All patch & vulnerability trackers

The exploited open-source packages hiding in your dependencies

A free, no registration required, searchable table of exploited open-source vulnerabilities and the package version that fixes each, refreshed three times a day (5 AM, 12:30 PM, and 7 PM US Central). Open-source vulnerabilities that have a known package fix, ranked by real-world risk: actively exploited (CISA KEV, VulnCheck KEV, and the EU's EUVD) pinned to the top, then by EPSS exploit probability. Each row maps the CVE to the exact upgrade: the ecosystem (Maven, npm, PyPI, NuGet, Go, RubyGems, Packagist, and more), the package, and the fixed version, from the GitHub Advisory Database and OSV.dev. It is open data: search, sort, and export the whole table to CSV or JSON.

Senserva is a Microsoft Intelligent Security Association member

Open-source advisories with a fix from the GitHub Advisory Database and OSV.dev, cross-referenced with CISA KEV, VulnCheck KEV, the ENISA EUVD, and FIRST.org EPSS. Last updated 2026-07-20 20:33 GMT.

Most-affected open-source projects
Open-source projects with the most vulnerabilities that have a package fix. The red portion of each bar is the ransomware-linked share.
Exploitation trend
Exploited open-source CVEs added to CISA KEV per month, ransomware-linked highlighted.
12 months
SenservaSenserva provides Three Free Unlimited Audits, including all tenants and full Claude MCP.Start my Audit
Export:RSS

Take this data to your AI

Generated from the live data above, refreshed three times a day (5 AM, 12:30 PM, and 7 PM US Central). Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Tracking Microsoft instead?
See the Microsoft Patch Tracker for every Patch Tuesday KB and the CVEs it fixes, EPSS-ranked.
Microsoft Patch Tracker

Data sources

Every row is built from authoritative, public security feeds, refreshed automatically.

Source What it provides
CISA KEV catalogThe actively-exploited list: which CVEs are exploited in the wild, plus ransomware use and the date added.
OSV.devThe open-source package and the fixed version for each CVE. OSV.dev aggregates GitHub Security Advisories, PyPA, RustSec, and other OSV-schema sources across Maven, npm, PyPI, NuGet, Go, RubyGems, Packagist, and more.
NVD (NIST)CVSS base score and severity for each CVE.
CIRCL CVE SearchCVSS fallback when NVD has no score yet, so newly added CVEs still get a severity.
EPSS (FIRST.org)Exploit Prediction Scoring System: probability a CVE is exploited within 30 days, used to rank the list.
VulnCheck KEVA broader Known Exploited Vulnerabilities list than CISA KEV, surfaced as a "VulnCheck KEV" signal. Data courtesy of VulnCheck, used with attribution.
ENISA EUVDThe European Union Vulnerability Database (ENISA, under NIS2), surfaced as an "EU EUVD" signal for EU teams. Courtesy of ENISA, used with attribution.

Package and fixed-version data from OSV.dev and the google/osv.dev project, used under the Apache License 2.0. Underlying GitHub Security Advisory records are licensed CC BY 4.0. Exploitation data labeled VulnCheck KEV is provided by VulnCheck and used with attribution per VulnCheck's terms; EU cross-references are from the ENISA EUVD. Senserva is not affiliated with or endorsed by OSV.dev, Google, VulnCheck, or ENISA. Always confirm the fixed version against the linked advisory before deploying.

Open-source fixes, mapped to what you run

This tracker ranks exploited open-source CVEs and the package versions that fix them. Senserva matches the same OSV, CISA KEV, and EPSS intelligence to the components and apps it finds across your Microsoft 365, Intune, Defender, and Entra ID estate, so you upgrade the few that are actually exposed.

Matched to your tenant

Senserva connects these package fixes to the software it inventories, so a fixed version becomes a concrete upgrade for a system you actually run.

CVE and patch management

One connected model

Open-source exposure joins configuration, logs, and Conditional Access in one model, so exploited-and-exposed rises to the top.

The unified security model

AI remediation you approve

Bring your own AI for validated, reviewable upgrade guidance grounded in your estate.

AI remediation

Compliance evidence

Every exposed component maps to the frameworks an auditor asks about, from the same model.

Compliance evidence
Senserva
Three Free Unlimited Audits
1 scan to find, 2 to review your fixes.
Setup and running in minutes. Your data stays local, in a results database only you hold.
Everything Siemserva by Senserva does: every missing patch ranked by real attacks, all 650+ security checks, and full reports.
All users · All settings · All patches · All tenants
Includes our advanced Claude MCP: everything you need to run full audits.
Start my free audit Watch a guided first scan

Free registration is all it takes, no card. Want it always on? Summer Special: unlimited use, up to 50 tenants, $600/mo or $6,500/yr.

Reference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together, and where third-party patch vendors fit in.

Data notice: the trackers, feeds, and API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data and accepts no liability for actions taken based on it; verify against the primary source before acting. All use of this data is subject to the Senserva EULA.

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.

See where your own tenant stands

This tracker follows patches across the open-source world. To see where your own Microsoft 365 stands, run a free, unlimited audit.

Three free audits, across every tenant you manage: 1 scan to find, 2 to review your fixes. It finds:

  • Every missing patch, ranked by real attacks (CISA KEV, EPSS), so you fix the right things first.
  • The machines your consoles cannot see: unenrolled devices, silent patch failures, and servers with no patch path.
  • All 650+ security checks and audit-ready evidence, in an open results database that stays yours.

Includes our advanced Claude MCP: everything you need to run full audits.

Start my free audit