Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2025-47729 | TeleMessage | TM SGNL | TeleMessage TM SGNL Hidden Functionality Vulnerability | 75 Urgent | 0.004 (35.8th pctl) | Unknown/None | 2025-06-02 |
| CVE-2021-25394 | Samsung | Mobile Devices | Samsung Mobile Devices Race Condition Vulnerability | 75 Urgent | 0.004 (33.3rd pctl) | Unknown/None | 2023-07-20 |
| CVE-2022-22265 | Samsung | Mobile Devices | Samsung Mobile Devices Use-After-Free Vulnerability | 75 Urgent | 0.004 (32.3rd pctl) | Unknown/None | 2023-10-09 |
| CVE-2021-25395 | Samsung | Mobile Devices | Samsung Mobile Devices Race Condition Vulnerability | 75 Urgent | 0.004 (29.6th pctl) | Unknown/None | 2023-07-20 |
| CVE-2025-43510 | Apple | Multiple Products | Apple Multiple Products Improper Locking Vulnerability | 75 Urgent | 0.004 (29th pctl) | Unknown/None | 2026-04-03 |
| CVE-2023-21237 | Android | Pixel | Android Pixel Information Disclosure Vulnerability | 75 Urgent | 0.003 (18th pctl) | Unknown/None | 2024-03-26 |
| CVE-2025-48633 | Android | Framework | Android Framework Information Disclosure Vulnerability | 75 Urgent | 0.003 (17th pctl) | Unknown/None | 2025-12-23 |
| CVE-2025-48572 | Android | Framework | Android Framework Privilege Escalation Vulnerability | 75 Urgent | 0.003 (16.6th pctl) | Unknown/None | 2025-12-23 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2025-47729 — TeleMessage TM SGNL: TeleMessage TM SGNL Hidden Functionality Vulnerability
TeleMessage TM SGNL contains a hidden functionality vulnerability in which the archiving backend holds cleartext copies of messages from TM SGNL application users.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 4.9 (NVD)
FIRST EPSS: 0.004 (35.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-05-12
CISA remediation due: 2025-06-02
Known ransomware campaign use: Unknown/None
CVE-2021-25394 — Samsung Mobile Devices: Samsung Mobile Devices Race Condition Vulnerability
Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
CVSS: 6.4 (NVD)
FIRST EPSS: 0.004 (33.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-29
CISA remediation due: 2023-07-20
Known ransomware campaign use: Unknown/None
CVE-2022-22265 — Samsung Mobile Devices: Samsung Mobile Devices Use-After-Free Vulnerability
Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.004 (32.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-09-18
CISA remediation due: 2023-10-09
Known ransomware campaign use: Unknown/None
CVE-2021-25395 — Samsung Mobile Devices: Samsung Mobile Devices Race Condition Vulnerability
Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
CVSS: 6.4 (NVD)
FIRST EPSS: 0.004 (29.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-29
CISA remediation due: 2023-07-20
Known ransomware campaign use: Unknown/None
CVE-2025-43510 — Apple Multiple Products: Apple Multiple Products Improper Locking Vulnerability
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.004 (29th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-03-20
CISA remediation due: 2026-04-03
Known ransomware campaign use: Unknown/None
CVE-2023-21237 — Android Pixel: Android Pixel Information Disclosure Vulnerability
Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 5.5 (NVD)
FIRST EPSS: 0.003 (18th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-03-05
CISA remediation due: 2024-03-26
Known ransomware campaign use: Unknown/None
CVE-2025-48633 — Android Framework: Android Framework Information Disclosure Vulnerability
Android Framework contains an unspecified vulnerability that allows for information disclosure.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 5.5 (NVD)
FIRST EPSS: 0.003 (17th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-02
CISA remediation due: 2025-12-23
Known ransomware campaign use: Unknown/None
CVE-2025-48572 — Android Framework: Android Framework Privilege Escalation Vulnerability
Android Framework contains an unspecified vulnerability that allows for privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.003 (16.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-02
CISA remediation due: 2025-12-23
Known ransomware campaign use: Unknown/None