Every change, newest first
These rows are not counted anywhere on this site. Checked and refused means we compared this change and then rejected it: the false positive filter for this kind of change judged it to be a false positive rather than a real change. The row is shown so you can check the filter and disagree with us, and it is counted in no figure on this site. No advisory change is here: the advisory engine counts the 2,291 version pairs its filters refused by class rather than writing them out one by one, so this view holds CVE and KEV changes only.
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Kind | Record or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together. | Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|---|
| Thu 4 Jun 2026· 5 record changes | |||||
| 2026-06-04 | Product added | CVE-2026-46447 | mitre | not named as affected at publication, now names ironicNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' from | Days to revision 1 |
| 2026-06-04 | CVSS base score changed | CVE-2026-6074 | whole record icscert | stated at publication 9.3, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 42 |
| 2026-06-04 | CVSS base score changed | whole record icscert | stated at publication 7.3, now states 7.8Assessments not comparable · base scoreHighHighnot counted: CVSS version set changed | Days to revision 23 to 175 | |
| 2026-06-04 | same kind of change as the line above | CVE-2025-12659 | same vendor as the line above | same change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 23 |
| 2026-06-04 | same kind of change as the line above | CVE-2025-66585 | same vendor as the line above | same change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 175 |
| 2026-06-04 | same kind of change as the line above | CVE-2025-66586 | same vendor as the line above | same change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 175 |
| Wed 3 Jun 2026· 3 record changes | |||||
| 2026-06-03 | Fix version moved | CVE-2024-14036 | drägercore VulnCheck | stated at publication 1.0.5, now states 1.0.5Release branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operator | Days to revision 1 |
| 2026-06-03 | Fix version moved | CVE-2024-14036 | drägerm540 converter service VulnCheck | stated at publication 1.0.9, now states 1.0.9Release branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operator | Days to revision 1 |
| 2026-06-03 | Product added | CVE-2026-33554 | mitre | not named as affected at publication, now names freeipmiNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' from | Days to revision 71 |
| Fri 29 May 2026· 6 record changes | |||||
| 2026-05-29 | Product added | CVE-2025-40946 | not named as affected at publication, now names blueplanet gridsave 110 tl3-s and 2 morenot counted: Product identity rewritten with unchanged scope | Days to revision 17 | |
| 2026-05-29 | same kind of change as the line above | CVE-2025-40946 | same vendor as the line above | not named as affected at publication, now names blueplanet gridsave 110 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 110 tl3-s; a new product identity is not established | Days to revision 17 |
| 2026-05-29 | same kind of change as the line above | CVE-2025-40946 | same vendor as the line above | not named as affected at publication, now names blueplanet gridsave 137 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 137 tl3-s; a new product identity is not established | Days to revision 17 |
| 2026-05-29 | same kind of change as the line above | CVE-2025-40946 | same vendor as the line above | not named as affected at publication, now names blueplanet gridsave 92.0 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 92.0 tl3-s; a new product identity is not established | Days to revision 17 |
| 2026-05-29 | Product added | CVE-2026-41125 | not named as affected at publication, now names blueplanet gridsave 110 tl3-s and 2 morenot counted: Product identity rewritten with unchanged scope | Days to revision 17 | |
| 2026-05-29 | same kind of change as the line above | CVE-2026-41125 | same vendor as the line above | not named as affected at publication, now names blueplanet gridsave 110 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 110 tl3-s; a new product identity is not established | Days to revision 17 |
| 2026-05-29 | same kind of change as the line above | CVE-2026-41125 | same vendor as the line above | not named as affected at publication, now names blueplanet gridsave 137 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 137 tl3-s; a new product identity is not established | Days to revision 17 |
| 2026-05-29 | same kind of change as the line above | CVE-2026-41125 | same vendor as the line above | not named as affected at publication, now names blueplanet gridsave 92.0 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 92.0 tl3-s; a new product identity is not established | Days to revision 17 |
| Thu 28 May 2026· 10 record changes | |||||
| 2026-05-28 | Affected range extended | CVE-2026-43001 | openstackkeystone mitre | stated at publication 29, now states 29.0.2Release branch starts at *.Not counted: Release branches rewritten. the range layout was rewritten: a branch stated at publication is gone and another appeared, so no branch can be matched | not dated |
| 2026-05-28 | CVSS base score changed | whole record VulnCheck | stated at publication 4.3, now states 5.3Assessments not comparable · base scoreMediumMediumnot counted: CVSS version set changed | Days to revision 13 | |
| 2026-05-28 | same kind of change as the line above | CVE-2026-45007 | same vendor as the line above | same change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 13 |
| 2026-05-28 | same kind of change as the line above | CVE-2026-45009 | same vendor as the line above | same change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 13 |
| 2026-05-28 | CVSS base score changed | CVE-2026-45008 | whole record VulnCheck | stated at publication 6.5, now states 7.0Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 13 |
| 2026-05-28 | CVSS base score changed | CVE-2026-45010 | whole record VulnCheck | stated at publication 9.1, now states 9.3Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 13 |
| 2026-05-28 | CVSS base score changed | CVE-2026-46359 | whole record VulnCheck | stated at publication 7.5, now states 7.7Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 13 |
| 2026-05-28 | CVSS base score changed | CVE-2026-46361 | whole record VulnCheck | stated at publication 6.9, now states 8.2Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 13 |
| 2026-05-28 | CVSS base score changed | CVE-2026-46362 | whole record VulnCheck | stated at publication 6.5, now states 7.1Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 13 |
| 2026-05-28 | CVSS base score changed | CVE-2026-46366 | whole record VulnCheck | stated at publication 7.5, now states 8.7Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 13 |
| 2026-05-28 | CVSS base score changed | CVE-2026-46367 | whole record VulnCheck | stated at publication 7.6, now states 8.3Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 13 |
| Tue 26 May 2026· 4 record changes | |||||
| 2026-05-26 | Affected range extended | langgeniusdify VulnCheck | stated at publication 1.14.1, now states 1.14.2Release branch starts at 0.not counted: Same claim, other operator | Days to revision 8 | |
| 2026-05-26 | same kind of change as the line above | CVE-2026-41947 | same vendor as the line above | same change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operator | Days to revision 8 |
| 2026-05-26 | same kind of change as the line above | CVE-2026-41949 | same vendor as the line above | same change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operator | Days to revision 8 |
| 2026-05-26 | Affected range extended | CVE-2026-45444 | wp swingsgift cards for woocommerce pro Patchstack | stated at publication 4.2.6, now states 4.2.7Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 4.2.6 still holds | not dated |
| 2026-05-26 | CVSS base score changed | CVE-2026-41948 | whole record VulnCheck | stated at publication 9.2, now states 9.4Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparable | Days to revision 8 |
| Mon 25 May 2026· 11 record changes | |||||
| 2026-05-25 | Fix version moved | d-linknuclias connect VulnCheck | stated at publication 1.3.1.4, now states 1.3.1.4Release branch starts at 0.not counted: Same claim, other operator | Days to revision 221 | |
| 2026-05-25 | same kind of change as the line above | CVE-2025-34254 | same vendor as the line above | same change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operator | Days to revision 221 |
| 2026-05-25 | same kind of change as the line above | CVE-2025-34255 | same vendor as the line above | same change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operator | Days to revision 221 |
| 2026-05-25 | Fix version moved | CVE-2026-25068 | alsa projectalsa-lib VulnCheck | stated at publication 1.2.15.2, now states 1.2.15.2Release branch starts at 1.2.2.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operator | Days to revision 116 |
| 2026-05-25 | Fix version moved | CVE-2026-44400 | mailenablemailenable enterprise premium VulnCheck | stated at publication 10.55, now states 10.55Release branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operator | Days to revision 17 |
