Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

3,930 record edits refused · 339 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
ChangedSourceRows

These rows are not counted anywhere on this site. Checked and refused means we compared this change and then rejected it: the false positive filter for this kind of change judged it to be a false positive rather than a real change. The row is shown so you can check the filter and disagree with us, and it is counted in no figure on this site. No advisory change is here: the advisory engine counts the 2,291 version pairs its filters refused by class rather than writing them out one by one, so this view holds CVE and KEV changes only.

Rows we checked and refused, counted nowhere, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Fri 7 Aug 2026· 7 record changes
2026-08-07Product addedCVE-2026-58016not named as affected at publication, now names red hat enterprise linux 10.0 extended update support and 1 morenot counted: A variant beneath an already affected parentDays to revision 38
2026-08-07same kind of change as the line aboveCVE-2026-58016same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 38
2026-08-07same kind of change as the line aboveCVE-2026-58016same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.6 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 38
2026-08-07CVSS base score changed
whole record
WatchGuard
stated at publication 9.1, now states 9.3Assessments not comparable · base scoreCriticalCriticalnot counted: CVSS version set changedDays to revision 682
2026-08-07same kind of change as the line aboveCVE-2024-6592same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 682
2026-08-07same kind of change as the line aboveCVE-2024-6593same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 682
2026-08-07CVSS base score changedCVE-2024-6594
whole record
WatchGuard
stated at publication 7.5, now states 8.7Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 682
2026-08-07CVSS base score changedCVE-2024-8424
whole record
WatchGuard
stated at publication 7.8, now states 8.5Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 638
2026-08-07CVSS base score changedCVE-2024-5974
whole record
WatchGuard
stated at publication 7.2, now states 8.6Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 760
Thu 6 Aug 2026· 7 record changes
2026-08-06Product addedCVE-2026-58016not named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-on and 5 morenot counted: A variant beneath an already affected parentDays to revision 37
2026-08-06same kind of change as the line aboveCVE-2026-58016same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 37
2026-08-06same kind of change as the line aboveCVE-2026-58016same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 37
2026-08-06same kind of change as the line aboveCVE-2026-58016same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 37
2026-08-06same kind of change as the line aboveCVE-2026-58016same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 37
2026-08-06same kind of change as the line aboveCVE-2026-58016same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.2 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 37
2026-08-06same kind of change as the line aboveCVE-2026-58016same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.4 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 37
2026-08-06Product addedCVE-2026-5674not named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 21
Wed 5 Aug 2026· 36 record changes
2026-08-05Affected range extendedCVE-2026-24457
eclipse foundationeclipse openmq
eclipse
stated at publication 6.5.1, now states 6.5.2Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 153
2026-08-053 commitsProduct added33 rows, one per record and productnot named as affected at publication, now names red hat build of keycloak 26.6.5 and 3 moreBranches and original-value intervals are stated on each row.not counted: 2 classesDays to revision 0 to 70
2026-08-05same kind of change as the line aboveCVE-2026-11986same vendor as the line abovenot named as affected at publication, now names red hat build of keycloak 26.6.5Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 55
2026-08-05same kind of change as the line aboveCVE-2026-14209same vendor as the line abovenot named as affected at publication, now names red hat build of keycloak 26.4.14Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 36
2026-08-05same kind of change as the line aboveCVE-2026-14209same vendor as the line abovenot named as affected at publication, now names red hat build of keycloak 26.6.5Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 36
2026-08-05same kind of change as the line aboveCVE-2026-14614same vendor as the line abovenot named as affected at publication, now names red hat build of keycloak 26.4.14Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 33
2026-08-05same kind of change as the line aboveCVE-2026-14614same vendor as the line abovenot named as affected at publication, now names red hat build of keycloak 26.6.5Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 33
2026-08-05same kind of change as the line aboveCVE-2026-14615same vendor as the line abovenot named as affected at publication, now names red hat build of keycloak 26.4.14Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 33
2026-08-05same kind of change as the line aboveCVE-2026-14615same vendor as the line abovenot named as affected at publication, now names red hat build of keycloak 26.6.5Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 33
2026-08-05same kind of change as the line aboveCVE-2026-15572same vendor as the line abovenot named as affected at publication, now names red hat build of keycloak 26.4.14Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
25 more rows in this change are not listed here. Open all 33 rows
2026-08-05CVSS base score changedCVE-2026-71208
whole record
TuranSec
stated at publication 7.1, now states 6.5Assessments not comparable · base scoreHighMediumNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
2026-08-05CVSS base score changedCVE-2026-49004
whole record
zte
stated at publication 10.0, now states 6.5Assessments not comparable · base scoreCriticalMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 0
Tue 4 Aug 2026· 16 record changes
2026-08-04Affected range extendedCVE-2025-61813
adobecoldfusion
stated at publication 2021.22, now states 2025.4Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 2021.22 still holdsnot dated
2026-08-04Product addedCVE-2026-36214mitrenot named as affected at publication, now names osticketNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 22
2026-08-042 commitsProduct addedCVE-2026-14476not named as affected at publication, now names red hat enterprise linux 9.6 extended update support and 6 moreBranches and original-value intervals are stated on each row.not counted: A variant beneath an already affected parentDays to revision 28
2026-08-04same kind of change as the line aboveCVE-2026-14476same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.6 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 28
2026-08-04same kind of change as the line aboveCVE-2026-14476same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 28
2026-08-04same kind of change as the line aboveCVE-2026-14476same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 28
2026-08-04same kind of change as the line aboveCVE-2026-14476same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 28
2026-08-04same kind of change as the line aboveCVE-2026-14476same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 28
2026-08-04same kind of change as the line aboveCVE-2026-14476same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.2 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 28
2026-08-04same kind of change as the line aboveCVE-2026-14476same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.4 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 28
2026-08-042 commitsProduct addedCVE-2026-14474not named as affected at publication, now names red hat enterprise linux 9.6 extended update support and 6 moreBranches and original-value intervals are stated on each row.not counted: A variant beneath an already affected parentDays to revision 28
2026-08-04same kind of change as the line aboveCVE-2026-14474same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.6 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 28
2026-08-04same kind of change as the line aboveCVE-2026-14474same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 28
2026-08-04same kind of change as the line aboveCVE-2026-14474same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 28
2026-08-04same kind of change as the line aboveCVE-2026-14474same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 28
2026-08-04same kind of change as the line aboveCVE-2026-14474same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 28
2026-08-04same kind of change as the line aboveCVE-2026-14474same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.2 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 28
2026-08-04same kind of change as the line aboveCVE-2026-14474same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.4 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 28
Mon 3 Aug 2026· 8 record changes
2026-08-03Affected range extendedCVE-2026-65321
laughingman7743pyathena
VulnCheck
stated at publication 3.35.3, now states 3.35.4Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 3.35.3 still holdsnot dated
2026-08-03Affected range extended
shenzhen i365-tech co. ltd.setracker2 parental control app (android) package com.tgelec.setracker
icscert
stated at publication 3.1.5, now states 3.4.1Release branch starts at *.not counted: Another branch advancednot dated
2026-08-03same kind of change as the line aboveCVE-2026-9219same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 3.1.5 still holdsnot dated
2026-08-03same kind of change as the line aboveCVE-2026-9220same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 3.1.5 still holdsnot dated
2026-08-03same kind of change as the line aboveCVE-2026-9221same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 3.1.5 still holdsnot dated
2026-08-03Product addedCVE-2026-12912not named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 35
2026-08-032 commitsProduct addedCVE-2026-53705not named as affected at publication, now names red hat enterprise linux 8.6 extended update support long-life add-on and 1 moreBranches and original-value intervals are stated on each row.not counted: A variant beneath an already affected parentDays to revision 49
2026-08-03same kind of change as the line aboveCVE-2026-53705same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 49
2026-08-03same kind of change as the line aboveCVE-2026-53705same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 49
2026-08-03CVSS base score changedCVE-2024-21539
whole record
snyk
stated at publication 7.5, now states 8.7Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 622
Sun 2 Aug 2026· 1 record change
2026-08-02CVSS base score changedCVE-2026-67308
whole record
VulnCheck
stated at publication 10.0, now states 9.3Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1
Sat 1 Aug 2026· 1 record change
2026-08-01CVSS base score changedCVE-2024-21536
whole record
snyk
stated at publication 7.5, now states 8.7Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 651
Fri 31 Jul 2026· 25 record changes · 1 advisory change
2026-07-31Fix version movedCVE-2026-10031
drakkansftpgo
VulnCheck
stated at publication 2.7.4, now states 2.7.4Release branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2026-07-31Fix version moved
leantimeleantime
VulnCheck
stated at publication 3.6.2, now states 3.6.2Release branch starts at 0.not counted: Same claim, other operatorDays to revision 1
2026-07-31same kind of change as the line aboveCVE-2026-66414same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2026-07-31same kind of change as the line aboveCVE-2026-66415same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2026-07-31same kind of change as the line aboveCVE-2026-66416same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2026-07-31Affected range extendedCVE-2026-58586
zapadimage::webp
CPANSec
stated at publication 0.2, now states 0.3.0Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 7
2026-07-314 commitsProduct added18 rows, one per record and productnot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-on and 7 moreBranches and original-value intervals are stated on each row.not counted: A variant beneath an already affected parentDays to revision 49 to 72
2026-07-31same kind of change as the line aboveCVE-2026-48864same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 66
2026-07-31same kind of change as the line aboveCVE-2026-48864same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 66
2026-07-31same kind of change as the line aboveCVE-2026-48864same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 66
2026-07-31same kind of change as the line aboveCVE-2026-48864same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.4 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 66
2026-07-31same kind of change as the line aboveCVE-2026-48864same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.6 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 66
2026-07-31same kind of change as the line aboveCVE-2026-48864same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 66
2026-07-31same kind of change as the line aboveCVE-2026-54228same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 49
2026-07-31same kind of change as the line aboveCVE-2026-54228same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 49
10 more rows in this change are not listed here. Open all 18 rows
2026-07-31Product addedCVE-2026-18358redhatnot named as affected at publication, now names gnome-remote-desktopNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-07-31CVSS base score changedCVE-2024-4944
whole record
WatchGuard
stated at publication 7.8, now states 8.6Assessments not comparable · base scoreHighHighOriginal value first replaced 2026-07-29; this value first seen 2026-07-31.Not counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 751
2026-07-31published 2026-07-31Advisory fix version movedGHSA-q6hh-gp44-4hcmCVE-2026-52857
gogithub.com/pterodactyl/wings
moderate
stated at publication 1.12.4-0.20260604185925-5f71f65711b6, now states 1.13.0Days to revision 0
Thu 30 Jul 2026· 8 record changes
2026-07-303 commitsProduct added8 rows, one per record and productnot named as affected at publication, now names red hat enterprise linux 10.0 extended update support and 2 moreBranches and original-value intervals are stated on each row.not counted: A variant beneath an already affected parentDays to revision 45
2026-07-30same kind of change as the line aboveCVE-2026-52718same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 45
2026-07-30same kind of change as the line aboveCVE-2026-52719same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 45
2026-07-30same kind of change as the line aboveCVE-2026-52720same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 45
2026-07-30same kind of change as the line aboveCVE-2026-52722same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 45
2026-07-30same kind of change as the line aboveCVE-2026-52720same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 45
2026-07-30same kind of change as the line aboveCVE-2026-52720same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 45
2026-07-30same kind of change as the line aboveCVE-2026-52722same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 45
2026-07-30same kind of change as the line aboveCVE-2026-52722same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 45
Wed 29 Jul 2026· 2 record changes
2026-07-29Affected range extendedCVE-2023-1829
linuxlinux kernel
Google
stated at publication 6.2, now states 6.3.0Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.2 still holdsnot dated
2026-07-29CVSS base score changedCVE-2024-21537
whole record
snyk
stated at publication 8.8, now states 9.3Assessments not comparable · base scoreHighCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 636
Tue 28 Jul 2026· 24 record changes
2026-07-288 commitsProduct added22 rows, one per record and productnot named as affected at publication, now names red hat enterprise linux 6 and 8 moreBranches and original-value intervals are stated on each row.not counted: 2 classesDays to revision 0 to 43
2026-07-28same kind of change as the line aboveCVE-2026-16313same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 6Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-07-28same kind of change as the line aboveCVE-2026-53705same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 43
2026-07-28same kind of change as the line aboveCVE-2026-53705same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 43
2026-07-28same kind of change as the line aboveCVE-2026-52718same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.4 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 43
2026-07-28same kind of change as the line aboveCVE-2026-52718same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.6 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 43
2026-07-28same kind of change as the line aboveCVE-2026-52719same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.4 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 43
2026-07-28same kind of change as the line aboveCVE-2026-52719same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.6 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 43
2026-07-28same kind of change as the line aboveCVE-2026-52720same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 43
14 more rows in this change are not listed here. Open all 22 rows
2026-07-28CVSS base score changed
whole record
VulnCheck
stated at publication 7.2, now states 6.3Assessments not comparable · base scoreHighMediumnot counted: CVSS assessments are not comparableDays to revision 0
2026-07-28same kind of change as the line aboveCVE-2026-66752same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
2026-07-28same kind of change as the line aboveCVE-2026-67181same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Mon 27 Jul 2026· 3 record changes
2026-07-27Affected range extendedCVE-2026-63094
signozsignoz
VulnCheck
stated at publication 0.133.0, now states 0.134.0Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 10
2026-07-27Product addednot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportnot counted: A variant beneath an already affected parentDays to revision 20
2026-07-27same kind of change as the line aboveCVE-2026-14474same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 20
2026-07-27same kind of change as the line aboveCVE-2026-14476same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 20
Fri 24 Jul 2026· 1 record change
2026-07-24Affected range extendedCVE-2026-29009
u-bootu-boot
