Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

1,056 record changes · 21 advisory changes · newest first · grouped by dayCSVJSONRSS

SinceClear the filter
ChangedSourceRows
Counted changes from the last 30 days, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Wed 26 Aug 2026· 5 record changes · 1 advisory change
2026-08-26Record state changedCVE-2026-78467
whole record
Wordfence
stated at publication PUBLISHED, now states REJECTEDDays to revision 2
2026-08-26Record state changedCVE-2026-78468
whole record
Wordfence
stated at publication PUBLISHED, now states REJECTEDDays to revision 1
2026-08-26Record state changedCVE-2026-78466
whole record
Wordfence
stated at publication PUBLISHED, now states REJECTEDDays to revision 2
2026-08-26Record state changedCVE-2026-74234
whole record
VulnCheck
stated at publication PUBLISHED, now states REJECTEDDays to revision 9
2026-08-26Record state changedCVE-2026-80216
whole record
mitre
stated at publication PUBLISHED, now states REJECTEDDays to revision 0
2026-08-26published 2026-02-25Advisory severity changedGHSA-wfx3-6g53-9fgcCVE-2026-56368whole advisorymoderatestated at publication LOW, now states MODERATEA CVSS version was added; the existing vectors stayed the same.Days to revision 182
Tue 25 Aug 2026· 43 record changes · 1 advisory change
2026-08-25Added to CISA KEVCVE-2026-60004
GiteaGitea
CISA KEV
fix due 2026-08-28Not applicable: Added to CISA KEV has no earlier value
2026-08-25Product addedCVE-2026-12339TPLinknot named as affected at publication, now names tl-mr100 v3.20Days to revision 15
2026-08-25Product addedCVE-2026-12339TPLinknot named as affected at publication, now names tl-mr150 v3.20Days to revision 15
2026-08-25Product addedCVE-2026-12339TPLinknot named as affected at publication, now names tl-mr6400 v8.0Days to revision 15
2026-08-25Product addedCVE-2026-16313not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 28
2026-08-25Product addedCVE-2026-16313not named as affected at publication, now names red hat enterprise linux 8.4 extended update support long-life add-onDays to revision 28
2026-08-25Product addedCVE-2026-16313not named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportDays to revision 28
2026-08-25Product addedCVE-2026-16313not named as affected at publication, now names red hat enterprise linux 8.6 extended update support long-life add-onDays to revision 28
2026-08-25Product addedCVE-2026-16313not named as affected at publication, now names red hat enterprise linux 8.8 telecommunications update serviceDays to revision 28
2026-08-25Product addedCVE-2026-16313not named as affected at publication, now names red hat enterprise linux 8.8 update services for sap solutionsDays to revision 28
2026-08-25Product addedCVE-2026-28984not named as affected at publication, now names macosDays to revision 8
2026-08-25Product addedCVE-2026-28984not named as affected at publication, now names safariDays to revision 8
2026-08-25Product addedCVE-2026-28984not named as affected at publication, now names tvosDays to revision 8
2026-08-25Product addedCVE-2026-28984not named as affected at publication, now names visionosDays to revision 8
2026-08-25Product addedCVE-2026-28984not named as affected at publication, now names watchosDays to revision 8
2026-08-25Product addedCVE-2026-39877not named as affected at publication, now names tvosDays to revision 29
2026-08-25Product addedCVE-2026-39877not named as affected at publication, now names visionosDays to revision 29
2026-08-25Product addedCVE-2026-39877not named as affected at publication, now names watchosDays to revision 29
2026-08-25Product addedCVE-2026-43667not named as affected at publication, now names macosDays to revision 8
2026-08-25Product addedCVE-2026-43667not named as affected at publication, now names visionosDays to revision 8
2026-08-25Product addedCVE-2026-43667not named as affected at publication, now names watchosDays to revision 8
2026-08-25Product addedCVE-2026-64732not named as affected at publication, now names macosDays to revision 29
2026-08-25Product addedCVE-2024-5647Wordfencenot named as affected at publication, now names bethemeDays to revision 418
2026-08-25Product addedCVE-2025-57847not named as affected at publication, now names red hat ansible automation platform ansible core 2Days to revision 139
2026-08-25Product addedCVE-2026-16313not named as affected at publication, now names red hat enterprise linux 9.6 extended update supportDays to revision 28
2026-08-25Product addedCVE-2026-78376redhatnot named as affected at publication, now names webkitDays to revision 1
2026-08-25Product addedCVE-2026-78376redhatnot named as affected at publication, now names webkitgtkDays to revision 1
2026-08-25Product addedCVE-2026-78465redhatnot named as affected at publication, now names gimpDays to revision 1
2026-08-25Product addedCVE-2026-78475redhatnot named as affected at publication, now names gimpDays to revision 1
