Every change, newest first
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Kind | Record, Which record was edited, by its CVE id, or how many records one collapsed line stands on. | Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|---|
| Fri 15 Aug 2025· 3 record changes | |||||
| 2025-08-15 | Product added | CVE-2025-50171 | not named as affected at publication, now names windows 11 version 22h3 | Days to revision 3 | |
| 2025-08-15 | Product added | CVE-2025-50171 | not named as affected at publication, now names windows 11 version 23h2 | Days to revision 3 | |
| 2025-08-15 | Product added | CVE-2025-50171 | not named as affected at publication, now names windows 11 version 24h2 | Days to revision 3 | |
| Tue 12 Aug 2025· 3 record changes | |||||
| 2025-08-12 | Added to CISA KEV | CVE-2007-0671 | MicrosoftOffice CISA KEV | fix due 2025-09-02 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-08-12 | Added to CISA KEV | CVE-2013-3893 | MicrosoftInternet Explorer CISA KEV | fix due 2025-09-02 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-08-12 | Fix version moved | CVE-2025-53729 | microsoftazure file sync | stated at publication 18.0.0.0, now states 18.3.0.0Release branch starts at 1.0.0.same day | Days to revision 0 |
| Tue 5 Aug 2025· 4 record changes | |||||
| 2025-08-05 | Ransomware use confirmed | CVE-2025-53770 | MicrosoftSharePoint CISA KEV | stated at publication Unknown, now states Known | Days to revision 15 |
| 2025-08-05 | KEV required action changed | CVE-2025-49704 | MicrosoftSharePoint CISA KEV | stated at publication CISA recommends disconnecting public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS). For example, SharePoint Server 2013 and earlier versions are end-of-life and should be discontinued if still in use. For supported versions, please follow the mitigations according to CISA and vendor instructions. Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available., now states Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. | Days to revision 14 |
| 2025-08-05 | KEV required action changed | CVE-2025-49706 | MicrosoftSharePoint CISA KEV | stated at publication CISA recommends disconnecting public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS). For example, SharePoint Server 2013 and earlier versions are end-of-life and should be discontinued if still in use. For supported versions, please follow the mitigations according to CISA and vendor instructions. Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available., now states Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. | Days to revision 14 |
| 2025-08-05 | KEV required action changed | CVE-2025-53770 | MicrosoftSharePoint CISA KEV | stated at publication CISA recommends configuring AMSI integration in SharePoint and deploying Defender AV on all SharePoint servers. If AMSI cannot be enabled, CISA recommends disconnecting affected products that are public-facing on the internet from service until official mitigations are available. Once mitigations are provided, apply them according to CISA and vendor instructions. Follow the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. , now states Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. | Days to revision 15 |
| Fri 25 Jul 2025· 2 record changes | |||||
| 2025-07-25 | Ransomware use confirmed | CVE-2025-49704 | MicrosoftSharePoint CISA KEV | stated at publication Unknown, now states Known | Days to revision 3 |
| 2025-07-25 | Ransomware use confirmed | CVE-2025-49706 | MicrosoftSharePoint CISA KEV | stated at publication Unknown, now states Known | Days to revision 3 |
| Tue 22 Jul 2025· 2 record changes | |||||
| 2025-07-22 | Added to CISA KEV | CVE-2025-49704 | MicrosoftSharePoint CISA KEV | fix due 2025-07-23 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-07-22 | Added to CISA KEV | CVE-2025-49706 | MicrosoftSharePoint CISA KEV | fix due 2025-07-23 | Not applicable: Added to CISA KEV has no earlier value |
| Mon 21 Jul 2025· 1 record change | |||||
| 2025-07-21 | Added to CISA KEV | CVE-2025-53770 | MicrosoftSharePoint CISA KEV | fix due 2025-07-21 · listed 2025-07-20 | Not applicable: Added to CISA KEV has no earlier value |
| Fri 18 Jul 2025· 1 record change | |||||
| 2025-07-18 | Ransomware use confirmed | CVE-2019-0708 | MicrosoftRemote Desktop Services CISA KEV | stated at publication Unknown, now states Known | Days to revision at least 143 |
| Fri 11 Jul 2025· 1 record change | |||||
| 2025-07-11 | Fix version moved | CVE-2025-47956 | microsoftwindows security app | stated at publication 1000.27840.0.1000, now states 1000.27840.1000.0Release branch starts at 1000.0.0.0. | Days to revision 31 |
| Tue 8 Jul 2025· 4 record changes | |||||
| 2025-07-08 | Fix version moved | CVE-2024-49000 | microsoftmicrosoft sql server 2016 service pack 3 (gdr) | stated at publication 13.0.6455.2, now states 13.0.6460.7Release branch starts at 13.0.0. | Days to revision 238 |
| 2025-07-08 | Fix version moved | CVE-2024-49000 | microsoftmicrosoft sql server 2016 service pack 3 azure connect feature pack | stated at publication 13.0.7050.2, now states 13.0.7055.9Release branch starts at 13.0.0. | Days to revision 238 |
| 2025-07-08 | Product added | CVE-2025-30399 | not named as affected at publication, now names powershell 7.4 | Days to revision 26 | |
| 2025-07-08 | Product added | CVE-2025-30399 | not named as affected at publication, now names powershell 7.5 | Days to revision 26 | |
| Mon 16 Jun 2025· 1 record change | |||||
| 2025-06-16 | Product added | CVE-2024-38179 | not named as affected at publication, now names azure stack os hci | Days to revision 250 | |
| Thu 22 May 2025· 1 record change | |||||
| 2025-05-22 | Fix version moved | CVE-2025-26646 | microsoftmicrosoft visual studio 2022 version 17.10 | stated at publication 17.10.14, now states 17.10.15Release branch starts at 17.10. | Days to revision 9 |
| Thu 15 May 2025· 20 record changes | |||||
| 2025-05-15 | Product added | CVE-2025-29977 | not named as affected at publication, now names microsoft office ltsc for mac 2021 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-29977 | not named as affected at publication, now names microsoft office ltsc for mac 2024 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-29979 | not named as affected at publication, now names microsoft office ltsc for mac 2021 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-29979 | not named as affected at publication, now names microsoft office ltsc for mac 2024 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-30375 | not named as affected at publication, now names microsoft office ltsc for mac 2021 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-30375 | not named as affected at publication, now names microsoft office ltsc for mac 2024 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-30379 | not named as affected at publication, now names microsoft office ltsc for mac 2021 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-30379 | not named as affected at publication, now names microsoft office ltsc for mac 2024 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-30381 | not named as affected at publication, now names microsoft office ltsc for mac 2021 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-30381 | not named as affected at publication, now names microsoft office ltsc for mac 2024 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-30383 | not named as affected at publication, now names microsoft office ltsc for mac 2021 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-30383 | not named as affected at publication, now names microsoft office ltsc for mac 2024 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-30393 | not named as affected at publication, now names microsoft office ltsc for mac 2021 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-30393 | not named as affected at publication, now names microsoft office ltsc for mac 2024 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-30376 | not named as affected at publication, now names microsoft office ltsc for mac 2021 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-30376 | not named as affected at publication, now names microsoft office ltsc for mac 2024 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-32709 | not named as affected at publication, now names windows server 2008 r2 service pack 1 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-32709 | not named as affected at publication, now names windows server 2008 r2 service pack 1 (server core installation) | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-32709 | not named as affected at publication, now names windows server 2008 service pack 2 | Days to revision 2 | |
| 2025-05-15 | Product added | CVE-2025-32709 | not named as affected at publication, now names windows server 2008 service pack 2 (server core installation) | Days to revision 2 | |
| Tue 13 May 2025· 7 record changes | |||||
| 2025-05-13 | Added to CISA KEV | CVE-2025-32709 | MicrosoftWindows CISA KEV | fix due 2025-06-03 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-05-13 | Added to CISA KEV | CVE-2025-30397 | MicrosoftWindows CISA KEV | fix due 2025-06-03 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-05-13 | Added to CISA KEV | CVE-2025-32706 | MicrosoftWindows CISA KEV | fix due 2025-06-03 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-05-13 | Added to CISA KEV | CVE-2025-32701 | MicrosoftWindows CISA KEV | fix due 2025-06-03 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-05-13 | Added to CISA KEV | CVE-2025-30400 | MicrosoftWindows CISA KEV | fix due 2025-06-03 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-05-13 | Ransomware use confirmed | CVE-2022-21999 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Days to revision at least 77 |
| 2025-05-13 | Ransomware use confirmed | CVE-2021-43890 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Days to revision at least 77 |
| Mon 12 May 2025· 3 record changes | |||||
| 2025-05-12 | Ransomware use confirmed | CVE-2022-41091 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Days to revision at least 76 |
| 2025-05-12 | Ransomware use confirmed | CVE-2022-30190 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Days to revision at least 76 |
| 2025-05-12 | Ransomware use confirmed | CVE-2014-1812 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Days to revision at least 76 |
| Thu 17 Apr 2025· 1 record change | |||||
| 2025-04-17 | Added to CISA KEV | CVE-2025-24054 | MicrosoftWindows CISA KEV | fix due 2025-05-08 | Not applicable: Added to CISA KEV has no earlier value |
| Wed 9 Apr 2025· 1 record change | |||||
| 2025-04-09 | Ransomware use confirmed | CVE-2025-29824 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Days to revision 1 |
| Tue 8 Apr 2025· 1 record change | |||||
| 2025-04-08 | Added to CISA KEV | CVE-2025-29824 | MicrosoftWindows CISA KEV | fix due 2025-04-29 | Not applicable: Added to CISA KEV has no earlier value |
| Mon 7 Apr 2025· 3 record changes | |||||
| 2025-04-07 | Ransomware use confirmed | CVE-2018-8639 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Days to revision 35 |
| 2025-04-07 | Ransomware use confirmed | CVE-2024-38094 | MicrosoftSharePoint CISA KEV | stated at publication Unknown, now states Known | Days to revision at least 41 |
| 2025-04-07 | Ransomware use confirmed | CVE-2024-30051 | MicrosoftDWM Core Library CISA KEV | stated at publication Unknown, now states Known | Days to revision at least 41 |
| Mon 31 Mar 2025· 1 record change | |||||
| 2025-03-31 | Ransomware use confirmed | CVE-2025-26633 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Days to revision 20 |
| Tue 18 Mar 2025· 1 record change | |||||
| 2025-03-18 | Ransomware use confirmed | CVE-2023-23376 | MicrosoftWindows CISA KEV | stated at publication Unknown, now states Known | Days to revision at least 21 |
| Tue 11 Mar 2025· 10 record changes | |||||
| 2025-03-11 | Added to CISA KEV | CVE-2025-24993 | MicrosoftWindows CISA KEV | fix due 2025-04-01 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-03-11 | Added to CISA KEV | CVE-2025-24991 | MicrosoftWindows CISA KEV | fix due 2025-04-01 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-03-11 | Added to CISA KEV | CVE-2025-24985 | MicrosoftWindows CISA KEV | fix due 2025-04-01 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-03-11 | Added to CISA KEV | CVE-2025-24984 | MicrosoftWindows CISA KEV | fix due 2025-04-01 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-03-11 | Added to CISA KEV | CVE-2025-24983 | MicrosoftWindows CISA KEV | fix due 2025-04-01 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-03-11 | Added to CISA KEV | CVE-2025-26633 | MicrosoftWindows CISA KEV | fix due 2025-04-01 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-03-11 | Fix version moved | CVE-2025-24036 | microsoftmicrosoft autoupdate for mac | stated at publication 4.77.24121924, now states 4.78.25022527Release branch starts at 0. | Days to revision 28 |
| 2025-03-11 | Product added | CVE-2024-30098 | not named as affected at publication, now names windows 11 version 24h2 | Days to revision 245 | |
| 2025-03-11 | Product added | CVE-2024-30098 | not named as affected at publication, now names windows server 2025 | Days to revision 245 | |
| 2025-03-11 | Product added | CVE-2024-30098 | not named as affected at publication, now names windows server 2025 (server core installation) | Days to revision 245 | |
| Mon 3 Mar 2025· 1 record change | |||||
| 2025-03-03 | Added to CISA KEV | CVE-2018-8639 | MicrosoftWindows CISA KEV | fix due 2025-03-24 | Not applicable: Added to CISA KEV has no earlier value |
| Tue 25 Feb 2025· 1 record change | |||||
| 2025-02-25 | Added to CISA KEV | CVE-2024-49035 | MicrosoftPartner Center CISA KEV | fix due 2025-03-18 | Not applicable: Added to CISA KEV has no earlier value |
| Fri 21 Feb 2025· 1 record change | |||||
| 2025-02-21 | Added to CISA KEV | CVE-2025-24989 | MicrosoftPower Pages CISA KEV | fix due 2025-03-14 | Not applicable: Added to CISA KEV has no earlier value |
| Fri 14 Feb 2025· 1 record change | |||||
| 2025-02-14 | Product added | CVE-2025-21178 | not named as affected at publication, now names microsoft visual studio 2015 update 3 | Days to revision 31 | |
| Tue 11 Feb 2025· 8 record changes | |||||
| 2025-02-11 | Added to CISA KEV | CVE-2025-21418 | MicrosoftWindows CISA KEV | fix due 2025-03-04 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-02-11 | Added to CISA KEV | CVE-2025-21391 | MicrosoftWindows CISA KEV | fix due 2025-03-04 | Not applicable: Added to CISA KEV has no earlier value |
| 2025-02-11 | Fix version moved | CVE-2025-21198 | microsoftmicrosoft hpc pack 2019 | stated at publication 6.3.8322.0, now states 6.3.8328.0Release branch starts at 1.0.0.same day | Days to revision 0 |
| 2025-02-11 | Product added | CVE-2023-24932 | not named as affected at publication, now names windows 11 version 24h2 | Days to revision 644 | |
| 2025-02-11 | Product added | CVE-2023-24932 | not named as affected at publication, now names windows server 2025 | Days to revision 644 | |
| 2025-02-11 | Product added | CVE-2023-24932 | not named as affected at publication, now names windows server 2025 (server core installation) | Days to revision 644 | |
| 2025-02-11 | Product added | CVE-2025-21172 | not named as affected at publication, now names microsoft visual studio 2015 update 3 | Days to revision 28 | |
| 2025-02-11 | Product added | CVE-2025-21176 | not named as affected at publication, now names microsoft visual studio 2015 update 3 | Days to revision 28 | |
| Fri 7 Feb 2025· 1 record change | |||||
| 2025-02-07 | Added to CISA KEV | CVE-2024-21413 | MicrosoftOffice Outlook CISA KEV | fix due 2025-02-27 · listed 2025-02-06 | Not applicable: Added to CISA KEV has no earlier value |
| Tue 4 Feb 2025· 1 record change | |||||
| 2025-02-04 | Added to CISA KEV | CVE-2024-29059 | Microsoft.NET Framework CISA KEV | fix due 2025-02-25 | Not applicable: Added to CISA KEV has no earlier value |
| Wed 29 Jan 2025· 4 record changes | |||||
| 2025-01-29 | Product added | CVE-2024-43485 | not named as affected at publication, now names powershell 7.5 | Days to revision 113 | |
| 2025-01-29 | Product added | CVE-2024-43498 | not named as affected at publication, now names powershell 7.5 | Days to revision 78 | |
| 2025-01-29 | Product added | CVE-2024-43499 | not named as affected at publication, now names powershell 7.5 | Days to revision 78 | |
| 2025-01-29 | Product added | CVE-2025-21171 | not named as affected at publication, now names powershell 7.5 | Days to revision 15 | |
| Tue 31 Dec 2024· 4 record changes | |||||
| 2024-12-31 | Fix version moved | CVE-2024-29059 | microsoftmicrosoft .net framework 3.5 and 4.8 | stated at publication 4.8.4682.0, now states 4.8.04690.02Release branch starts at 4.8.0.Original value first replaced 2024-05-08; this value first seen 2024-12-31. | Days to revision 47 |
| 2024-12-31 | Fix version moved | CVE-2024-29059 | microsoftmicrosoft .net framework 4.6.2/4.7/4.7.1/4.7.2 | stated at publication 4.7.4076.0, now states 4.7.04081.03Release branch starts at 4.7.0.Original value first replaced 2024-05-08; this value first seen 2024-12-31. | Days to revision 47 |
| 2024-12-31 | Fix version moved | CVE-2024-49051 | microsoftmicrosoft pc manager | stated at publication 3.14.10.0, now states 3.14.14.0Release branch starts at 1.0.0. | Days to revision 49 |
| 2024-12-31 | Product added | CVE-2024-35264 | not named as affected at publication, now names .net 6.0 | Days to revision 175 | |
| Fri 27 Dec 2024· 1 record change | |||||
| 2024-12-27 | Product added | CVE-2024-30077 | not named as affected at publication, now names windows 11 version 24h2 | Days to revision 199 | |
| Fri 20 Dec 2024· 3 record changes | |||||
| 2024-12-20 | Product added | CVE-2024-43594 | not named as affected at publication, now names microsoft system center 2019 | Days to revision 10 | |
| 2024-12-20 | Product added | CVE-2024-43594 | not named as affected at publication, now names microsoft system center 2022 | Days to revision 10 | |
| 2024-12-20 | Product added | CVE-2024-43594 | not named as affected at publication, now names microsoft system center 2025 | Days to revision 10 | |
| Tue 10 Dec 2024· 3 record changes | |||||
| 2024-12-10 | Fix version moved | CVE-2023-38171 | microsoft.net 7.0 | stated at publication 7.0.12, now states 7.0.13Release branch starts at 7.0.0. | Days to revision 427 |
| 2024-12-10 | Fix version moved | CVE-2023-38171 | microsoftmicrosoft visual studio 2022 version 17.2 | stated at publication 17.2.20, now states 17.2.21Release branch starts at 17.2.0. | Days to revision 427 |
| 2024-12-10 | Fix version moved | CVE-2023-38171 | microsoftmicrosoft visual studio 2022 version 17.4 | stated at publication 17.4.12, now states 17.4.13Release branch starts at 17.4.0. | Days to revision 427 |
Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none.
Data sources and quality
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →