CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 3h agofresh within 24h
66,364things
9,006named by two sources or more
1,118conflicts
7sources

Only one source knows: Exploit-DB 23133 · GitHub advisories 35 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12674 · Red Hat 19828 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

severity=low ✕severity=low ✕

EverythingExploited, and severearticle 10exploit 49396vulnerability 50274

Found

26–50 of 3,828
ThingKindSeverityCvssDate
chromium-browser: chromium-browser: Unchecked return value in Performance
CVE-2026-95316 · Red Hat, GitHub advisories, NVD
vulnerability 3 low2.9 / 3.32026-09-29
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress...
CVE-2026-102002 · GitHub advisories, NVD
vulnerability 2 low3.12026-10-02
poppler: poppler: Denial of Service via integer overflow in SplashClip
CVE-2026-102621 · Red Hat, GitHub advisories, NVD
vulnerability 3 low3.32026-09-29
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
CVE-2026-74802 · GitHub advisories
vulnerability 1 low—2026-10-02
ImageMagick: ImageMagick: Information disclosure via crafted GIF file
CVE-2026-102635 · Red Hat, NVD, GitHub advisories
vulnerability 3 low / medium3.72026-09-29
Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to...
CVE-2026-104994 · GitHub advisories, NVD
vulnerability 2 low2.52026-10-02
russh: russh: Denial of Service via improper MAC negotiation with block ciphers
CVE-2026-102822 · Red Hat, GitHub advisories, NVD
vulnerability 3 low3.72026-09-29
The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to...
CVE-2026-91023 · GitHub advisories, NVD
vulnerability 2 low3.12026-10-02
vllm: vLLM: Denial of service via sampler subclass decoder limit bypass
CVE-2026-100649 · Red Hat, NVD, GitHub advisories
vulnerability 4 low / medium3.72026-09-26
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state
CVE-2026-104855 · GitHub advisories, Red Hat, NVD
vulnerability 3 low / medium4.72026-10-02
php: php: Denial of Service via out-of-bounds read in mysqlnd wire protocol parser
CVE-2025-1218 · Red Hat, NVD
vulnerability 2 low3.4 / 3.72026-09-25
A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is...
CVE-2026-104625 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-02
rabbitmq-server: rabbitmq-server: Unauthorized user impersonation via stale OAuth token refresh
CVE-2026-67420 · Red Hat, NVD
vulnerability 2 low3.12026-09-25
A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function...
CVE-2026-104054 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-02
kernel: cifs: validate idmap key payload length
CVE-2026-93785 · Red Hat, NVD, GitHub advisories
vulnerability 4 low / unknown5.52026-09-24
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')...
CVE-2026-39601 · GitHub advisories, NVD
vulnerability 2 low3.72026-10-02
kernel: wifi: iwlwifi: acpi: validate WGDS table revision index
CVE-2026-93788 · Red Hat, NVD, GitHub advisories
vulnerability 4 low / unknown5.52026-09-24
A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue...
CVE-2026-104614 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-02
open-cluster-management: Open-Cluster-Management: Privilege escalation and unauthorized resource modification in gRPC broker
CVE-2026-91182 · Red Hat
vulnerability 1 low3.32026-09-23
A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted...
CVE-2026-104053 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-02
hpack: golang.org/x/net/http2/hpack: hpack: Denial of Service via malformed HTTP/2 header encoding
CVE-2026-59980 · Red Hat, NVD, GitHub advisories
vulnerability 4 low / medium5.32026-09-23
A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected...
CVE-2026-104052 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-02
busybox: busybox: dpkg write_status_file() stale cursor causes out-of-bounds read and status file corruption
CVE-2026-88841 · Red Hat
vulnerability 1 low3.32026-09-23
A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This...
CVE-2026-104613 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-02
gimp: gimp: one-byte out-of-bounds heap read in the uncompressed DDS loader
CVE-2026-96546 · Red Hat, GitHub advisories, NVD
vulnerability 4 low2.52026-09-22

Facets

Kind 99680 of 99680 claims

exploit49396

Severity 26560 of 99680 claims

low3915

Exploited 1733 of 99680 claims

yes1733

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1733

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22765

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19632

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing6144

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10