Patch Advisories
Microsoft's monthly release and every non-Microsoft advisory, in one browser. Switch scope below; everything under it follows.
At a glance — everything in scope
- 1,756 Entries in scope 448 Microsoft · 1,308 Non-Microsoft
- 361 Exigent KEV-listed, exploited, CVSS ≥ 9.0 and a live urgency signal — of 1,752 entries with a resolved score; 4 not yet scored and so not counted
- 238 Ransomware-linked CISA records a known ransomware campaign using these
- 1,294 Past CISA deadline Overdue against CISA's federal remediation date. Microsoft CVEs carry no CISA deadline, so none of them are counted here.
EVULNABLE Risk across both halves
Scope
Microsoft only, non-Microsoft, or both. Everything below follows the choice.
Why the two halves are ranked separately
One browser over both halves — search, filter and export Microsoft and non-Microsoft CVEs together. Ranking stays per half: every KEV entry is exploited by construction, which floors it above every Microsoft CVE, so one merged leaderboard would just rebuild the Dashboard.
Browse every advisory
Microsoft's release and every non-Microsoft CISA KEV advisory in one list, ranked on one EVULNABLE Risk scale. Ranking is not the point here — see the two Patch First sections below for that — searching across both is.
1,756 of 1,756 entries match the current filters, sorted by EVULNABLE Risk.
| CVE | Source | Vendor | Title | EVRS | CVSS | EPSS | Flags | CISA due |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-56290 | Non-Microsoft | Joomlack | Joomlack Page Builder Improper Access Control Vulnerability | 75 Urgent | 10.0 | 0.304 (98.1st pctl) | Overdue | 2026-07-10 |
| CVE-2026-48558 | Non-Microsoft | SimpleHelp | SimpleHelp Authentication Bypass Vulnerability | 75 Urgent | 9.5 | 0.300 (98.1st pctl) | Overdue | 2026-07-02 |
| CVE-2019-13608 | Non-Microsoft | Citrix | Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability | 75 Urgent | 7.5 | 0.300 (98.1st pctl) | RansomwareOverdue | 2022-05-03 |
| CVE-2025-20393 | Non-Microsoft | Cisco | Cisco Multiple Products Improper Input Validation Vulnerability | 75 Urgent | 10.0 | 0.299 (98.1st pctl) | Overdue | 2025-12-24 |
| CVE-2025-32756 | Non-Microsoft | Fortinet | Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability | 75 Urgent | 9.8 | 0.298 (98.1st pctl) | Overdue | 2025-06-04 |
| CVE-2023-2533 | Non-Microsoft | PaperCut | PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability | 75 Urgent | 8.8 | 0.292 (98th pctl) | Overdue | 2025-08-18 |
| CVE-2023-41993 | Non-Microsoft | Apple | Apple Multiple Products WebKit Code Execution Vulnerability | 75 Urgent | 8.8 | 0.292 (98th pctl) | Overdue | 2023-10-16 |
| CVE-2025-68686 | Non-Microsoft | Fortinet | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | 75 Urgent | 5.9 | 0.291 (98th pctl) | Overdue | 2026-08-10 |
| CVE-2014-3931 | Non-Microsoft | Looking Glass | Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability | 75 Urgent | 9.8 | 0.290 (98th pctl) | Overdue | 2025-07-28 |
| CVE-2018-2380 | Non-Microsoft | SAP | SAP Customer Relationship Management (CRM) Path Traversal Vulnerability | 75 Urgent | 6.6 | 0.289 (98th pctl) | RansomwareOverdue | 2022-05-03 |
| CVE-2021-30807 | Non-Microsoft | Apple | Apple Multiple Products Memory Corruption Vulnerability | 75 Urgent | 7.8 | 0.288 (98th pctl) | Overdue | 2021-11-17 |
| CVE-2023-33010 | Non-Microsoft | Zyxel | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | 75 Urgent | 9.8 | 0.288 (98th pctl) | Overdue | 2023-06-26 |
| CVE-2024-3393 | Non-Microsoft | Palo Alto Networks | Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability | 75 Urgent | 8.7 | 0.286 (98th pctl) | Overdue | 2025-01-20 |
| CVE-2024-11120 | Non-Microsoft | GeoVision | GeoVision Devices OS Command Injection Vulnerability | 75 Urgent | 9.8 | 0.284 (98th pctl) | Overdue | 2025-05-28 |
| CVE-2020-3153 | Non-Microsoft | Cisco | Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability | 75 Urgent | 6.5 | 0.283 (98th pctl) | RansomwareOverdue | 2022-11-14 |
| CVE-2026-20262 | Non-Microsoft | Cisco | Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability | 75 Urgent | 6.5 | 0.282 (98th pctl) | Overdue | 2026-06-29 |
| CVE-2019-19356 | Non-Microsoft | Netis | Netis WF2419 Devices Remote Code Execution Vulnerability | 75 Urgent | 7.5 | 0.282 (98th pctl) | Overdue | 2022-05-03 |
| CVE-2023-33009 | Non-Microsoft | Zyxel | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | 75 Urgent | 9.8 | 0.281 (98th pctl) | Overdue | 2023-06-26 |
| CVE-2024-1086 | Non-Microsoft | Linux | Linux Kernel Use-After-Free Vulnerability | 75 Urgent | 7.8 | 0.281 (98th pctl) | RansomwareOverdue | 2024-06-20 |
| CVE-2025-27363 | Non-Microsoft | FreeType | FreeType Out-of-Bounds Write Vulnerability | 75 Urgent | 8.1 | 0.278 (98th pctl) | Overdue | 2025-05-27 |
| CVE-2026-45247 | Non-Microsoft | Mirasvit | Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability | 75 Urgent | 9.3 | 0.275 (97.9th pctl) | Overdue | 2026-06-06 |
| CVE-2023-28205 | Non-Microsoft | Apple | Apple Multiple Products WebKit Use-After-Free Vulnerability | 75 Urgent | 8.8 | 0.271 (97.9th pctl) | Overdue | 2023-05-01 |
| CVE-2018-4063 | Non-Microsoft | Sierra Wireless | Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability | 75 Urgent | 8.8 | 0.271 (97.9th pctl) | Overdue | 2026-01-02 |
| CVE-2024-4978 | Non-Microsoft | Justice AV Solutions | Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability | 75 Urgent | 8.7 | 0.269 (97.9th pctl) | Overdue | 2024-06-19 |
| CVE-2025-68461 | Non-Microsoft | Roundcube | RoundCube Webmail Cross-site Scripting Vulnerability | 75 Urgent | 6.1 | 0.268 (97.9th pctl) | Overdue | 2026-03-13 |
Exactly the 1,756 entry(ies) matching the filters above, both sources in one file.