Is your software actually safe to run?
Paste any version — in one second see if it's vulnerable, being exploited right now, or past end-of-life, plus the exact version to upgrade to.
Name, name + version, the output of nginx -v, or a CVE ID like CVE-2021-44228
Emerging BETA iA live newsroom that links trusted security reporting (first-party vendor advisories, research & CISA) to the software we track — often ahead of full NVD enrichment.
Breaking security reporting, auto-linked to tracked software — newest first. Open the newsroom →
Recently patched iTracked products that have just shipped a new supported release — the safe version to move to. The positive counterpart to the exploitation radar.
Freshly released safe versions across tracked software — newest first.
Needs attention iScore 0–100. Starts at 100, minus points per open Critical / High / Medium CVE. Capped at 20 if actively exploited (in CISA KEV), and 40 if the version is end-of-life. Higher = safer.
The most at-risk tracked products, worst first.
Live exploitation radar iThe most recently published vulnerabilities being actively exploited in the wild (CISA KEV), affecting products we track.
Actively-exploited CVEs across tracked products — newest first.
Upcoming end-of-life iTracked product release cycles reaching end-of-life soon — after these dates they no longer receive security patches.
Releases reaching end-of-life soon — soonest first.
CVE disclosure trend iNew CVEs published across tracked products, by month — last 12 months. A volume signal, not a verdict.
6,746 CVEs disclosed across tracked products in the last 12 months.
Security overview
IsItPatched tracks 638 widely-used software products — web servers, databases, CMS platforms, frameworks and infrastructure — and checks every version against known vulnerabilities (NVD), active exploitation (CISA KEV), exploitation probability (EPSS) and end-of-life dates. Right now 88 tracked products are affected by vulnerabilities under active exploitation, and the average health score across the catalogue is 61/100. The products needing attention most urgently include Fortinet FortiOS, Palo Alto PAN-OS, Red Hat Enterprise Linux. The next release to reach end-of-life is JFrog Artifactory (cycle 7.104) on 2026-07-30. On the positive side of the ledger, 161 tracked products have shipped a new supported release in the last 180 days — the safe versions to move to. For any product, IsItPatched shows the minimum safe version you should upgrade to.
What the statuses mean
Missing a product or a feature?
Tell us what you'd like IsItPatched to track or build next — we read every message.