Patch Advisories

Microsoft's monthly release and every non-Microsoft advisory, in one browser. Switch scope below; everything under it follows.

At a glance — everything in scope

  • 1,756 Entries in scope 448 Microsoft · 1,308 Non-Microsoft
  • 355 Exigent KEV-listed, exploited, CVSS ≥ 9.0 and a live urgency signal — of 1,752 entries with a resolved score; 4 not yet scored and so not counted
  • 238 Ransomware-linked CISA records a known ransomware campaign using these
  • 1,293 Past CISA deadline Overdue against CISA's federal remediation date. Microsoft CVEs carry no CISA deadline, so none of them are counted here.

EVULNABLE Risk across both halves

Immediate 465 26% · 85-100 Urgent 844 48% · 65-84 Elevated 387 22% · 10-64 Routine 59 3% · 4-9 Informational 1 <1% · 0-3 Exigent flag 362 counted within Immediate

Scope

Microsoft only, non-Microsoft, or both. Everything below follows the choice.

Why the two halves are ranked separately

One browser over both halves — search, filter and export Microsoft and non-Microsoft CVEs together. Ranking stays per half: every KEV entry is exploited by construction, which floors it above every Microsoft CVE, so one merged leaderboard would just rebuild the Dashboard.

Browse every advisory

Microsoft's release and every non-Microsoft CISA KEV advisory in one list, ranked on one EVULNABLE Risk scale. Ranking is not the point here — see the two Patch First sections below for that — searching across both is.

Risk band
Source
Exploitation

1,293 of 1,756 entries match the current filters, sorted by EVULNABLE Risk.

Microsoft and non-Microsoft advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Source Vendor Title EVRS CVSS EPSSFlags CISA due
CVE-2025-54253 Non-Microsoft Adobe Adobe Experience Manager Forms Code Execution Vulnerability 87 Immediate 10.0 0.875 (99.75th pctl) Overdue 2025-11-05
CVE-2022-27924 Non-Microsoft Synacor Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability 87 Immediate 7.5 0.854 (99.7th pctl) RansomwareOverdue 2022-08-25
CVE-2023-27351 Non-Microsoft PaperCut PaperCut NG/MF Improper Authentication Vulnerability 87 Immediate 7.5 0.781 (99.54th pctl) RansomwareOverdue 2026-05-04
CVE-2021-42258 Non-Microsoft BQE BQE BillQuick Web Suite SQL Injection Vulnerability 87 Immediate 9.8 0.744 (99.45th pctl) ExigentRansomwareOverdue 2021-11-17
CVE-2023-1389 Non-Microsoft TP-Link TP-Link Archer AX-21 Command Injection Vulnerability 86 Immediate 8.8 0.999 (99.99th pctl) Overdue 2023-05-22
CVE-2023-4863 Non-Microsoft Google Google Chromium WebP Heap-Based Buffer Overflow Vulnerability 86 Immediate 8.8 0.999 (99.98th pctl) Overdue 2023-10-04
CVE-2024-4879 Non-Microsoft ServiceNow ServiceNow Improper Input Validation Vulnerability 86 Immediate 9.3 0.999 (99.98th pctl) ExigentOverdue 2024-08-19
CVE-2016-6277 Non-Microsoft NETGEAR NETGEAR Multiple Routers Remote Code Execution Vulnerability 86 Immediate 8.8 0.998 (99.96th pctl) Overdue 2022-09-07
CVE-2024-5217 Non-Microsoft ServiceNow ServiceNow Incomplete List of Disallowed Inputs Vulnerability 86 Immediate 9.2 0.996 (99.95th pctl) ExigentOverdue 2024-08-19
CVE-2011-0611 Non-Microsoft Adobe Adobe Flash Player Remote Code Execution Vulnerability 86 Immediate 8.8 0.994 (99.94th pctl) Overdue 2022-03-24
CVE-2020-11978 Non-Microsoft Apache Apache Airflow Command Injection 86 Immediate 8.8 0.992 (99.93rd pctl) Overdue 2022-07-18
CVE-2012-3152 Non-Microsoft Oracle Oracle Fusion Middleware Unspecified Vulnerability 86 Immediate 9.1 0.988 (99.92nd pctl) ExigentOverdue 2022-05-03
CVE-2025-0108 Non-Microsoft Palo Alto Networks Palo Alto Networks PAN-OS Authentication Bypass Vulnerability 86 Immediate 8.8 0.985 (99.92nd pctl) Overdue 2025-03-11
CVE-2021-45382 Non-Microsoft D-Link D-Link Multiple Routers Remote Code Execution Vulnerability 86 Immediate 9.8 0.978 (99.9th pctl) ExigentOverdue 2022-04-25
CVE-2015-7450 Non-Microsoft IBM IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. 86 Immediate 9.8 0.977 (99.9th pctl) ExigentOverdue 2022-07-10
CVE-2021-36380 Non-Microsoft Sunhillo Sunhillo SureLine OS Command Injection Vulnerablity 86 Immediate 9.8 0.976 (99.9th pctl) ExigentOverdue 2024-03-26
CVE-2016-3714 Non-Microsoft ImageMagick ImageMagick Improper Input Validation Vulnerability 86 Immediate 8.4 0.975 (99.9th pctl) Overdue 2024-09-30
CVE-2024-4358 Non-Microsoft Progress Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability 86 Immediate 9.8 0.975 (99.9th pctl) ExigentOverdue 2024-07-04
CVE-2007-3010 Non-Microsoft Alcatel Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability 86 Immediate 9.8 0.974 (99.89th pctl) ExigentOverdue 2022-05-06
CVE-2023-27524 Non-Microsoft Apache Apache Superset Insecure Default Initialization of Resource Vulnerability 86 Immediate 9.8 0.974 (99.89th pctl) ExigentOverdue 2024-01-29
CVE-2021-22054 Non-Microsoft Omnissa Omnissa Workspace ONE Server-Side Request Forgery 86 Immediate 7.5 0.974 (99.89th pctl) Overdue 2026-03-23
CVE-2023-24489 Non-Microsoft Citrix Citrix Content Collaboration ShareFile Improper Access Control Vulnerability 86 Immediate 9.8 0.973 (99.89th pctl) ExigentOverdue 2023-09-06
CVE-2020-25213 Non-Microsoft WordPress WordPress File Manager Plugin Remote Code Execution Vulnerability 86 Immediate 9.8 0.973 (99.89th pctl) ExigentOverdue 2022-05-03
CVE-2019-7256 Non-Microsoft Nice Nice Linear eMerge E3-Series OS Command Injection Vulnerability 86 Immediate 9.8 0.971 (99.89th pctl) ExigentOverdue 2024-04-15
CVE-2020-2555 Non-Microsoft Oracle Oracle Multiple Products Remote Code Execution Vulnerability 86 Immediate 9.8 0.971 (99.89th pctl) ExigentOverdue 2022-05-03
Download filtered entries (CSV)

Exactly the 1,293 entry(ies) matching the filters above, both sources in one file.

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.