Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

3,930 record edits refused · 339 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
ChangedSourceRows

These rows are not counted anywhere on this site. Checked and refused means we compared this change and then rejected it: the false positive filter for this kind of change judged it to be a false positive rather than a real change. The row is shown so you can check the filter and disagree with us, and it is counted in no figure on this site. No advisory change is here: the advisory engine counts the 2,291 version pairs its filters refused by class rather than writing them out one by one, so this view holds CVE and KEV changes only.

Rows we checked and refused, counted nowhere, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Thu 4 Jun 2026· 5 record changes
2026-06-04Product addedCVE-2026-46447mitrenot named as affected at publication, now names ironicNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 1
2026-06-04CVSS base score changedCVE-2026-6074
whole record
icscert
stated at publication 9.3, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 42
2026-06-04CVSS base score changed
whole record
icscert
stated at publication 7.3, now states 7.8Assessments not comparable · base scoreHighHighnot counted: CVSS version set changedDays to revision 23 to 175
2026-06-04same kind of change as the line aboveCVE-2025-12659same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 23
2026-06-04same kind of change as the line aboveCVE-2025-66585same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 175
2026-06-04same kind of change as the line aboveCVE-2025-66586same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 175
Wed 3 Jun 2026· 3 record changes
2026-06-03Fix version movedCVE-2024-14036
drägercore
VulnCheck
stated at publication 1.0.5, now states 1.0.5Release branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2026-06-03Fix version movedCVE-2024-14036
drägerm540 converter service
VulnCheck
stated at publication 1.0.9, now states 1.0.9Release branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2026-06-03Product addedCVE-2026-33554mitrenot named as affected at publication, now names freeipmiNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 71
Fri 29 May 2026· 6 record changes
2026-05-29Product addedCVE-2025-40946not named as affected at publication, now names blueplanet gridsave 110 tl3-s and 2 morenot counted: Product identity rewritten with unchanged scopeDays to revision 17
2026-05-29same kind of change as the line aboveCVE-2025-40946same vendor as the line abovenot named as affected at publication, now names blueplanet gridsave 110 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 110 tl3-s; a new product identity is not establishedDays to revision 17
2026-05-29same kind of change as the line aboveCVE-2025-40946same vendor as the line abovenot named as affected at publication, now names blueplanet gridsave 137 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 137 tl3-s; a new product identity is not establishedDays to revision 17
2026-05-29same kind of change as the line aboveCVE-2025-40946same vendor as the line abovenot named as affected at publication, now names blueplanet gridsave 92.0 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 92.0 tl3-s; a new product identity is not establishedDays to revision 17
2026-05-29Product addedCVE-2026-41125not named as affected at publication, now names blueplanet gridsave 110 tl3-s and 2 morenot counted: Product identity rewritten with unchanged scopeDays to revision 17
2026-05-29same kind of change as the line aboveCVE-2026-41125same vendor as the line abovenot named as affected at publication, now names blueplanet gridsave 110 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 110 tl3-s; a new product identity is not establishedDays to revision 17
2026-05-29same kind of change as the line aboveCVE-2026-41125same vendor as the line abovenot named as affected at publication, now names blueplanet gridsave 137 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 137 tl3-s; a new product identity is not establishedDays to revision 17
2026-05-29same kind of change as the line aboveCVE-2026-41125same vendor as the line abovenot named as affected at publication, now names blueplanet gridsave 92.0 tl3-sNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed siemens/blueplanet gridsafe 92.0 tl3-s; a new product identity is not establishedDays to revision 17
Thu 28 May 2026· 10 record changes
2026-05-28Affected range extendedCVE-2026-43001
openstackkeystone
mitre
stated at publication 29, now states 29.0.2Release branch starts at *.Not counted: Release branches rewritten. the range layout was rewritten: a branch stated at publication is gone and another appeared, so no branch can be matchednot dated
