The trackers
Each is a free, searchable, daily-refreshed view, ranked the same way: actively exploited (CISA KEV) first, then EPSS and CVSS.
Data sources
Every tracker is built from authoritative, public feeds, refreshed automatically. No login, no telemetry, no scan data.
For EU teams: vulnerabilities are cross-referenced to the ENISA EU Vulnerability Database (EUVD), the EU's official database under the NIS2 directive.
- Microsoft patches RSS (ranked by risk)
- Non-Microsoft KEV RSS (actively exploited)
- Microsoft patches JSON (machine-readable)
JSON and RSS feeds included, no login required. All feeds, the API, and quick-start examples.
The feeds are pulled and rebuilt daily, then ranked: actively exploited (CISA KEV) first, then EPSS exploit probability and CVSS severity. Every KB and CVE gets its own linkable, cross-referenced page. Static and fast, with no account required.
These trackers cover the public picture. Senserva ranks the same data against the patches and CVEs actually present across your Microsoft 365, Intune, Defender, and Entra ID estate.
Patch and vulnerability tracker FAQ
Common questions about the free patch and vulnerability trackers and how the rankings work.
What is the Siemserva by Senserva patch and vulnerability tracker?
The patch and vulnerability tracker is a free, daily-refreshed hub that ranks Microsoft and open-source patches and CVEs by real-world risk: actively exploited (CISA KEV) first, then EPSS exploit probability and CVSS severity. It links the Microsoft patch tracker, Microsoft CVE and vulnerability management, the non-Microsoft exploited-CVE tracker, the open-source patch tracker, and the end-of-life tracker.
Is the patch and vulnerability tracker free?
Yes. Every tracker is free to use, with no sign-in and no telemetry. Running Senserva adds the part a public tracker cannot: which of these patches and CVEs are actually present on your own devices, ranked, so you fix the right things first.
How often is the patch and vulnerability data updated?
Daily. The trackers auto-refresh from Microsoft MSRC, NVD, CISA KEV, FIRST.org EPSS, OSV.dev, and other public feeds, so the counts, charts, and tables reflect the latest Patch Tuesday and the current exploitation signals.
What data sources does the tracker use?
Microsoft MSRC for Patch Tuesday KB-to-CVE data, NVD and CIRCL for CVSS, CISA KEV for actively-exploited status, FIRST.org EPSS for exploit probability, OSV.dev and the GitHub Advisory Database for open-source package fixes, plus VulnCheck KEV and the ENISA EUVD for broader exploitation signals.
How are patches and vulnerabilities ranked?
By what is actually exploited, not just severity. Actively-exploited CVEs (CISA KEV) rank first, then FIRST.org EPSS exploit probability, then CVSS severity. This surfaces the handful attackers are really using, a better fix-first order than CVSS alone.
How is this different from a CVE list or the MSRC Update Guide?
A CVE list tells you what is broken. These trackers rank every patch and CVE by real-world exploitation and tie each one to the fix, the KB for Microsoft or the package version for open source, so you know what to patch first and exactly how.
Which trackers are included?
The Microsoft patch tracker (Patch Tuesday KBs), Microsoft CVE and vulnerability management, the non-Microsoft exploited-CVE tracker (CISA KEV), the open-source patch tracker (package fixes), and the end-of-life tracker (out-of-support products).
Can I take this data to my own AI?
Yes. Every tracker includes a free copy-paste AI prompt generated from its live data each day, and this page has a cross-tracker prompt covering the whole landscape: Microsoft KBs, exploited CVEs, open-source fixes, and end-of-life dates, ready for Claude, ChatGPT, or Copilot.