Patch Advisories
Microsoft's monthly release and every non-Microsoft advisory, in one browser. Switch scope below; everything under it follows.
At a glance — everything in scope
- 1,756 Entries in scope 448 Microsoft · 1,308 Non-Microsoft
- 355 Exigent KEV-listed, exploited, CVSS ≥ 9.0 and a live urgency signal — of 1,752 entries with a resolved score; 4 not yet scored and so not counted
- 238 Ransomware-linked CISA records a known ransomware campaign using these
- 1,293 Past CISA deadline Overdue against CISA's federal remediation date. Microsoft CVEs carry no CISA deadline, so none of them are counted here.
EVULNABLE Risk across both halves
Scope
Microsoft only, non-Microsoft, or both. Everything below follows the choice.
Why the two halves are ranked separately
One browser over both halves — search, filter and export Microsoft and non-Microsoft CVEs together. Ranking stays per half: every KEV entry is exploited by construction, which floors it above every Microsoft CVE, so one merged leaderboard would just rebuild the Dashboard.
Browse every advisory
Microsoft's release and every non-Microsoft CISA KEV advisory in one list, ranked on one EVULNABLE Risk scale. Ranking is not the point here — see the two Patch First sections below for that — searching across both is.
1,293 of 1,756 entries match the current filters, sorted by EVULNABLE Risk.
| CVE | Source | Vendor | Title | EVRS | CVSS | EPSS | Flags | CISA due |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-11317 | Non-Microsoft | Telerik | Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability | 83 Urgent | 9.8 | 0.842 (99.68th pctl) | Overdue | 2022-05-02 |
| CVE-2020-3161 | Non-Microsoft | Cisco | Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability | 83 Urgent | 9.8 | 0.839 (99.67th pctl) | Overdue | 2022-05-03 |
| CVE-2016-10174 | Non-Microsoft | NETGEAR | NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability | 83 Urgent | 9.8 | 0.835 (99.66th pctl) | Overdue | 2022-04-15 |
| CVE-2024-42009 | Non-Microsoft | Roundcube | RoundCube Webmail Cross-Site Scripting Vulnerability | 83 Urgent | 9.3 | 0.829 (99.65th pctl) | Overdue | 2025-06-30 |
| CVE-2024-0769 | Non-Microsoft | D-Link | D-Link DIR-859 Router Path Traversal Vulnerability | 83 Urgent | 9.8 | 0.827 (99.64th pctl) | Overdue | 2025-07-16 |
| CVE-2026-16232 | Non-Microsoft | Check Point | Check Point SmartConsole Improper Authentication Vulnerability | 83 Urgent | 9.3 | 0.721 (99.39th pctl) | Overdue | 2026-07-25 |
| CVE-2020-3259 | Non-Microsoft | Cisco | Cisco ASA and FTD Information Disclosure Vulnerability | 83 Urgent | 7.5 | 0.718 (99.38th pctl) | RansomwareOverdue | 2024-03-07 |
| CVE-2015-7645 | Non-Microsoft | Adobe | Adobe Flash Player Arbitrary Code Execution Vulnerability | 83 Urgent | 7.8 | 0.684 (99.28th pctl) | RansomwareOverdue | 2022-03-24 |
| CVE-2021-26086 | Non-Microsoft | Atlassian | Atlassian Jira Server and Data Center Path Traversal Vulnerability | 82 Urgent | 5.3 | 0.999 (99.99th pctl) | Overdue | 2024-12-03 |
| CVE-2020-5849 | Non-Microsoft | Unraid | Unraid Authentication Bypass Vulnerability | 82 Urgent | 7.5 | 0.932 (99.83rd pctl) | Overdue | 2022-05-03 |
| CVE-2019-2616 | Non-Microsoft | Oracle | Oracle BI Publisher Unauthorized Access Vulnerability | 82 Urgent | 7.2 | 0.922 (99.81st pctl) | Overdue | 2022-04-15 |
| CVE-2021-21315 | Non-Microsoft | Npm package | System Information Library for Node.JS Command Injection | 82 Urgent | 7.8 | 0.907 (99.79th pctl) | Overdue | 2022-02-01 |
| CVE-2021-20123 | Non-Microsoft | DrayTek | Draytek VigorConnect Path Traversal Vulnerability | 82 Urgent | 7.5 | 0.902 (99.79th pctl) | Overdue | 2024-09-24 |
| CVE-2024-13161 | Non-Microsoft | Ivanti | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | 82 Urgent | 7.5 | 0.901 (99.79th pctl) | Overdue | 2025-03-31 |
| CVE-2022-0847 | Non-Microsoft | Linux | Linux Kernel Privilege Escalation Vulnerability | 82 Urgent | 7.8 | 0.897 (99.78th pctl) | Overdue | 2022-05-16 |
| CVE-2017-5521 | Non-Microsoft | NETGEAR | NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability | 82 Urgent | 8.1 | 0.894 (99.77th pctl) | Overdue | 2022-09-29 |
| CVE-2014-3120 | Non-Microsoft | Elastic | Elasticsearch Remote Code Execution Vulnerability | 82 Urgent | 8.1 | 0.886 (99.76th pctl) | Overdue | 2022-04-15 |
| CVE-2024-8190 | Non-Microsoft | Ivanti | Ivanti Cloud Services Appliance OS Command Injection Vulnerability | 82 Urgent | 7.2 | 0.885 (99.76th pctl) | Overdue | 2024-10-04 |
| CVE-2016-6366 | Non-Microsoft | Cisco | Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability | 82 Urgent | 8.8 | 0.876 (99.75th pctl) | Overdue | 2022-06-14 |
| CVE-2021-21017 | Non-Microsoft | Adobe | Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability | 82 Urgent | 8.8 | 0.863 (99.72nd pctl) | Overdue | 2021-11-17 |
| CVE-2018-17463 | Non-Microsoft | Google Chromium V8 Remote Code Execution Vulnerability | 82 Urgent | 8.8 | 0.846 (99.69th pctl) | Overdue | 2022-06-22 | |
| CVE-2021-21224 | Non-Microsoft | Google Chromium V8 Type Confusion Vulnerability | 82 Urgent | 8.8 | 0.842 (99.68th pctl) | Overdue | 2021-11-17 | |
| CVE-2021-27561 | Non-Microsoft | Yealink | Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability | 82 Urgent | 9.8 | 0.829 (99.65th pctl) | Overdue | 2021-11-17 |
| CVE-2015-1187 | Non-Microsoft | D-Link and TRENDnet | D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability | 82 Urgent | 9.8 | 0.829 (99.65th pctl) | Overdue | 2022-04-15 |
| CVE-2022-26258 | Non-Microsoft | D-Link | D-Link DIR-820L Remote Code Execution Vulnerability | 82 Urgent | 9.8 | 0.804 (99.59th pctl) | Overdue | 2022-09-29 |
Exactly the 1,293 entry(ies) matching the filters above, both sources in one file.