2026-05-28CVSS base score changed
whole record
VulnCheck
stated at publication 4.3, now states 5.3Assessments not comparable · base scoreMediumMediumnot counted: CVSS version set changedDays to revision 13
2026-05-28same kind of change as the line aboveCVE-2026-45007same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28same kind of change as the line aboveCVE-2026-45009same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28CVSS base score changedCVE-2026-45008
whole record
VulnCheck
stated at publication 6.5, now states 7.0Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28CVSS base score changedCVE-2026-45010
whole record
VulnCheck
stated at publication 9.1, now states 9.3Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28CVSS base score changedCVE-2026-46359
whole record
VulnCheck
stated at publication 7.5, now states 7.7Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28CVSS base score changedCVE-2026-46361
whole record
VulnCheck
stated at publication 6.9, now states 8.2Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28CVSS base score changedCVE-2026-46362
whole record
VulnCheck
stated at publication 6.5, now states 7.1Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28CVSS base score changedCVE-2026-46366
whole record
VulnCheck
stated at publication 7.5, now states 8.7Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2026-05-28CVSS base score changedCVE-2026-46367
whole record
VulnCheck
stated at publication 7.6, now states 8.3Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
Tue 26 May 2026· 4 record changes
2026-05-26Affected range extendedVulnCheckstated at publication 1.14.1, now states 1.14.2Release branch starts at 0.not counted: Same claim, other operatorDays to revision 8
2026-05-26same kind of change as the line aboveCVE-2026-41947same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 8
2026-05-26same kind of change as the line aboveCVE-2026-41949same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 8
2026-05-26Affected range extendedCVE-2026-45444
wp swingsgift cards for woocommerce pro
Patchstack
stated at publication 4.2.6, now states 4.2.7Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 4.2.6 still holdsnot dated
2026-05-26CVSS base score changedCVE-2026-41948
whole record
VulnCheck
stated at publication 9.2, now states 9.4Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 8
Mon 25 May 2026· 11 record changes
2026-05-25Fix version moved
d-linknuclias connect
VulnCheck
stated at publication 1.3.1.4, now states 1.3.1.4Release branch starts at 0.not counted: Same claim, other operatorDays to revision 221
2026-05-25same kind of change as the line aboveCVE-2025-34254same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 221
2026-05-25same kind of change as the line aboveCVE-2025-34255same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 221
2026-05-25Fix version movedCVE-2026-25068
alsa projectalsa-lib
VulnCheck
stated at publication 1.2.15.2, now states 1.2.15.2Release branch starts at 1.2.2.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 116
2026-05-25Fix version movedCVE-2026-44400
mailenablemailenable enterprise premium
VulnCheck
stated at publication 10.55, now states 10.55Release branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 17
2026-05-25Affected range extended
smoothwallexpress
VulnCheck
stated at publication 3.1 Update 13, now states 3.1 Update 13Release branch starts at 0.not counted: Same claim, other operatorDays to revision 56
2026-05-25same kind of change as the line aboveCVE-2026-26352same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 56
2026-05-25same kind of change as the line aboveCVE-2026-27508same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 56
2026-05-25Affected range extendedCVE-2026-27510
unitreeroboticsunitree go2
VulnCheck
stated at publication 1.1.9, now states 1.1.11Release branch starts at 1.1.7.Not counted: Description already named the later value. the record's own description at publication already named 1.1.11 — the structured field was corrected to the value the prose stated, not a fix that movedDays to revision 88
2026-05-25Affected range extendedCVE-2026-28481
openclawopenclaw
VulnCheck
stated at publication 2026.1.30, now states 2026.2.1Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 2026.1.30 still holdsnot dated
2026-05-25Affected range extendedCVE-2026-28532VulnCheckstated at publication 10.5.3, now states 10.5.3Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 25
2026-05-25Affected range extendedCVE-2026-34963
bareboxbarebox
VulnCheck
