Patch Advisories
Microsoft's monthly release and every non-Microsoft advisory, in one browser. Switch scope below; everything under it follows.
At a glance — everything in scope
- 1,756 Entries in scope 448 Microsoft · 1,308 Non-Microsoft
- 355 Exigent KEV-listed, exploited, CVSS ≥ 9.0 and a live urgency signal — of 1,752 entries with a resolved score; 4 not yet scored and so not counted
- 238 Ransomware-linked CISA records a known ransomware campaign using these
- 1,294 Past CISA deadline Overdue against CISA's federal remediation date. Microsoft CVEs carry no CISA deadline, so none of them are counted here.
EVULNABLE Risk across both halves
Scope
Microsoft only, non-Microsoft, or both. Everything below follows the choice.
Why the two halves are ranked separately
One browser over both halves — search, filter and export Microsoft and non-Microsoft CVEs together. Ranking stays per half: every KEV entry is exploited by construction, which floors it above every Microsoft CVE, so one merged leaderboard would just rebuild the Dashboard.
Browse every advisory
Microsoft's release and every non-Microsoft CISA KEV advisory in one list, ranked on one EVULNABLE Risk scale. Ranking is not the point here — see the two Patch First sections below for that — searching across both is.
1,294 of 1,756 entries match the current filters, sorted by EVULNABLE Risk.
| CVE | Source | Vendor | Title | EVRS | CVSS | EPSS | Flags | CISA due |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-0411 | Non-Microsoft | 7-Zip | 7-Zip Mark of the Web Bypass Vulnerability | 76 Urgent | 7.0 | 0.671 (99.25th pctl) | Overdue | 2025-02-27 |
| CVE-2011-0609 | Non-Microsoft | Adobe | Adobe Flash Player Unspecified Vulnerability | 76 Urgent | 7.8 | 0.668 (99.24th pctl) | Overdue | 2022-06-22 |
| CVE-2021-30551 | Non-Microsoft | Google Chromium V8 Type Confusion Vulnerability | 76 Urgent | 8.8 | 0.647 (99.19th pctl) | Overdue | 2021-11-17 | |
| CVE-2021-30632 | Non-Microsoft | Google Chromium V8 Out-of-Bounds Write Vulnerability | 76 Urgent | 8.8 | 0.645 (99.18th pctl) | Overdue | 2021-11-17 | |
| CVE-2015-4068 | Non-Microsoft | Arcserve | Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability | 76 Urgent | 9.1 | 0.636 (99.16th pctl) | Overdue | 2022-04-15 |
| CVE-2020-4428 | Non-Microsoft | IBM | IBM Data Risk Manager Remote Code Execution Vulnerability | 76 Urgent | 9.1 | 0.617 (99.11st pctl) | Overdue | 2022-05-03 |
| CVE-2025-32463 | Non-Microsoft | Sudo | Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability | 76 Urgent | 7.8 | 0.594 (99.06th pctl) | Overdue | 2025-10-20 |
| CVE-2025-31125 | Non-Microsoft | Vite | Vite Vitejs Improper Access Control Vulnerability | 76 Urgent | 7.5 | 0.585 (99.03rd pctl) | Overdue | 2026-02-12 |
| CVE-2020-26919 | Non-Microsoft | NETGEAR | Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability | 76 Urgent | 9.8 | 0.572 (99th pctl) | Overdue | 2022-05-03 |
| CVE-2019-11708 | Non-Microsoft | Mozilla | Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability | 76 Urgent | 10.0 | 0.559 (99th pctl) | Overdue | 2022-06-13 |
| CVE-2024-38812 | Non-Microsoft | VMware | VMware vCenter Server Heap-Based Buffer Overflow Vulnerability | 76 Urgent | 9.8 | 0.546 (98.9th pctl) | Overdue | 2024-12-11 |
| CVE-2025-53690 | Non-Microsoft | Sitecore | Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability | 76 Urgent | 9.0 | 0.511 (98.9th pctl) | Overdue | 2025-09-25 |
| CVE-2026-48282 | Non-Microsoft | Adobe | Adobe ColdFusion Path Traversal Vulnerability | 76 Urgent | 10.0 | 0.424 (98.6th pctl) | Overdue | 2026-07-10 |
| CVE-2017-6884 | Non-Microsoft | Zyxel | Zyxel EMG2926 Routers Command Injection Vulnerability | 76 Urgent | 8.8 | 0.368 (98.4th pctl) | RansomwareOverdue | 2023-10-09 |
| CVE-2013-2423 | Non-Microsoft | Oracle | Oracle JRE Unspecified Vulnerability | 75 Urgent | 3.7 | 0.853 (99.7th pctl) | Overdue | 2022-06-15 |
| CVE-2016-3718 | Non-Microsoft | ImageMagick | ImageMagick Server-Side Request Forgery (SSRF) Vulnerability | 75 Urgent | 5.5 | 0.769 (99.51st pctl) | Overdue | 2022-05-03 |
| CVE-2023-5631 | Non-Microsoft | Roundcube | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability | 75 Urgent | 5.4 | 0.759 (99.49th pctl) | Overdue | 2023-11-16 |
| CVE-2016-3715 | Non-Microsoft | ImageMagick | ImageMagick Arbitrary File Deletion Vulnerability | 75 Urgent | 5.5 | 0.754 (99.48th pctl) | Overdue | 2022-05-03 |
| CVE-2019-9978 | Non-Microsoft | WordPress | WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability | 75 Urgent | 6.1 | 0.729 (99.41st pctl) | Overdue | 2022-05-03 |
| CVE-2022-28810 | Non-Microsoft | Zoho | Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability | 75 Urgent | 6.8 | 0.710 (99.36th pctl) | Overdue | 2023-03-28 |
| CVE-2016-11021 | Non-Microsoft | D-Link | D-Link DCS-930L Devices OS Command Injection Vulnerability | 75 Urgent | 7.2 | 0.689 (99.3rd pctl) | Overdue | 2022-04-15 |
| CVE-2020-4430 | Non-Microsoft | IBM | IBM Data Risk Manager Directory Traversal Vulnerability | 75 Urgent | 4.3 | 0.685 (99.29th pctl) | Overdue | 2022-05-03 |
| CVE-2021-30657 | Non-Microsoft | Apple | Apple macOS Unspecified Vulnerability | 75 Urgent | 5.5 | 0.685 (99.29th pctl) | Overdue | 2021-11-17 |
| CVE-2013-0629 | Non-Microsoft | Adobe | Adobe ColdFusion Directory Traversal Vulnerability | 75 Urgent | 7.5 | 0.659 (99.22nd pctl) | Overdue | 2022-09-07 |
| CVE-2023-29552 | Non-Microsoft | IETF | Service Location Protocol (SLP) Denial-of-Service Vulnerability | 75 Urgent | 7.5 | 0.659 (99.22nd pctl) | Overdue | 2023-11-29 |
Exactly the 1,294 entry(ies) matching the filters above, both sources in one file.