All patch & vulnerability trackers

The exploited open-source packages hiding in your dependencies

Exploited CVEs across all software are on the exploited-CVE tracker; Microsoft updates are on the Microsoft patch tracker; the whole picture is Senserva Live.

A free, no registration required, searchable table of exploited open-source vulnerabilities and the package version that fixes each, refreshed three times a day (5 AM, 12:30 PM, and 7 PM US Central). Open-source vulnerabilities that have a known package fix, ranked by real-world risk: actively exploited (CISA KEV, VulnCheck KEV, and the EU's EUVD) pinned to the top, then by EPSS exploit probability. Each row maps the CVE to the exact upgrade: the ecosystem (Maven, npm, PyPI, NuGet, Go, RubyGems, Packagist, and more), the package, and the fixed version, from the GitHub Advisory Database and OSV.dev. It is open data: search, sort, and export the whole table to CSV or JSON.

Senserva is a Microsoft Intelligent Security Association member

Open-source advisories with a fix from the GitHub Advisory Database and OSV.dev, cross-referenced with CISA KEV, VulnCheck KEV, the ENISA EUVD, and FIRST.org EPSS. Last updated 2026-07-16 15:10 GMT.

Most-affected open-source projects
Open-source projects with the most vulnerabilities that have a package fix. The red portion of each bar is the ransomware-linked share.
Exploitation trend
Exploited open-source CVEs added to CISA KEV per month, ransomware-linked highlighted.
12 months
Export:RSS

Take this data to your AI

Generated from the live data above, refreshed three times a day (5 AM, 12:30 PM, and 7 PM US Central). Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Tracking Microsoft instead?
See the Microsoft Patch Tracker for every Patch Tuesday KB and the CVEs it fixes, EPSS-ranked.
Microsoft Patch Tracker

Data sources

Every row is built from authoritative, public security feeds, refreshed automatically.

Source What it provides
CISA KEV catalogThe actively-exploited list: which CVEs are exploited in the wild, plus ransomware use and the date added.
OSV.devThe open-source package and the fixed version for each CVE. OSV.dev aggregates GitHub Security Advisories, PyPA, RustSec, and other OSV-schema sources across Maven, npm, PyPI, NuGet, Go, RubyGems, Packagist, and more.
NVD (NIST)CVSS base score and severity for each CVE.
CIRCL CVE SearchCVSS fallback when NVD has no score yet, so newly added CVEs still get a severity.
EPSS (FIRST.org)Exploit Prediction Scoring System: probability a CVE is exploited within 30 days, used to rank the list.
VulnCheck KEVA broader Known Exploited Vulnerabilities list than CISA KEV, surfaced as a "VulnCheck KEV" signal. Data courtesy of VulnCheck, used with attribution.
ENISA EUVDThe European Union Vulnerability Database (ENISA, under NIS2), surfaced as an "EU EUVD" signal for EU teams. Courtesy of ENISA, used with attribution.

Package and fixed-version data from OSV.dev and the google/osv.dev project, used under the Apache License 2.0. Underlying GitHub Security Advisory records are licensed CC BY 4.0. Exploitation data labeled VulnCheck KEV is provided by VulnCheck and used with attribution per VulnCheck's terms; EU cross-references are from the ENISA EUVD. Senserva is not affiliated with or endorsed by OSV.dev, Google, VulnCheck, or ENISA. Always confirm the fixed version against the linked advisory before deploying.

Open-source fixes, mapped to what you run

This tracker ranks exploited open-source CVEs and the package versions that fix them. Senserva matches the same OSV, CISA KEV, and EPSS intelligence to the components and apps it finds across your Microsoft 365, Intune, Defender, and Entra ID estate, so you upgrade the few that are actually exposed.

Matched to your tenant

Senserva connects these package fixes to the software it inventories, so a fixed version becomes a concrete upgrade for a system you actually run.

CVE and patch management

One connected model

Open-source exposure joins configuration, logs, and Conditional Access in one model, so exploited-and-exposed rises to the top.

The unified security model

AI remediation you approve

Bring your own AI for validated, reviewable upgrade guidance grounded in your estate.

AI remediation

Compliance evidence

Every exposed component maps to the frameworks an auditor asks about, from the same model.

Compliance evidence

Sponsored by Senserva

Siemserva by Senserva reports patch status for your own devices: which ones are missing the updates on this page, ranked by what attackers actually exploit.

  • Patch status in one scan: which devices are affected, which are not
  • Missing updates ranked by CISA KEV and EPSS, so you fix the right things first
  • Data from Intune, Microsoft Defender, Windows Autopatch, and Azure Update Manager, with more sources on the way
  • Third-party app patching too: updates published to Intune by PatchMyPC, Scappman, Robopack, or any vendor, read vendor-neutrally
  • Optional AI Enhanced Reporting: plain-language summaries and recommended next steps written into your reports
  • Then go further: 650+ security checks find the drift management gaps across Microsoft 365, Intune, Defender, and Entra ID, with compliance evidence and Senserva Trustworthy AI remediation
Senserva patching for Microsoft 365
Two minutes, click to play

Patching in action in two minutes. Watch page · All videos.

3 actively exploited CVEs are unmitigated on devices in this tenant, per CISA KEV.View fix-first list ↓
312
Devices scanned
Intune + Autopatch + Defender
3
Exploited updates missing
CISA KEV, unmitigated
905
Microsoft updates tracked
Refreshed daily, MSRC + NVD
650+
Security checks in scan
Patch, config, identity, logs

Triage order for this list

Same order in the dashboard, the report, and every AI answer
1st · overrides everything
Actively exploited (KEV)
e.g. KB5040219, CVE-2026-31210
→
2nd · tiebreaker
Severity (Critical → Low)
MSRC + EPSS probability
→
3rd · tiebreaker
Days waiting
Oldest unresolved first

Ranked missing updates, fix-first order

27 findings · showing top 2
#UpdateCVESeveritySourceDevicesWaiting
1KB5040219
Windows 11 23H2 cumulative
CVE-2026-31210
KEV EPSS 0.94
CriticalDefender4119 daysAdd to fix-first
2KB5040088
.NET Framework security update
CVE-2026-29981
KEV
CriticalIntune1712 daysAdd to fix-first
Estimated dashboard, sample data for illustration

Ask Senserva

via Claude + MCP
Which devices are still missing the fix for CVE-2026-31210?
41 devices are missing KB5040219, which resolves CVE-2026-31210. This CVE is on CISA KEV, so CISA BOD 22-01 calls for remediation within 14 days. You are at 19 days and counting.
source: scan_db · defender_posture · kev_join, not model memory
Get Devices Found Get Devices Missing
Senserva is a Microsoft Intelligent Security Association member. Get Going with Senserva Senserva patching Built for IT admins and security teams, with audit-ready data for compliance.

Reference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together, and where third-party patch vendors fit in.

Data notice: the trackers, feeds, and API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data and accepts no liability for actions taken based on it; verify against the primary source before acting. All use of this data is subject to the Senserva EULA.

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.