Security

Actively exploited (CISA KEV) and known vulnerabilities across the software PemSync tracks. Covers our tracked catalogue only — this is not a complete CVE database; see NVD for that. Absence of data does not mean software is secure.

A CVE source is mapped for 55 of 66 tracked apps — 53 with findings, 2 checked with none found. The remaining 11 have no source yet, so they appear with no findings regardless — a coverage gap, not a clean bill of health.

Last checked 6 Sep 2026, 0:15

Actively exploited

CISA KEV

Confirmed exploitation in the wild, and the latest tracked build is affected — or its status could not be confirmed. Patch these first. Resolved findings on the same app collapse in green inside its card.

Windows Server

Microsoft

Assessed against latest tracked build 10.0.26100.33296

1 affecting69 not affecting
Show 69 not affecting

Verdict covers your latest tracked line only — other supported versions may need a different update. See the advisory for the full affected list.

Windows

Microsoft

Assessed against latest tracked build 10.0.28000.2804

1 affecting68 not affecting
Show 68 not affecting

Verdict covers your latest tracked line only — other supported versions may need a different update. See the advisory for the full affected list.

Known CVEs — no confirmed exploitation

Vulnerabilities not in CISA KEV. Rows flagged affecting latest have unpatched CVEs on the current release — update those first; the rest can wait for normal patch cycles. Apps with exploited findings also appear above; counts here cover their non-exploited CVEs only.

SoftwareVendorAffecting latestKnown CVEs
Neo4j DesktopNeo4j4 affecting9View
Adobe Acrobat ProAdobe3 affecting1357View
Google ChromeGoogle6190View
Microsoft EdgeMicrosoft3706View
FirefoxMozilla3293View
ThunderbirdMozilla1900View
Adobe Acrobat ReaderAdobe1064View
WiresharkWireshark Foundation776View
Microsoft 365 AppsMicrosoft656View
Oracle VirtualBoxOracle463View
Foxit PDF ReaderFoxit372View
Node.jsOpenJS Foundation185View
PythonPython Software Foundation140View
.NET RuntimeMicrosoft117View
VLC media playerVideoLAN113View
Visual Studio CodeMicrosoft77View
LibreOfficeThe Document Foundation71View
IntelliJ IDEAJetBrains70View
Cisco Webex AppCisco69View
Zoom WorkplaceZoom63View
Visual StudioMicrosoft56View
.NET Desktop RuntimeMicrosoft48View
MySQL WorkbenchOracle42View
ASP.NET Core RuntimeMicrosoft37View
PuTTYSimon Tatham36View
BlenderBlender Foundation35View
7-Zip7-Zip31View
PowerShellMicrosoft30View
Microsoft TeamsMicrosoft28View
Microsoft Defender AntivirusMicrosoft26View
WinRARRARLAB24View
Notepad++Notepad++19View
AnyDeskAnyDesk19View
WinSCPWinSCP17View
Cloudflare One AgentCloudflare16View
OneDriveMicrosoft15View
TeamViewerTeamViewer14View
Docker DesktopDocker13View
GitGit13View
PyCharmJetBrains10View
MobaXtermMobatek10View
TelegramTelegram9View
SQL Server Management StudioMicrosoft7View
DropboxDropbox5View
NmapNmap Project5View
BitwardenBitwarden4View
TailscaleTailscale3View
Citrix WorkspaceCitrix2View
PostmanPostman2View
AWS VPN ClientAmazon2View
DiscordDiscord2View
DBeaver CommunityDBeaver1View
Google Drive for DesktopGoogle1View
Tableau DesktopTableau1View
Exploited in the wild — latest tracked builds not affected17 apps

CISA-KEV findings that we verified do not affect the build we track as latest — it is already past the fix. Nothing to act on now; staying current is what keeps it that way.

Impact unverified3 apps · 20 findings

We could not determine whether these exploited vulnerabilities reach the build we track — the match carried no usable version data. Treat them as unknown rather than resolved, and check the vendor advisory directly.