49396

Severity 26070 of 98717 claims

high7071

Exploited 1731 of 98717 claims

yes1731

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1731

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22689

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19161

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing5730

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10