stated at publication 2026.04.0, now states 2026.04.0Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 14
2026-05-25Affected range extendedCVE-2026-40032
tclahruac
VulnCheck
stated at publication 3.2.0, now states 3.3.0-rc1Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 47
Fri 22 May 2026· 2 record changes
2026-05-22Fix version movedCVE-2026-32185
microsoftmicrosoft teams for android
stated at publication 1.0.0.2026092103, now states 1.0.0.2026092402Release branch starts at 1.0.0.Original value first replaced 2026-05-18; this value first seen 2026-05-22.Not counted: Build number corrected to the one that shipped. only the build revision moved, 10.2 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 6
2026-05-22Product addedCVE-2026-34909hackeronenot named as affected at publication, now names expressNot counted: Already named at publication. already named at publication inside ubiquiti inc/express 7 — the record spelled this product out all alongDays to revision 1
Wed 20 May 2026· 2 record changes
2026-05-20CVSS base score changedCVE-2026-47107
whole record
VulnCheck
stated at publication 9.6, now states 8.6Assessments not comparable · base scoreCriticalHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1
2026-05-20CVSS base score changedCVE-2026-20994
whole record
SamsungMobile
stated at publication 7.0, now states 6.9Assessments not comparable · base scoreHighMediumNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 65
Sat 16 May 2026· 1 record change
2026-05-16Product addedCVE-2026-0974Wordfencenot named as affected at publication, now names orderable – restaurant & food ordering systemNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed orderable/orderable – wordpress restaurant online ordering system and food ordering plugin; a new product identity is not establishedDays to revision 86
Thu 14 May 2026· 1 advisory change
2026-05-14published 2026-05-14Package added to advisoryGHSA-mxmp-wr3w-rvqxCVE-2026-46356moderatenot named as affected when the advisory was published, now names github.com/fleetdm/fleet/v4Days to revision 0
Wed 13 May 2026· 4 record changes
2026-05-13Affected range extended
scott patersoneasy-paypal-events-tickets
VulnCheck
stated at publication 1.3, now states 1.4.0Release branch starts at 0.not counted: Same claim, other operatorDays to revision 9
2026-05-13same kind of change as the line aboveCVE-2026-32834same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 9
2026-05-13same kind of change as the line aboveCVE-2026-41471same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 9
2026-05-13CVSS base score changedCVE-2026-44112
whole record
VulnCheck
stated at publication 6.0, now states 9.6Assessments not comparable · base scoreMediumCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 7
2026-05-13CVSS base score changedCVE-2026-8053
whole record
mongodb
stated at publication 8.7, now states 8.8Assessments not comparable · base scoreHighHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Tue 12 May 2026· 5 record changes
2026-05-12Affected range extendedCVE-2026-29204
webproswhmcs
hackerone
stated at publication 8.12.2, now states 18.12.2Release branch starts at 7.4.0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bumpDays to revision 0
2026-05-12Affected range extendedCVE-2026-44916
openstackironic
mitre
stated at publication 35.0.1, now states 35.0.2Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 4
2026-05-12Product addedCVE-2026-45185mitrenot named as affected at publication, now names eximNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 1
2026-05-12CVSS base score changedCVE-2025-15617
whole record
VulnCheck
stated at publication 6.5, now states 8.3Assessments not comparable · base scoreMediumHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 46
2026-05-12CVSS base score changedCVE-2025-15620
whole record
VulnCheck
stated at publication 9.3, now states 9.2Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 40
Mon 11 May 2026· 5 record changes
2026-05-11Fix version movedCVE-2026-29201
webproswp squared
hackerone
stated at publication 11.136.1.10, now states 11.136.1.11Release branch starts at 11.136.1.0.Not counted: Build number corrected to the one that shipped. only the build revision moved, 3.2 days after publication — the publisher corrected the build number to the one that shipped, which is not a fix that movedDays to revision 3
2026-05-11Fix version movedCVE-2026-20657
appleios and ipados
stated at publication 18.7.7, now states 26.4Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 18.7.7 still holdsnot dated
2026-05-11Fix version movedCVE-2026-20657
applemacos
stated at publication 15.7.5, now states 26.4Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 15.7.5 still holdsnot dated
