Zetlyn

CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 43m agofresh within 24h

freeSign in20878 claims are newer than 30 days and need a subscription

65,940things
8,540named by two sources or more
960conflicts
7sources

Only one source knows: Exploit-DB 23131 · GitHub advisories 30 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12667 · Red Hat 19884 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

severity=low ✕

EverythingExploited, and severearticle 10exploit 49396vulnerability 49311

Found

1–25 of 3,371
ThingKindSeverityCvssDate
jenkins: Jenkins: Unauthorized configuration modification due to incorrect permission checks
CVE-2026-84653 · Red Hat, NVD
vulnerability 2 low2.7 / 3.52026-09-02
firefox: thunderbird: Integer overflow in the Graphics: ImageLib component
CVE-2026-84141 · Red Hat
vulnerability 1 low3.42026-09-01
firefox: thunderbird: Site isolation issue in the DOM: Push Subscriptions component
CVE-2026-84133 · Red Hat
vulnerability 1 low3.42026-09-01
firefox: thunderbird: Other issue in the Profile Backup component
CVE-2026-84134 · Red Hat
vulnerability 1 low3.42026-09-01
firefox: thunderbird: Site isolation issue in the DOM: Navigation component
CVE-2026-84140 · Red Hat
vulnerability 1 low3.42026-09-01
joi: @hapi/joi: joi: Prototype pollution via untrusted input in schema configuration
CVE-2026-84368 · Red Hat
vulnerability 1 low3.72026-09-01
thunderbird: Allowed UNC hostnames for attachments interpreted as a regular expression
CVE-2026-84642 · Red Hat
vulnerability 1 low3.42026-09-01
thunderbird: Information disclosure due to malicious IMAP server response
CVE-2026-84641 · Red Hat
vulnerability 1 low3.42026-09-01
chromium-browser: chromium-browser: UI misrepresentation in FullScreen
CVE-2026-84356 · Red Hat
vulnerability 1 low4.32026-09-01
otp: inets: OTP inets httpd: HTTP Request Smuggling vulnerability via malformed headers
CVE-2026-73276 · Red Hat
vulnerability 1 low5.42026-09-01
chromium-browser: chromium-browser: Confused deputy in CredentialProvider
CVE-2026-84329 · Red Hat
vulnerability 1 low2.82026-09-01
firefox: thunderbird: Denial-of-service in the PDF Viewer component
CVE-2026-84138 · Red Hat
vulnerability 1 low3.42026-09-01
firefox: Other issue in Firefox Focus for Android
CVE-2026-84135 · Red Hat
vulnerability 1 low3.42026-09-01
firefox: thunderbird: Other issue in the DOM: Navigation component
CVE-2026-84136 · Red Hat
vulnerability 1 low3.42026-09-01
firefox: thunderbird: Spoofing issue in the DOM: Core & HTML component
CVE-2026-84137 · Red Hat
vulnerability 1 low3.42026-09-01
firefox: thunderbird: Clickjacking issue in the DOM: Events component
CVE-2026-84139 · Red Hat
vulnerability 1 low3.42026-09-01
valkey: Valkey: Use-after-free vulnerability in Blocked-on-keys subsystem
CVE-2026-82631 · Red Hat
vulnerability 1 low—2026-08-31
qs: qs: Denial of Service via array limit bypass in query string parsing
CVE-2026-82562 · Red Hat
vulnerability 1 low3.72026-08-29
kernel: accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer
CVE-2026-80657 · Red Hat
vulnerability 1 low5.52026-08-28
kernel: ACPI: processor_idle: Mark LPI enter functions as __cpuidle
CVE-2026-80611 · Red Hat
vulnerability 1 low5.52026-08-28
kernel: scsi: hisi_sas: Add slave_destroy interface for v3 hw
CVE-2026-80653 · Red Hat
vulnerability 1 low5.52026-08-28
kernel: HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()
CVE-2026-80605 · Red Hat
vulnerability 1 low5.52026-08-28
dovecot: dovecot: lda_mailbox_autocreate can bypass acl restrictions
CVE-2026-40204 · Red Hat
vulnerability 1 low3.12026-08-28
multer: Multer: File size limit bypass via asynchronous file filter race condition
CVE-2026-77063 · Red Hat
vulnerability 1 low3.72026-08-28
dovecot: Dovecot: Information disclosure via timing attack on `doveadm` password/API key comparison
CVE-2026-42393 · Red Hat
vulnerability 1 low3.12026-08-28
← PreviousPage 1 of 135Next →

Facets

Kind 98717 of 98717 claims

exploit49396

Severity 26070 of 98717 claims

low3886

Exploited 1731 of 98717 claims

yes1731

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1731

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22689

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19161

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing5730

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10