CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 4h agofresh within 24h
66,364things
9,006named by two sources or more
1,118conflicts
7sources

Only one source knows: Exploit-DB 23133 · GitHub advisories 35 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12674 · Red Hat 19828 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

severity=low ✕severity=low ✕severity=low ✕

EverythingExploited, and severearticle 10exploit 49396vulnerability 50274

Found

1–25 of 3,828
ThingKindSeverityCvssDate
ImageMagick: ImageMagick: Security policy bypass via alternate XML DOCTYPE declaration
CVE-2026-105083 · Red Hat, GitHub advisories, NVD
vulnerability 3 low3.92026-10-03
Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID...
CVE-2026-105051 · GitHub advisories, NVD
vulnerability 2 low1.92026-10-02
next: Next.js: Information disclosure via SSRF in Image Optimization
CVE-2026-94483 · Red Hat, NVD
vulnerability 2 low3.72026-10-02
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file...
CVE-2026-80517 · GitHub advisories, NVD
vulnerability 2 low3.52026-10-03
next: Next.js: Information disclosure via shared cache fills in Draft Mode
CVE-2026-94544 · Red Hat, NVD
vulnerability 2 low3.72026-10-02
A flaw has been found in Linux Mint Xreader up to 4.6.5. This issue affects the function...
CVE-2026-104982 · GitHub advisories, NVD
vulnerability 2 low4.32026-10-03
httpd: httpd: Information disclosure via session cookie leakage during internal redirects
CVE-2026-47360 · Red Hat, NVD, GitHub advisories
vulnerability 3 high / low3.7 / 7.52026-10-01
A vulnerability has been found in Linux Mint Xreader up to 4.6.9. Impacted is the function...
CVE-2026-104983 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-03
httpd: httpd: Denial of service via forged Authorization headers in mod_auth_digest
CVE-2026-48005 · Red Hat, NVD, GitHub advisories
vulnerability 3 high / low3.7 / 7.52026-10-01
OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated...
CVE-2026-105118 · GitHub advisories, NVD
vulnerability 2 low4.72026-10-03
next: Next.js: Information disclosure via cache key omission in nested cache handlers
CVE-2026-103004 · Red Hat, NVD
vulnerability 2 low3.72026-10-01
MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are...
CVE-2026-105043 · GitHub advisories, NVD
vulnerability 2 low3.62026-10-02
httpd: httpd: Denial of Service via crafted HTTP response bodies in mod_proxy_html
CVE-2026-56449 · Red Hat, NVD, GitHub advisories
vulnerability 3 high / low3.7 / 7.52026-10-01
The MetForm WordPress plugin before 4.3.1 does not properly restrict access to a debug file it...
CVE-2026-86834 · GitHub advisories, NVD
vulnerability 2 low3.72026-10-03
httpd: httpd: arbitrary code execution via incorrect handler assignment during internal CGI redirects
CVE-2026-42356 · Red Hat, GitHub advisories, NVD
vulnerability 3 low3.72026-10-01
claude-code: claude-code: Security policy bypass via improper credential prioritization
CVE-2026-103012 · Red Hat, NVD
vulnerability 2 low3.32026-09-30
The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code...
CVE-2026-96962 · GitHub advisories, NVD
vulnerability 2 low3.72026-10-03
openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing
CVE-2026-35189 · Red Hat, NVD, GitHub advisories
vulnerability 3 low / medium3.7 / 5.32026-09-29
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret...
CVE-2026-80518 · GitHub advisories, NVD
vulnerability 2 low3.72026-10-03
russh: russh: Authentication attempt limit bypass via unenforced maximum authentication attempts
CVE-2026-102825 · Red Hat, GitHub advisories, NVD
vulnerability 3 low3.72026-09-29
A security flaw has been discovered in itsourcecode Online Admission System Project 1.0. The...
CVE-2026-104606 · GitHub advisories, NVD
vulnerability 2 low6.32026-10-02
chromium-browser: chromium-browser: Incorrect authorization in SiteIsolation
CVE-2026-102330 · Red Hat, NVD, GitHub advisories
vulnerability 3 low / medium3.1 / 6.52026-09-29
Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API...
CVE-2026-104415 · GitHub advisories, NVD
vulnerability 2 low3.12026-10-02
openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting
CVE-2026-35191 · Red Hat, GitHub advisories, NVD
vulnerability 3 low3.72026-09-29
A vulnerability was found in SourceCodester Student Result Management System 1.0. This affects an...
CVE-2026-104612 · GitHub advisories, NVD
vulnerability 2 low4.32026-10-02
← PreviousPage 1 of 154Next →

Facets

Kind 99680 of 99680 claims

exploit49396

Severity 26560 of 99680 claims

low3915

Exploited 1733 of 99680 claims

yes1733

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1733

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22765

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19632

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing6144

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10