CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 7h agofresh within 24h
66,157things
8,747named by two sources or more
1,072conflicts
7sources

Only one source knows: Exploit-DB 23133 · GitHub advisories 30 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12679 · Red Hat 19880 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

severity=low ✕severity=low ✕

EverythingExploited, and severearticle 10exploit 49396vulnerability 49746

Found

1–25 of 3,812
ThingKindSeverityCvssDate
httpd: httpd: Information disclosure via session cookie leakage during internal redirects
CVE-2026-47360 · Red Hat, NVD, GitHub advisories
vulnerability 3 high / low3.7 / 7.52026-10-01
A security flaw has been discovered in itsourcecode Online Admission System Project 1.0. The...
CVE-2026-104606 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-02
httpd: httpd: Denial of service via forged Authorization headers in mod_auth_digest
CVE-2026-48005 · Red Hat, NVD, GitHub advisories
vulnerability 3 high / low3.7 / 7.52026-10-01
Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API...
CVE-2026-104415 · GitHub advisories, NVD
vulnerability 2 low3.12026-10-02
next: Next.js: Information disclosure via cache key omission in nested cache handlers
CVE-2026-103004 · Red Hat, NVD
vulnerability 2 low3.72026-10-01
A vulnerability was found in SourceCodester Student Result Management System 1.0. This affects an...
CVE-2026-104612 · GitHub advisories, NVD
vulnerability 2 low4.32026-10-02
httpd: httpd: Denial of Service via crafted HTTP response bodies in mod_proxy_html
CVE-2026-56449 · Red Hat, NVD, GitHub advisories
vulnerability 3 high / low3.7 / 7.52026-10-01
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress...
CVE-2026-102002 · GitHub advisories, NVD
vulnerability 2 low3.12026-10-02
httpd: httpd: arbitrary code execution via incorrect handler assignment during internal CGI redirects
CVE-2026-42356 · Red Hat, GitHub advisories, NVD
vulnerability 3 low3.72026-10-01
The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to...
CVE-2026-91023 · GitHub advisories, NVD
vulnerability 2 low3.12026-10-02
claude-code: claude-code: Security policy bypass via improper credential prioritization
CVE-2026-103012 · Red Hat, NVD
vulnerability 2 low3.32026-09-30
A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is...
CVE-2026-104625 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-02
openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing
CVE-2026-35189 · Red Hat, NVD, GitHub advisories
vulnerability 3 low / medium3.7 / 5.32026-09-29
A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function...
CVE-2026-104054 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-02
russh: russh: Authentication attempt limit bypass via unenforced maximum authentication attempts
CVE-2026-102825 · Red Hat, GitHub advisories, NVD
vulnerability 3 low3.72026-09-29
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')...
CVE-2026-39601 · GitHub advisories, NVD
vulnerability 2 low3.72026-10-02
chromium-browser: chromium-browser: Incorrect authorization in SiteIsolation
CVE-2026-102330 · Red Hat, NVD, GitHub advisories
vulnerability 3 low / medium3.1 / 6.52026-09-29
A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue...
CVE-2026-104614 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-02
openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting
CVE-2026-35191 · Red Hat, GitHub advisories, NVD
vulnerability 3 low3.72026-09-29
A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted...
CVE-2026-104053 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-02
chromium-browser: chromium-browser: Unchecked return value in Performance
CVE-2026-95316 · Red Hat, GitHub advisories, NVD
vulnerability 3 low2.9 / 3.32026-09-29
A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected...
CVE-2026-104052 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-02
poppler: poppler: Denial of Service via integer overflow in SplashClip
CVE-2026-102621 · Red Hat, GitHub advisories, NVD
vulnerability 3 low3.32026-09-29
A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This...
CVE-2026-104613 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-02
ImageMagick: ImageMagick: Information disclosure via crafted GIF file
CVE-2026-102635 · Red Hat, NVD, GitHub advisories
vulnerability 3 low / medium3.72026-09-29
← PreviousPage 1 of 153Next →

Facets

Kind 99152 of 99152 claims

exploit49396

Severity 26286 of 99152 claims

low3898

Exploited 1731 of 99152 claims

yes1731

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1731

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22719

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19380

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing5916

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10