Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

3,872 changes refused · newest first · grouped by dayCSVJSONRSS

SinceClear the filter
ChangedSourceRows

These rows are not counted anywhere on this site. Checked and refused means we compared this change and then rejected it: the false positive filter for this kind of change judged it to be a false positive rather than a real change. The row is shown so you can check the filter and disagree with us, and it is counted in no figure on this site. No advisory change is here: the advisory engine counts the 2,291 version pairs its filters refused by class rather than writing them out one by one, so this view holds CVE and KEV changes only.

Rows we checked and refused, counted nowhere, newest first, one line per change to a CVE record, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord, Which record was edited, by its CVE id, or how many records one collapsed line stands on.Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Tue 28 Jul 2026· 2 record changes
2026-07-28CVSS base score changed
whole record
VulnCheck
stated at publication 7.2, now states 6.3Assessments not comparable · base scoreHighMediumnot counted: CVSS assessments are not comparableDays to revision 0
2026-07-28same kind of change as the line aboveCVE-2026-66752same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
2026-07-28same kind of change as the line aboveCVE-2026-67181same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Mon 27 Jul 2026· 3 record changes
2026-07-27Affected range extendedCVE-2026-63094
signozsignoz
VulnCheck
stated at publication 0.133.0, now states 0.134.0Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 10
2026-07-27Product addednot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportnot counted: A variant beneath an already affected parentDays to revision 20
2026-07-27same kind of change as the line aboveCVE-2026-14474same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 20
2026-07-27same kind of change as the line aboveCVE-2026-14476same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 20
Fri 24 Jul 2026· 1 record change
2026-07-24Affected range extendedCVE-2026-29009
u-bootu-boot
VulnCheck
stated at publication 2026.04-rc3, now states 2026.07-rc2Release branch starts at 0.Not counted: Prerelease named as the boundary. a prerelease qualifier on one side — a beta or release candidate is not a version anyone was told to patch toDays to revision 16
Thu 23 Jul 2026· 1 record change
2026-07-23Affected range extendedCVE-2026-27403
nerdpresshubbub lite
Patchstack
stated at publication 1.36.3, now states 1.36.3.1Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 1.36.3 still holdsnot dated
Wed 22 Jul 2026· 255 record changes
2026-07-22Fix version moved
microsoftwindows 11 version 26h1
stated at publication 10.0.28000.2269, now states 10.0.28000.2525Release branch starts at 10.0.28000.0.not counted: Build number corrected to the one that shippedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-33842same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-34328same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-34346same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-34348same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-34349same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-40378same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-40422same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-41087same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.28000.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 8.0 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 8
183 more rows in this change are not listed here. Open all 191 rows
2026-07-22Product addednot named as affected at publication, now names thunderbirdnot counted: Added entry does not state affected statusDays to revision 1 to 8
2026-07-22same kind of change as the line aboveCVE-2026-15718same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-15719same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 8
2026-07-22same kind of change as the line aboveCVE-2026-16349same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
2026-07-22same kind of change as the line aboveCVE-2026-16350same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
2026-07-22same kind of change as the line aboveCVE-2026-16351same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
2026-07-22same kind of change as the line aboveCVE-2026-16352same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
2026-07-22same kind of change as the line aboveCVE-2026-16353same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
2026-07-22same kind of change as the line aboveCVE-2026-16354same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
55 more rows in this change are not listed here. Open all 63 rows
2026-07-22Product addedCVE-2023-52355not named as affected at publication, now names red hat enterprise linux 9.6 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 909
Tue 21 Jul 2026· 4 record changes
2026-07-21Fix version movedCVE-2026-1995
idriveidrive cloud backup client for windows
certcc
stated at publication 7.0.0.63, now states 7.0.0.63Release branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 119
2026-07-21Affected range extendedCVE-2026-57807
miniorange security software pvt ltd.oauth single sign on - sso (oauth client)
Patchstack
stated at publication 38.5.8, now states 38.5.8.1Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 38.5.8 still holdsnot dated
