Patch Advisories
Microsoft's monthly release and every non-Microsoft advisory, in one browser. Switch scope below; everything under it follows.
At a glance — everything in scope
- 1,756 Entries in scope 448 Microsoft · 1,308 Non-Microsoft
- 355 Exigent KEV-listed, exploited, CVSS ≥ 9.0 and a live urgency signal — of 1,752 entries with a resolved score; 4 not yet scored and so not counted
- 238 Ransomware-linked CISA records a known ransomware campaign using these
- 1,294 Past CISA deadline Overdue against CISA's federal remediation date. Microsoft CVEs carry no CISA deadline, so none of them are counted here.
EVULNABLE Risk across both halves
Scope
Microsoft only, non-Microsoft, or both. Everything below follows the choice.
Why the two halves are ranked separately
One browser over both halves — search, filter and export Microsoft and non-Microsoft CVEs together. Ranking stays per half: every KEV entry is exploited by construction, which floors it above every Microsoft CVE, so one merged leaderboard would just rebuild the Dashboard.
Browse every advisory
Microsoft's release and every non-Microsoft CISA KEV advisory in one list, ranked on one EVULNABLE Risk scale. Ranking is not the point here — see the two Patch First sections below for that — searching across both is.
1,294 of 1,756 entries match the current filters, sorted by EVULNABLE Risk.
| CVE | Source | Vendor | Title | EVRS | CVSS | EPSS | Flags | CISA due |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10987 | Non-Microsoft | Tenda | Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability | 82 Urgent | 9.8 | 0.798 (99.58th pctl) | Overdue | 2022-05-03 |
| CVE-2010-0738 | Non-Microsoft | Red Hat | Red Hat JBoss Authentication Bypass Vulnerability | 82 Urgent | 5.3 | 0.794 (99.57th pctl) | RansomwareOverdue | 2022-06-15 |
| CVE-2025-20333 | Non-Microsoft | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability | 82 Urgent | 9.9 | 0.707 (99.35th pctl) | Overdue | 2025-09-26 |
| CVE-2026-34909 | Non-Microsoft | Ubiquiti | Ubiquiti UniFi OS Path Traversal Vulnerability | 82 Urgent | 10.0 | 0.639 (99.16th pctl) | Overdue | 2026-06-26 |
| CVE-2026-0770 | Non-Microsoft | Langflow | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | 82 Urgent | 9.8 | 0.634 (99.15th pctl) | Overdue | 2026-07-24 |
| CVE-2023-23752 | Non-Microsoft | Joomla! | Joomla! Improper Access Control Vulnerability | 81 Urgent | 5.3 | 0.998 (99.96th pctl) | Overdue | 2024-01-29 |
| CVE-2020-8243 | Non-Microsoft | Ivanti | Ivanti Pulse Connect Secure Code Execution Vulnerability | 81 Urgent | 7.2 | 0.908 (99.8th pctl) | Overdue | 2022-05-03 |
| CVE-2021-20123 | Non-Microsoft | DrayTek | Draytek VigorConnect Path Traversal Vulnerability | 81 Urgent | 7.5 | 0.902 (99.79th pctl) | Overdue | 2024-09-24 |
| CVE-2023-20273 | Non-Microsoft | Cisco | Cisco IOS XE Web UI Command Injection Vulnerability | 81 Urgent | 7.2 | 0.896 (99.78th pctl) | Overdue | 2023-10-27 |
| CVE-2016-9079 | Non-Microsoft | Mozilla | Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability | 81 Urgent | 7.5 | 0.874 (99.74th pctl) | Overdue | 2023-07-13 |
| CVE-2016-6415 | Non-Microsoft | Cisco | Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability | 81 Urgent | 7.5 | 0.873 (99.74th pctl) | Overdue | 2023-06-09 |
| CVE-2018-9276 | Non-Microsoft | Paessler | Paessler PRTG Network Monitor OS Command Injection Vulnerability | 81 Urgent | 7.2 | 0.872 (99.74th pctl) | Overdue | 2025-02-25 |
| CVE-2013-0640 | Non-Microsoft | Adobe | Adobe Reader and Acrobat Memory Corruption Vulnerability | 81 Urgent | 7.8 | 0.870 (99.73rd pctl) | Overdue | 2022-03-24 |
| CVE-2018-6961 | Non-Microsoft | VMware | VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability | 81 Urgent | 8.1 | 0.863 (99.72nd pctl) | Overdue | 2022-04-15 |
| CVE-2023-38950 | Non-Microsoft | ZKTeco | ZKTeco BioTime Path Traversal Vulnerability | 81 Urgent | 7.5 | 0.847 (99.69th pctl) | Overdue | 2025-06-09 |
| CVE-2009-3953 | Non-Microsoft | Adobe | Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability | 81 Urgent | 8.8 | 0.839 (99.67th pctl) | Overdue | 2022-06-22 |
| CVE-2010-1871 | Non-Microsoft | Red Hat | Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability | 81 Urgent | 8.8 | 0.834 (99.66th pctl) | Overdue | 2022-06-10 |
| CVE-2026-1603 | Non-Microsoft | Ivanti | Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability | 81 Urgent | 7.5 | 0.806 (99.59th pctl) | Overdue | 2026-03-23 |
| CVE-2013-4810 | Non-Microsoft | Hewlett Packard (HP) | HP Multiple Products Remote Code Execution Vulnerability | 81 Urgent | 9.8 | 0.790 (99.57th pctl) | Overdue | 2022-04-15 |
| CVE-2021-22555 | Non-Microsoft | Linux | Linux Kernel Heap Out-of-Bounds Write Vulnerability | 81 Urgent | 7.8 | 0.787 (99.56th pctl) | Overdue | 2025-10-27 |
| CVE-2013-3346 | Non-Microsoft | Adobe | Adobe Reader and Acrobat Memory Corruption Vulnerability | 81 Urgent | 9.8 | 0.786 (99.56th pctl) | Overdue | 2022-03-24 |
| CVE-2022-26318 | Non-Microsoft | WatchGuard | WatchGuard Firebox and XTM Appliances Arbitrary Code Execution | 81 Urgent | 9.8 | 0.782 (99.54th pctl) | Overdue | 2022-04-15 |
| CVE-2023-34192 | Non-Microsoft | Synacor | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | 81 Urgent | 9.0 | 0.773 (99.52nd pctl) | Overdue | 2025-03-18 |
| CVE-2019-7238 | Non-Microsoft | Sonatype | Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability | 81 Urgent | 9.8 | 0.771 (99.52nd pctl) | Overdue | 2022-06-10 |
| CVE-2025-6204 | Non-Microsoft | Dassault Systèmes | Dassault Systèmes DELMIA Apriso Code Injection Vulnerability | 81 Urgent | 8.0 | 0.771 (99.52nd pctl) | Overdue | 2025-11-18 |
Exactly the 1,294 entry(ies) matching the filters above, both sources in one file.