2026-05-11Product addedCVE-2026-28950not named as affected at publication, now names ipadosNot counted: Already named at publication. already named at publication inside apple/ios and ipados — the record spelled this product out all alongDays to revision 19
2026-05-11Product addedCVE-2026-32226not named as affected at publication, now names microsoft .net framework 3.5Not counted: Already named at publication. already named at publication inside microsoft/microsoft .net framework 3.5 and 4.7.2 — the record spelled this product out all alongDays to revision 27
Tue 5 May 2026· 1 advisory change
2026-05-05published 2026-04-07Package added to advisoryGHSA-mh2q-q3fh-2475CVE-2026-29181highnot named as affected when the advisory was published, now names go.opentelemetry.io/otelDays to revision 28
Mon 4 May 2026· 1 record change
2026-05-04Product addedCVE-2026-6266not named as affected at publication, now names red hat ansible automation platform 2.6Not counted: Already named at publication. already named at publication inside red hat/red hat ansible automation platform 2.6 for rhel 9 — the record spelled this product out all alongDays to revision 0
Fri 1 May 2026· 1 record change
2026-05-01CVSS base score changedCVE-2026-41226
whole record
jpcert
stated at publication 6.1, now states 5.1Assessments not comparable · base scoreMediumMediumNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1
Thu 30 Apr 2026· 1 record change
2026-04-30CVSS base score changedCVE-2026-3861
whole record
LY-Corporation
stated at publication 6.5, now states 7.1Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 14
Wed 29 Apr 2026· 1 record change
2026-04-29CVSS base score changedCVE-2026-41446
whole record
VulnCheck
stated at publication 9.2, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 1
Mon 27 Apr 2026· 3 record changes
2026-04-27Fix version movedCVE-2026-41080mitrestated at publication 2.7.6, now states 2.8.0Release branch starts at 0.Not counted: The earlier release did not ship. the publisher states 2.7.6 was not shipped; this is a catalog correction to 2.8.0, not a superseded installed fix — https://api.github.com/repos/libexpat/libexpat/tags?per_page=100Days to revision 11
2026-04-27Product addedCVE-2026-30368mitrenot named as affected at publication, now names lightspeed classroomNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 3
2026-04-27CVSS base score changedCVE-2026-3008
whole record
CSA
stated at publication 10.0, now states 6.6Assessments not comparable · base scoreCriticalMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 0
Fri 24 Apr 2026· 1 record change
2026-04-24CVSS base score changedCVE-2026-6349
whole record
twcert
stated at publication 10.0, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 8
Thu 23 Apr 2026· 4 record changes
2026-04-23Affected range extendedCVE-2024-49671
dogu pekgozai image generator for your content & featured images – ai postpix
Patchstack
stated at publication 1.1.8, now states 1.1.8.1Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 1.1.8 still holdsnot dated
2026-04-23Affected range extendedCVE-2026-39669
nitropacknitropack
Patchstack
stated at publication 1.19.3, now states 1.19.4Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 1.19.3 still holdsnot dated
2026-04-23CVSS base score changedCVE-2026-41461
whole record
VulnCheck
stated at publication 6.3, now states 8.5Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 0
2026-04-23CVSS base score changedCVE-2026-41460
whole record
VulnCheck
stated at publication 9.3, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 0
Wed 22 Apr 2026· 4 record changes
2026-04-22CVSS base score changedCVE-2026-22191
whole record
VulnCheck
stated at publication 6.9, now states 5.2Assessments not comparable · base scoreMediumMediumNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 41
2026-04-22CVSS base score changedCVE-2026-22192
whole record
VulnCheck
stated at publication 6.3, now states 9.9Assessments not comparable · base scoreMediumCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 41
2026-04-22CVSS base score changedCVE-2026-41469
whole record
VulnCheck
stated at publication 5.1, now states 5.2Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 0
2026-04-22CVSS base score changedCVE-2026-22199
whole record
VulnCheck
stated at publication 6.9, now states 8.7Assessments not comparable · base scoreMediumHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 41
Tue 21 Apr 2026· 1 record change
2026-04-21Affected range extendedCVE-2026-40525
volcengineopenviking
VulnCheck
stated at publication 0.3.8, now states 0.3.9Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 4
Mon 20 Apr 2026· 2 record changes
2026-04-20Product addedCVE-2026-41285mitrenot named as affected at publication, now names openbsdNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 1
2026-04-20CVSS base score changedCVE-2026-23758
whole record
VulnCheck
stated at publication 5.1, now states 6.4Assessments not comparable · base scoreMediumMediumNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Thu 16 Apr 2026· 5 record changes
2026-04-16Fix version movedCVE-2025-64669
microsoftwindows admin center
stated at publication 2.5.1.49, now states 2.6.5.16Release branch starts at 1809.0.Original value first replaced 2025-12-11; this value first seen 2026-04-16.Not counted: Boundary below its own start. the boundary stated at publication was below the range's own start — a malformed range, not a fix anyone patched toDays to revision 0
2026-04-16Fix version movedCVE-2026-39922
geonodegeonode
VulnCheck
stated at publication 4.4.5, now states 4.4.5Release branch starts at 4.0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 5
2026-04-16Fix version movedCVE-2026-39922
geonodegeonode
VulnCheck
stated at publication 5.0.2, now states 5.0.2Release branch starts at 5.0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 5
2026-04-16Product addedCVE-2025-22870Gonot named as affected at publication, now names net/httpNot counted: Already named at publication. already named at publication inside golang.org/x/net/golang.org/x/net/http/httpproxy — the record spelled this product out all alongDays to revision 400
2026-04-16CVSS base score changedCVE-2025-61594
whole record
GitHub_M
stated at publication 2.7, now states 2.1Assessments not comparable · base scoreLowLowNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 107
Wed 15 Apr 2026· 2 record changes
2026-04-15CVSS base score changedCVE-2026-34940
whole record
GitHub_M
stated at publication 0.0, now states 8.7Assessments not comparable · base scoreNoneHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 9
2026-04-15CVSS base score changedCVE-2026-32236
whole record
GitHub_M
stated at publication 0.0, now states 1.7Assessments not comparable · base scoreNoneLowNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 34
Mon 13 Apr 2026· 22 record changes
2026-04-13Fix version moved
linuxlinux
stated at publication 6.19.1, now states 7.0Release branch starts at *.not counted: Another branch advancednot dated
2026-04-13same kind of change as the line aboveCVE-2025-71229same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holdsnot dated
2026-04-13same kind of change as the line aboveCVE-2025-71230same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holdsnot dated
2026-04-13same kind of change as the line aboveCVE-2025-71231same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holdsnot dated
2026-04-13same kind of change as the line aboveCVE-2025-71232same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holdsnot dated
2026-04-13same kind of change as the line aboveCVE-2025-71233same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holdsnot dated
2026-04-13same kind of change as the line aboveCVE-2025-71234same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holdsnot dated
2026-04-13same kind of change as the line aboveCVE-2025-71235same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holdsnot dated
2026-04-13same kind of change as the line aboveCVE-2025-71236same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.1 still holdsnot dated
12 more rows in this change are not listed here. Open all 20 rows
2026-04-13Fix version movedCVE-2026-31788
linuxlinux
stated at publication 6.19.10, now states 7.0Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 6.19.10 still holdsnot dated
2026-04-13CVSS base score changedCVE-2026-26221
whole record
VulnCheck
stated at publication 10.0, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 59
Fri 10 Apr 2026· 1 record change
2026-04-10Product addedCVE-2023-41743not named as affected at publication, now names acronis cyber protect cloud agentNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed acronis/acronis agent; a new product identity is not establishedDays to revision 953
Thu 9 Apr 2026· 2 record changes
2026-04-09CVSS base score changed
whole record
GitHub_M
stated at publication 1.7, now states 8.6Assessments not comparable · base scoreLowHighnot counted: CVSS version set changedDays to revision 65
2026-04-09same kind of change as the line aboveCVE-2025-62599same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 65
2026-04-09same kind of change as the line aboveCVE-2025-62600same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 65
Wed 8 Apr 2026· 32 record changes
2026-04-08Affected range extendedCVE-2023-4948
yan&cowoocommerce cvr payment gateway
Wordfence
