Patch Advisories

Microsoft's monthly release and every non-Microsoft advisory, in one browser. Switch scope below; everything under it follows.

At a glance — everything in scope

  • 1,317 Entries in scope 9 Microsoft · 1,308 Non-Microsoft
  • 362 Exigent KEV-listed, exploited, CVSS ≥ 9.0 and a live urgency signal — of 1,314 entries with a resolved score; 3 not yet scored and so not counted
  • 238 Ransomware-linked CISA records a known ransomware campaign using these
  • 1,293 Past CISA deadline Overdue against CISA's federal remediation date. Microsoft CVEs carry no CISA deadline, so none of them are counted here.

EVULNABLE Risk across both halves

Immediate 465 35% · 85-100 Urgent 843 64% · 65-84 Elevated 9 <1% · 10-64 Routine 0 0% · 4-9 Informational 0 0% · 0-3 Exigent flag 362 counted within Immediate

Scope

Microsoft only, non-Microsoft, or both. Everything below follows the choice.

Why the two halves are ranked separately

One browser over both halves — search, filter and export Microsoft and non-Microsoft CVEs together. Ranking stays per half: every KEV entry is exploited by construction, which floors it above every Microsoft CVE, so one merged leaderboard would just rebuild the Dashboard.

Browse every advisory

Microsoft's release and every non-Microsoft CISA KEV advisory in one list, ranked on one EVULNABLE Risk scale. Ranking is not the point here — see the two Patch First sections below for that — searching across both is.

Risk band
Source
Exploitation

1,317 of 1,317 entries match the current filters, sorted by EVULNABLE Risk.

Microsoft and non-Microsoft advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Source Vendor Title EVRS CVSS EPSSFlags CISA due
CVE-2020-6418 Non-Microsoft Google Google Chromium V8 Type Confusion Vulnerability 80 Urgent 8.8 0.788 (99.56th pctl) Overdue 2022-05-03
CVE-2026-60137 Non-Microsoft WordPress WordPress Core SQL Injection Vulnerability 80 Urgent 5.9 0.783 (99.55th pctl) Overdue 2026-08-04
CVE-2019-15949 Non-Microsoft Nagios Nagios XI Remote Code Execution Vulnerability 80 Urgent 8.8 0.770 (99.52nd pctl) Overdue 2022-05-03
CVE-2017-9248 Non-Microsoft Progress Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability 80 Urgent 9.8 0.751 (99.47th pctl) Overdue 2022-05-03
CVE-2014-0780 Non-Microsoft InduSoft InduSoft Web Studio NTWebServer Directory Traversal Vulnerability 80 Urgent 9.8 0.745 (99.46th pctl) Overdue 2022-05-06
CVE-2018-14667 Non-Microsoft Red Hat Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability 80 Urgent 9.8 0.742 (99.45th pctl) Overdue 2023-10-19
CVE-2024-21182 Non-Microsoft Oracle Oracle WebLogic Server Unspecified Vulnerability 80 Urgent 7.5 0.742 (99.45th pctl) Overdue 2026-06-04
CVE-2005-2773 Non-Microsoft Hewlett Packard (HP) HP OpenView Network Node Manager Remote Code Execution Vulnerability 80 Urgent 9.8 0.741 (99.45th pctl) Overdue 2022-04-15
CVE-2015-3043 Non-Microsoft Adobe Adobe Flash Player Memory Corruption Vulnerability 80 Urgent 9.8 0.739 (99.44th pctl) Overdue 2022-03-24
CVE-2019-1003029 Non-Microsoft Jenkins Jenkins Script Security Plugin Sandbox Bypass Vulnerability 80 Urgent 9.9 0.739 (99.44th pctl) Overdue 2022-05-16
CVE-2018-7841 Non-Microsoft Schneider Electric Schneider Electric U.motion Builder SQL Injection Vulnerability 80 Urgent 9.8 0.727 (99.4th pctl) Overdue 2022-05-06
CVE-2017-6316 Non-Microsoft Citrix Citrix Multiple Products Remote Code Execution Vulnerability 80 Urgent 9.8 0.726 (99.4th pctl) Overdue 2022-04-15
CVE-2022-20699 Non-Microsoft Cisco Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability 80 Urgent 9.8 0.725 (99.4th pctl) Overdue 2022-03-17
CVE-2010-4344 Non-Microsoft Exim Exim Heap-Based Buffer Overflow Vulnerability 80 Urgent 9.8 0.719 (99.38th pctl) Overdue 2022-04-15
CVE-2025-20337 Non-Microsoft Cisco Cisco Identity Services Engine Injection Vulnerability 80 Urgent 10.0 0.673 (99.25th pctl) Overdue 2025-08-18
CVE-2025-58360 Non-Microsoft OSGeo OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability 80 Urgent 9.8 0.649 (99.19th pctl) Overdue 2026-01-01
CVE-2021-22681 Non-Microsoft Rockwell Rockwell Multiple Products Insufficient Protected Credentials Vulnerability 80 Urgent 9.8 0.636 (99.16th pctl) Overdue 2026-03-26
CVE-2023-36844 Non-Microsoft Juniper Juniper Junos OS EX Series PHP External Variable Modification Vulnerability 79 Urgent 5.3 0.910 (99.8th pctl) Overdue 2023-11-17
CVE-2020-11652 Non-Microsoft SaltStack SaltStack Salt Path Traversal Vulnerability 79 Urgent 6.5 0.862 (99.72nd pctl) Overdue 2022-05-03
CVE-2020-11023 Non-Microsoft JQuery JQuery Cross-Site Scripting (XSS) Vulnerability 79 Urgent 6.1 0.838 (99.67th pctl) Overdue 2025-02-13
CVE-2019-0193 Non-Microsoft Apache Apache Solr DataImportHandler Code Injection Vulnerability 79 Urgent 7.2 0.835 (99.66th pctl) Overdue 2022-06-10
CVE-2016-5195 Non-Microsoft Linux Linux Kernel Race Condition Vulnerability 79 Urgent 7.0 0.835 (99.66th pctl) Overdue 2022-03-24
CVE-2010-2883 Non-Microsoft Adobe Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability 79 Urgent 7.3 0.825 (99.64th pctl) Overdue 2022-06-22
CVE-2023-4911 Non-Microsoft GNU GNU C Library Buffer Overflow Vulnerability 79 Urgent 7.8 0.814 (99.61st pctl) Overdue 2023-12-12
CVE-2021-21551 Non-Microsoft Dell Dell dbutil Driver Insufficient Access Control Vulnerability 79 Urgent 7.8 0.792 (99.57th pctl) Overdue 2022-04-21
Download filtered entries (CSV)

Exactly the 1,317 entry(ies) matching the filters above, both sources in one file.

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.