Know What to Patch First

AI-powered CVE intelligence that classifies every vulnerability by patching urgency — so your team knows exactly what to fix and when.

Priority Levels

Emergency FixPatch immediately. Actively exploited, internet-facing, no auth required.
Fix SoonPatch within days. High-risk conditions partially met.
Planned FixSchedule in next patch cycle. Lower immediate risk.

Trending CVEs

8
Fix Soon
CVE-2025-53521RCE in F5 BIG-IP APM Access Policy on Virtual Server

The BIG-IP APM component contains a remote code execution vulnerability when an Access Policy is configured on a virtual server. It can be exploited by unauthenticated network traffic to trigger code execution with high impact, potentially leading to full compromise of the BIG-IP appliance and disruption of services.

RCE (Remote Code Execution)Auth: NoPoC: No9.8F5 Networks / BIG-IP
1 articleLoading...
Fix Soon
CVE-2026-21992Unauthenticated Remote Code Execution in Oracle Identity Manager and Oracle Web Services Manager

CVE-2026-21992 describes an unauthenticated remote code execution vulnerability in Oracle Identity Manager and Oracle Web Services Manager, components of Oracle Fusion Middleware. An attacker with network access via HTTP can compromise the affected products, potentially taking over the systems and impacting confidentiality, integrity, and availability. The CVSS base score is 9.8 (CVSS v3.1).

RCE (Remote Code Execution)Auth: NoPoC: No9.8Oracle / Oracle Identity Manager and Oracle Web Services Manager
1 articleLoading...
Planned Fix
Citrix / Citrix NetScaler ADC and NetScaler Gateway
2 articlesLoading...
Planned Fix
Langflow / Langflow
2 articlesLoading...
Planned Fix
CVE-2026-4368Session mix-up race condition in Citrix NetScaler ADC/Gateway

A race condition in NetScaler Gateway/session handling may cause user sessions to be mixed up under certain gateway or AAA configurations, potentially exposing sensitive data and impacting session integrity.

UnknownPoC: NoCitrix / NetScaler ADC and NetScaler Gateway
1 articleLoading...
Planned Fix
CVE-2025-32975Authentication Bypass in Quest KACE SMA (pre-auth)

Authentication bypass vulnerability in Quest KACE SMA that allows an attacker to impersonate legitimate users without credentials. This pre-auth flaw can lead to a full administrative takeover of the appliance in affected versions before patches. It is addressed by upgrading to patched releases as described by Quest.

Auth Bypass (Authentication Bypass)Auth: NoPoC: No10.0Quest Software / KACE Systems Management Appliance (SMA)
1 articleLoading...
Planned Fix
CVE-2026-4681Unspecified vulnerability

Public sources do not reveal detailed information for this CVE (CVE-2026-4681). There is no entry in the NVD with published details as of the current verification window, and no authoritative advisories publicly attributed to this ID. This profile is a placeholder pending authoritative data; no remediation guidance or exploit details are available at this time.

UnknownPoC: No
1 articleLoading...
Planned Fix
CVE-2025-31277Memory corruption in Apple Safari and related OS components (user interaction)

Apple Safari and several Apple OS components contain a memory corruption vulnerability that can be triggered by processing malicious web content. Exploitation requires user interaction to visit a crafted page, and the impact can be memory corruption with potential code execution on the device. Apple issued security updates fixing Safari and related OS components (e.g., macOS Sequoia, iOS/iPadOS, tvOS, watchOS, VisionOS) to mitigate the issue; the vulnerability is tracked under a high CVSS score and is listed in government KEV catalogs.

UnknownAuth: NoPoC: No8.8Apple Inc. / Safari
1 articleLoading...