CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 5h agofresh within 24h
65,943things
8,553named by two sources or more
1,057conflicts
7sources

Only one source knows: Exploit-DB 23133 · GitHub advisories 30 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12654 · Red Hat 19885 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

severity=low ✕source=zetlyn/cve-nvd ✕

EverythingExploited, and severearticle 10exploit 49396vulnerability 49311

Found

1–25 of 93
ThingKindSeverityCvssDate
In the Linux kernel, the following vulnerability has been resolved: timers/itimer: Zero-init old itimerval before copy to userspace On native sparc64, struct __kernel_old_timeval contains a four-byte hole after tv_usec because tv_sec is 64-bit while __kernel_suseconds_t is 32-bit. put_itimerval() fills only the named fields in a stack-allocated __kernel_old_itimerval and copies the entire object to userspace, so getitimer() can expose the two padding holes. Zero-initialize the aggregate before assigning the fields so implicit padding is deterministic before it crosses the user/kernel boundary.
CVE-2026-89765 · NVD, Red Hat · matched kernel
vulnerability 2 low5.52026-09-11
kernel: Linux kernel: Denial of Service in BPF redirect helpers
CVE-2026-68337 · Red Hat, NVD · matched kernel
vulnerability 2 low4.42026-08-10
In the Linux kernel, the following vulnerability has been resolved: net: phylink: correctly validate returned PCS in phylink_inband_caps In phylink_inband_caps(), the PCS returned by mac_select_pcs is only checked if NULL but mac_select_pcs can also return an error pointer. This can cause a kernel panic as phylink_pcs_inband_caps() only checks if passed PCS is not NULL and directly dereference ops from the phylink_pcs struct. Use the IS_ERR_OR_NULL macro to address both case where the returned PCS can be NULL or an error pointer and prevent a kernel panic.
CVE-2026-80993 · NVD, Red Hat · matched kernel
vulnerability 2 low5.52026-09-11
kernel: Linux kernel: Denial of Service in BPF due to improper context access
CVE-2025-38591 · Red Hat, NVD · matched kernel
vulnerability 2 low4.4 / 5.52025-08-19
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: pci: fix resource leak on failed NAPI setup rtw_pci_probe() allocates PCI resources through rtw_pci_setup_resource() before it sets up NAPI. If rtw_pci_napi_init() fails, the error path jumps straight to err_pci_declaim and skips rtw_pci_destroy(), leaving the PCI resources allocated by rtw_pci_setup_resource() behind. Add a dedicated cleanup label for the NAPI setup failure path so probe destroys the PCI resources. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing current mainline kernels. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1-rc7. An x86_64 allyesconfig build showed no new warnings. As we do not have a suitable rtw88 PCI board to test with, no runtime testing was able to be performed.
CVE-2026-80940 · NVD, Red Hat · matched kernel
vulnerability 2 low5.52026-09-11
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: acpi: validate WGDS table revision index Check tbl_rev bounds before BIT(tbl_rev) to avoid undefined shifts when firmware reports an invalid revision value.
CVE-2026-93788 · NVD, Red Hat, GitHub advisories · matched kernel
vulnerability 4 low / unknown5.52026-09-24
kernel: efivarfs: Rate limit statfs() handler
CVE-2026-89604 · Red Hat, NVD · matched kernel
vulnerability 2 low5.52026-09-11
In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Add a NULL check for sst_inst[] To be consistent with other places, add a NULL check for failed socket loading by checking isst_common.sst_inst[].
CVE-2026-89439 · NVD, Red Hat · matched kernel
vulnerability 2 low5.52026-09-11
In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-base: Fix resource leak on module load failure We need to properly clean up the SMBIOS request and the privacy driver when the module load fails.
CVE-2026-93130 · NVD, Red Hat · matched kernel
vulnerability 2 low5.52026-09-17
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Proper rollback if the ioremap fails bnxt_qplib_alloc_dpi returns success even if ioremap fails. Add the proper rollback when the ioremap fails and return -ENOMEM status.
CVE-2026-72496 · NVD, Red Hat · matched kernel
vulnerability 2 low5.5 / 9.22026-08-15
kernel: cifs: validate idmap key payload length
CVE-2026-93785 · Red Hat, NVD, GitHub advisories · matched kernel
vulnerability 4 low / unknown5.52026-09-24
kernel: SUNRPC: reject duplicate CREDS_VALUE options
CVE-2026-89539 · Red Hat, NVD · matched kernel
vulnerability 2 low5.52026-09-11
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix memory leak in guest debug handling bp_data is freed only for the error case by kfree(bp_data). Every successful KVM_SET_GUEST_DEBUG will leak bp_data.
CVE-2026-89925 · NVD, Red Hat · matched kernel
vulnerability 2 low5.52026-09-16
kernel: iommufd: Avoid locking internal accesses during unmap
CVE-2026-89447 · Red Hat, NVD · matched kernel
vulnerability 2 low5.52026-09-11
kernel: ecryptfs: release message context on send failure
CVE-2026-89605 · Red Hat, NVD · matched kernel
vulnerability 2 low5.5 / 7.82026-09-11
kernel: NTB: ntb_transport: Reject oversized TX buffers
CVE-2026-80987 · Red Hat, NVD · matched kernel
vulnerability 2 low5.5 / 7.52026-09-11
kernel: params: fix charp corruption on allocation failure
CVE-2026-89552 · Red Hat, NVD · matched kernel
vulnerability 2 low5.52026-09-11
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix crash passing ERR_PTR to kthread_stop() event_test_stuff() calls kthread_run() and unconditionally passes the returned task_struct pointer to kthread_stop(). kthread_run() returns an error pointer such as ERR_PTR(-ENOMEM) when kthread creation fails, for example under memory pressure during the boot-time event self-test. kthread_stop() then dereferences the invalid pointer, crashing the kernel. Check the result of kthread_run() before passing it to kthread_stop(). Use WARN_ON() so that a failure to create the self-test thread does not go unnoticed, matching the ring-buffer self-test fix in commit 91542863abad ("ring-buffer: Fix crash passing ERR_PTR to kthread_stop()").
CVE-2026-89749 · NVD, Red Hat · matched kernel
vulnerability 2 low5.52026-09-11
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Free cpu_buffer::free_page with subbuf_order When sub-buffers use an order greater than 0, cpu_buffer->free_page is allocated with subbuf_order. Use the correct order for cpu_buffer->free_page.
CVE-2026-89502 · NVD, Red Hat · matched kernel
vulnerability 2 low5.52026-09-11
kernel: netfilter: nft_counter: serialize reset with spinlock
CVE-2026-45897 · Red Hat, NVD · matched kernel
vulnerability 2 low5.52026-05-27
kernel: cpuset: fix warning when disabling remote partition
CVE-2025-71142 · Red Hat, NVD · matched kernel
vulnerability 2 low5.52026-01-14
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Skip Update HDCP Config In Transition State Transition state does not have a valid dm_stream_ctx that should skip configuring HDCP routine. The routine is valid to go through only when a valid stream is created.
CVE-2026-89773 · NVD, Red Hat · matched kernel
vulnerability 2 low5.52026-09-11
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() The memory allocated for buf is not freed in some of the error paths in brcmf_sdio_read_control(). Fix that by adding vfree() calls. [arend: rework as suggested by Johannes]
CVE-2026-80949 · NVD, Red Hat · matched kernel
vulnerability 2 low5.52026-09-11
kernel: fbdev: ssd1307fb: defer I2C transfers from damage callbacks
CVE-2026-89598 · Red Hat, NVD · matched kernel
vulnerability 2 low5.52026-09-11
kernel: iommufd: Release current IOAS on xa_store() failure
CVE-2026-89446 · Red Hat, NVD · matched kernel
vulnerability 2 low5.52026-09-11
← PreviousPage 1 of 4Next →

Facets

Kind 98717 of 98717 claims

exploit49396

Severity 26070 of 98717 claims

low3886

Exploited 1731 of 98717 claims

yes1731

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1731

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22689

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19161

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing5730

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10