stated at publication 6.1.0, now states 6.1.0Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 938
2026-04-082 commitsAffected range extended
homeasapmy idx home search
Wordfence
stated at publication 2.0.1, now states 2.1.1Branches and original-value intervals are stated on each row.not counted: Product line renumberedDays to revision 481
2026-04-08same kind of change as the line aboveCVE-2024-12502same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bumpDays to revision 481
2026-04-08same kind of change as the line aboveCVE-2024-11889same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bumpDays to revision 481
2026-04-08Affected range extendedCVE-2025-8484
nickclarkwebcode quality control tool
Wordfence
stated at publication 0.1, now states 2.1Release branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bumpDays to revision 179
2026-04-08Affected range extendedCVE-2024-10587
funnelformsinteractive contact form and multi step form builder with drag & drop editor – funnelforms free
Wordfence
stated at publication 3.7.4.1, now states 3.7.5.1Release branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bumpDays to revision 491
2026-04-08Affected range extendedCVE-2024-12024
metagausseventprime – events calendar, bookings and tickets
Wordfence
stated at publication 4.0.5.3, now states 4.0.7.3Release branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bumpDays to revision 477
2026-04-08Affected range extendedCVE-2025-6754
seometricspluginseo metrics
Wordfence
stated at publication 1.0.5, now states 1.0.15Release branch starts at 0.Not counted: Description already named the later value. the record's own description at publication already named 1.0.15 — the structured field was corrected to the value the prose stated, not a fix that movedDays to revision 249
2026-04-08Product addedCVE-2023-0292Wordfencenot named as affected at publication, now names quiz and survey master (qsm) – easy quiz and survey makerNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed expresstech/quiz and survey master – best quiz, exam and survey plugin for wordpress; a new product identity is not establishedDays to revision 1,035
2026-04-08Product addedCVE-2023-0895Wordfencenot named as affected at publication, now names wp coder – insert & manage code snippetsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpcalc/wp coder – add custom html, css and js code; a new product identity is not establishedDays to revision 1,146
2026-04-08Product addedCVE-2023-1807Wordfencenot named as affected at publication, now names stax addons for elementorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed staxwp/elementor addons, widgets and enhancements – stax; a new product identity is not establishedDays to revision 1,035
2026-04-08Product addedWordfencenot named as affected at publication, now names directorist: ai-powered business directory, listings & classified adsnot counted: Product identity rewritten with unchanged scopeDays to revision 778 to 1,035
2026-04-08same kind of change as the line aboveCVE-2023-1889same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpwax/directorist – wordpress business directory plugin with classified ads listings; a new product identity is not establishedDays to revision 1,035
2026-04-08same kind of change as the line aboveCVE-2024-1322same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpwax/directorist – wordpress business directory plugin with classified ads listings; a new product identity is not establishedDays to revision 778
2026-04-08Product addedWordfencenot named as affected at publication, now names gutenberg essential blocks – page builder for gutenberg blocks & patternsnot counted: Product identity rewritten with unchanged scopeDays to revision 407 to 1,035
2026-04-08same kind of change as the line aboveCVE-2023-2083same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not establishedDays to revision 1,035
2026-04-08same kind of change as the line aboveCVE-2023-2085same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not establishedDays to revision 1,035
2026-04-08same kind of change as the line aboveCVE-2023-2087same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not establishedDays to revision 1,035
2026-04-08same kind of change as the line aboveCVE-2023-4386same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not establishedDays to revision 901
2026-04-08same kind of change as the line aboveCVE-2023-7071same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not establishedDays to revision 818
2026-04-08same kind of change as the line aboveCVE-2024-12045same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not establishedDays to revision 456
2026-04-08same kind of change as the line aboveCVE-2024-13803same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not establishedDays to revision 407
2026-04-08same kind of change as the line aboveCVE-2024-4891same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not establishedDays to revision 691
2026-04-08Product addedCVE-2023-2170Wordfencenot named as affected at publication, now names tag, category, and taxonomy manager – ai autotagger with openaiNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed stevejburge/taxopress is the wordpress tag, category, and taxonomy manager; a new product identity is not establishedDays to revision 1,085
2026-04-08Product addedCVE-2023-2275Wordfencenot named as affected at publication, now names wcfm – multivendor marketplace rest api for woocommerceNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wclovers/woocommerce multivendor marketplace – rest api; a new product identity is not establishedDays to revision 1,035
2026-04-08Product addedWordfencenot named as affected at publication, now names iptanus file uploadnot counted: Product identity rewritten with unchanged scopeDays to revision 456 to 1,035
2026-04-08same kind of change as the line aboveCVE-2023-2688same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed nickboss/wordpress file upload; a new product identity is not establishedDays to revision 1,035
2026-04-08same kind of change as the line aboveCVE-2024-11635same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed nickboss/wordpress file upload; a new product identity is not establishedDays to revision 456
2026-04-08Product addedCVE-2023-2706Wordfencenot named as affected at publication, now names otp login & register woocommerceNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed xootix/otp login woocommerce & gravity forms; a new product identity is not establishedDays to revision 1,058
2026-04-08Product addedCVE-2023-2717Wordfencenot named as affected at publication, now names groundhogg — crm, newsletters, and marketing automationNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed trainingbusinesspros/wordpress crm, email & marketing automation for wordpress | award winner — groundhogg; a new product identity is not establishedDays to revision 1,055
2026-04-08Product addedCVE-2023-3087Wordfencenot named as affected at publication, now names fluentsmtp – wp smtp plugin with amazon ses, sendgrid, mailgun, postmark, google and any smtp providerNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed techjewel/fluentsmtp – wp mail smtp, amazon ses, sendgrid, mailgun and any smtp connector plugin; a new product identity is not establishedDays to revision 1,002
2026-04-08Product addedWordfencenot named as affected at publication, now names b2bking — ultimate woocommerce b2b and wholesale plugin — wholesale prices, bulk order form & morenot counted: Product identity rewritten with unchanged scopeDays to revision 1,037
2026-04-08same kind of change as the line aboveCVE-2023-3125same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed webwizardsdev/b2bking — ultimate woocommerce wholesale and b2b solution; a new product identity is not establishedDays to revision 1,037
2026-04-08same kind of change as the line aboveCVE-2023-3126same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed webwizardsdev/b2bking — ultimate woocommerce wholesale and b2b solution; a new product identity is not establishedDays to revision 1,037
2026-04-08Product addedCVE-2023-3132Wordfencenot named as affected at publication, now names mainwp child – securely connects to the mainwp dashboard to manage multiple sitesNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed mainwp/mainwp child – securely connects sites to the mainwp wordpress manager dashboard; a new product identity is not establishedDays to revision 1,017
2026-04-08Product addedWordfencenot named as affected at publication, now names user registration & membership – free & paid memberships, subscriptions, content restriction, user profile, custom user registration & login buildernot counted: Product identity rewritten with unchanged scopeDays to revision 706 to 1,001
2026-04-08same kind of change as the line aboveCVE-2023-3342same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpeverest/user registration – custom registration form, login form and user profile for wordpress; a new product identity is not establishedDays to revision 1,001
2026-04-08same kind of change as the line aboveCVE-2024-2417same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpeverest/user registration – custom registration form, login form, and user profile wordpress plugin; a new product identity is not establishedDays to revision 706

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →