Patch Advisories
Microsoft's monthly release and every non-Microsoft advisory, in one browser. Switch scope below; everything under it follows.
At a glance — every other vendor
- 1,308 Advisories CISA KEV entries, every vendor except Microsoft
- 282 Vendors Distinct vendors named across them
- 238 Ransomware-associated CISA records a known ransomware campaign using these
- 1,308 / 1,308 CVSS resolved CISA's schema carries no CVSS. It is filled in by cross-referencing Cisco, Red Hat and Chrome first, then a rate-limited NVD lookup for what is left. Chrome's severity is categorical, so scores derived from it are marked estimated and cannot trigger Exigent.
1,293 advisory(ies) are past CISA's federal remediation due date and 11 fall due within 7 days. Past-deadline is the catalog's normal condition — it reaches back to 2021 — so the small due-within-7-days figure is the one that means act this week.
Priority Advisories: every other vendor
The highest EVULNABLE Risk advisories in the current scope. Every row here is KEV-listed and confirmed exploited by construction, so the card says that once as its source rather than repeating it as a second pill.
Rank 1 CVE-2025-55182
ExigentRansomwareCISA KEV
EVULNABLE Risk · priority
97/100
Immediate
Intelligence coverage 75/90 — no pre-patch disclosure data
Rank 2 CVE-2026-35273
ExigentRansomwareCISA KEV
Oracle — Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
EVULNABLE Risk · priority
97/100
Immediate
Intelligence coverage 75/90 — no pre-patch disclosure data
Rank 3 CVE-2025-10035
ExigentRansomwareCISA KEV
Fortra — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability
EVULNABLE Risk · priority
96/100
Immediate
Intelligence coverage 75/90 — no pre-patch disclosure data
Rank 4 CVE-2025-61882
ExigentRansomwareCISA KEV
Oracle — Oracle E-Business Suite Unspecified Vulnerability
EVULNABLE Risk · priority
96/100
Immediate
Intelligence coverage 75/90 — no pre-patch disclosure data
Rank 5 CVE-2025-3248
ExigentRansomwareCISA KEV
Langflow — Langflow Missing Authentication Vulnerability
EVULNABLE Risk · priority
95/100
Immediate
Intelligence coverage 75/90 — no pre-patch disclosure data
Rank 6 CVE-2025-22457
ExigentRansomwareCISA KEV
Ivanti — Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
EVULNABLE Risk · priority
95/100
Immediate
Intelligence coverage 75/90 — no pre-patch disclosure data
Rank 7 CVE-2025-31161
ExigentRansomwareCISA KEV
CrushFTP — CrushFTP Authentication Bypass Vulnerability
EVULNABLE Risk · priority
95/100
Immediate
Intelligence coverage 75/90 — no pre-patch disclosure data
Rank 8 CVE-2025-31324
ExigentRansomwareCISA KEV
SAP — SAP NetWeaver Unrestricted File Upload Vulnerability
EVULNABLE Risk · priority
95/100
Immediate
Intelligence coverage 75/90 — no pre-patch disclosure data
Advisory Dashboard
Advisories by EVULNABLE Risk band
Band · Advisories
Select a bar to filter the advisory browser below.
Top Vendors
Vendor · Advisories
Select a bar to filter the advisory browser below to that vendor.