LIVE
NEW KEV CVE-2026-45247 Mirasvit Mirasvit Full Page Cache Warmer|NEW KEV CVE-2025-48595 Android Framework · CVSS 8.4|NEW KEV CVE-2022-0492 Linux Kernel · CVSS 7.8
1645 PATCH NOW 52,738 WATCH +1 24H1 NEW KEVWX ELEVATED 5.5SYNC —
YOUR EXPOSURE RADAR · LIVE

What's in your stack?

Stop browsing 350,000+ CVEs. Tell us what you run and this page becomes your war room — exposure, patch queue, and deadlines, tuned to your environment.

Fortinet nginx Microsoft Exchange Cisco ASA
QUICK ADD+ VMware ESXi+ Ivanti Connect Secure+ Citrix NetScaler+ Apache Struts+ MOVEitclear all ×

91 items need patching now across 4 of your 4 tracked products. Nearest deadline OVERDUE.

EXPOSURES
200
PATCH NOW
91
NEAREST DEADLINE
OVERDUE
PRODUCTS WATCHED
4/4
EXPOSURE INDEX
10.0 / 10
YOUR PATCH QUEUE · SHOWING 25 OF 200RANKED BY URGENCY · TUNED TO YOUR STACK
VERDICTCVEPRODUCTCVSSEPSSDUECVE PUBLISHEDWE COVEREDWHY IT MATTERS
PATCH NOWCVE-2025-20333Secure Firewall Adaptive Security Appliance and Secure Firewall Threat DefenseCRIT9.930%OVERDUESep 25, 25Jun 2, 26A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute a
PATCH NOWCVE-2022-40684Multiple ProductsCRIT9.894%OVERDUEOct 18, 22Jun 2, 26An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManag
PATCH NOWCVE-2024-55591FortiOS and FortiProxyCRIT9.894%OVERDUEJan 14, 25Jun 2, 26An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote atta
PATCH NOWCVE-2023-48788FortiClient EMSCRIT9.894%OVERDUEMar 12, 24Jun 2, 26A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized c
PATCH NOWCVE-2022-42475FortiOSCRIT9.894%OVERDUEJan 2, 23Jun 2, 26A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1
PATCH NOWCVE-2024-47575FortiManagerCRIT9.894%OVERDUEOct 23, 24Jun 2, 26A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager
PATCH NOWCVE-2025-64446FortiWebCRIT9.893%OVERDUENov 14, 25Jun 2, 26A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an atta
PATCH NOWCVE-2024-21762FortiOSCRIT9.893%OVERDUEFeb 9, 24Jun 2, 26A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2
PATCH NOWCVE-2023-27997FortiOS and FortiProxy SSL-VPNCRIT9.892%OVERDUEJun 13, 23Jun 2, 26A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9
PATCH NOWCVE-2026-21643FortiClient EMSCRIT9.863%OVERDUEFeb 6, 26Jun 2, 26An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via sp
PATCH NOWCVE-2024-23113Multiple ProductsCRIT9.854%OVERDUEFeb 15, 24Jun 2, 26A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14
PATCH NOWCVE-2026-35616FortiClient EMSCRIT9.835%OVERDUEApr 3, 26Jun 2, 26A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
PATCH NOWCVE-2025-25257FortiWebCRIT9.826%OVERDUEJul 17, 25Jun 2, 26An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through
PATCH NOWCVE-2025-32756Multiple ProductsCRIT9.822%OVERDUEMay 13, 25Jun 2, 26A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0
PATCH NOWCVE-2025-59718Multiple ProductsCRIT9.89%OVERDUEDec 9, 25Jun 2, 26A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through
PATCH NOWCVE-2024-21410Exchange ServerCRIT9.86%OVERDUEFeb 13, 24Jun 2, 26Microsoft Exchange Server Elevation of Privilege Vulnerability
PATCH NOWCVE-2026-24858Multiple ProductsCRIT9.84%OVERDUEJan 27, 26Jun 2, 26An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, Fort
PATCH NOWCVE-2021-34473Exchange ServerCRIT9.194%OVERDUEJul 14, 21Jun 2, 26Microsoft Exchange Server Remote Code Execution Vulnerability
PATCH NOWCVE-2021-34523Exchange ServerCRIT9.094%OVERDUEJul 14, 21Jun 2, 26Microsoft Exchange Server Elevation of Privilege Vulnerability
PATCH NOWCVE-2022-41040Exchange ServerHIGH8.894%OVERDUEOct 2, 22Jun 2, 26Microsoft Exchange Server Elevation of Privilege Vulnerability
PATCH NOWCVE-2022-41080Exchange ServerHIGH8.894%OVERDUENov 9, 22Jun 2, 26Microsoft Exchange Server Elevation of Privilege Vulnerability
PATCH NOWCVE-2021-42321ExchangeHIGH8.894%OVERDUENov 9, 21Jun 2, 26Microsoft Exchange Server Remote Code Execution Vulnerability
PATCH NOWCVE-2023-21529Exchange ServerHIGH8.828%OVERDUEFeb 14, 23Jun 2, 26Microsoft Exchange Server Remote Code Execution Vulnerability
PATCH NOWCVE-2024-20353Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)HIGH8.617%OVERDUEApr 24, 24Jun 2, 26A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the de
PATCH NOWCVE-2025-24472FortiOS and FortiProxyHIGH8.110%OVERDUEFeb 11, 25Jun 2, 26An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated atta
of 200 total
WHY TRUST THIS
Human-guided. Evidence-driven. AI-assisted, never AI-decided.
SOURCES
NVD · CISA KEV · EPSS · vendor patch bulletins · 1000+ trusted feeds
CADENCE
Patch taxonomy synced every 24h · KEV / EPSS hourly
MATCHING
Vendor · product · description tokens
PRIVACY
Your stack stays in your browser. No login required.
Get pinged when your stack moves.
One email the moment a CVE lands on a product you watch — plus a five-minute morning brief. No fluff.