Zetlyn

CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 43m agofresh within 24h

freeSign in20878 claims are newer than 30 days and need a subscription

65,940things
8,540named by two sources or more
960conflicts
7sources

Only one source knows: Exploit-DB 23131 · GitHub advisories 30 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12667 · Red Hat 19884 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

severity=high ✕

EverythingExploited, and severearticle 10exploit 49396vulnerability 49311

Found

1–25 of 4,384
ThingKindSeverityCvssDate
jenkins: Jenkins: Remote Code Execution via crafted configuration files
CVE-2026-84645 · Red Hat, NVD
vulnerability 2 high8.82026-09-02
util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks
CVE-2026-76642 · Red Hat, NVD
vulnerability 2 high7.82026-09-02
jenkins: Jenkins: Privilege escalation via agent configuration overwrite
CVE-2026-84651 · Red Hat, NVD
vulnerability 2 high6.3 / 8.12026-09-02
jenkins: stapler: Stapler: Cross-site request forgery token disclosure allows session hijacking
CVE-2026-84649 · Red Hat
vulnerability 1 high8.12026-09-02
Stapler: Jenkins: Stapler: Unintended configuration object instantiation via form data binding
CVE-2026-84647 · Red Hat
vulnerability 1 high8.52026-09-02
fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies
CVE-2026-84394 · Red Hat, GitHub advisories
vulnerability 2 high7.52026-09-02
util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks
CVE-2026-78409 · Red Hat
vulnerability 1 high72026-09-02
grafana: Grafana: Session takeover via Auth Proxy cache key collision
CVE-2026-14199 · Red Hat, NVD
vulnerability 2 high7.12026-09-02
httpx2: httpcore2: HTTPX2: WebSocket traffic sent in plaintext via SOCKS5 proxy due to TLS failure
CVE-2026-84381 · Red Hat
vulnerability 1 high8.12026-09-02
httpx2: HTTPX2: Denial of Service via streaming response decompression memory amplification
CVE-2026-84382 · Red Hat
vulnerability 1 high7.52026-09-02
util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection
CVE-2026-78410 · Red Hat
vulnerability 1 high7.82026-09-02
jenkins: Jenkins: Stored cross-site scripting vulnerability in system log viewer
CVE-2026-84648 · Red Hat, NVD
vulnerability 2 high7.3 / 8.82026-09-02
util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority
CVE-2026-78408 · Red Hat
vulnerability 1 high7.92026-09-02
jenkins: Jenkins: Configuration overwrite via transient field deserialization
CVE-2026-84650 · Red Hat, NVD
vulnerability 2 high8.82026-09-02
fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization
CVE-2026-84292 · Red Hat, NVD, GitHub advisories
vulnerability 3 high7.52026-09-02
jenkins: Jenkins: Authentication bypass via session cookie non-rotation
CVE-2026-84652 · Red Hat, NVD
vulnerability 2 high7.3 / 7.52026-09-02
advisor-backend: advisor-backend: Unauthenticated /private/import_content/ endpoint allows global rule-catalogue overwrite
CVE-2026-76594 · Red Hat
vulnerability 1 high8.12026-09-02
xmldom: xmldom: XML Structure Injection via Unvalidated Processing Instruction Targets
CVE-2026-83616 · Red Hat
vulnerability 1 high7.52026-09-01
xmldom: @xmldom/xmldom: xmldom: Denial of Service via quadratic memory consumption
CVE-2026-83615 · Red Hat
vulnerability 1 high7.52026-09-01
composer: Composer: Arbitrary code execution via malicious Perforce source URL
CVE-2026-84361 · Red Hat
vulnerability 1 high7.32026-09-01
chromium-browser: chromium-browser: Use after free in Browser
CVE-2026-84349 · Red Hat
vulnerability 1 high82026-09-01
xmldom: @xmldom/xmldom: xmldom: Attribute injection allows client-side script execution
CVE-2026-83605 · Red Hat
vulnerability 1 high8.12026-09-01
firefox: Use-after-free in the DOM: Core & HTML component
CVE-2026-84124 · Red Hat
vulnerability 1 high7.52026-09-01
inets: Erlang/OTP inets httpd: Directory protection bypass allows information disclosure
CVE-2026-66835 · Red Hat
vulnerability 1 high7.52026-09-01
firefox: thunderbird: Use-after-free in the JavaScript: GC component
CVE-2026-84118 · Red Hat
vulnerability 1 high7.52026-09-01
← PreviousPage 1 of 176Next →

Facets

Kind 98717 of 98717 claims

exploit49396

Severity 26070 of 98717 claims

high7071

Exploited 1731 of 98717 claims

yes1731

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1731

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22689

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19161

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing5730

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10