VulnCheck
stated at publication 2026.04-rc3, now states 2026.07-rc2Release branch starts at 0.Not counted: Prerelease named as the boundary. a prerelease qualifier on one side — a beta or release candidate is not a version anyone was told to patch toDays to revision 16
Thu 23 Jul 2026· 1 record change
2026-07-23Affected range extendedCVE-2026-27403
nerdpresshubbub lite
Patchstack
stated at publication 1.36.3, now states 1.36.3.1Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 1.36.3 still holdsnot dated
Wed 22 Jul 2026· 255 record changes
2026-07-22Fix version moved
microsoftwindows 11 version 26h1
stated at publication 10.0.28000.2269, now states 10.0.28000.2525Release branch starts at 10.0.28000.0.not counted: Build number corrected to the one that shippedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-33842same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-34328same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-34346same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-34348same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-34349same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-40378same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-40422same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-41087same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
183 more rows in this change are not listed here. Open all 191 rows
2026-07-22Product addednot named as affected at publication, now names thunderbirdnot counted: Added entry does not state affected statusDays to revision 1 to 8
2026-07-22same kind of change as the line aboveCVE-2026-15718same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-15719same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-16349same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
2026-07-22same kind of change as the line aboveCVE-2026-16350same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
2026-07-22same kind of change as the line aboveCVE-2026-16351same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
2026-07-22same kind of change as the line aboveCVE-2026-16352same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
2026-07-22same kind of change as the line aboveCVE-2026-16353same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
2026-07-22same kind of change as the line aboveCVE-2026-16354same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
55 more rows in this change are not listed here. Open all 63 rows
2026-07-22Product addedCVE-2023-52355not named as affected at publication, now names red hat enterprise linux 9.6 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 909
Tue 21 Jul 2026· 4 record changes
2026-07-21Fix version movedCVE-2026-1995
idriveidrive cloud backup client for windows
certcc
stated at publication 7.0.0.63, now states 7.0.0.63Release branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 119
2026-07-21Affected range extendedCVE-2026-57807
miniorange security software pvt ltd.oauth single sign on - sso (oauth client)
Patchstack
stated at publication 38.5.8, now states 38.5.8.1Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 38.5.8 still holdsnot dated
2026-07-21Affected range extendedCVE-2026-8149bcorgstated at publication 2.1.2, now states 2.1.3Release branch starts at 2.1.0.Original value first replaced 2026-05-18; this value first seen 2026-07-21.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 11
2026-07-21CVSS base score changedCVE-2026-64877
whole record
tenable
stated at publication 9.6, now states 9.4Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Mon 20 Jul 2026· 22 record changes
2026-07-20Fix version movedCVE-2024-58362
surrealdbsurrealdb
VulnCheck
stated at publication 1.5.2, now states 2.0.0-beta.3Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 1.5.2 still holdsnot dated
2026-07-20Affected range extended
sankonet::bittorrent
CPANSec
stated at publication 2.0.1, now states 2.1.0Release branch starts at 0.not counted: Same claim, other operatorDays to revision 20
2026-07-20same kind of change as the line aboveCVE-2026-57079same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 20
2026-07-20same kind of change as the line aboveCVE-2026-57082same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 20
2026-07-202 commitsProduct addedCVE-2026-10649not named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-on and 3 moreBranches and original-value intervals are stated on each row.not counted: A variant beneath an already affected parentDays to revision 34
2026-07-20same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-20same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-20same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-20same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-202 commitsProduct addedmitrenot named as affected at publication, now names busyboxBranches and original-value intervals are stated on each row.not counted: No products named at publicationDays to revision 6
2026-07-20same kind of change as the line aboveCVE-2026-38755same vendor as the line abovesame change as the line aboveNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 6
2026-07-20same kind of change as the line aboveCVE-2026-38752same vendor as the line abovesame change as the line aboveNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 6
2026-07-20same kind of change as the line aboveCVE-2026-38753same vendor as the line abovesame change as the line aboveNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 6
2026-07-20same kind of change as the line aboveCVE-2026-38754same vendor as the line abovesame change as the line aboveNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 6
2026-07-202 commitsProduct addednot named as affected at publication, now names red hat enterprise linux 9.2 update services for sap solutionsBranches and original-value intervals are stated on each row.not counted: A variant beneath an already affected parentDays to revision 34 to 81
2026-07-20same kind of change as the line aboveCVE-2026-3833same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 81
2026-07-20same kind of change as the line aboveCVE-2026-42011same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 74
2026-07-20same kind of change as the line aboveCVE-2026-42012same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 55
