Synced 12 Sept 2026 01:32 UTC Account

Is your software actually safe to run?

Paste any version — in one second see if it's vulnerable, being exploited right now, or past end-of-life, plus the exact version to upgrade to.

Name, name + version, the output of nginx -v, or a CVE ID like CVE-2021-44228

Free, no account No lookup tracking 647 products
Powered by authoritative data NVD National Vulnerability Database CISA KEV Known Exploited FIRST EPSS Exploit prediction endoflife.date Lifecycle
647
Products tracked iThe software products IsItPatched monitors — 647 today, expanding over time.
138
Products being exploited iTracked products with at least one vulnerability in CISA's Known Exploited Vulnerabilities (KEV) catalog — being exploited in the wild right now.
0
Nothing new today iNew CVEs added to CISA's exploited list today (UTC) affecting tracked products. Resets at midnight UTC.
560
CVEs actively exploited iTotal vulnerabilities across tracked products currently on CISA's KEV list. Tap to see them all.

Needs attention iScore 0–100. Starts at 100, minus points per open Critical / High / Medium CVE. Capped at 20 if actively exploited (in CISA KEV), and 40 if the version is end-of-life. Higher = safer.

The most at-risk tracked products, worst first.

Healthy / Good: 207Attention: 48High risk / Critical: 204Unknown: 188 440 of 647 need attention
Cisco ASACisco · all versions
0/100
Critical · exploited
Fortinet FortiOSFortinet · all versions
0/100
Critical · exploited
Palo Alto PAN-OSPalo Alto Networks · all versions
0/100
Critical · exploited
Oracle WebLogicOracle · all versions
0/100
Critical · exploited
Red Hat Enterprise LinuxRed Hat
10.20/100
Critical · exploited
Windows Server 2016Microsoft
10.0.261000/100
Critical · exploited
View & search all 647 products →

CVE disclosure trend iNew CVEs published across tracked products, by month — last 12 months. A volume signal, not a verdict.

10,621 CVEs disclosed across tracked products in the last 12 months.

Oct 2025: 229 CVEs disclosedNov 2025: 54 CVEs disclosedDec 2025: 117 CVEs disclosedJan 2026: 301 CVEs disclosedFeb 2026: 229 CVEs disclosedMar 2026: 380 CVEs disclosedApr 2026: 694 CVEs disclosedMay 2026: 1052 CVEs disclosedJun 2026: 2568 CVEs disclosedJul 2026: 2818 CVEs disclosedAug 2026: 1523 CVEs disclosedSept 2026: 656 CVEs disclosed
OctNovDecJanFebMarAprMayJunJulAugSept

Security overview

IsItPatched tracks 647 widely-used software products — web servers, databases, CMS platforms, frameworks and infrastructure — and checks every version against known vulnerabilities (NVD), active exploitation (CISA KEV), exploitation probability (EPSS) and end-of-life dates. Right now 138 tracked products are affected by vulnerabilities under active exploitation, and the average health score across the catalogue is 55/100. The products needing attention most urgently include Cisco ASA, Fortinet FortiOS, Palo Alto PAN-OS. The next release to reach end-of-life is DuckDB (cycle 1.4) on 2026-09-16. On the positive side of the ledger, 155 tracked products have shipped a new supported release in the last 180 days — the safe versions to move to. For any product, IsItPatched shows the minimum safe version you should upgrade to.

What the statuses mean

Healthy / GoodOn the latest supported version — no, or only minor, known issues.
AttentionHas open vulnerabilities worth patching soon.
High risk / CriticalSerious open vulnerabilities (high CVSS severity). A fix almost always exists — upgrade to the recommended version.
Critical · exploitedSerious vulnerabilities being actively exploited right now (in CISA's KEV list). Patch urgently.
End of lifeNo longer receives security patches — this is the true "no-fix" case. Move to a supported version.

Missing a product or a feature?

Tell us what you'd like IsItPatched to track or build next — we read every message.

Send feedback →