2026-07-21Affected range extendedCVE-2026-8149bcorgstated at publication 2.1.2, now states 2.1.3Release branch starts at 2.1.0.Original value first replaced 2026-05-18; this value first seen 2026-07-21.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 11
2026-07-21CVSS base score changedCVE-2026-64877
whole record
tenable
stated at publication 9.6, now states 9.4Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Mon 20 Jul 2026· 22 record changes
2026-07-20Fix version movedCVE-2024-58362
surrealdbsurrealdb
VulnCheck
stated at publication 1.5.2, now states 2.0.0-beta.3Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 1.5.2 still holdsnot dated
2026-07-20Affected range extended
sankonet::bittorrent
CPANSec
stated at publication 2.0.1, now states 2.1.0Release branch starts at 0.not counted: Same claim, other operatorDays to revision 20
2026-07-20same kind of change as the line aboveCVE-2026-57079same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 20
2026-07-20same kind of change as the line aboveCVE-2026-57082same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 20
2026-07-202 commitsProduct addedCVE-2026-10649not named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-on and 3 moreBranches and original-value intervals are stated on each row.not counted: A variant beneath an already affected parentDays to revision 34
2026-07-20same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-20same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-20same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-20same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-202 commitsProduct addedmitrenot named as affected at publication, now names busyboxBranches and original-value intervals are stated on each row.not counted: No products named at publicationDays to revision 6
2026-07-20same kind of change as the line aboveCVE-2026-38755same vendor as the line abovesame change as the line aboveNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 6
2026-07-20same kind of change as the line aboveCVE-2026-38752same vendor as the line abovesame change as the line aboveNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 6
2026-07-20same kind of change as the line aboveCVE-2026-38753same vendor as the line abovesame change as the line aboveNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 6
2026-07-20same kind of change as the line aboveCVE-2026-38754same vendor as the line abovesame change as the line aboveNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 6
2026-07-202 commitsProduct addednot named as affected at publication, now names red hat enterprise linux 9.2 update services for sap solutionsBranches and original-value intervals are stated on each row.not counted: A variant beneath an already affected parentDays to revision 34 to 81
2026-07-20same kind of change as the line aboveCVE-2026-3833same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 81
2026-07-20same kind of change as the line aboveCVE-2026-42011same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 74
2026-07-20same kind of change as the line aboveCVE-2026-42012same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 55
2026-07-20same kind of change as the line aboveCVE-2026-42013same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 55
2026-07-20same kind of change as the line aboveCVE-2026-42014same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-20same kind of change as the line aboveCVE-2026-42015same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 55
2026-07-20same kind of change as the line aboveCVE-2026-5260same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 55
2026-07-20same kind of change as the line aboveCVE-2026-33845same vendor as the line abovesame change as the line aboveNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 81
3 more rows in this change are not listed here. Open all 11 rows
Fri 17 Jul 2026· 2 record changes
2026-07-17Product addedCVE-2026-10649not named as affected at publication, now names red hat enterprise linux 10.0 extended update support and 1 morenot counted: A variant beneath an already affected parentDays to revision 31
2026-07-17same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 31
2026-07-17same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.6 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 31
Thu 16 Jul 2026· 2 record changes
2026-07-162 commitsProduct addedCVE-2026-10649not named as affected at publication, now names red hat enterprise linux 9.4 update services for sap solutions and 1 moreBranches and original-value intervals are stated on each row.not counted: A variant beneath an already affected parentDays to revision 30
2026-07-16same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.4 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 30
2026-07-16same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9.2 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 9; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 30
Wed 15 Jul 2026· 1 record change
2026-07-15Affected range extendedCVE-2026-15146
gnu wgetwget
certcc
stated at publication 1.25.0 before commit 4f85853f641863d5915786a8413e1a213726a62b, now states 1.25.0+4f85853f64Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 5
Tue 14 Jul 2026· 56 record changes
2026-07-14Fix version moved54 rows, one per record, product and release branch
siemens18 products
stated at publication V2.9.9, now states V4.1.6Release branch starts at *.not counted: Another branch advancednot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
