Zetlyn

CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 83m agofresh within 24h

freeSign in20878 claims are newer than 30 days and need a subscription

65,943things
8,553named by two sources or more
1,057conflicts
7sources

Only one source knows: Exploit-DB 23133 · GitHub advisories 30 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12654 · Red Hat 19885 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

source=zetlyn/cve-ghsa ✕severity=high ✕

EverythingExploited, and severearticle 10exploit 49396vulnerability 49311

Found

1–7 of 7
ThingKindSeverityCvssDate
fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies
CVE-2026-84394 · Red Hat, GitHub advisories
vulnerability 2 high7.52026-09-02
fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization
CVE-2026-84292 · Red Hat, NVD, GitHub advisories
vulnerability 3 high7.52026-09-02
oauth-proxy: Open Redirect via /\ and /\t Bypass in Post-Login Redirect
CVE-2026-83589 · Red Hat, NVD, GitHub advisories
vulnerability 3 high / medium6.12026-08-31
compliance-trestle: Trestle: Arbitrary file write via path traversal in author generate commands
CVE-2026-57171 · Red Hat, GitHub advisories
vulnerability 3 high7.7 / 8.42026-08-25
compliance-trestle: Trestle: Arbitrary code execution via Server-Side Template Injection
CVE-2026-57170 · Red Hat, GitHub advisories
vulnerability 3 high7.82026-08-25
webpack-dev-middleware: webpack-dev-middleware: Information Disclosure via Path Traversal
CVE-2026-76844 · Red Hat, NVD, GitHub advisories
vulnerability 3 high7.4 / 8.62026-08-24
podman: Podman: Information disclosure via malicious container image environment variables
CVE-2026-57231 · Red Hat, GitHub advisories
vulnerability 3 high7.52026-06-26

Facets

Kind 98717 of 98717 claims

exploit49396

Severity 26070 of 98717 claims

high7071

Exploited 1731 of 98717 claims

yes1731

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1731

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22689

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19161

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing5730

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10