Criminals already know which of your apps they can break into. Now you do too.
We score the apps small businesses run every day against the flaws attackers are using right now. The data comes from CISA, NIST and FIRST and refreshes every night. The hotter the patch, the more attackers are working on it.
Every app, sized and heated by Patch Pressure
Each patch is one app, grouped by category. Bigger and brighter means attackers are working on it harder. Hover for the reasons, click for the flaws and support dates.
Is your business running software attackers are already using?
Pick the apps you run. You get a grade, the next step for each app, and the exploited flaws behind it. Your picks stay in this browser.
Patch Pressure, in plain numbers
Every app gets a score from 0 to 100. Five signals feed it. Each count is scaled so the first few flaws matter most, then capped. The caps and weights below are the ones the nightly build uses.
| Signal | Weight | Full weight at |
|---|
75 and up: patch now. 50 to 74: this week. 25 to 49: this month. Under 25: keep current. Any app whose newest release is past end of life gets "Replace", whatever its score.
Where the data comes from
- CISA Known Exploited Vulnerabilities: flaws attackers are confirmed to be using, and which ones ransomware crews use.
- NIST National Vulnerability Database: every published CVE and its CVSS severity.
- FIRST EPSS: the odds a flaw gets exploited in the next 30 days.
- endoflife.date: when each release stops getting security fixes.
What it can't tell you
- Scores are per product, not per version you run. A fully patched app can still score high.
- Matching CVEs to products uses NVD's product names, which sometimes miss or over-include.
- Vendor-hosted apps (Salesforce, Shopify and the like) get patched by the vendor and rarely get CVEs.
- NVD stopped tagging most Linux distribution packages, so distro counts run low.
- This page doesn't scan anything. For that, talk to us.