2026-07-14same kind of change as the line aboveCVE-2026-25786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so V2.9.9 still holdsnot dated
46 more rows in this change are not listed here. Open all 54 rows
2026-07-14CVSS base score changedCVE-2024-21529
whole record
snyk
stated at publication 8.2, now states 8.8Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 671
2026-07-14CVSS base score changedCVE-2026-7891
whole record
DIVD
stated at publication 9.3, now states 9.1Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 68
Mon 13 Jul 2026· 4 record changes
2026-07-13Affected range extendedCVE-2026-12948
digi international3 products
Digi
stated at publication 82000747_AB, now states 82000774_ABRelease branch starts at *.not counted: Release branches rewrittennot dated
2026-07-13same kind of change as the line aboveCVE-2026-12948same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Release branches rewritten. the range layout was rewritten: a branch stated at publication is gone and another appeared, so no branch can be matchednot dated
2026-07-13same kind of change as the line aboveCVE-2026-12948same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Release branches rewritten. the range layout was rewritten: a branch stated at publication is gone and another appeared, so no branch can be matchednot dated
2026-07-13same kind of change as the line aboveCVE-2026-12948same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Release branches rewritten. the range layout was rewritten: a branch stated at publication is gone and another appeared, so no branch can be matchednot dated
2026-07-13Product addedCVE-2025-14087not named as affected at publication, now names red hat openshift container platform 4Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 216
Fri 10 Jul 2026· 3 record changes
2026-07-10Product addedCVE-2026-11332not named as affected at publication, now names openshift service mesh 3 and 2 morenot counted: Added entry does not state affected statusDays to revision 35
2026-07-10same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names openshift service mesh 3Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 35
2026-07-10same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names red hat advanced cluster management for kubernetes 2Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 35
2026-07-10same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names service telemetry framework 1.5Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 35
Thu 9 Jul 2026· 27 record changes
2026-07-09Product added21 rows, one per record and productnot named as affected at publication, now names red hat enterprise linux 10.0 extended update support and 2 morenot counted: A variant beneath an already affected parentDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50256same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50256same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50256same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50257same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50257same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50257same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50258same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
2026-07-09same kind of change as the line aboveCVE-2026-50258same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 34
13 more rows in this change are not listed here. Open all 21 rows
2026-07-09CVSS base score changed
whole record
VulDB
stated at publication 6.5, now states 8.6Assessments not comparable · base scoreMediumHighnot counted: CVSS assessments are not comparableDays to revision 1,168
2026-07-09same kind of change as the line aboveCVE-2023-2373same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1,168
2026-07-09same kind of change as the line aboveCVE-2023-2374same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1,168
2026-07-09same kind of change as the line aboveCVE-2023-2375same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1,168
2026-07-09same kind of change as the line aboveCVE-2023-2376same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1,168
2026-07-09same kind of change as the line aboveCVE-2023-2377same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1,168
2026-07-09same kind of change as the line aboveCVE-2023-2378same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1,168
Wed 8 Jul 2026· 31 record changes
2026-07-08Affected range extendedCVE-2026-5724Temporalstated at publication 1.30.3, now states 1.31.2Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 1.30.3 still holdsnot dated
2026-07-086 commitsProduct added30 rows, one per record and productnot named as affected at publication, now names red hat enterprise linux 10.0 extended update support and 6 moreBranches and original-value intervals are stated on each row.not counted: A variant beneath an already affected parentDays to revision 1 to 33
2026-07-08same kind of change as the line aboveCVE-2026-50262same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
2026-07-08same kind of change as the line aboveCVE-2026-50262same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
2026-07-08same kind of change as the line aboveCVE-2026-50262same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
2026-07-08same kind of change as the line aboveCVE-2026-50263same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10.0 extended update supportNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 10; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
2026-07-08same kind of change as the line aboveCVE-2026-50263same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
2026-07-08same kind of change as the line aboveCVE-2026-50263same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
2026-07-08same kind of change as the line aboveCVE-2026-50256same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
2026-07-08same kind of change as the line aboveCVE-2026-50257same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 33
22 more rows in this change are not listed here. Open all 30 rows
Tue 7 Jul 2026· 27 record changes
2026-07-074 commitsProduct added26 rows, one per record and productnot named as affected at publication, now names red hat jboss enterprise application platform 8.1 for rhel 10 and 8 moreBranches and original-value intervals are stated on each row.not counted: A variant beneath an already affected parentDays to revision 0 to 32
2026-07-07same kind of change as the line aboveCVE-2025-12799same vendor as the line abovenot named as affected at publication, now names red hat jboss enterprise application platform 8.1 for rhel 10Not counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat jboss enterprise application platform 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 0
2026-07-07same kind of change as the line aboveCVE-2025-12799same vendor as the line abovenot named as affected at publication, now names red hat jboss enterprise application platform 8.1 for rhel 8Not counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat jboss enterprise application platform 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 0
2026-07-07same kind of change as the line aboveCVE-2025-12799same vendor as the line abovenot named as affected at publication, now names red hat jboss enterprise application platform 8.1 for rhel 9Not counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat jboss enterprise application platform 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 0
2026-07-07same kind of change as the line aboveCVE-2026-11610same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 0
2026-07-07same kind of change as the line aboveCVE-2026-11610same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 0
2026-07-07same kind of change as the line aboveCVE-2026-11774same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 26
2026-07-07same kind of change as the line aboveCVE-2026-11774same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 extended update support long-life add-onNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 26
2026-07-07same kind of change as the line aboveCVE-2026-11610same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceNot counted: A variant beneath an already affected parent. support or installation label under already affected red hat/red hat enterprise linux 8; the record does not establish whether this newly names affected scope or refines the existing product listingDays to revision 0
18 more rows in this change are not listed here. Open all 26 rows
2026-07-07CVSS base score changedCVE-2026-3823
whole record
twcert
stated at publication 9.3, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 120
Sat 4 Jul 2026· 1 record change
2026-07-04Product addedCVE-2026-39087mitrenot named as affected at publication, now names ntfyNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 73
Fri 3 Jul 2026· 198 record changes
2026-07-032 commitsFix version moved198 rows, one per record, product and release branch
mbs18 products
CERTVDE
stated at publication V6_0_0_7, now states V6_00_07Branches and original-value intervals are stated on each row.not counted: Version respelledDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
2026-07-03same kind of change as the line aboveCVE-2026-35076same vendor as the line abovesame change as the line aboveRelease branch starts at V1_0_0_0.Not counted: Version respelled. the same version rewritten — the range start or versionType was rewritten in the same change, or the dropped prefix is the product's own nameDays to revision 30
190 more rows in this change are not listed here. Open all 198 rows
Thu 2 Jul 2026· 5 record changes
2026-07-02Product addedCVE-2026-30689mitrenot named as affected at publication, now names blog.coreNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 98
2026-07-02Product addedCVE-2026-9800not named as affected at publication, now names red hat build of quarkus and 2 morenot counted: Added entry does not state affected statusDays to revision 7
2026-07-02same kind of change as the line aboveCVE-2026-9800same vendor as the line abovenot named as affected at publication, now names red hat build of quarkusNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 7
2026-07-02same kind of change as the line aboveCVE-2026-9800same vendor as the line abovenot named as affected at publication, now names red hat jboss enterprise application platform expansion packNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 7
2026-07-02same kind of change as the line aboveCVE-2026-9800same vendor as the line abovenot named as affected at publication, now names red hat single sign-on 7Not counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 7
2026-07-02CVSS base score changedCVE-2024-21527
whole record
snyk
stated at publication 8.2, now states 8.8Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 714
Mon 29 Jun 2026· 2 record changes
2026-06-29Affected range extendedCVE-2026-3256
ktathttp::session
CPANSec
stated at publication 0.53, now states 0.54Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 93
2026-06-29Product addedCVE-2026-9105TPLinknot named as affected at publication, now names tl-wr841n v14Not counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed tp-link systems inc./tl-wr841m v14; a new product identity is not establishedDays to revision 0
Fri 26 Jun 2026· 21 record changes
2026-06-26Product addednot named as affected at publication, now names red hat build of keycloak 26.4.13not counted: Added entry does not state affected statusDays to revision 1 to 92
2026-06-26same kind of change as the line aboveCVE-2026-37977same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 81
2026-06-26same kind of change as the line aboveCVE-2026-4874same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 92
2026-06-26same kind of change as the line aboveCVE-2026-7500same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 57
2026-06-26same kind of change as the line aboveCVE-2026-8830same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 38
2026-06-26same kind of change as the line aboveCVE-2026-8922same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 38
2026-06-26same kind of change as the line aboveCVE-2026-9083same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
2026-06-26same kind of change as the line aboveCVE-2026-9086same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 1
2026-06-26same kind of change as the line aboveCVE-2026-9087same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 37
13 more rows in this change are not listed here. Open all 21 rows
Thu 25 Jun 2026· 8 record changes
2026-06-253 commitsProduct addednot named as affected at publication, now names red hat build of keycloak 26.6.4Branches and original-value intervals are stated on each row.not counted: Added entry does not state affected statusDays to revision 0 to 29
2026-06-25same kind of change as the line aboveCVE-2026-9705same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-25same kind of change as the line aboveCVE-2026-9799same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-25same kind of change as the line aboveCVE-2026-9083same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-25same kind of change as the line aboveCVE-2026-9086same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-25same kind of change as the line aboveCVE-2026-9099same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-25same kind of change as the line aboveCVE-2026-9795same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 29
2026-06-25same kind of change as the line aboveCVE-2026-9800same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-25CVSS base score changedCVE-2026-56115
whole record
VulnCheck
stated at publication 6.0, now states 8.8Assessments not comparable · base scoreMediumHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 2
Tue 23 Jun 2026· 2 record changes
2026-06-23Affected range extendedCVE-2026-54390
jtl softwarejtl shop
VulnCheck
stated at publication 5.3.x, now states 5.4.0Release branch starts at 5.2.0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 5
2026-06-23CVSS base score changedCVE-2026-56784
whole record
VulnCheck
stated at publication 8.3, now states 8.6Assessments not comparable · base scoreHighHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Thu 18 Jun 2026· 1 record change
2026-06-18Fix version movedCVE-2025-13590
wso2org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl
stated at publication 9.32.147.2, now states 9.32.167Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 9.32.147.2 still holdsnot dated
Wed 17 Jun 2026· 1 record change
2026-06-17Affected range extendedCVE-2026-43003
openstackironic-python-agent
mitre
stated at publication 11.5.0, now states 11.5.1Release branch starts at *.Not counted: Release branches rewritten. the range layout was rewritten: a branch stated at publication is gone and another appeared, so no branch can be matchednot dated
Tue 16 Jun 2026· 14 record changes
2026-06-16Affected range extendedCVE-2026-54421
openstackironic
mitre
stated at publication 35.0.1, now states 35.0.2Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 3
2026-06-16Product addednot named as affected at publication, now names thunderbirdnot counted: Added entry does not state affected statusDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12289same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12290same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12291same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12292same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12293same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12294same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12295same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
2026-06-16same kind of change as the line aboveCVE-2026-12296same vendor as the line abovesame change as the line aboveNot counted: Added entry does not state affected status. the added entry states no affected version or affected default — membership in affected[] alone does not establish exposureDays to revision 0
5 more rows in this change are not listed here. Open all 13 rows
Sun 14 Jun 2026· 59 record changes
2026-06-14Fix version moved
linuxlinux
stated at publication 7.0.1, now states 7.1Release branch starts at *.not counted: Another branch advancednot dated
2026-06-14same kind of change as the line aboveCVE-2026-31532same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31574same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31575same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31576same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31577same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31578same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31579same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31580same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.1 still holdsnot dated
49 more rows in this change are not listed here. Open all 57 rows
2026-06-14Fix version moved
linuxlinux
stated at publication 7.0.3, now states 7.1Release branch starts at *.not counted: Another branch advancednot dated
2026-06-14same kind of change as the line aboveCVE-2026-31786same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.3 still holdsnot dated
2026-06-14same kind of change as the line aboveCVE-2026-31787same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0.3 still holdsnot dated
Wed 10 Jun 2026· 4 record changes
2026-06-10Fix version movedCVE-2025-71319
image-sizeimage-size
VulnCheck
stated at publication 1.2.1, now states 1.2.1Release branch starts at 1.1.0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2026-06-10Fix version movedCVE-2025-71319
image-sizeimage-size
VulnCheck
stated at publication 2.0.2, now states 2.0.2Release branch starts at 2.0.0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2026-06-10Affected range extended
limesurveylimesurvey
VulnCheck
stated at publication 7.0, now states 7.0.1Release branch starts at *.not counted: Another branch advancednot dated
2026-06-10same kind of change as the line aboveCVE-2026-50635same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0 still holdsnot dated
2026-06-10same kind of change as the line aboveCVE-2026-50636same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 7.0 still holdsnot dated
Tue 9 Jun 2026· 41 record changes
2026-06-09Fix version moved
microsoftwindows 11 version 23h2
stated at publication 10.0.22631.7079, now states 10.0.22631.7219Release branch starts at *.not counted: Another branch advancednot dated
2026-06-09same kind of change as the line aboveCVE-2026-21530same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
2026-06-09same kind of change as the line aboveCVE-2026-32161same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
2026-06-09same kind of change as the line aboveCVE-2026-32170same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
2026-06-09same kind of change as the line aboveCVE-2026-32209same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
2026-06-09same kind of change as the line aboveCVE-2026-33834same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
2026-06-09same kind of change as the line aboveCVE-2026-33835same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
2026-06-09same kind of change as the line aboveCVE-2026-33837same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
2026-06-09same kind of change as the line aboveCVE-2026-33838same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 10.0.22631.7079 still holdsnot dated
29 more rows in this change are not listed here. Open all 37 rows
2026-06-09Affected range extendedCVE-2026-10725
cruxprotocol::http2
CPANSec
stated at publication 1.12, now states 1.13Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 3
2026-06-09Product addedsapnot named as affected at publication, now names sap netweaver as abap and abap platformnot counted: Product identity rewritten with unchanged scopeDays to revision 0
2026-06-09same kind of change as the line aboveCVE-2026-27671same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed sap_se/sap netweaver and abap platform; a new product identity is not establishedDays to revision 0
2026-06-09same kind of change as the line aboveCVE-2026-44751same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed sap_se/sap netweaver and abap platform; a new product identity is not establishedDays to revision 0
2026-06-09Product addedCVE-2026-44746sapnot named as affected at publication, now names sap netweaver as java (jdbc test servlet)Not counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed sap_se/sap netweaver as java component udi; a new product identity is not establishedDays to revision 0
Thu 4 Jun 2026· 5 record changes
2026-06-04Product addedCVE-2026-46447mitrenot named as affected at publication, now names ironicNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 1
2026-06-04CVSS base score changedCVE-2026-6074
whole record
icscert
stated at publication 9.3, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 42
2026-06-04CVSS base score changed
whole record
icscert
stated at publication 7.3, now states 7.8Assessments not comparable · base scoreHighHighnot counted: CVSS version set changedDays to revision 23 to 175
2026-06-04same kind of change as the line aboveCVE-2025-12659same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 23
2026-06-04same kind of change as the line aboveCVE-2025-66585same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 175
2026-06-04same kind of change as the line aboveCVE-2025-66586same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 175
Wed 3 Jun 2026· 3 record changes
2026-06-03Fix version movedCVE-2024-14036
drägercore
VulnCheck
stated at publication 1.0.5, now states 1.0.5Release branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2026-06-03Fix version movedCVE-2024-14036
drägerm540 converter service
VulnCheck
stated at publication 1.0.9, now states 1.0.9Release branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2026-06-03Product addedCVE-2026-33554mitrenot named as affected at publication, now names freeipmiNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 71
Fri 29 May 2026· 6 record changes
2026-05-29Product addedCVE-2025-40946not named as affected at publication, now names blueplanet gridsave 110 tl3-s and 2 morenot counted: Product identity rewritten with unchanged scopeDays to revision 17
2026-05-29same kind of change as the line aboveCVE-2025-40946same vendor as the line abovenot named as affected at publication, now names blueplanet gridsave 110 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 110 tl3-s; a new product identity is not establishedDays to revision 17
2026-05-29same kind of change as the line aboveCVE-2025-40946same vendor as the line abovenot named as affected at publication, now names blueplanet gridsave 137 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 137 tl3-s; a new product identity is not establishedDays to revision 17
2026-05-29same kind of change as the line aboveCVE-2025-40946same vendor as the line abovenot named as affected at publication, now names blueplanet gridsave 92.0 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 92.0 tl3-s; a new product identity is not establishedDays to revision 17
2026-05-29Product addedCVE-2026-41125not named as affected at publication, now names blueplanet gridsave 110 tl3-s and 2 morenot counted: Product identity rewritten with unchanged scopeDays to revision 17
2026-05-29same kind of change as the line aboveCVE-2026-41125same vendor as the line abovenot named as affected at publication, now names blueplanet gridsave 110 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 110 tl3-s; a new product identity is not establishedDays to revision 17
2026-05-29same kind of change as the line aboveCVE-2026-41125same vendor as the line abovenot named as affected at publication, now names blueplanet gridsave 137 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 137 tl3-s; a new product identity is not establishedDays to revision 17
2026-05-29same kind of change as the line aboveCVE-2026-41125same vendor as the line abovenot named as affected at publication, now names blueplanet gridsave 92.0 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 92.0 tl3-s; a new product identity is not establishedDays to revision 17
Thu 28 May 2026· 10 record changes
2026-05-28Affected range extendedCVE-2026-43001
openstackkeystone
mitre
stated at publication 29, now states 29.0.2Release branch starts at *.Not counted: Release branches rewritten. the range layout was rewritten: a branch stated at publication is gone and another appeared, so no branch can be matchednot dated
2026-05-28CVSS base score changed
whole record
VulnCheck
stated at publication 4.3, now states 5.3Assessments not comparable · base scoreMediumMediumnot counted: CVSS version set changedDays to revision 13
2026-05-28same kind of change as the line aboveCVE-2026-45007same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28same kind of change as the line aboveCVE-2026-45009same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28CVSS base score changedCVE-2026-45008
whole record
VulnCheck
stated at publication 6.5, now states 7.0Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28CVSS base score changedCVE-2026-45010
whole record
VulnCheck
stated at publication 9.1, now states 9.3Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28CVSS base score changedCVE-2026-46359
whole record
VulnCheck
stated at publication 7.5, now states 7.7Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28CVSS base score changedCVE-2026-46361
whole record
VulnCheck
stated at publication 6.9, now states 8.2Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28CVSS base score changedCVE-2026-46362
whole record
VulnCheck
stated at publication 6.5, now states 7.1Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28CVSS base score changedCVE-2026-46366
whole record
VulnCheck
stated at publication 7.5, now states 8.7Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28CVSS base score changedCVE-2026-46367
whole record
VulnCheck
stated at publication 7.6, now states 8.3Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
Tue 26 May 2026· 4 record changes
2026-05-26Affected range extendedVulnCheckstated at publication 1.14.1, now states 1.14.2Release branch starts at 0.not counted: Same claim, other operatorDays to revision 8
2026-05-26same kind of change as the line aboveCVE-2026-41947same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 8
2026-05-26same kind of change as the line aboveCVE-2026-41949same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 8
2026-05-26Affected range extendedCVE-2026-45444
wp swingsgift cards for woocommerce pro
Patchstack
stated at publication 4.2.6, now states 4.2.7Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 4.2.6 still holdsnot dated
2026-05-26CVSS base score changedCVE-2026-41948
whole record
VulnCheck
stated at publication 9.2, now states 9.4Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 8
Mon 25 May 2026· 11 record changes
2026-05-25Fix version moved
d-linknuclias connect
VulnCheck
stated at publication 1.3.1.4, now states 1.3.1.4Release branch starts at 0.not counted: Same claim, other operatorDays to revision 221
2026-05-25same kind of change as the line aboveCVE-2025-34254same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 221
2026-05-25same kind of change as the line aboveCVE-2025-34255same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 221
2026-05-25Fix version movedCVE-2026-25068
alsa projectalsa-lib
VulnCheck
stated at publication 1.2.15.2, now states 1.2.15.2Release branch starts at 1.2.2.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 116
2026-05-25Fix version movedCVE-2026-44400
mailenablemailenable enterprise premium
VulnCheck
stated at publication 10.55, now states 10.55Release branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 17
2026-05-25Affected range extended
smoothwallexpress
VulnCheck
stated at publication 3.1 Update 13, now states 3.1 Update 13Release branch starts at 0.not counted: Same claim, other operatorDays to revision 56
2026-05-25same kind of change as the line aboveCVE-2026-26352same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 56
2026-05-25same kind of change as the line aboveCVE-2026-27508same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 56
2026-05-25Affected range extendedCVE-2026-27510
unitreeroboticsunitree go2
VulnCheck
stated at publication 1.1.9, now states 1.1.11Release branch starts at 1.1.7.Not counted: Description already named the later value. the record's own description at publication already named 1.1.11 — the structured field was corrected to the value the prose stated, not a fix that movedDays to revision 88
2026-05-25Affected range extendedCVE-2026-28481
openclawopenclaw
VulnCheck
stated at publication 2026.1.30, now states 2026.2.1Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 2026.1.30 still holdsnot dated
2026-05-25Affected range extendedCVE-2026-28532VulnCheckstated at publication 10.5.3, now states 10.5.3Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 25
2026-05-25Affected range extendedCVE-2026-34963
bareboxbarebox
VulnCheck
stated at publication 2026.04.0, now states 2026.04.0Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 14
2026-05-25Affected range extendedCVE-2026-40032
tclahruac
VulnCheck
stated at publication 3.2.0, now states 3.3.0-rc1Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 47
Fri 22 May 2026· 2 record changes
2026-05-22Fix version movedCVE-2026-32185
microsoftmicrosoft teams for android
stated at publication 1.0.0.2026092103, now states 1.0.0.2026092402Release branch starts at 1.0.0.Original value first replaced 2026-05-18; this value first seen 2026-05-22.Not counted: Build number corrected to the one that shipped. only the build revision moved, 10.2 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 6
2026-05-22Product addedCVE-2026-34909hackeronenot named as affected at publication, now names expressNot counted: Already named at publication. already named at publication inside ubiquiti inc/express 7 — the record spelled this product out all alongDays to revision 1
Wed 20 May 2026· 2 record changes
2026-05-20CVSS base score changedCVE-2026-47107
whole record
VulnCheck
stated at publication 9.6, now states 8.6Assessments not comparable · base scoreCriticalHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1
2026-05-20CVSS base score changedCVE-2026-20994
whole record
SamsungMobile
stated at publication 7.0, now states 6.9Assessments not comparable · base scoreHighMediumNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 65
Sat 16 May 2026· 1 record change
2026-05-16Product addedCVE-2026-0974Wordfencenot named as affected at publication, now names orderable – restaurant & food ordering systemNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed orderable/orderable – wordpress restaurant online ordering system and food ordering plugin; a new product identity is not establishedDays to revision 86
Wed 13 May 2026· 4 record changes
2026-05-13Affected range extended
scott patersoneasy-paypal-events-tickets
VulnCheck
stated at publication 1.3, now states 1.4.0Release branch starts at 0.not counted: Same claim, other operatorDays to revision 9
2026-05-13same kind of change as the line aboveCVE-2026-32834same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 9
2026-05-13same kind of change as the line aboveCVE-2026-41471same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 9
2026-05-13CVSS base score changedCVE-2026-44112
whole record
VulnCheck
stated at publication 6.0, now states 9.6Assessments not comparable · base scoreMediumCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 7
2026-05-13CVSS base score changedCVE-2026-8053
whole record
mongodb
stated at publication 8.7, now states 8.8Assessments not comparable · base scoreHighHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Tue 12 May 2026· 5 record changes
2026-05-12Affected range extendedCVE-2026-29204
webproswhmcs
hackerone
stated at publication 8.12.2, now states 18.12.2Release branch starts at 7.4.0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bumpDays to revision 0
2026-05-12Affected range extendedCVE-2026-44916
openstackironic
mitre
stated at publication 35.0.1, now states 35.0.2Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 4
2026-05-12Product addedCVE-2026-45185mitrenot named as affected at publication, now names eximNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 1
2026-05-12CVSS base score changedCVE-2025-15617
whole record
VulnCheck
stated at publication 6.5, now states 8.3Assessments not comparable · base scoreMediumHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 46
2026-05-12CVSS base score changedCVE-2025-15620
whole record
VulnCheck
stated at publication 9.3, now states 9.2Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 40
Mon 11 May 2026· 1 record change
2026-05-11Fix version movedCVE-2026-29201
webproswp squared
hackerone
stated at publication 11.136.1.10, now states 11.136.1.11Release branch starts at 11.136.1.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 3.2 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 3

Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →