Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

690 changes · newest first · grouped by dayCSVJSONRSS

SinceClear the filter
ChangedSourceRows
Counted changes from Microsoft, newest first, one line per change to a CVE record, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord, Which record was edited, by its CVE id, or how many records one collapsed line stands on.Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Fri 15 Aug 2025· 3 record changes
2025-08-15Product addedCVE-2025-50171not named as affected at publication, now names windows 11 version 22h3Days to revision 3
2025-08-15Product addedCVE-2025-50171not named as affected at publication, now names windows 11 version 23h2Days to revision 3
2025-08-15Product addedCVE-2025-50171not named as affected at publication, now names windows 11 version 24h2Days to revision 3
Tue 12 Aug 2025· 3 record changes
2025-08-12Added to CISA KEVCVE-2007-0671
MicrosoftOffice
CISA KEV
fix due 2025-09-02Not applicable: Added to CISA KEV has no earlier value
2025-08-12Added to CISA KEVCVE-2013-3893
MicrosoftInternet Explorer
CISA KEV
fix due 2025-09-02Not applicable: Added to CISA KEV has no earlier value
2025-08-12Fix version movedCVE-2025-53729
microsoftazure file sync
stated at publication 18.0.0.0, now states 18.3.0.0Release branch starts at 1.0.0.same dayDays to revision 0
Tue 5 Aug 2025· 4 record changes
2025-08-05Ransomware use confirmedCVE-2025-53770
MicrosoftSharePoint
CISA KEV
stated at publication Unknown, now states KnownDays to revision 15
2025-08-05KEV required action changedCVE-2025-49704
MicrosoftSharePoint
CISA KEV
stated at publication CISA recommends disconnecting public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS). For example, SharePoint Server 2013 and earlier versions are end-of-life and should be discontinued if still in use. For supported versions, please follow the mitigations according to CISA and vendor instructions. Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available., now states Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.Days to revision 14
2025-08-05KEV required action changedCVE-2025-49706
MicrosoftSharePoint
CISA KEV
stated at publication CISA recommends disconnecting public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS). For example, SharePoint Server 2013 and earlier versions are end-of-life and should be discontinued if still in use. For supported versions, please follow the mitigations according to CISA and vendor instructions. Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available., now states Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.Days to revision 14
2025-08-05KEV required action changedCVE-2025-53770
MicrosoftSharePoint
CISA KEV
stated at publication CISA recommends configuring AMSI integration in SharePoint and deploying Defender AV on all SharePoint servers. If AMSI cannot be enabled, CISA recommends disconnecting affected products that are public-facing on the internet from service until official mitigations are available. Once mitigations are provided, apply them according to CISA and vendor instructions. Follow the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. , now states Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.Days to revision 15
Fri 25 Jul 2025· 2 record changes
2025-07-25Ransomware use confirmedCVE-2025-49704
MicrosoftSharePoint
CISA KEV
stated at publication Unknown, now states KnownDays to revision 3
2025-07-25Ransomware use confirmedCVE-2025-49706
MicrosoftSharePoint
CISA KEV
stated at publication Unknown, now states KnownDays to revision 3
Tue 22 Jul 2025· 2 record changes
2025-07-22Added to CISA KEVCVE-2025-49704
MicrosoftSharePoint
CISA KEV
fix due 2025-07-23Not applicable: Added to CISA KEV has no earlier value
2025-07-22Added to CISA KEVCVE-2025-49706
MicrosoftSharePoint
CISA KEV
fix due 2025-07-23Not applicable: Added to CISA KEV has no earlier value
Mon 21 Jul 2025· 1 record change
2025-07-21Added to CISA KEVCVE-2025-53770
MicrosoftSharePoint
CISA KEV
fix due 2025-07-21 · listed 2025-07-20Not applicable: Added to CISA KEV has no earlier value
Fri 18 Jul 2025· 1 record change
2025-07-18Ransomware use confirmedCVE-2019-0708
MicrosoftRemote Desktop Services
CISA KEV
stated at publication Unknown, now states KnownDays to revision at least 143
Fri 11 Jul 2025· 1 record change
2025-07-11Fix version movedCVE-2025-47956
microsoftwindows security app
stated at publication 1000.27840.0.1000, now states 1000.27840.1000.0Release branch starts at 1000.0.0.0.Days to revision 31
Tue 8 Jul 2025· 4 record changes
2025-07-08Fix version movedCVE-2024-49000
microsoftmicrosoft sql server 2016 service pack 3 (gdr)
stated at publication 13.0.6455.2, now states 13.0.6460.7Release branch starts at 13.0.0.Days to revision 238
2025-07-08Fix version movedCVE-2024-49000
microsoftmicrosoft sql server 2016 service pack 3 azure connect feature pack
stated at publication 13.0.7050.2, now states 13.0.7055.9Release branch starts at 13.0.0.Days to revision 238
2025-07-08Product addedCVE-2025-30399not named as affected at publication, now names powershell 7.4Days to revision 26
2025-07-08Product addedCVE-2025-30399not named as affected at publication, now names powershell 7.5Days to revision 26
Mon 16 Jun 2025· 1 record change
2025-06-16Product addedCVE-2024-38179not named as affected at publication, now names azure stack os hciDays to revision 250
Thu 22 May 2025· 1 record change
2025-05-22Fix version movedCVE-2025-26646
microsoftmicrosoft visual studio 2022 version 17.10
stated at publication 17.10.14, now states 17.10.15Release branch starts at 17.10.Days to revision 9
Thu 15 May 2025· 20 record changes
2025-05-15Product addedCVE-2025-29977not named as affected at publication, now names microsoft office ltsc for mac 2021Days to revision 2
2025-05-15Product addedCVE-2025-29977not named as affected at publication, now names microsoft office ltsc for mac 2024Days to revision 2
2025-05-15Product addedCVE-2025-29979not named as affected at publication, now names microsoft office ltsc for mac 2021Days to revision 2
2025-05-15Product addedCVE-2025-29979not named as affected at publication, now names microsoft office ltsc for mac 2024Days to revision 2
2025-05-15Product addedCVE-2025-30375not named as affected at publication, now names microsoft office ltsc for mac 2021Days to revision 2
2025-05-15Product addedCVE-2025-30375not named as affected at publication, now names microsoft office ltsc for mac 2024Days to revision 2
2025-05-15Product addedCVE-2025-30379not named as affected at publication, now names microsoft office ltsc for mac 2021Days to revision 2
2025-05-15Product addedCVE-2025-30379not named as affected at publication, now names microsoft office ltsc for mac 2024Days to revision 2
2025-05-15Product addedCVE-2025-30381not named as affected at publication, now names microsoft office ltsc for mac 2021Days to revision 2
2025-05-15Product addedCVE-2025-30381not named as affected at publication, now names microsoft office ltsc for mac 2024Days to revision 2
2025-05-15Product addedCVE-2025-30383not named as affected at publication, now names microsoft office ltsc for mac 2021Days to revision 2
2025-05-15Product addedCVE-2025-30383not named as affected at publication, now names microsoft office ltsc for mac 2024Days to revision 2
2025-05-15Product addedCVE-2025-30393not named as affected at publication, now names microsoft office ltsc for mac 2021Days to revision 2
2025-05-15Product addedCVE-2025-30393not named as affected at publication, now names microsoft office ltsc for mac 2024Days to revision 2
2025-05-15Product addedCVE-2025-30376not named as affected at publication, now names microsoft office ltsc for mac 2021Days to revision 2
2025-05-15Product addedCVE-2025-30376not named as affected at publication, now names microsoft office ltsc for mac 2024Days to revision 2
2025-05-15Product addedCVE-2025-32709not named as affected at publication, now names windows server 2008 r2 service pack 1Days to revision 2
2025-05-15Product addedCVE-2025-32709not named as affected at publication, now names windows server 2008 r2 service pack 1 (server core installation)Days to revision 2
2025-05-15Product addedCVE-2025-32709not named as affected at publication, now names windows server 2008 service pack 2Days to revision 2
2025-05-15Product addedCVE-2025-32709not named as affected at publication, now names windows server 2008 service pack 2 (server core installation)Days to revision 2
Tue 13 May 2025· 7 record changes
2025-05-13Added to CISA KEVCVE-2025-32709
MicrosoftWindows
CISA KEV
fix due 2025-06-03Not applicable: Added to CISA KEV has no earlier value
2025-05-13Added to CISA KEVCVE-2025-30397
MicrosoftWindows
CISA KEV
fix due 2025-06-03Not applicable: Added to CISA KEV has no earlier value
2025-05-13Added to CISA KEVCVE-2025-32706
MicrosoftWindows
CISA KEV
fix due 2025-06-03Not applicable: Added to CISA KEV has no earlier value
2025-05-13Added to CISA KEVCVE-2025-32701
MicrosoftWindows
CISA KEV
fix due 2025-06-03Not applicable: Added to CISA KEV has no earlier value
2025-05-13Added to CISA KEVCVE-2025-30400
MicrosoftWindows
CISA KEV
fix due 2025-06-03Not applicable: Added to CISA KEV has no earlier value
2025-05-13Ransomware use confirmedCVE-2022-21999
MicrosoftWindows
CISA KEV
stated at publication Unknown, now states KnownDays to revision at least 77
2025-05-13Ransomware use confirmedCVE-2021-43890
MicrosoftWindows
CISA KEV
stated at publication Unknown, now states KnownDays to revision at least 77
Mon 12 May 2025· 3 record changes
2025-05-12Ransomware use confirmedCVE-2022-41091
MicrosoftWindows
CISA KEV
stated at publication Unknown, now states KnownDays to revision at least 76
2025-05-12Ransomware use confirmedCVE-2022-30190
MicrosoftWindows
CISA KEV
stated at publication Unknown, now states KnownDays to revision at least 76
2025-05-12Ransomware use confirmedCVE-2014-1812
MicrosoftWindows
CISA KEV
stated at publication Unknown, now states KnownDays to revision at least 76
Thu 17 Apr 2025· 1 record change
2025-04-17Added to CISA KEVCVE-2025-24054
MicrosoftWindows
CISA KEV
fix due 2025-05-08Not applicable: Added to CISA KEV has no earlier value
Wed 9 Apr 2025· 1 record change
2025-04-09Ransomware use confirmedCVE-2025-29824
MicrosoftWindows
CISA KEV
stated at publication Unknown, now states KnownDays to revision 1
Tue 8 Apr 2025· 1 record change
2025-04-08Added to CISA KEVCVE-2025-29824
MicrosoftWindows
CISA KEV
fix due 2025-04-29Not applicable: Added to CISA KEV has no earlier value
Mon 7 Apr 2025· 3 record changes
2025-04-07Ransomware use confirmedCVE-2018-8639
MicrosoftWindows
CISA KEV
stated at publication Unknown, now states KnownDays to revision 35
2025-04-07Ransomware use confirmedCVE-2024-38094
MicrosoftSharePoint
CISA KEV
stated at publication Unknown, now states KnownDays to revision at least 41
2025-04-07Ransomware use confirmedCVE-2024-30051
MicrosoftDWM Core Library
CISA KEV
stated at publication Unknown, now states KnownDays to revision at least 41
Mon 31 Mar 2025· 1 record change
2025-03-31Ransomware use confirmedCVE-2025-26633
MicrosoftWindows
CISA KEV
stated at publication Unknown, now states KnownDays to revision 20
Tue 18 Mar 2025· 1 record change
2025-03-18Ransomware use confirmedCVE-2023-23376
MicrosoftWindows
CISA KEV
stated at publication Unknown, now states KnownDays to revision at least 21
Tue 11 Mar 2025· 10 record changes
2025-03-11Added to CISA KEVCVE-2025-24993
MicrosoftWindows
CISA KEV
fix due 2025-04-01Not applicable: Added to CISA KEV has no earlier value
2025-03-11Added to CISA KEVCVE-2025-24991
MicrosoftWindows
CISA KEV
fix due 2025-04-01Not applicable: Added to CISA KEV has no earlier value
2025-03-11Added to CISA KEVCVE-2025-24985
MicrosoftWindows
CISA KEV
fix due 2025-04-01Not applicable: Added to CISA KEV has no earlier value
2025-03-11Added to CISA KEVCVE-2025-24984
MicrosoftWindows
CISA KEV
fix due 2025-04-01Not applicable: Added to CISA KEV has no earlier value
2025-03-11Added to CISA KEVCVE-2025-24983
MicrosoftWindows
CISA KEV
fix due 2025-04-01Not applicable: Added to CISA KEV has no earlier value
2025-03-11Added to CISA KEVCVE-2025-26633
MicrosoftWindows
CISA KEV
fix due 2025-04-01Not applicable: Added to CISA KEV has no earlier value
2025-03-11Fix version movedCVE-2025-24036
microsoftmicrosoft autoupdate for mac
stated at publication 4.77.24121924, now states 4.78.25022527Release branch starts at 0.Days to revision 28
2025-03-11Product addedCVE-2024-30098not named as affected at publication, now names windows 11 version 24h2Days to revision 245
2025-03-11Product addedCVE-2024-30098not named as affected at publication, now names windows server 2025Days to revision 245
2025-03-11Product addedCVE-2024-30098not named as affected at publication, now names windows server 2025 (server core installation)Days to revision 245
Mon 3 Mar 2025· 1 record change
2025-03-03Added to CISA KEVCVE-2018-8639
MicrosoftWindows
CISA KEV
fix due 2025-03-24Not applicable: Added to CISA KEV has no earlier value
Tue 25 Feb 2025· 1 record change
2025-02-25Added to CISA KEVCVE-2024-49035
MicrosoftPartner Center
CISA KEV
fix due 2025-03-18Not applicable: Added to CISA KEV has no earlier value
Fri 21 Feb 2025· 1 record change
2025-02-21Added to CISA KEVCVE-2025-24989
MicrosoftPower Pages
CISA KEV
fix due 2025-03-14Not applicable: Added to CISA KEV has no earlier value
Fri 14 Feb 2025· 1 record change
2025-02-14Product addedCVE-2025-21178not named as affected at publication, now names microsoft visual studio 2015 update 3Days to revision 31
Tue 11 Feb 2025· 8 record changes
2025-02-11Added to CISA KEVCVE-2025-21418
MicrosoftWindows
CISA KEV
fix due 2025-03-04Not applicable: Added to CISA KEV has no earlier value
2025-02-11Added to CISA KEVCVE-2025-21391
MicrosoftWindows
CISA KEV
fix due 2025-03-04Not applicable: Added to CISA KEV has no earlier value
2025-02-11Fix version movedCVE-2025-21198
microsoftmicrosoft hpc pack 2019
stated at publication 6.3.8322.0, now states 6.3.8328.0Release branch starts at 1.0.0.same dayDays to revision 0
2025-02-11Product addedCVE-2023-24932not named as affected at publication, now names windows 11 version 24h2Days to revision 644
2025-02-11Product addedCVE-2023-24932not named as affected at publication, now names windows server 2025Days to revision 644
2025-02-11Product addedCVE-2023-24932not named as affected at publication, now names windows server 2025 (server core installation)Days to revision 644
2025-02-11Product addedCVE-2025-21172not named as affected at publication, now names microsoft visual studio 2015 update 3Days to revision 28
2025-02-11Product addedCVE-2025-21176not named as affected at publication, now names microsoft visual studio 2015 update 3Days to revision 28
Fri 7 Feb 2025· 1 record change
2025-02-07Added to CISA KEVCVE-2024-21413
MicrosoftOffice Outlook
CISA KEV
fix due 2025-02-27 · listed 2025-02-06Not applicable: Added to CISA KEV has no earlier value
Tue 4 Feb 2025· 1 record change
2025-02-04Added to CISA KEVCVE-2024-29059
Microsoft.NET Framework
CISA KEV
fix due 2025-02-25Not applicable: Added to CISA KEV has no earlier value
Wed 29 Jan 2025· 4 record changes
2025-01-29Product addedCVE-2024-43485not named as affected at publication, now names powershell 7.5Days to revision 113
2025-01-29Product addedCVE-2024-43498not named as affected at publication, now names powershell 7.5Days to revision 78
2025-01-29Product addedCVE-2024-43499not named as affected at publication, now names powershell 7.5Days to revision 78
2025-01-29Product addedCVE-2025-21171not named as affected at publication, now names powershell 7.5Days to revision 15
Tue 31 Dec 2024· 4 record changes
2024-12-31Fix version movedCVE-2024-29059
microsoftmicrosoft .net framework 3.5 and 4.8
stated at publication 4.8.4682.0, now states 4.8.04690.02Release branch starts at 4.8.0.Original value first replaced 2024-05-08; this value first seen 2024-12-31.Days to revision 47
2024-12-31Fix version movedCVE-2024-29059
microsoftmicrosoft .net framework 4.6.2/4.7/4.7.1/4.7.2
stated at publication 4.7.4076.0, now states 4.7.04081.03Release branch starts at 4.7.0.Original value first replaced 2024-05-08; this value first seen 2024-12-31.Days to revision 47
2024-12-31Fix version movedCVE-2024-49051
microsoftmicrosoft pc manager
stated at publication 3.14.10.0, now states 3.14.14.0Release branch starts at 1.0.0.Days to revision 49
2024-12-31Product addedCVE-2024-35264not named as affected at publication, now names .net 6.0Days to revision 175
Fri 27 Dec 2024· 1 record change
2024-12-27Product addedCVE-2024-30077not named as affected at publication, now names windows 11 version 24h2Days to revision 199
Fri 20 Dec 2024· 3 record changes
2024-12-20Product addedCVE-2024-43594not named as affected at publication, now names microsoft system center 2019Days to revision 10
2024-12-20Product addedCVE-2024-43594not named as affected at publication, now names microsoft system center 2022Days to revision 10
2024-12-20Product addedCVE-2024-43594not named as affected at publication, now names microsoft system center 2025Days to revision 10
Tue 10 Dec 2024· 3 record changes
2024-12-10Fix version movedCVE-2023-38171
microsoft.net 7.0
stated at publication 7.0.12, now states 7.0.13Release branch starts at 7.0.0.Days to revision 427
2024-12-10Fix version movedCVE-2023-38171
microsoftmicrosoft visual studio 2022 version 17.2
stated at publication 17.2.20, now states 17.2.21Release branch starts at 17.2.0.Days to revision 427
2024-12-10Fix version movedCVE-2023-38171
microsoftmicrosoft visual studio 2022 version 17.4
stated at publication 17.4.12, now states 17.4.13Release branch starts at 17.4.0.Days to revision 427

Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →