Fix the vulnerabilities that actually matter
There are hundreds of thousands of CVEs. PatchRadar ranks them by real exploitation signals — whether they're actively exploited (CISA KEV), how likely they are to be exploited (EPSS) and how severe they are (CVSS) — so you know what to patch first.
377,708CVEs tracked
1,716Act-now (exploited)
1,716on CISA KEV
2026-09-18EPSS data date
Recently added to CISA KEV — actively exploited
| CVE | Priority | Added | Due | EPSS | What |
|---|---|---|---|---|---|
| CVE-2025-39682 | Act now | 2026-09-18 | 2026-09-21 | 0.5% | In the Linux kernel, the following vulnerability has been resolved: tls: fix ha… |
| CVE-2025-39964 | Act now | 2026-09-18 | 2026-09-21 | 0.3% | In the Linux kernel, the following vulnerability has been resolved: crypto: af_… |
| CVE-2026-53266 | Act now | 2026-09-18 | 2026-09-21 | 0.1% | In the Linux kernel, the following vulnerability has been resolved: netfilter: … |
| CVE-2026-87886 | Act now | 2026-09-16 | 2026-09-19 | 0.3% | Local privilege escalation due to insecure file permissions. The following produ… |
| CVE-2026-58704 | Act now | 2026-09-16 | 2026-09-19 | 0.2% | Google Pixel devices contain an improper authorization vulnerability in the cell… |
| CVE-2026-76460 | Act now | 2026-09-16 | 2026-09-19 | 0.8% | Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (I… |
| CVE-2026-76461 | Act now | 2026-09-14 | 2026-09-17 | 2.0% | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure … |
| CVE-2026-84869 | Act now | 2026-09-11 | 2026-09-14 | 0.7% | A condition in the ScreenConnect client may allow files to be transferred and ex… |
| CVE-2026-85706 | Act now | 2026-09-11 | 2026-09-14 | 14.6% | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 … |
| CVE-2026-42016 | Act now | 2026-09-11 | 2026-09-25 | 0.9% | JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri… |
| CVE-2026-42018 | Act now | 2026-09-11 | 2026-09-25 | 0.9% | JFrog Artifactory could return an internal anonymous-user token to an unauthenti… |
| CVE-2026-86060 | Act now | 2026-09-10 | 2026-09-13 | 1.1% | RouterOS contains an argument-handling flaw in the SSH login path involving user… |
Highest exploit probability (EPSS) — not yet on KEV
| CVE | Priority | EPSS | CVSS | What |
|---|---|---|---|---|
| CVE-2014-3566 | High | 100.0% | — | — |
| CVE-2021-45105 | High | 100.0% | 5.9 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) di… |
| CVE-2023-50387 | High | 100.0% | — | — |
| CVE-2014-0195 | High | 100.0% | — | — |
| CVE-2014-3704 | High | 100.0% | — | — |
| CVE-2015-7297 | High | 100.0% | — | — |
| CVE-2012-1456 | High | 99.9% | — | — |
| CVE-2022-42889 | High | 99.9% | — | — |
| CVE-2024-29825 | High | 99.9% | — | — |
| CVE-2024-29826 | High | 99.9% | — | — |
| CVE-2015-4000 | High | 99.9% | — | — |
| CVE-2024-29823 | High | 99.9% | — | — |
Machine-readable: KEV RSS · High-priority RSS · KEV JSON · CVE JSON