| 2026-05-25 | Affected range extended | smoothwallexpress VulnCheck | stated at publication 3.1 Update 13, now states 3.1 Update 13Release branch starts at 0.not counted: Same claim, other operator | Days to revision 56 | |
| 2026-05-25 | same kind of change as the line above | CVE-2026-26352 | same vendor as the line above | same change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operator | Days to revision 56 |
| 2026-05-25 | same kind of change as the line above | CVE-2026-27508 | same vendor as the line above | same change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operator | Days to revision 56 |
| 2026-05-25 | Affected range extended | CVE-2026-27510 | unitreeroboticsunitree go2 VulnCheck | stated at publication 1.1.9, now states 1.1.11Release branch starts at 1.1.7.Not counted: Description already named the later value. the record's own description at publication already named 1.1.11 — the structured field was corrected to the value the prose stated, not a fix that moved | Days to revision 88 |
| 2026-05-25 | Affected range extended | CVE-2026-28481 | openclawopenclaw VulnCheck | stated at publication 2026.1.30, now states 2026.2.1Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 2026.1.30 still holds | not dated |
| 2026-05-25 | Affected range extended | CVE-2026-28532 | frroutingfrr VulnCheck | stated at publication 10.5.3, now states 10.5.3Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operator | Days to revision 25 |
| 2026-05-25 | Affected range extended | CVE-2026-34963 | bareboxbarebox VulnCheck | stated at publication 2026.04.0, now states 2026.04.0Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operator | Days to revision 14 |
| 2026-05-25 | Affected range extended | CVE-2026-40032 | tclahruac VulnCheck | stated at publication 3.2.0, now states 3.3.0-rc1Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operator | Days to revision 47 |
| Fri 22 May 2026· 2 record changes | |||||
| 2026-05-22 | Fix version moved | CVE-2026-32185 | microsoftmicrosoft teams for android | stated at publication 1.0.0.2026092103, now states 1.0.0.2026092402Release branch starts at 1.0.0.Original value first replaced 2026-05-18; this value first seen 2026-05-22.Not counted: Build number corrected to the one that shipped. only the build revision moved, 10.2 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that moved | Days to revision 6 |
| 2026-05-22 | Product added | CVE-2026-34909 | hackerone | not named as affected at publication, now names expressNot counted: Already named at publication. already named at publication inside ubiquiti inc/express 7 — the record spelled this product out all along | Days to revision 1 |
| Wed 20 May 2026· 2 record changes | |||||
| 2026-05-20 | CVSS base score changed | CVE-2026-47107 | whole record VulnCheck | stated at publication 9.6, now states 8.6Assessments not comparable · base scoreCriticalHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparable | Days to revision 1 |
| 2026-05-20 | CVSS base score changed | CVE-2026-20994 | whole record SamsungMobile | stated at publication 7.0, now states 6.9Assessments not comparable · base scoreHighMediumNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparable | Days to revision 65 |
| Sat 16 May 2026· 1 record change | |||||
| 2026-05-16 | Product added | CVE-2026-0974 | Wordfence | not named as affected at publication, now names orderable – restaurant & food ordering systemNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed orderable/orderable – wordpress restaurant online ordering system and food ordering plugin; a new product identity is not established | Days to revision 86 |
| Thu 14 May 2026· 1 advisory change | |||||
| 2026-05-14published 2026-05-14 | Package added to advisory | GHSA-mxmp-wr3w-rvqxCVE-2026-46356 | moderate | not named as affected when the advisory was published, now names github.com/fleetdm/fleet/v4 | Days to revision 0 |
| Wed 13 May 2026· 4 record changes | |||||
| 2026-05-13 | Affected range extended | scott patersoneasy-paypal-events-tickets VulnCheck | stated at publication 1.3, now states 1.4.0Release branch starts at 0.not counted: Same claim, other operator | Days to revision 9 | |
| 2026-05-13 | same kind of change as the line above | CVE-2026-32834 | same vendor as the line above | same change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operator | Days to revision 9 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-41471 | same vendor as the line above | same change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operator | Days to revision 9 |
| 2026-05-13 | CVSS base score changed | CVE-2026-44112 | whole record VulnCheck | stated at publication 6.0, now states 9.6Assessments not comparable · base scoreMediumCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparable | Days to revision 7 |
| 2026-05-13 | CVSS base score changed | CVE-2026-8053 | whole record mongodb | stated at publication 8.7, now states 8.8Assessments not comparable · base scoreHighHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparable | Days to revision 0 |
| Tue 12 May 2026· 5 record changes | |||||
| 2026-05-12 | Affected range extended | CVE-2026-29204 | webproswhmcs hackerone | stated at publication 8.12.2, now states 18.12.2Release branch starts at 7.4.0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bump | Days to revision 0 |
| 2026-05-12 | Affected range extended | CVE-2026-44916 | openstackironic mitre | stated at publication 35.0.1, now states 35.0.2Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operator | Days to revision 4 |
| 2026-05-12 | Product added | CVE-2026-45185 | mitre | not named as affected at publication, now names eximNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' from | Days to revision 1 |
| 2026-05-12 | CVSS base score changed | CVE-2025-15617 | whole record VulnCheck | stated at publication 6.5, now states 8.3Assessments not comparable · base scoreMediumHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparable | Days to revision 46 |
| 2026-05-12 | CVSS base score changed | CVE-2025-15620 | whole record VulnCheck | stated at publication 9.3, now states 9.2Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparable | Days to revision 40 |
| Mon 11 May 2026· 5 record changes | |||||
| 2026-05-11 | Fix version moved | CVE-2026-29201 | webproswp squared hackerone | stated at publication 11.136.1.10, now states 11.136.1.11Release branch starts at 11.136.1.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 3.2 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that moved | Days to revision 3 |
| 2026-05-11 | Fix version moved | CVE-2026-20657 | appleios and ipados | stated at publication 18.7.7, now states 26.4Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 18.7.7 still holds | not dated |
| 2026-05-11 | Fix version moved | CVE-2026-20657 | applemacos | stated at publication 15.7.5, now states 26.4Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 15.7.5 still holds | not dated |
| 2026-05-11 | Product added | CVE-2026-28950 | not named as affected at publication, now names ipadosNot counted: Already named at publication. already named at publication inside apple/ios and ipados — the record spelled this product out all along | Days to revision 19 | |
| 2026-05-11 | Product added | CVE-2026-32226 | not named as affected at publication, now names microsoft .net framework 3.5Not counted: Already named at publication. already named at publication inside microsoft/microsoft .net framework 3.5 and 4.7.2 — the record spelled this product out all along | Days to revision 27 | |
| Tue 5 May 2026· 1 advisory change | |||||
| 2026-05-05published 2026-04-07 | Package added to advisory | GHSA-mh2q-q3fh-2475CVE-2026-29181 | high | not named as affected when the advisory was published, now names go.opentelemetry.io/otel | Days to revision 28 |
| Mon 4 May 2026· 1 record change | |||||
| 2026-05-04 | Product added | CVE-2026-6266 | not named as affected at publication, now names red hat ansible automation platform 2.6Not counted: Already named at publication. already named at publication inside red hat/red hat ansible automation platform 2.6 for rhel 9 — the record spelled this product out all along | Days to revision 0 | |
| Fri 1 May 2026· 1 record change | |||||
| 2026-05-01 | CVSS base score changed | CVE-2026-41226 | whole record jpcert | stated at publication 6.1, now states 5.1Assessments not comparable · base scoreMediumMediumNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparable | Days to revision 1 |
| Thu 30 Apr 2026· 1 record change | |||||
| 2026-04-30 | CVSS base score changed | CVE-2026-3861 | whole record LY-Corporation | stated at publication 6.5, now states 7.1Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 14 |
| Wed 29 Apr 2026· 1 record change | |||||
| 2026-04-29 | CVSS base score changed | CVE-2026-41446 | whole record VulnCheck | stated at publication 9.2, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 1 |
| Mon 27 Apr 2026· 3 record changes | |||||
| 2026-04-27 | Fix version moved | CVE-2026-41080 | libexpat projectlibexpat mitre | stated at publication 2.7.6, now states 2.8.0Release branch starts at 0.Not counted: The earlier release did not ship. the publisher states 2.7.6 was not shipped; this is a catalog correction to 2.8.0, not a superseded installed fix — https://api.github.com/repos/libexpat/libexpat/tags?per_page=100 | Days to revision 11 |
