Patch Advisories
Microsoft's monthly release and every non-Microsoft advisory, in one browser. Switch scope below; everything under it follows.
At a glance — everything in scope
- 1,756 Entries in scope 448 Microsoft · 1,308 Non-Microsoft
- 362 Exigent KEV-listed, exploited, CVSS ≥ 9.0 and a live urgency signal — of 1,752 entries with a resolved score; 4 not yet scored and so not counted
- 238 Ransomware-linked CISA records a known ransomware campaign using these
- 1,293 Past CISA deadline Overdue against CISA's federal remediation date. Microsoft CVEs carry no CISA deadline, so none of them are counted here.
EVULNABLE Risk across both halves
Scope
Microsoft only, non-Microsoft, or both. Everything below follows the choice.
Why the two halves are ranked separately
One browser over both halves — search, filter and export Microsoft and non-Microsoft CVEs together. Ranking stays per half: every KEV entry is exploited by construction, which floors it above every Microsoft CVE, so one merged leaderboard would just rebuild the Dashboard.
Browse every advisory
Microsoft's release and every non-Microsoft CISA KEV advisory in one list, ranked on one EVULNABLE Risk scale. Ranking is not the point here — see the two Patch First sections below for that — searching across both is.
1,756 of 1,756 entries match the current filters, sorted by EVULNABLE Risk.
| CVE | Source | Vendor | Title | EVRS | CVSS | EPSS | Flags | CISA due |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-9082 | Non-Microsoft | Drupal | Drupal Core SQL Injection Vulnerability | 87 Immediate | 9.8 | 0.879 (99.75th pctl) | Overdue | 2026-05-27 |
| CVE-2025-54253 | Non-Microsoft | Adobe | Adobe Experience Manager Forms Code Execution Vulnerability | 87 Immediate | 10.0 | 0.875 (99.75th pctl) | Overdue | 2025-11-05 |
| CVE-2022-27924 | Non-Microsoft | Synacor | Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability | 87 Immediate | 7.5 | 0.854 (99.7th pctl) | RansomwareOverdue | 2022-08-25 |
| CVE-2023-27351 | Non-Microsoft | PaperCut | PaperCut NG/MF Improper Authentication Vulnerability | 87 Immediate | 7.5 | 0.781 (99.54th pctl) | RansomwareOverdue | 2026-05-04 |
| CVE-2021-42258 | Non-Microsoft | BQE | BQE BillQuick Web Suite SQL Injection Vulnerability | 87 Immediate | 9.8 | 0.744 (99.45th pctl) | ExigentRansomwareOverdue | 2021-11-17 |
| CVE-2023-1389 | Non-Microsoft | TP-Link | TP-Link Archer AX-21 Command Injection Vulnerability | 86 Immediate | 8.8 | 0.999 (99.99th pctl) | Overdue | 2023-05-22 |
| CVE-2023-4863 | Non-Microsoft | Google Chromium WebP Heap-Based Buffer Overflow Vulnerability | 86 Immediate | 8.8 | 0.999 (99.98th pctl) | Overdue | 2023-10-04 | |
| CVE-2024-4879 | Non-Microsoft | ServiceNow | ServiceNow Improper Input Validation Vulnerability | 86 Immediate | 9.3 | 0.999 (99.98th pctl) | ExigentOverdue | 2024-08-19 |
| CVE-2016-6277 | Non-Microsoft | NETGEAR | NETGEAR Multiple Routers Remote Code Execution Vulnerability | 86 Immediate | 8.8 | 0.998 (99.96th pctl) | Overdue | 2022-09-07 |
| CVE-2024-5217 | Non-Microsoft | ServiceNow | ServiceNow Incomplete List of Disallowed Inputs Vulnerability | 86 Immediate | 9.2 | 0.996 (99.95th pctl) | ExigentOverdue | 2024-08-19 |
| CVE-2011-0611 | Non-Microsoft | Adobe | Adobe Flash Player Remote Code Execution Vulnerability | 86 Immediate | 8.8 | 0.994 (99.94th pctl) | Overdue | 2022-03-24 |
| CVE-2020-11978 | Non-Microsoft | Apache | Apache Airflow Command Injection | 86 Immediate | 8.8 | 0.992 (99.93rd pctl) | Overdue | 2022-07-18 |
| CVE-2012-3152 | Non-Microsoft | Oracle | Oracle Fusion Middleware Unspecified Vulnerability | 86 Immediate | 9.1 | 0.988 (99.92nd pctl) | ExigentOverdue | 2022-05-03 |
| CVE-2025-0108 | Non-Microsoft | Palo Alto Networks | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | 86 Immediate | 8.8 | 0.985 (99.92nd pctl) | Overdue | 2025-03-11 |
| CVE-2021-45382 | Non-Microsoft | D-Link | D-Link Multiple Routers Remote Code Execution Vulnerability | 86 Immediate | 9.8 | 0.978 (99.9th pctl) | ExigentOverdue | 2022-04-25 |
| CVE-2015-7450 | Non-Microsoft | IBM | IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. | 86 Immediate | 9.8 | 0.977 (99.9th pctl) | ExigentOverdue | 2022-07-10 |
| CVE-2021-36380 | Non-Microsoft | Sunhillo | Sunhillo SureLine OS Command Injection Vulnerablity | 86 Immediate | 9.8 | 0.976 (99.9th pctl) | ExigentOverdue | 2024-03-26 |
| CVE-2016-3714 | Non-Microsoft | ImageMagick | ImageMagick Improper Input Validation Vulnerability | 86 Immediate | 8.4 | 0.975 (99.9th pctl) | Overdue | 2024-09-30 |
| CVE-2024-4358 | Non-Microsoft | Progress | Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability | 86 Immediate | 9.8 | 0.975 (99.9th pctl) | ExigentOverdue | 2024-07-04 |
| CVE-2007-3010 | Non-Microsoft | Alcatel | Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability | 86 Immediate | 9.8 | 0.974 (99.89th pctl) | ExigentOverdue | 2022-05-06 |
| CVE-2023-27524 | Non-Microsoft | Apache | Apache Superset Insecure Default Initialization of Resource Vulnerability | 86 Immediate | 9.8 | 0.974 (99.89th pctl) | ExigentOverdue | 2024-01-29 |
| CVE-2021-22054 | Non-Microsoft | Omnissa | Omnissa Workspace ONE Server-Side Request Forgery | 86 Immediate | 7.5 | 0.974 (99.89th pctl) | Overdue | 2026-03-23 |
| CVE-2023-24489 | Non-Microsoft | Citrix | Citrix Content Collaboration ShareFile Improper Access Control Vulnerability | 86 Immediate | 9.8 | 0.973 (99.89th pctl) | ExigentOverdue | 2023-09-06 |
| CVE-2020-25213 | Non-Microsoft | WordPress | WordPress File Manager Plugin Remote Code Execution Vulnerability | 86 Immediate | 9.8 | 0.973 (99.89th pctl) | ExigentOverdue | 2022-05-03 |
| CVE-2019-7256 | Non-Microsoft | Nice | Nice Linear eMerge E3-Series OS Command Injection Vulnerability | 86 Immediate | 9.8 | 0.971 (99.89th pctl) | ExigentOverdue | 2024-04-15 |
Exactly the 1,756 entry(ies) matching the filters above, both sources in one file.