2026-07-20same kind of change as the line aboveCVE-2026-42013same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 55
2026-07-20same kind of change as the line aboveCVE-2026-42014same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-20same kind of change as the line aboveCVE-2026-42015same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 55
2026-07-20same kind of change as the line aboveCVE-2026-5260same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 55
2026-07-20same kind of change as the line aboveCVE-2026-33845same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 81
3 more rows in this change are not listed here. Open all 11 rows
Fri 17 Jul 2026· 2 record changes
2026-07-17Product addedCVE-2026-10649not named as affected at publication, now names red hat enterprise linux 10.0 extended update support and 1 morenot counted: A variant beneath an already affected parentDays to revision 31
2026-07-17same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 31
2026-07-17same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.6 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 31
Thu 16 Jul 2026· 2 record changes
2026-07-162 commitsProduct addedCVE-2026-10649not named as affected at publication, now names red hat enterprise linux 9.4 update services for sap solutions and 1 moreBranches and original-value intervals are stated on each row.not counted: A variant beneath an already affected parentDays to revision 30
2026-07-16same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.4 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 30
2026-07-16same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.2 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 30
Wed 15 Jul 2026· 1 record change · 1 advisory change
2026-07-15Affected range extendedCVE-2026-15146
gnu wgetwget
certcc
stated at publication 1.25.0 before commit 4f85853f641863d5915786a8413e1a213726a62b, now states 1.25.0+4f85853f64Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 5
2026-07-15published 2026-05-28Package added to advisoryGHSA-995v-fvrw-c78mCVE-2026-45287lownot named as affected when the advisory was published, now names go.opentelemetry.io/otel/schemaDays to revision 48
Tue 14 Jul 2026· 56 record changes
2026-07-14Fix version moved54 rows, one per record, product and release branch
siemens18 products
stated at publication V2.9.9, now states V4.1.6Release branch starts at *.not counted: Another branch advancednot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
46 more rows in this change are not listed here. Open all 54 rows
2026-07-14CVSS base score changedCVE-2024-21529
whole record
snyk
stated at publication 8.2, now states 8.8Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 671
2026-07-14CVSS base score changedCVE-2026-7891
whole record
DIVD
stated at publication 9.3, now states 9.1Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 68
Mon 13 Jul 2026· 4 record changes
2026-07-13Affected range extendedCVE-2026-12948
digi international3 products
Digi
stated at publication 82000747_AB, now states 82000774_ABRelease branch starts at *.not counted: Release branches rewrittennot dated
2026-07-13same kind of change as the line aboveCVE-2026-12948same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Release branches rewritten. the range layout was rewritten: a branch stated at publication is gone and another appeared, so no branch can be matchednot dated
2026-07-13same kind of change as the line aboveCVE-2026-12948same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Release branches rewritten. the range layout was rewritten: a branch stated at publication is gone and another appeared, so no branch can be matchednot dated
2026-07-13same kind of change as the line aboveCVE-2026-12948same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Release branches rewritten. the range layout was rewritten: a branch stated at publication is gone and another appeared, so no branch can be matchednot dated
2026-07-13Product addedCVE-2025-14087not named as affected at publication, now names red hat openshift container platform 4Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 216
Fri 10 Jul 2026· 3 record changes · 1 advisory change
2026-07-10Product addedCVE-2026-11332not named as affected at publication, now names openshift service mesh 3 and 2 morenot counted: Added entry does not state affected statusDays to revision 35
2026-07-10same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names openshift service mesh 3Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 35
2026-07-10same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names red hat advanced cluster management for kubernetes 2Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 35
2026-07-10same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names service telemetry framework 1.5Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 35
2026-07-10published 2026-07-10Package added to advisoryGHSA-hvr9-72v2-fff3CVE-2026-54069criticalnot named as affected when the advisory was published, now names github.com/siyuan-note/siyuan/kernelDays to revision 0
Thu 9 Jul 2026· 27 record changes
2026-07-09Product added21 rows, one per record and productnot named as affected at publication, now names red hat enterprise linux 10.0 extended update support and 2 morenot counted: A variant beneath an already affected parentDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50256same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50256same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50256same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50257same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50257same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50257same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50258same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50258same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
13 more rows in this change are not listed here. Open all 21 rows
2026-07-09CVSS base score changed
whole record
VulDB
stated at publication 6.5, now states 8.6Assessments not comparable · base scoreMediumHighnot counted: CVSS assessments are not comparableDays to revision 1,168
2026-07-09same kind of change as the line aboveCVE-2023-2373same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1,168
2026-07-09same kind of change as the line aboveCVE-2023-2374same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1,168
2026-07-09same kind of change as the line aboveCVE-2023-2375same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1,168
2026-07-09same kind of change as the line aboveCVE-2023-2376same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1,168
2026-07-09same kind of change as the line aboveCVE-2023-2377same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1,168
2026-07-09same kind of change as the line aboveCVE-2023-2378same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1,168
Wed 8 Jul 2026· 31 record changes
2026-07-08Affected range extendedCVE-2026-5724Temporalstated at publication 1.30.3, now states 1.31.2Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 1.30.3 still holdsnot dated
2026-07-086 commitsProduct added30 rows, one per record and productnot named as affected at publication, now names red hat enterprise linux 10.0 extended update support and 6 moreBranches and original-value intervals are stated on each row.not counted: A variant beneath an already affected parentDays to revision 1 to 33
2026-07-08same kind of change as the line aboveCVE-2026-50262same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
2026-07-08same kind of change as the line aboveCVE-2026-50262same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
2026-07-08same kind of change as the line aboveCVE-2026-50262same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
2026-07-08same kind of change as the line aboveCVE-2026-50263same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
2026-07-08same kind of change as the line aboveCVE-2026-50263same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
2026-07-08same kind of change as the line aboveCVE-2026-50263same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
2026-07-08same kind of change as the line aboveCVE-2026-50256same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
2026-07-08same kind of change as the line aboveCVE-2026-50257same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
22 more rows in this change are not listed here. Open all 30 rows
Tue 7 Jul 2026· 27 record changes · 13 advisory changes
2026-07-074 commitsProduct added26 rows, one per record and productnot named as affected at publication, now names red hat jboss enterprise application platform 8.1 for rhel 10 and 8 moreBranches and original-value intervals are stated on each row.not counted: A variant beneath an already affected parentDays to revision 0 to 32
2026-07-07same kind of change as the line aboveCVE-2025-12799same vendor as the line abovenot named as affected at publication, now names red hat jboss enterprise application platform 8.1 for rhel 10Not counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat jboss enterprise application platform 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 0
2026-07-07same kind of change as the line aboveCVE-2025-12799same vendor as the line abovenot named as affected at publication, now names red hat jboss enterprise application platform 8.1 for rhel 8Not counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat jboss enterprise application platform 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 0
2026-07-07same kind of change as the line aboveCVE-2025-12799same vendor as the line abovenot named as affected at publication, now names red hat jboss enterprise application platform 8.1 for rhel 9Not counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat jboss enterprise application platform 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 0
2026-07-07same kind of change as the line aboveCVE-2026-11610same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 0
2026-07-07same kind of change as the line aboveCVE-2026-11610same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 0
2026-07-07same kind of change as the line aboveCVE-2026-11774same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 26
2026-07-07same kind of change as the line aboveCVE-2026-11774same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 26
2026-07-07same kind of change as the line aboveCVE-2026-11610same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 0
18 more rows in this change are not listed here. Open all 26 rows
2026-07-07CVSS base score changedCVE-2026-3823
whole record
twcert
stated at publication 9.3, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 120
2026-07-07published 2026-06-25Package added to advisory3 bandsnot named as affected when the advisory was published, now names golang.org/x/cryptoDays to revision 12
2026-07-07published 2026-06-25same kind of change as the line aboveGHSA-x527-x647-q7ggCVE-2026-46595same package registry as the line abovecriticalsame change as the line aboveDays to revision 12
2026-07-07published 2026-06-25same kind of change as the line aboveGHSA-5cgq-3rg8-m6cvCVE-2026-42508same package registry as the line abovecriticalsame change as the line aboveDays to revision 12
2026-07-07published 2026-06-25same kind of change as the line aboveGHSA-rm3j-f69w-wqmqCVE-2026-39834same package registry as the line abovecriticalsame change as the line aboveDays to revision 12
2026-07-07published 2026-06-25same kind of change as the line aboveGHSA-89gr-r52h-f8rxCVE-2026-39831same package registry as the line abovecriticalsame change as the line aboveDays to revision 12
2026-07-07published 2026-06-25same kind of change as the line aboveGHSA-w879-237q-wc7rCVE-2026-39829same package registry as the line abovehighsame change as the line aboveDays to revision 12
2026-07-07published 2026-06-25same kind of change as the line aboveGHSA-vgwf-h737-ff37CVE-2026-39830same package registry as the line abovecriticalsame change as the line aboveDays to revision 12
2026-07-07published 2026-06-25same kind of change as the line aboveGHSA-f5wc-c3c7-36mcCVE-2026-39832same package registry as the line abovecriticalsame change as the line aboveDays to revision 12
2026-07-07published 2026-06-25same kind of change as the line aboveGHSA-jppx-rxg9-jmrxCVE-2026-39833same package registry as the line abovecriticalsame change as the line aboveDays to revision 12
5 more rows in this change are not listed here. Open all 13 rows
Sat 4 Jul 2026· 1 record change
2026-07-04Product addedCVE-2026-39087mitrenot named as affected at publication, now names ntfyNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 73
Fri 3 Jul 2026· 198 record changes
2026-07-032 commitsFix version moved198 rows, one per record, product and release branch
mbs18 products
CERTVDE
stated at publication V6_0_0_7, now states V6_00_07Branches and original-value intervals are stated on each row.not counted: Version respelledDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
190 more rows in this change are not listed here. Open all 198 rows
Thu 2 Jul 2026· 5 record changes
2026-07-02Product addedCVE-2026-30689mitrenot named as affected at publication, now names blog.coreNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 98
2026-07-02Product addedCVE-2026-9800not named as affected at publication, now names red hat build of quarkus and 2 morenot counted: Added entry does not state affected statusDays to revision 7
2026-07-02same kind of change as the line aboveCVE-2026-9800same vendor as the line abovenot named as affected at publication, now names red hat build of quarkusNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 7
2026-07-02same kind of change as the line aboveCVE-2026-9800same vendor as the line abovenot named as affected at publication, now names red hat jboss enterprise application platform expansion packNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 7
2026-07-02same kind of change as the line aboveCVE-2026-9800same vendor as the line abovenot named as affected at publication, now names red hat single sign-on 7Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 7
2026-07-02CVSS base score changedCVE-2024-21527
whole record
snyk
stated at publication 8.2, now states 8.8Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 714
Mon 29 Jun 2026· 2 record changes
2026-06-29Affected range extendedCVE-2026-3256
ktathttp::session
CPANSec
stated at publication 0.53, now states 0.54Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 93
2026-06-29Product addedCVE-2026-9105TPLinknot named as affected at publication, now names tl-wr841n v14Not counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed tp-link systems inc./tl-wr841m v14; a new product identity is not establishedDays to revision 0
Fri 26 Jun 2026· 21 record changes · 1 advisory change
2026-06-26Product addednot named as affected at publication, now names red hat build of keycloak 26.4.13not counted: Added entry does not state affected statusDays to revision 1 to 92
2026-06-26same kind of change as the line aboveCVE-2026-37977same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 81
2026-06-26same kind of change as the line aboveCVE-2026-4874same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 92
2026-06-26same kind of change as the line aboveCVE-2026-7500same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 57
2026-06-26same kind of change as the line aboveCVE-2026-8830same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 38
2026-06-26same kind of change as the line aboveCVE-2026-8922same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 38
2026-06-26same kind of change as the line aboveCVE-2026-9083same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
2026-06-26same kind of change as the line aboveCVE-2026-9086same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
2026-06-26same kind of change as the line aboveCVE-2026-9087same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 37
13 more rows in this change are not listed here. Open all 21 rows
2026-06-26published 2026-04-07Package added to advisoryGHSA-xgrm-4fwx-7qm8CVE-2026-33815criticalnot named as affected when the advisory was published, now names github.com/jackc/pgx/v5Days to revision 80
Thu 25 Jun 2026· 8 record changes
2026-06-253 commitsProduct addednot named as affected at publication, now names red hat build of keycloak 26.6.4Branches and original-value intervals are stated on each row.not counted: Added entry does not state affected statusDays to revision 0 to 29
2026-06-25same kind of change as the line aboveCVE-2026-9705same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-25same kind of change as the line aboveCVE-2026-9799same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-25same kind of change as the line aboveCVE-2026-9083same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-25same kind of change as the line aboveCVE-2026-9086same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-25same kind of change as the line aboveCVE-2026-9099same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-25same kind of change as the line aboveCVE-2026-9795same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 29
2026-06-25same kind of change as the line aboveCVE-2026-9800same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-25CVSS base score changedCVE-2026-56115
whole record
VulnCheck
stated at publication 6.0, now states 8.8Assessments not comparable · base scoreMediumHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 2
Tue 23 Jun 2026· 2 record changes
2026-06-23Affected range extendedCVE-2026-54390
jtl softwarejtl shop
VulnCheck
stated at publication 5.3.x, now states 5.4.0Release branch starts at 5.2.0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 5
2026-06-23CVSS base score changedCVE-2026-56784
whole record
VulnCheck
stated at publication 8.3, now states 8.6Assessments not comparable · base scoreHighHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Thu 18 Jun 2026· 1 record change · 1 advisory change
2026-06-18Fix version movedCVE-2025-13590
wso2org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl
stated at publication 9.32.147.2, now states 9.32.167Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 9.32.147.2 still holdsnot dated
2026-06-18published 2026-01-14Package added to advisoryGHSA-mqqf-5wvp-8fh8CVE-2025-69725moderatenot named as affected when the advisory was published, now names github.com/go-chi/chi/v5Days to revision 155
Wed 17 Jun 2026· 1 record change
2026-06-17Affected range extendedCVE-2026-43003
openstackironic-python-agent
mitre
stated at publication 11.5.0, now states 11.5.1Release branch starts at *.Not counted: Release branches rewritten. the range layout was rewritten: a branch stated at publication is gone and another appeared, so no branch can be matchednot dated
Tue 16 Jun 2026· 17 record changes
2026-06-16Affected range extendedCVE-2026-54421
openstackironic
mitre
stated at publication 35.0.1, now states 35.0.2Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 3
2026-06-16Product addednot named as affected at publication, now names thunderbirdnot counted: Added entry does not state affected statusDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12289same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12290same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12291same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12292same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12293same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12294same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12295same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12296same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
8 more rows in this change are not listed here. Open all 16 rows
Sun 14 Jun 2026· 59 record changes
2026-06-14Fix version moved
linuxlinux
stated at publication 7.0.1, now states 7.1Release branch starts at *.not counted: Another branch advancednot dated
2026-06-14same kind of change as the line aboveCVE-2026-31532same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31574same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31575same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31576same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31577same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31578same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31579same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31580same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
49 more rows in this change are not listed here. Open all 57 rows
2026-06-14Fix version moved
linuxlinux
stated at publication 7.0.3, now states 7.1Release branch starts at *.not counted: Another branch advancednot dated
2026-06-14same kind of change as the line aboveCVE-2026-31786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.3 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31787same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.3 still holdsnot dated
Wed 10 Jun 2026· 4 record changes
2026-06-10Fix version movedCVE-2025-71319
image-sizeimage-size
VulnCheck
stated at publication 1.2.1, now states 1.2.1Release branch starts at 1.1.0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2026-06-10Fix version movedCVE-2025-71319
image-sizeimage-size
VulnCheck
stated at publication 2.0.2, now states 2.0.2Release branch starts at 2.0.0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2026-06-10Affected range extended
limesurveylimesurvey
VulnCheck
stated at publication 7.0, now states 7.0.1Release branch starts at *.not counted: Another branch advancednot dated
2026-06-10same kind of change as the line aboveCVE-2026-50635same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0 still holdsnot dated
2026-06-10same kind of change as the line aboveCVE-2026-50636same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0 still holdsnot dated
Tue 9 Jun 2026· 41 record changes
2026-06-09Fix version moved
microsoftwindows 11 version 23h2
stated at publication 10.0.22631.7079, now states 10.0.22631.7219Release branch starts at *.not counted: Another branch advancednot dated
2026-06-09same kind of change as the line aboveCVE-2026-21530same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
2026-06-09same kind of change as the line aboveCVE-2026-32161same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
2026-06-09same kind of change as the line aboveCVE-2026-32170same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
2026-06-09same kind of change as the line aboveCVE-2026-32209same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
2026-06-09same kind of change as the line aboveCVE-2026-33834same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
2026-06-09same kind of change as the line aboveCVE-2026-33835same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
2026-06-09same kind of change as the line aboveCVE-2026-33837same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
2026-06-09same kind of change as the line aboveCVE-2026-33838same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
29 more rows in this change are not listed here. Open all 37 rows
2026-06-09Affected range extendedCVE-2026-10725
cruxprotocol::http2
CPANSec
stated at publication 1.12, now states 1.13Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 3
2026-06-09Product addedsapnot named as affected at publication, now names sap netweaver as abap and abap platformnot counted: Product identity rewritten with unchanged scopeDays to revision 0
2026-06-09same kind of change as the line aboveCVE-2026-27671same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed sap_se/sap netweaver and abap platform; a new product identity is not establishedDays to revision 0
2026-06-09same kind of change as the line aboveCVE-2026-44751same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed sap_se/sap netweaver and abap platform; a new product identity is not establishedDays to revision 0
2026-06-09Product addedCVE-2026-44746sapnot named as affected at publication, now names sap netweaver as java (jdbc test servlet)Not counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed sap_se/sap netweaver as java component udi; a new product identity is not establishedDays to revision 0
Mon 8 Jun 2026· 3 advisory changes
2026-06-08published 2026-03-17Package added to advisoryGHSA-2cpp-j2fc-qhp7CVE-2026-4270moderatenot named as affected when the advisory was published, now names awslabs-aws-api-mcp-serverDays to revision 83
2026-06-08published 2026-05-12Package added to advisoryGHSA-2g4x-fq3j-cgq4CVE-2026-45090highnot named as affected when the advisory was published, now names github.com/hahwul/dalfoxDays to revision 27
2026-06-08published 2026-03-02Package added to advisoryGHSA-43gx-6gv6-3jcpCVE-2026-28413moderatenot named as affected when the advisory was published, now names products-isurlinportalDays to revision 98
Thu 4 Jun 2026· 2 record changes
2026-06-04Product addedCVE-2026-46447mitrenot named as affected at publication, now names ironicNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 1
2026-06-04CVSS base score changedCVE-2026-6074
whole record
icscert
stated at publication 9.3, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 42

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →