Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2025-47729 TeleMessage TM SGNL TeleMessage TM SGNL Hidden Functionality Vulnerability 75 Urgent 0.004 (35.8th pctl) Unknown/None 2025-06-02
CVE-2021-25394 Samsung Mobile Devices Samsung Mobile Devices Race Condition Vulnerability 75 Urgent 0.004 (33.3rd pctl) Unknown/None 2023-07-20
CVE-2022-22265 Samsung Mobile Devices Samsung Mobile Devices Use-After-Free Vulnerability 75 Urgent 0.004 (32.3rd pctl) Unknown/None 2023-10-09
CVE-2021-25395 Samsung Mobile Devices Samsung Mobile Devices Race Condition Vulnerability 75 Urgent 0.004 (29.6th pctl) Unknown/None 2023-07-20
CVE-2025-43510 Apple Multiple Products Apple Multiple Products Improper Locking Vulnerability 75 Urgent 0.004 (29th pctl) Unknown/None 2026-04-03
CVE-2023-21237 Android Pixel Android Pixel Information Disclosure Vulnerability 75 Urgent 0.003 (18th pctl) Unknown/None 2024-03-26
CVE-2025-48633 Android Framework Android Framework Information Disclosure Vulnerability 75 Urgent 0.003 (17th pctl) Unknown/None 2025-12-23
CVE-2025-48572 Android Framework Android Framework Privilege Escalation Vulnerability 75 Urgent 0.003 (16.6th pctl) Unknown/None 2025-12-23
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2025-47729 — TeleMessage TM SGNL: TeleMessage TM SGNL Hidden Functionality Vulnerability

TeleMessage TM SGNL contains a hidden functionality vulnerability in which the archiving backend holds cleartext copies of messages from TM SGNL application users.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 4.9 (NVD)

FIRST EPSS: 0.004 (35.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-05-12

CISA remediation due: 2025-06-02

Known ransomware campaign use: Unknown/None

CVE-2021-25394 — Samsung Mobile Devices: Samsung Mobile Devices Race Condition Vulnerability

Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVSS: 6.4 (NVD)

FIRST EPSS: 0.004 (33.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-06-29

CISA remediation due: 2023-07-20

Known ransomware campaign use: Unknown/None

CVE-2022-22265 — Samsung Mobile Devices: Samsung Mobile Devices Use-After-Free Vulnerability

Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.004 (32.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-09-18

CISA remediation due: 2023-10-09

Known ransomware campaign use: Unknown/None

CVE-2021-25395 — Samsung Mobile Devices: Samsung Mobile Devices Race Condition Vulnerability

Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVSS: 6.4 (NVD)

FIRST EPSS: 0.004 (29.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-06-29

CISA remediation due: 2023-07-20

Known ransomware campaign use: Unknown/None

CVE-2025-43510 — Apple Multiple Products: Apple Multiple Products Improper Locking Vulnerability

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.004 (29th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-20

CISA remediation due: 2026-04-03

Known ransomware campaign use: Unknown/None

CVE-2023-21237 — Android Pixel: Android Pixel Information Disclosure Vulnerability

Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 5.5 (NVD)

FIRST EPSS: 0.003 (18th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-03-05

CISA remediation due: 2024-03-26

Known ransomware campaign use: Unknown/None

CVE-2025-48633 — Android Framework: Android Framework Information Disclosure Vulnerability

Android Framework contains an unspecified vulnerability that allows for information disclosure.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 5.5 (NVD)

FIRST EPSS: 0.003 (17th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-12-02

CISA remediation due: 2025-12-23

Known ransomware campaign use: Unknown/None

CVE-2025-48572 — Android Framework: Android Framework Privilege Escalation Vulnerability

Android Framework contains an unspecified vulnerability that allows for privilege escalation.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.003 (16.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-12-02

CISA remediation due: 2025-12-23

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.