| 2026-04-27 | Product added | CVE-2026-30368 | mitre | not named as affected at publication, now names lightspeed classroomNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' from | Days to revision 3 |
| 2026-04-27 | CVSS base score changed | CVE-2026-3008 | whole record CSA | stated at publication 10.0, now states 6.6Assessments not comparable · base scoreCriticalMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 0 |
| Fri 24 Apr 2026· 1 record change | |||||
| 2026-04-24 | CVSS base score changed | CVE-2026-6349 | whole record twcert | stated at publication 10.0, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparable | Days to revision 8 |
| Thu 23 Apr 2026· 4 record changes | |||||
| 2026-04-23 | Affected range extended | CVE-2024-49671 | dogu pekgozai image generator for your content & featured images – ai postpix Patchstack | stated at publication 1.1.8, now states 1.1.8.1Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 1.1.8 still holds | not dated |
| 2026-04-23 | Affected range extended | CVE-2026-39669 | nitropacknitropack Patchstack | stated at publication 1.19.3, now states 1.19.4Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 1.19.3 still holds | not dated |
| 2026-04-23 | CVSS base score changed | CVE-2026-41461 | whole record VulnCheck | stated at publication 6.3, now states 8.5Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 0 |
| 2026-04-23 | CVSS base score changed | CVE-2026-41460 | whole record VulnCheck | stated at publication 9.3, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 0 |
| Wed 22 Apr 2026· 4 record changes | |||||
| 2026-04-22 | CVSS base score changed | CVE-2026-22191 | whole record VulnCheck | stated at publication 6.9, now states 5.2Assessments not comparable · base scoreMediumMediumNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparable | Days to revision 41 |
| 2026-04-22 | CVSS base score changed | CVE-2026-22192 | whole record VulnCheck | stated at publication 6.3, now states 9.9Assessments not comparable · base scoreMediumCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparable | Days to revision 41 |
| 2026-04-22 | CVSS base score changed | CVE-2026-41469 | whole record VulnCheck | stated at publication 5.1, now states 5.2Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 0 |
| 2026-04-22 | CVSS base score changed | CVE-2026-22199 | whole record VulnCheck | stated at publication 6.9, now states 8.7Assessments not comparable · base scoreMediumHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparable | Days to revision 41 |
| Tue 21 Apr 2026· 1 record change | |||||
| 2026-04-21 | Affected range extended | CVE-2026-40525 | volcengineopenviking VulnCheck | stated at publication 0.3.8, now states 0.3.9Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operator | Days to revision 4 |
| Mon 20 Apr 2026· 2 record changes | |||||
| 2026-04-20 | Product added | CVE-2026-41285 | mitre | not named as affected at publication, now names openbsdNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' from | Days to revision 1 |
| 2026-04-20 | CVSS base score changed | CVE-2026-23758 | whole record VulnCheck | stated at publication 5.1, now states 6.4Assessments not comparable · base scoreMediumMediumNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparable | Days to revision 0 |
| Thu 16 Apr 2026· 5 record changes | |||||
| 2026-04-16 | Fix version moved | CVE-2025-64669 | microsoftwindows admin center | stated at publication 2.5.1.49, now states 2.6.5.16Release branch starts at 1809.0.Original value first replaced 2025-12-11; this value first seen 2026-04-16.Not counted: Boundary below its own start. the boundary stated at publication was below the range's own start — a malformed range, not a fix anyone patched to | Days to revision 0 |
| 2026-04-16 | Fix version moved | CVE-2026-39922 | geonodegeonode VulnCheck | stated at publication 4.4.5, now states 4.4.5Release branch starts at 4.0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operator | Days to revision 5 |
| 2026-04-16 | Fix version moved | CVE-2026-39922 | geonodegeonode VulnCheck | stated at publication 5.0.2, now states 5.0.2Release branch starts at 5.0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operator | Days to revision 5 |
| 2026-04-16 | Product added | CVE-2025-22870 | Go | not named as affected at publication, now names net/httpNot counted: Already named at publication. already named at publication inside golang.org/x/net/golang.org/x/net/http/httpproxy — the record spelled this product out all along | Days to revision 400 |