2026-08-25Product addedCVE-2026-15809not named as affected at publication, now names red hat openshift container platform 4.22Days to revision 41
2026-08-25Product addedCVE-2026-15588not named as affected at publication, now names red hat update infrastructure 5Days to revision 36
2026-08-25Product addedCVE-2026-58010not named as affected at publication, now names red hat update infrastructure 5Days to revision 56
2026-08-25Product addedCVE-2026-58011not named as affected at publication, now names red hat update infrastructure 5Days to revision 56
2026-08-25Product addedCVE-2026-58012not named as affected at publication, now names red hat update infrastructure 5Days to revision 56
2026-08-25Product addedCVE-2026-58013not named as affected at publication, now names red hat update infrastructure 5Days to revision 56
2026-08-25Product addedCVE-2026-58014not named as affected at publication, now names red hat update infrastructure 5Days to revision 56
2026-08-25Product addedCVE-2026-58015not named as affected at publication, now names red hat update infrastructure 5Days to revision 56
2026-08-25Product addedCVE-2026-17527not named as affected at publication, now names red hat container native virtualization 4.19Days to revision 29
2026-08-25Product addedCVE-2026-17527not named as affected at publication, now names red hat container native virtualization 4.20Days to revision 29
2026-08-25Product addedCVE-2026-17527not named as affected at publication, now names red hat container native virtualization 4.21Days to revision 29
2026-08-25Record state changedCVE-2023-4010
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 1,121
2026-08-25Record state changedCVE-2026-73189
whole record
Patchstack
stated at publication PUBLISHED, now states REJECTEDDays to revision 7
2026-08-25Record state changedCVE-2026-78154
whole record
VulDB
stated at publication PUBLISHED, now states REJECTEDDays to revision 1
2026-08-25published 2026-07-02Advisory severity changedGHSA-83w9-h5wv-j9xmCVE-2026-53838whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 54
Mon 24 Aug 2026· 26 record changes
2026-08-24Added to CISA KEVCVE-2026-21962
OracleHTTP Server and Oracle Weblogic Server Proxy Plug-in
CISA KEV
fix due 2026-08-27Not applicable: Added to CISA KEV has no earlier value
2026-08-24Product addedCVE-2026-52902not named as affected at publication, now names red hat ansible automation platform 2.5 for rhel 8Days to revision 77
2026-08-24Product addedCVE-2026-52902not named as affected at publication, now names red hat ansible automation platform 2.5 for rhel 9Days to revision 77
2026-08-24Product addedCVE-2026-52902not named as affected at publication, now names red hat ansible automation platform 2.6 for rhel 9Days to revision 77
2026-08-24Product addedCVE-2026-52902not named as affected at publication, now names red hat ansible automation platform 2.7 for rhel 10Days to revision 76
2026-08-24Product addedCVE-2026-52902not named as affected at publication, now names red hat ansible automation platform 2.7 for rhel 9Days to revision 76
2026-08-24Product addedCVE-2026-11841not named as affected at publication, now names icr890-4Days to revision 27
2026-08-24Product addedCVE-2026-14164not named as affected at publication, now names red hat enterprise linux 9.6 extended update supportDays to revision 55
2026-08-24Product addedCVE-2026-14164not named as affected at publication, now names red hat enterprise linux 9.2 update services for sap solutionsDays to revision 55
2026-08-24Product addedCVE-2026-14164not named as affected at publication, now names red hat enterprise linux 9.4 update services for sap solutionsDays to revision 55
2026-08-24CVSS base score changedCVE-2026-78555
whole record
CIRCL
stated at publication 10.0, now states 9.4CVSS v4.0 · base scoreCriticalCriticalDays to revision 0
2026-08-24CVSS base score changedCVE-2023-50176
whole record
fortinet
stated at publication 7.1, now states 4.0CVSS v3.1 · base scoreHighMediumDays to revision 650
2026-08-24CVSS base score changedCVE-2026-26369
whole record
VulnCheck
stated at publication 9.8, now states 8.8CVSS v3.1 · base scoreCriticalHighDays to revision 190
2026-08-24CVSS base score changedCVE-2026-34100
whole record
VulnCheck
stated at publication 9.8, now states 8.8CVSS v3.1 · base scoreCriticalHighDays to revision 54
2026-08-24CVSS base score changedCVE-2026-34101
whole record
VulnCheck
stated at publication 9.8, now states 8.8CVSS v3.1 · base scoreCriticalHighDays to revision 54
2026-08-24CVSS base score changedCVE-2026-34102
whole record
VulnCheck
stated at publication 9.8, now states 8.8CVSS v3.1 · base scoreCriticalHighDays to revision 54
2026-08-24CVSS base score changedCVE-2026-34103
whole record
VulnCheck
stated at publication 9.8, now states 8.8CVSS v3.1 · base scoreCriticalHighDays to revision 54
2026-08-24CVSS base score changedCVE-2026-34104
whole record
VulnCheck
stated at publication 9.8, now states 8.8CVSS v3.1 · base scoreCriticalHighDays to revision 54
2026-08-24CVSS base score changedCVE-2026-34105
whole record
VulnCheck
stated at publication 9.8, now states 8.8CVSS v3.1 · base scoreCriticalHighDays to revision 54
2026-08-24CVSS base score changedCVE-2026-39910
whole record
VulnCheck
stated at publication 9.8, now states 8.8CVSS v3.1 · base scoreCriticalHighDays to revision 77
2026-08-24CVSS base score changedCVE-2026-72822
whole record
VulnCheck
stated at publication 9.8, now states 8.8CVSS v3.1 · base scoreCriticalHighDays to revision 10
2026-08-24CVSS base score changedCVE-2026-72824
whole record
VulnCheck
stated at publication 9.8, now states 8.8CVSS v3.1 · base scoreCriticalHighDays to revision 10
2026-08-24CVSS base score changedCVE-2026-72826
whole record
VulnCheck
stated at publication 9.8, now states 8.8CVSS v3.1 · base scoreCriticalHighDays to revision 10
2026-08-24CVSS base score changedCVE-2026-72829
whole record
VulnCheck
stated at publication 9.8, now states 8.8CVSS v3.1 · base scoreCriticalHighDays to revision 10
2026-08-24CVSS base score changedCVE-2026-72830
whole record
VulnCheck
stated at publication 9.8, now states 8.8CVSS v3.1 · base scoreCriticalHighDays to revision 10
2026-08-24CVSS base score changedCVE-2026-18652
whole record
rapid7
stated at publication 4.9, now states 6.5CVSS v3.1 · base scoreMediumMediumDays to revision 12
Sun 23 Aug 2026· 2 record changes
2026-08-23Product addedCVE-2026-42965not named as affected at publication, now names red hat openshift container platform 4.2Days to revision 86
2026-08-23CVSS base score changedCVE-2026-76613
whole record
Joomla
stated at publication 9.2, now states 8.6CVSS v4.0 · base scoreCriticalHighDays to revision 2
Fri 21 Aug 2026· 12 record changes · 2 advisory changes
2026-08-21Added to CISA KEVCVE-2026-69836
MicrosoftEntra ID
CISA KEV
fix due 2026-08-24Not applicable: Added to CISA KEV has no earlier value
2026-08-21Added to CISA KEVCVE-2026-73570
SynacorZimbra Collaboration Suite (ZCS)
CISA KEV
fix due 2026-08-24Not applicable: Added to CISA KEV has no earlier value
2026-08-21Ransomware use confirmedCVE-2021-43226
MicrosoftWindows
CISA KEV
stated at publication Unknown, now states KnownDays to revision 319
2026-08-21Ransomware use confirmedCVE-2020-5135
SonicWallSonicOS
CISA KEV
stated at publication Unknown, now states KnownDays to revision at least 541
2026-08-21Ransomware use confirmedCVE-2012-0158
MicrosoftMSCOMCTL.OCX
CISA KEV
stated at publication Unknown, now states KnownDays to revision at least 541
2026-08-21Fix version movedCVE-2026-18952
githubopensearch
AMZN
stated at publication 3.5.0, now states 3.7.0Release branch starts at 2.15.0.Days to revision 9
2026-08-21Product addedCVE-2026-14544redhatnot named as affected at publication, now names hplipDays to revision 49
2026-08-21Product addedCVE-2026-28896not named as affected at publication, now names ios and ipadosDays to revision 24
2026-08-21Product addedCVE-2026-28896not named as affected at publication, now names tvosDays to revision 24
2026-08-21Product addedCVE-2026-28896not named as affected at publication, now names visionosDays to revision 24
2026-08-21Product addedCVE-2026-28896not named as affected at publication, now names watchosDays to revision 24
2026-08-21Record state changedCVE-2026-69159
whole record
GitHub_M
stated at publication PUBLISHED, now states REJECTEDDays to revision 2
2026-08-21published 2026-08-20Advisory severity changedGHSA-fm29-4mq3-phg6whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 1
2026-08-21published 2026-07-24Advisory severity changedGHSA-r292-9mhp-454mCVE-2026-73566whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 28
Thu 20 Aug 2026· 8 record changes
2026-08-20Added to CISA KEVCVE-2026-72530
TrueConfServer
CISA KEV
fix due 2026-09-03Not applicable: Added to CISA KEV has no earlier value
2026-08-20Added to CISA KEVCVE-2026-72529
TrueConfServer
CISA KEV
fix due 2026-08-23Not applicable: Added to CISA KEV has no earlier value
2026-08-20Fix version movedCVE-2026-17561TR-CERTstated at publication 6.4.108, now states 6.4.115Release branch starts at 0.Days to revision 20
2026-08-20Product addedCVE-2026-14476not named as affected at publication, now names red hat openshift container platform 4.13Days to revision 45
2026-08-20Product addedCVE-2026-14474not named as affected at publication, now names red hat openshift container platform 4.13Days to revision 45
2026-08-20Product addedCVE-2025-12131Silabsnot named as affected at publication, now names emberznet sdkDays to revision 196
2026-08-20Product addedCVE-2026-44188not named as affected at publication, now names red hat ansible automation platform 2.6Days to revision 66
2026-08-20CVSS base score changedCVE-2026-76956
whole record
mitre
stated at publication 7.5, now states 5.9CVSS v3.1 · base scoreHighMediumDays to revision 1

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →