CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 2h agofresh within 24h

freeSign in20878 claims are newer than 30 days and need a subscription

65,943things
8,553named by two sources or more
1,057conflicts
7sources

Only one source knows: Exploit-DB 23133 · GitHub advisories 30 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12654 · Red Hat 19885 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

severity=critical ✕kind=vulnerability ✕kind=vulnerability ✕

EverythingExploited, and severearticle 10exploit 49396vulnerability 49311

Found

1–25 of 178
ThingKindSeverityCvssDate
advisor-backend: Unsafe YAML deserialization of associate-editable Task playbook (yaml.Loader)
CVE-2026-76595 · Red Hat
vulnerability 1 critical—2026-09-02
org.springframework:spring-expression: Spring Framework: Safety Guard Bypass via SpEL Expression Compilation
CVE-2026-59283 · Red Hat
vulnerability 1 critical9.82026-08-27
org.springframework/spring-webmvc: Spring Framework: Remote Code Execution via improper path limitation in XsltView
CVE-2026-47884 · Red Hat, NVD
vulnerability 2 critical9.82026-08-27
chromium-browser: angle: ANGLE: Remote code execution via crafted HTML page
CVE-2026-79043 · Red Hat
vulnerability 1 critical9.62026-08-25
chromium-browser: angle: ANGLE: Arbitrary code execution in Google Chrome via crafted HTML page
CVE-2026-78978 · Red Hat
vulnerability 1 critical9.62026-08-25
chromium-browser: angle: ANGLE: Arbitrary code execution via use after free
CVE-2026-79275 · Red Hat
vulnerability 1 critical9.62026-08-25
chromium-browser: angle: ANGLE: Arbitrary code execution via type confusion in crafted HTML
CVE-2026-78905 · Red Hat
vulnerability 1 critical9.62026-08-25
gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection
CVE-2026-78676 · Red Hat
vulnerability 1 critical9.82026-08-25
chromium-browser: angle: ANGLE: Arbitrary code execution via a crafted HTML page
CVE-2026-79189 · Red Hat
vulnerability 1 critical9.62026-08-25
openshell: NVIDIA OpenShell: sandbox escape leading to code execution and privilege escalation
CVE-2026-65093 · Red Hat
vulnerability 1 critical9.92026-08-25
chromium-browser: angle: ANGLE: Arbitrary code execution via a crafted HTML page
CVE-2026-79019 · Red Hat
vulnerability 1 critical9.62026-08-25
chromium-browser: angle: ANGLE in Google Chrome: Arbitrary code execution via crafted HTML page
CVE-2026-79282 · Red Hat
vulnerability 1 critical9.62026-08-25
chromium-browser: angle: Chromium: Remote code execution via out-of-bounds write in ANGLE
CVE-2026-79131 · Red Hat
vulnerability 1 critical9.62026-08-25
NVIDIA OpenShell: NVIDIA OpenShell: sandbox provisioning API allows code execution via incomplete input filtering
CVE-2026-65083 · Red Hat
vulnerability 1 critical9.92026-08-25
chromium-browser: angle: ANGLE in Google Chrome: Arbitrary code execution via crafted HTML page
CVE-2026-78989 · Red Hat
vulnerability 1 critical9.62026-08-25
chromium-browser: angle: Google Chrome ANGLE: Arbitrary code execution via crafted HTML page
CVE-2026-79130 · Red Hat
vulnerability 1 critical9.62026-08-25
chromium-browser: angle: ANGLE: Arbitrary code execution via type confusion in crafted HTML page
CVE-2026-78904 · Red Hat
vulnerability 1 critical9.62026-08-25
chromium-browser: angle: ANGLE in Google Chrome: Arbitrary code execution via out-of-bounds write
CVE-2026-79127 · Red Hat
vulnerability 1 critical9.62026-08-25
chromium-browser: angle: Chromium: Web origin policy bypass via uninitialized resource in ANGLE
CVE-2026-79269 · Red Hat
vulnerability 1 critical9.32026-08-25
chromium-browser: ANGLE: angle: ANGLE: Arbitrary Code Execution via Crafted HTML Page
CVE-2026-79142 · Red Hat
vulnerability 1 critical9.62026-08-25
ANGLE: chromium-browser: angle: ANGLE: Arbitrary code execution via use-after-free vulnerability
CVE-2026-79149 · Red Hat
vulnerability 1 critical9.62026-08-25
chromium-browser: angle: ANGLE in Google Chrome: Arbitrary code execution via improper input validation
CVE-2026-79230 · Red Hat
vulnerability 1 critical9.62026-08-25
chromium-browser: angle: chromium-browser: Arbitrary Code Execution via out-of-bounds write in ANGLE
CVE-2026-79138 · Red Hat
vulnerability 1 critical9.62026-08-25
chromium-browser: angle: Chromium ANGLE: Arbitrary code execution via crafted HTML page
CVE-2026-79188 · Red Hat
vulnerability 1 critical9.62026-08-25
incus: Incus has arbitrary file read+write on host via templates/ symlink in malicious image
CVE-2026-48752 · Red Hat, NVD
vulnerability 2 critical9.92026-08-21
← PreviousPage 1 of 8Next →

Facets

Kind 98717 of 98717 claims

exploit49396

Severity 26070 of 98717 claims

Exploited 1731 of 98717 claims

yes1731

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1731

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22689

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19161

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing5730

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10