| 2026-04-16 | CVSS base score changed | CVE-2025-61594 | whole record GitHub_M | stated at publication 2.7, now states 2.1Assessments not comparable · base scoreLowLowNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparable | Days to revision 107 |
| Wed 15 Apr 2026· 2 record changes | |||||
| 2026-04-15 | CVSS base score changed | CVE-2026-34940 | whole record GitHub_M | stated at publication 0.0, now states 8.7Assessments not comparable · base scoreNoneHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 9 |
| 2026-04-15 | CVSS base score changed | CVE-2026-32236 | whole record GitHub_M | stated at publication 0.0, now states 1.7Assessments not comparable · base scoreNoneLowNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 34 |
| Mon 13 Apr 2026· 22 record changes | |||||
| 2026-04-13 | Fix version moved | linuxlinux | stated at publication 6.19.1, now states 7.0Release branch starts at *.not counted: Another branch advanced | not dated | |
| 2026-04-13 | same kind of change as the line above | CVE-2025-71229 | same vendor as the line above | same change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holds | not dated |
| 2026-04-13 | same kind of change as the line above | CVE-2025-71230 | same vendor as the line above | same change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holds | not dated |
| 2026-04-13 | same kind of change as the line above | CVE-2025-71231 | same vendor as the line above | same change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holds | not dated |
| 2026-04-13 | same kind of change as the line above | CVE-2025-71232 | same vendor as the line above | same change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holds | not dated |
| 2026-04-13 | same kind of change as the line above | CVE-2025-71233 | same vendor as the line above | same change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holds | not dated |
| 2026-04-13 | same kind of change as the line above | CVE-2025-71234 | same vendor as the line above | same change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holds | not dated |
| 2026-04-13 | same kind of change as the line above | CVE-2025-71235 | same vendor as the line above | same change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holds | not dated |
| 2026-04-13 | same kind of change as the line above | CVE-2025-71236 | same vendor as the line above | same change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holds | not dated |
| 12 more rows in this change are not listed here. Open all 20 rows → | |||||
| 2026-04-13 | Fix version moved | CVE-2026-31788 | linuxlinux | stated at publication 6.19.10, now states 7.0Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.10 still holds | not dated |
| 2026-04-13 | CVSS base score changed | CVE-2026-26221 | whole record VulnCheck | stated at publication 10.0, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparable | Days to revision 59 |
| Fri 10 Apr 2026· 1 record change | |||||
| 2026-04-10 | Product added | CVE-2023-41743 | not named as affected at publication, now names acronis cyber protect cloud agentNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed acronis/acronis agent; a new product identity is not established | Days to revision 953 | |
| Thu 9 Apr 2026· 2 record changes | |||||
| 2026-04-09 | CVSS base score changed | whole record GitHub_M | stated at publication 1.7, now states 8.6Assessments not comparable · base scoreLowHighnot counted: CVSS version set changed | Days to revision 65 | |
| 2026-04-09 | same kind of change as the line above | CVE-2025-62599 | same vendor as the line above | same change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 65 |
| 2026-04-09 | same kind of change as the line above | CVE-2025-62600 | same vendor as the line above | same change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removed | Days to revision 65 |
| Wed 8 Apr 2026· 32 record changes | |||||
| 2026-04-08 | Affected range extended | CVE-2023-4948 | yan&cowoocommerce cvr payment gateway Wordfence | stated at publication 6.1.0, now states 6.1.0Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operator | Days to revision 938 |
| 2026-04-082 commits | Affected range extended | homeasapmy idx home search Wordfence | stated at publication 2.0.1, now states 2.1.1Branches and original-value intervals are stated on each row.not counted: Product line renumbered | Days to revision 481 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-12502 | same vendor as the line above | same change as the line aboveRelease branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bump | Days to revision 481 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-11889 | same vendor as the line above | same change as the line aboveRelease branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bump | Days to revision 481 |
| 2026-04-08 | Affected range extended | CVE-2025-8484 | nickclarkwebcode quality control tool Wordfence | stated at publication 0.1, now states 2.1Release branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bump | Days to revision 179 |
| 2026-04-08 | Affected range extended | CVE-2024-10587 | funnelformsinteractive contact form and multi step form builder with drag & drop editor – funnelforms free Wordfence | stated at publication 3.7.4.1, now states 3.7.5.1Release branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bump | Days to revision 491 |
| 2026-04-08 | Affected range extended | CVE-2024-12024 | metagausseventprime – events calendar, bookings and tickets Wordfence | stated at publication 4.0.5.3, now states 4.0.7.3Release branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bump | Days to revision 477 |
| 2026-04-08 | Affected range extended | CVE-2025-6754 | seometricspluginseo metrics Wordfence | stated at publication 1.0.5, now states 1.0.15Release branch starts at 0.Not counted: Description already named the later value. the record's own description at publication already named 1.0.15 — the structured field was corrected to the value the prose stated, not a fix that moved | Days to revision 249 |
| 2026-04-08 | Product added | CVE-2023-0292 | Wordfence | not named as affected at publication, now names quiz and survey master (qsm) – easy quiz and survey makerNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed expresstech/quiz and survey master – best quiz, exam and survey plugin for wordpress; a new product identity is not established | Days to revision 1,035 |
| 2026-04-08 | Product added | CVE-2023-0895 | Wordfence | not named as affected at publication, now names wp coder – insert & manage code snippetsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpcalc/wp coder – add custom html, css and js code; a new product identity is not established | Days to revision 1,146 |
| 2026-04-08 | Product added | CVE-2023-1807 | Wordfence | not named as affected at publication, now names stax addons for elementorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed staxwp/elementor addons, widgets and enhancements – stax; a new product identity is not established | Days to revision 1,035 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names directorist: ai-powered business directory, listings & classified adsnot counted: Product identity rewritten with unchanged scope | Days to revision 778 to 1,035 | |
| 2026-04-08 | same kind of change as the line above | CVE-2023-1889 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpwax/directorist – wordpress business directory plugin with classified ads listings; a new product identity is not established | Days to revision 1,035 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1322 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpwax/directorist – wordpress business directory plugin with classified ads listings; a new product identity is not established | Days to revision 778 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names gutenberg essential blocks – page builder for gutenberg blocks & patternsnot counted: Product identity rewritten with unchanged scope | Days to revision 407 to 1,035 | |
| 2026-04-08 | same kind of change as the line above | CVE-2023-2083 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not established | Days to revision 1,035 |
| 2026-04-08 | same kind of change as the line above | CVE-2023-2085 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not established | Days to revision 1,035 |
| 2026-04-08 | same kind of change as the line above | CVE-2023-2087 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not established | Days to revision 1,035 |
| 2026-04-08 | same kind of change as the line above | CVE-2023-4386 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not established | Days to revision 901 |
| 2026-04-08 | same kind of change as the line above | CVE-2023-7071 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not established | Days to revision 818 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-12045 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not established | Days to revision 456 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-13803 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not established | Days to revision 407 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-4891 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not established | Days to revision 691 |
| 2026-04-08 | Product added | CVE-2023-2170 | Wordfence | not named as affected at publication, now names tag, category, and taxonomy manager – ai autotagger with openaiNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed stevejburge/taxopress is the wordpress tag, category, and taxonomy manager; a new product identity is not established | Days to revision 1,085 |
| 2026-04-08 | Product added | CVE-2023-2275 | Wordfence | not named as affected at publication, now names wcfm – multivendor marketplace rest api for woocommerceNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wclovers/woocommerce multivendor marketplace – rest api; a new product identity is not established | Days to revision 1,035 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names iptanus file uploadnot counted: Product identity rewritten with unchanged scope | Days to revision 456 to 1,035 | |
| 2026-04-08 | same kind of change as the line above | CVE-2023-2688 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed nickboss/wordpress file upload; a new product identity is not established | Days to revision 1,035 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-11635 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed nickboss/wordpress file upload; a new product identity is not established | Days to revision 456 |
| 2026-04-08 | Product added | CVE-2023-2706 | Wordfence | not named as affected at publication, now names otp login & register woocommerceNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed xootix/otp login woocommerce & gravity forms; a new product identity is not established | Days to revision 1,058 |
| 2026-04-08 | Product added | CVE-2023-2717 | Wordfence | not named as affected at publication, now names groundhogg — crm, newsletters, and marketing automationNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed trainingbusinesspros/wordpress crm, email & marketing automation for wordpress | award winner — groundhogg; a new product identity is not established | Days to revision 1,055 |
| 2026-04-08 | Product added | CVE-2023-3087 | Wordfence | not named as affected at publication, now names fluentsmtp – wp smtp plugin with amazon ses, sendgrid, mailgun, postmark, google and any smtp providerNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed techjewel/fluentsmtp – wp mail smtp, amazon ses, sendgrid, mailgun and any smtp connector plugin; a new product identity is not established | Days to revision 1,002 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names b2bking — ultimate woocommerce b2b and wholesale plugin — wholesale prices, bulk order form & morenot counted: Product identity rewritten with unchanged scope | Days to revision 1,037 | |
| 2026-04-08 | same kind of change as the line above | CVE-2023-3125 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed webwizardsdev/b2bking — ultimate woocommerce wholesale and b2b solution; a new product identity is not established | Days to revision 1,037 |
| 2026-04-08 | same kind of change as the line above | CVE-2023-3126 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed webwizardsdev/b2bking — ultimate woocommerce wholesale and b2b solution; a new product identity is not established | Days to revision 1,037 |
| 2026-04-08 | Product added | CVE-2023-3132 | Wordfence | not named as affected at publication, now names mainwp child – securely connects to the mainwp dashboard to manage multiple sitesNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed mainwp/mainwp child – securely connects sites to the mainwp wordpress manager dashboard; a new product identity is not established | Days to revision 1,017 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names user registration & membership – free & paid memberships, subscriptions, content restriction, user profile, custom user registration & login buildernot counted: Product identity rewritten with unchanged scope | Days to revision 706 to 1,001 | |
| 2026-04-08 | same kind of change as the line above | CVE-2023-3342 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpeverest/user registration – custom registration form, login form and user profile for wordpress; a new product identity is not established | Days to revision 1,001 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-2417 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpeverest/user registration – custom registration form, login form, and user profile wordpress plugin; a new product identity is not established | Days to revision 706 |
Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.
Data sources and quality
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →