Zetlyn

CVE

What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.

Behind7 sourcesupdated 57m agofresh within 24h

freeSign in20878 claims are newer than 30 days and need a subscription

65,940things
8,540named by two sources or more
960conflicts
7sources

Only one source knows: Exploit-DB 23131 · GitHub advisories 30 · CISA Known Exploited Vulnerabilities 1004 · Metasploit exploit modules 679 · NVD 12667 · Red Hat 19884 · Write-ups 5

Covers. Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE. Excludes. Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
Compared · what is held against what, and from which column of each source
PropertyCISA Known Exploited VulnerabilitiesRed HatNVDGitHub advisoriesMetasploit exploit modulesExploit-DBWrite-ups
Cvssnot saidcvss3_scorecve.metrics.cvssMetricV31[].cvssData.baseScorecvss.scorenot saidnot saidnot said
Exploitedconst:yesnot saidnot saidnot saidnot saidnot saidnot said
Severitynot saidseveritynot saidseveritynot saidnot saidnot said

Everything else the sources say is shown side by side, and not compared.

source=zetlyn/cve-nvd ✕source=zetlyn/cve-metasploit ✕

EverythingExploited, and severearticle 10exploit 49396vulnerability 49311

Found

1–25 of 37
ThingKindSeverityCvssDate
SonicWall SMA1000 Appliances OS Command Injection Vulnerability
CVE-2026-83549 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules
vulnerability 2 exploit 1 —7.82026-09-01
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
CVE-2026-81578 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules
vulnerability 2 exploit 1 —9.82026-08-27
PaperCut NG/MF Unsafe Reflection Vulnerability
CVE-2026-82078 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules
vulnerability 2 exploit 1 —9.12026-08-27
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.
CVE-2026-66066 · NVD, Red Hat, Metasploit exploit modules
vulnerability 2 exploit 1 high8.92026-07-29
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
CVE-2026-41940 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules, Exploit-DB
vulnerability 2 exploit 2 —9.82026-04-28
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-20079 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules
vulnerability 2 exploit 1 —102026-03-04
GNU InetUtils Argument Injection Vulnerability
CVE-2026-24061 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules, Exploit-DB
vulnerability 2 exploit 2 —9.82026-01-21
ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or file extension of uploaded files. As a result, an attacker can upload a web shell file and subsequently upload a .htaccess file to enable direct access to it. Once accessed, the uploaded web shell allows remote code execution (RCE) on the server. Version 6.5.3 fixes the issue.
CVE-2025-68109 · NVD, Metasploit exploit modules
vulnerability 1 exploit 1 —9.12025-12-17
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23.
CVE-2025-66039 · NVD, Metasploit exploit modules
vulnerability 1 exploit 2 —9.82025-12-09
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, under certain conditions, may also be exploited by unauthenticated attackers. This vulnerability stems from weak regex validation in the cleanDangerousTwig method. This vulnerability is fixed in 1.8.0-beta.27.
CVE-2025-66294 · NVD, Metasploit exploit modules
vulnerability 1 exploit 1 —8.82025-12-01
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the form is now able to change the functioning of the form through modifying the content of the data[_json][header][form] which is the YAML frontmatter which includes the process section which dictates what happens after a user submits the form which include some important actions that could lead to further vulnerabilities. This vulnerability is fixed in 1.8.0-beta.27.
CVE-2025-66301 · NVD, Metasploit exploit modules
vulnerability 1 exploit 1 —9.62025-12-01
A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.
CVE-2025-12548 · NVD, Red Hat, Metasploit exploit modules
vulnerability 2 exploit 1 high92025-12-01
Sangoma FreePBX Authentication Bypass Vulnerability
CVE-2025-57819 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules, Exploit-DB
vulnerability 2 exploit 2 —9.82025-08-28
Samsung MagicINFO 9 Server Path Traversal Vulnerability
CVE-2024-7399 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules
vulnerability 2 exploit 1 —8.82024-08-12
Craft CMS Code Injection Vulnerability
CVE-2025-32432 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules, Exploit-DB
vulnerability 2 exploit 2 —102025-04-14
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.
CVE-2024-21626 · NVD, Metasploit exploit modules
vulnerability 1 exploit 1 —8.62024-01-31
Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
CVE-2023-46805 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules
vulnerability 2 exploit 1 —8.22024-01-10
RARLAB UnRAR Directory Traversal Vulnerability
CVE-2022-30333 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules
vulnerability 2 exploit 2 —7.52022-05-09
Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
CVE-2022-41352 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules
vulnerability 2 exploit 1 —9.82022-06-28
Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
CVE-2022-27925 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules
vulnerability 2 exploit 1 —7.22022-04-21
VMware Server Side Request Forgery in vRealize Operations Manager API
CVE-2021-21975 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules
vulnerability 2 exploit 1 —7.52021-03-30
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-27065 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules, Exploit-DB
vulnerability 2 exploit 2 —7.82021-03-02
Microsoft SMBv3 Remote Code Execution Vulnerability
CVE-2020-0796 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules, Exploit-DB
vulnerability 2 exploit 5 —102020-03-12
Oracle WebLogic Server, Injection
CVE-2019-2725 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules, Exploit-DB
vulnerability 2 exploit 3 —9.82019-04-23
Adobe Flash Player Arbitrary Code Execution Vulnerability
CVE-2016-4117 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules, Exploit-DB
vulnerability 2 exploit 2 —9.82016-04-27
← PreviousPage 1 of 2Next →

Facets

Kind 98717 of 98717 claims

exploit49396

Severity 26070 of 98717 claims

high7071
medium13318
low3886

Exploited 1731 of 98717 claims

yes1731

Sources

CISA Known Exploited Vulnerabilities primary

The only source that says a vulnerability is being exploited right now.

vulnerability · current1731

Red Hat high

Its own severity, and the packages it tracks a vulnerability in.

vulnerability · current22689

NVD high

The CVSS baseline, and an anchor for CVEs the other members never reach.

vulnerability · current19161

GitHub advisories high

The ecosystem packages no distribution ships.

vulnerability · failing5730

Metasploit exploit modules normal

Whether a module exists for the tool an attacker actually runs.

exploit · current2698

Exploit-DB normal

Whether working code exists at all, which is a different question from how severe it is.

exploit · current46698

Write-ups normal

The prose that explains a vulnerability after the advisories have stopped.

article · current10