CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 8h agofresh within 24h
66,157things
8,747named by two sources or more
1,072conflicts
7sources

Only one source knows: Exploit-DB 23133 · GitHub advisories 30 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12679 · Red Hat 19880 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

severity=unknown ✕severity=unknown ✕

EverythingExploited, and severearticle 10exploit 49396vulnerability 49746

Found

1–25 of 617
ThingKindSeverityCvssDate
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An...
CVE-2026-51893 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
Ragflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps...
CVE-2026-51895 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable...
CVE-2026-51882 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A...
CVE-2026-102731 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is...
CVE-2026-51883 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in...
CVE-2026-51879 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>.
CVE-2026-51892 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
In Devika v1.0, the Patcher Agent save_code_to_project function contains a path traversal...
CVE-2026-51874 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An...
CVE-2026-51876 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
deeptutor 1.4.0 contains code injection in ExecTool.execute. Through the live tutorbot WebSocket...
CVE-2026-51881 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password...
CVE-2026-103880 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Through the live...
CVE-2026-51880 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue...
CVE-2026-103877 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app)....
CVE-2026-51897 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable...
CVE-2026-51894 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file...
CVE-2026-51888 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a...
CVE-2026-103552 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in...
CVE-2026-51878 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A...
CVE-2026-103878 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
infiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py)....
CVE-2026-51896 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3...
CVE-2026-51884 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server...
CVE-2026-103885 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-02
Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function,...
CVE-2026-51873 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code...
CVE-2026-51886 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
In Devika v1.0, the Feature Agent save_code_to_project function contains a path traversal...
CVE-2026-51875 · GitHub advisories, NVD
vulnerability 2 unknown—2026-10-01
← PreviousPage 1 of 25Next →

Facets

Kind 99152 of 99152 claims

exploit49396

Severity 26286 of 99152 claims

Exploited 1731 of 99152 claims

yes1731

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1731

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22719

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19380

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing5916

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10