Licence and how to cite
The text and the compiled data on whattopatch (https://whattopatch.com) are licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Credit "whattopatch" and link to the page you used. Each page names the sources of its data; data from a source keeps that source's terms. Full terms: https://whattopatch.com/license
How to cite a page
Give the page's title, its address and the date its reading sentence shows, like this:
whattopatch, "<the page's title>", <the page's address>, data as of <the date on the page>.
Sources
- CISA Known Exploited Vulnerabilities catalog. Not affiliated with or endorsed by CISA (source). Licence: CC0 1.0 Universal
- EPSS scores by FIRST (https://www.first.org/epss/), generated by Empirical Security (source). Licence: Facts, which no licence covers
- CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation (source). Licence: CVE Program Terms of Use
- CISA Vulnrichment: SSVC decision points in the CVE records (source). Licence: CC0 1.0 Universal
- CWE names: Copyright © 2006-2026, The MITRE Corporation. CWE, CWSS, CWRAF, and the CWE logo are trademarks of The MITRE Corporation (source). Licence: CWE Terms of Use
- Metasploit Framework module metadata, Copyright 2006-2026, Rapid7, Inc. (BSD 3-Clause) (source). Licence: Facts, which no licence covers
- Exploit-DB repository index (facts only; each entry linked) (source). Licence: Facts, which no licence covers
whattopatch is independent and not affiliated with or endorsed by CISA, FIRST or MITRE. Our patch-first rank is our own reading of public data, not advice for your systems.