Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

11,999 record changes · 5,026 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
Counted changes, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Thu 23 Apr 2026· 16 record changes
2026-04-23CVSS base score changedCVE-2025-49410
whole record
Patchstack
stated at publication 6.5, now states 10.0CVSS v3.1 · base scoreMediumCriticalDays to revision 246
2026-04-23CVSS base score changedCVE-2025-49413
whole record
Patchstack
stated at publication 5.9, now states 7.1CVSS v3.1 · base scoreMediumHighOriginal value first replaced 2026-04-01; this value first seen 2026-04-23.Days to revision 224
2026-04-23CVSS base score changedCVE-2025-49426
whole record
Patchstack
stated at publication 4.3, now states 8.1CVSS v3.1 · base scoreMediumHighOriginal value first replaced 2026-04-01; this value first seen 2026-04-23.Days to revision 224
2026-04-23CVSS base score changedCVE-2025-49428
whole record
Patchstack
stated at publication 5.9, now states 7.5CVSS v3.1 · base scoreMediumHighDays to revision 246
2026-04-23CVSS base score changedCVE-2025-49436
whole record
Patchstack
stated at publication 6.5, now states 8.1CVSS v3.1 · base scoreMediumHighOriginal value first replaced 2026-04-01; this value first seen 2026-04-23.Days to revision 224
2026-04-23CVSS base score changedCVE-2025-49438
whole record
Patchstack
stated at publication 7.2, now states 8.1CVSS v3.1 · base scoreHighHighDays to revision 246
2026-04-23CVSS base score changedCVE-2025-49455
whole record
Patchstack
stated at publication 9.8, now states 9.3CVSS v3.1 · base scoreCriticalCriticalOriginal value first replaced 2026-04-01; this value first seen 2026-04-23.Days to revision 295
2026-04-23CVSS base score changed
whole record
Patchstack
stated at publication 5.9, now states 8.1CVSS v3.1 · base scoreMediumHighOriginal value first replaced 2026-04-01; this value first seen 2026-04-23.Days to revision 224
2026-04-23same kind of change as the line aboveCVE-2025-49889same vendor as the line abovesame change as the line aboveOriginal value first replaced 2026-04-01; this value first seen 2026-04-23.Days to revision 224
2026-04-23same kind of change as the line aboveCVE-2025-49892same vendor as the line abovesame change as the line aboveOriginal value first replaced 2026-04-01; this value first seen 2026-04-23.Days to revision 224
2026-04-23same kind of change as the line aboveCVE-2025-49894same vendor as the line abovesame change as the line aboveOriginal value first replaced 2026-04-01; this value first seen 2026-04-23.Days to revision 224
2026-04-23CVSS base score changedCVE-2025-49891
whole record
Patchstack
stated at publication 5.9, now states 8.5CVSS v3.1 · base scoreMediumHighOriginal value first replaced 2026-04-01; this value first seen 2026-04-23.Days to revision 224
2026-04-23CVSS base score changedCVE-2025-49895
whole record
Patchstack
stated at publication 8.8, now states 6.5CVSS v3.1 · base scoreHighMediumDays to revision 251
2026-04-23CVSS base score changedCVE-2025-49896
whole record
Patchstack
stated at publication 4.3, now states 5.3CVSS v3.1 · base scoreMediumMediumDays to revision 246
2026-04-23CVSS base score changedCVE-2025-49897
whole record
Patchstack
stated at publication 8.5, now states 8.8CVSS v3.1 · base scoreHighHighDays to revision 251
2026-04-23CVSS base score changedCVE-2025-49898
whole record
Patchstack
stated at publication 5.9, now states 7.6CVSS v3.1 · base scoreMediumHighDays to revision 251
2026-04-23CVSS base score changedCVE-2025-62138
whole record
Patchstack
stated at publication 5.3, now states 5.4CVSS v3.1 · base scoreMediumMediumOriginal value first replaced 2026-04-01; this value first seen 2026-04-23.Days to revision 91
Wed 22 Apr 2026· 19 record changes · 1 advisory change
2026-04-22Added to CISA KEVCVE-2026-33825
MicrosoftDefender
CISA KEV
fix due 2026-05-06Not applicable: Added to CISA KEV has no earlier value
2026-04-22Product addedTPLinknot named as affected at publication, now names archer c20 v5Days to revision 76 to 280
2026-04-22same kind of change as the line aboveCVE-2025-15551same vendor as the line abovesame change as the line aboveDays to revision 76
2026-04-22same kind of change as the line aboveCVE-2025-6982same vendor as the line abovesame change as the line aboveDays to revision 280
2026-04-22same kind of change as the line aboveCVE-2026-0834same vendor as the line abovesame change as the line aboveDays to revision 91
2026-04-22Product addedCVE-2026-26171not named as affected at publication, now names powershell 7.5 and 1 moreDays to revision 8
2026-04-22same kind of change as the line aboveCVE-2026-26171same vendor as the line abovenot named as affected at publication, now names powershell 7.5Days to revision 8
2026-04-22same kind of change as the line aboveCVE-2026-26171same vendor as the line abovenot named as affected at publication, now names powershell 7.6Days to revision 8
2026-04-22Product addedCVE-2026-33471GitHub_Mnot named as affected at publication, now names nimiq-blockDays to revision 0
2026-04-22Product addedCVE-2026-22191VulnChecknot named as affected at publication, now names sicuroweb (sicuro24)Days to revision 41
2026-04-22Product addedVulnChecknot named as affected at publication, now names snmp web proDays to revision 41
2026-04-22same kind of change as the line aboveCVE-2026-22192same vendor as the line abovesame change as the line aboveDays to revision 41
2026-04-22same kind of change as the line aboveCVE-2026-22199same vendor as the line abovesame change as the line aboveDays to revision 41
2026-04-22Product addednot named as affected at publication, now names red hat insights proxy 1.5Days to revision 23 to 40
2026-04-22same kind of change as the line aboveCVE-2026-4111same vendor as the line abovesame change as the line aboveDays to revision 40
2026-04-22same kind of change as the line aboveCVE-2026-4424same vendor as the line abovesame change as the line aboveDays to revision 34
2026-04-22same kind of change as the line aboveCVE-2026-5121same vendor as the line abovesame change as the line aboveDays to revision 23
2026-04-22Product addedCVE-2026-4111not named as affected at publication, now names red hat openshift container platform 4.18Days to revision 40
2026-04-22Product addednot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 23 to 34
2026-04-22same kind of change as the line aboveCVE-2026-4424same vendor as the line abovesame change as the line aboveDays to revision 34
2026-04-22same kind of change as the line aboveCVE-2026-5121same vendor as the line abovesame change as the line aboveDays to revision 23
2026-04-22CVSS base score changedCVE-2026-41171
whole record
GitHub_M
stated at publication 5.7, now states 7.3CVSS v4.0 · base scoreMediumHighDays to revision 0
2026-04-22CVSS base score changedCVE-2026-0972
whole record
Fortra
stated at publication 7.3, now states 5.4CVSS v3.1 · base scoreHighMediumDays to revision 1
2026-04-22Record state changedCVE-2026-5358
whole record
glibc
stated at publication PUBLISHED, now states REJECTEDDays to revision 2
2026-04-22published 2026-02-19Package added to advisoryGHSA-4hfh-fch3-5q7pCVE-2026-27120moderatenot named as affected when the advisory was published, now names github.com/vapor/leaf-kitDays to revision 62
Tue 21 Apr 2026· 29 record changes
2026-04-21Ransomware use confirmedCVE-2023-27351
PaperCutNG/MF
CISA KEV
stated at publication Unknown, now states KnownDays to revision 1
2026-04-21Ransomware use confirmedCVE-2024-27199
JetBrainsTeamCity
CISA KEV
stated at publication Unknown, now states KnownDays to revision 1
2026-04-21Ransomware use confirmedCVE-2023-21529
MicrosoftExchange Server
CISA KEV
stated at publication Unknown, now states KnownDays to revision 8
2026-04-21Ransomware use confirmedCVE-2025-52691
SmarterToolsSmarterMail
CISA KEV
stated at publication Unknown, now states KnownDays to revision 85
2026-04-21Product addedCVE-2026-6443Wordfencenot named as affected at publication, now names album and image gallery plus lightbox and 20 moreDays to revision 5
2026-04-21same kind of change as the line aboveCVE-2026-6443same vendor as the line abovenot named as affected at publication, now names album and image gallery plus lightboxDays to revision 5
2026-04-21same kind of change as the line aboveCVE-2026-6443same vendor as the line abovenot named as affected at publication, now names blog designer – post and widgetDays to revision 5
2026-04-21same kind of change as the line aboveCVE-2026-6443same vendor as the line abovenot named as affected at publication, now names countdown timer ultimateDays to revision 5
2026-04-21same kind of change as the line aboveCVE-2026-6443same vendor as the line abovenot named as affected at publication, now names featured post creativeDays to revision 5
2026-04-21same kind of change as the line aboveCVE-2026-6443same vendor as the line abovenot named as affected at publication, now names meta slider and carousel with lightboxDays to revision 5
2026-04-21same kind of change as the line aboveCVE-2026-6443same vendor as the line abovenot named as affected at publication, now names popup maker and popup anything – popup for opt-ins and lead generation conversionsDays to revision 5
2026-04-21same kind of change as the line aboveCVE-2026-6443same vendor as the line abovenot named as affected at publication, now names portfolio and projectsDays to revision 5
2026-04-21same kind of change as the line aboveCVE-2026-6443same vendor as the line abovenot named as affected at publication, now names post grid and filter ultimateDays to revision 5
13 more rows in this change are not listed here. Open all 21 rows
2026-04-21Product addedCVE-2026-32203not named as affected at publication, now names microsoft visual studio 2026 version 18.4Days to revision 7
2026-04-21Product addedCVE-2026-5588bcorgnot named as affected at publication, now names bcpkix-fipsDays to revision 6
2026-04-21CVSS base score changedCVE-2026-5598
whole record
bcorg
stated at publication 10.0, now states 8.9CVSS v4.0 · base scoreCriticalHighDays to revision 6
2026-04-21Record state changedCVE-2026-39659
whole record
Patchstack
stated at publication PUBLISHED, now states REJECTEDDays to revision 13
Mon 20 Apr 2026· 12 record changes
2026-04-20Added to CISA KEVCVE-2026-20122
CiscoCatalyst SD-WAN Manger
CISA KEV
fix due 2026-04-23Not applicable: Added to CISA KEV has no earlier value
2026-04-20Added to CISA KEV
CiscoCatalyst SD-WAN Manager
fix due 2026-04-23Not applicable: Added to CISA KEV has no earlier value
2026-04-20same kind of change as the line aboveCVE-2026-20133same vendor as the line abovesame change as the line aboveNot applicable: Added to CISA KEV has no earlier value
2026-04-20same kind of change as the line aboveCVE-2026-20128same vendor as the line abovesame change as the line aboveNot applicable: Added to CISA KEV has no earlier value
2026-04-20Added to CISA KEVCVE-2025-2749
KenticoKentico Xperience
CISA KEV
fix due 2026-05-04Not applicable: Added to CISA KEV has no earlier value
2026-04-20Added to CISA KEVCVE-2023-27351
PaperCutNG/MF
CISA KEV
fix due 2026-05-04Not applicable: Added to CISA KEV has no earlier value
2026-04-20Added to CISA KEVCVE-2025-48700
SynacorZimbra Collaboration Suite (ZCS)
CISA KEV
fix due 2026-04-23Not applicable: Added to CISA KEV has no earlier value
2026-04-20Added to CISA KEVCVE-2025-32975
QuestKACE Systems Management Appliance (SMA)
CISA KEV
fix due 2026-05-04Not applicable: Added to CISA KEV has no earlier value
2026-04-20Added to CISA KEVCVE-2024-27199
JetBrainsTeamCity
CISA KEV
fix due 2026-05-04Not applicable: Added to CISA KEV has no earlier value
2026-04-20Product addednot named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportDays to revision 21 to 32
2026-04-20same kind of change as the line aboveCVE-2026-4424same vendor as the line abovesame change as the line aboveDays to revision 32
2026-04-20same kind of change as the line aboveCVE-2026-5121same vendor as the line abovesame change as the line aboveDays to revision 21
2026-04-20CVSS base score changed
whole record
INCIBE
stated at publication 9.1, now states 4.7CVSS v3.1 · base scoreCriticalMediumDays to revision 872
2026-04-20same kind of change as the line aboveCVE-2023-5965same vendor as the line abovesame change as the line aboveDays to revision 872
2026-04-20same kind of change as the line aboveCVE-2023-5966same vendor as the line abovesame change as the line aboveDays to revision 872
Sat 18 Apr 2026· 5 advisory changes
2026-04-18published 2026-03-26Advisory severity changedGHSA-mp66-rf4f-mhh8CVE-2026-35622whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 22
2026-04-18published 2026-03-26Advisory severity changedGHSA-xhq5-45pm-2gjrCVE-2026-35624whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 22
2026-04-18published 2026-03-29Advisory severity changedGHSA-52q4-3xjc-6778CVE-2026-35617whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 19
2026-04-18published 2026-03-29Advisory severity changedGHSA-h4jx-hjr3-fhgcCVE-2026-35645whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 19
2026-04-18published 2026-03-26Advisory severity changedGHSA-7xr2-q9vf-x4r5CVE-2026-35632whole advisorymoderatestated at publication HIGH, now states MODERATEA CVSS version was added; the existing vectors stayed the same.Days to revision 22
Fri 17 Apr 2026· 11 record changes · 2 advisory changes
2026-04-17Fix version movedCVE-2026-3854
githubenterprise server
GitHub_P
stated at publication 3.14.24, now states 3.14.25Release branch starts at 3.14.0.Days to revision 38
2026-04-17Fix version movedCVE-2026-3854
githubenterprise server
GitHub_P
stated at publication 3.15.19, now states 3.15.20Release branch starts at 3.15.0.Days to revision 38
2026-04-17Fix version movedCVE-2026-3854
githubenterprise server
GitHub_P
stated at publication 3.16.15, now states 3.16.16Release branch starts at 3.16.0.Days to revision 38
2026-04-17Fix version movedCVE-2026-3854
githubenterprise server
GitHub_P
stated at publication 3.17.12, now states 3.17.13Release branch starts at 3.17.0.Days to revision 38
2026-04-17Fix version movedCVE-2026-3854
githubenterprise server
GitHub_P
stated at publication 3.18.6, now states 3.18.7Release branch starts at 3.18.0.Days to revision 38
2026-04-17Fix version movedCVE-2026-3854
githubenterprise server
GitHub_P
stated at publication 3.19.3, now states 3.19.4Release branch starts at 3.19.0.Days to revision 38
2026-04-17Product addedhackeronenot named as affected at publication, now names backup and replicationDays to revision 36
2026-04-17same kind of change as the line aboveCVE-2026-21672same vendor as the line abovesame change as the line aboveDays to revision 36
2026-04-17same kind of change as the line aboveCVE-2026-21708same vendor as the line abovesame change as the line aboveDays to revision 36
2026-04-17Product addednot named as affected at publication, now names red hat ai inference server 3.3Days to revision 35 to 813
2026-04-17same kind of change as the line aboveCVE-2023-52356same vendor as the line abovesame change as the line aboveDays to revision 813
2026-04-17same kind of change as the line aboveCVE-2025-14831same vendor as the line abovesame change as the line aboveDays to revision 67
2026-04-17same kind of change as the line aboveCVE-2026-4111same vendor as the line abovesame change as the line aboveDays to revision 35
2026-04-17published 2022-05-14Package added to advisoryGHSA-6r5v-hp32-fjqwCVE-2015-0227moderatenot named as affected when the advisory was published, now names wss4j:wss4jnot dated
2026-04-17published 2024-05-03Package added to advisoryGHSA-4h8f-2wvx-gg5wCVE-2024-34447moderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onDays to revision 714
Thu 16 Apr 2026· 63 record changes · 6 advisory changes
2026-04-16Added to CISA KEVCVE-2026-34197
ApacheActiveMQ
CISA KEV
fix due 2026-04-30Not applicable: Added to CISA KEV has no earlier value
2026-04-16Affected range extendedCVE-2026-5329
rapid7velociraptor
stated at publication 0.76.1, now states 0.76.3Release branch starts at 0.Days to revision 7
2026-04-16Product addednot named as affected at publication, now names red hat enterprise linux 8.2 advanced update supportDays to revision 18 to 28
2026-04-16same kind of change as the line aboveCVE-2026-4424same vendor as the line abovesame change as the line aboveDays to revision 28
2026-04-16same kind of change as the line aboveCVE-2026-5121same vendor as the line abovesame change as the line aboveDays to revision 18
2026-04-16Product addedCVE-2025-36579not named as affected at publication, now names inspiron 13 5320 and 53 moreDays to revision 0
2026-04-16same kind of change as the line aboveCVE-2025-36579same vendor as the line abovenot named as affected at publication, now names inspiron 13 5320Days to revision 0
2026-04-16same kind of change as the line aboveCVE-2025-36579same vendor as the line abovenot named as affected at publication, now names inspiron 13 5330Days to revision 0
2026-04-16same kind of change as the line aboveCVE-2025-36579same vendor as the line abovenot named as affected at publication, now names inspiron 14 5420Days to revision 0
2026-04-16same kind of change as the line aboveCVE-2025-36579same vendor as the line abovenot named as affected at publication, now names inspiron 14 5430Days to revision 0
2026-04-16same kind of change as the line aboveCVE-2025-36579same vendor as the line abovenot named as affected at publication, now names inspiron 14 5440Days to revision 0
2026-04-16same kind of change as the line aboveCVE-2025-36579same vendor as the line abovenot named as affected at publication, now names inspiron 14 7420 2-in-1Days to revision 0
2026-04-16same kind of change as the line aboveCVE-2025-36579same vendor as the line abovenot named as affected at publication, now names inspiron 14 7430 2-in-1Days to revision 0
2026-04-16same kind of change as the line aboveCVE-2025-36579same vendor as the line abovenot named as affected at publication, now names inspiron 14 7440 2-in-1Days to revision 0
46 more rows in this change are not listed here. Open all 54 rows
2026-04-16Product addednot named as affected at publication, now names red hat openshift container platform 4.13Days to revision 34 to 149
2026-04-16same kind of change as the line aboveCVE-2025-61662same vendor as the line abovesame change as the line aboveDays to revision 149
2026-04-16same kind of change as the line aboveCVE-2026-4111same vendor as the line abovesame change as the line aboveDays to revision 34
2026-04-16Product addedCVE-2025-61662not named as affected at publication, now names red hat openshift container platform 4.19Days to revision 149
2026-04-16CVSS base score changedCVE-2025-62718
whole record
GitHub_M
stated at publication 9.3, now states 6.3CVSS v4.0 · base scoreCriticalMediumDays to revision 7
2026-04-16CVSS base score changedCVE-2026-40175
whole record
GitHub_M
stated at publication 10.0, now states 4.8CVSS v3.1 · base scoreCriticalMediumDays to revision 6
2026-04-16published 2022-04-22Package added to advisoryGHSA-4qqf-hmv6-r6whCVE-2011-2487moderatenot named as affected when the advisory was published, now names wss4j:wss4jnot dated
2026-04-16published 2025-07-21Package added to advisoryGHSA-9342-92gg-6v29CVE-2025-7962moderatenot named as affected when the advisory was published, now names com.sun.mail:jakarta.mailDays to revision 269
2026-04-16published 2024-10-04Package added to advisoryGHSA-wwcp-26wc-3fxmCVE-2024-47855moderatenot named as affected when the advisory was published, now names net.sf.json-lib:json-libDays to revision 560
2026-04-16published 2022-05-13Package added to advisoryGHSA-jwwr-fjgh-cv2xCVE-2014-3004moderatenot named as affected when the advisory was published, now names castor:castornot dated
2026-04-16published 2026-04-09 to 2026-04-10Advisory severity changedwhole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 6 to 7
2026-04-16published 2026-04-10same kind of change as the line aboveGHSA-fvcv-3m26-pcqxCVE-2026-40175same package and registry as the line abovemoderatesame change as the line aboveDays to revision 6
2026-04-16published 2026-04-09same kind of change as the line aboveGHSA-3p68-rc4w-qgx5CVE-2025-62718same package and registry as the line abovemoderatesame change as the line aboveDays to revision 7
Wed 15 Apr 2026· 5 record changes · 6 advisory changes
2026-04-15CVSS base score changedCVE-2026-5588
whole record
bcorg
stated at publication 10.0, now states 6.3CVSS v4.0 · base scoreCriticalMediumDays to revision 0
2026-04-15CVSS base score changedCVE-2026-3505
whole record
bcorg
stated at publication 10.0, now states 8.7CVSS v4.0 · base scoreCriticalHighDays to revision 0
2026-04-15CVSS base score changedCVE-2025-14813
whole record
bcorg
stated at publication 9.4, now states 9.3CVSS v4.0 · base scoreCriticalCriticalDays to revision 0
2026-04-15CVSS base score changedCVE-2026-0636
whole record
bcorg
stated at publication 10.0, now states 5.5CVSS v4.0 · base scoreCriticalMediumDays to revision 0
2026-04-15Record state changedCVE-2026-32187
whole record
microsoft
stated at publication PUBLISHED, now states REJECTEDDays to revision 19
2026-04-15published 2026-04-09Advisory fix version movedGHSA-h468-7pvh-8vr8CVE-2026-29146
mavenorg.apache.tomcat:tomcat
high
stated at publication 11.0.19, now states 11.0.20Days to revision 6
2026-04-15published 2026-04-09Package added to advisoryGHSA-8mc5-53m5-3qj2CVE-2026-32990moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 6
2026-04-15published 2026-04-09Package added to advisoryhighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-tribesDays to revision 6
2026-04-15published 2026-04-09same kind of change as the line aboveGHSA-69r9-qgr7-g2wjCVE-2026-34486same package registry as the line abovehighsame change as the line aboveDays to revision 6
2026-04-15published 2026-04-09same kind of change as the line aboveGHSA-h468-7pvh-8vr8CVE-2026-29146same package registry as the line abovehighsame change as the line aboveDays to revision 6
2026-04-15published 2026-04-14Advisory severity changedwhole advisoryhighstated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 1
2026-04-15published 2026-04-14same kind of change as the line aboveGHSA-37gx-xxp4-5rgxCVE-2026-33116same package and registry as the line abovehighsame change as the line aboveDays to revision 1
2026-04-15published 2026-04-14same kind of change as the line aboveGHSA-w3x6-4m5h-cxqfCVE-2026-26171same package and registry as the line abovehighsame change as the line aboveDays to revision 1
Tue 14 Apr 2026· 44 record changes · 2 advisory changes
2026-04-14Added to CISA KEVCVE-2009-0238
MicrosoftOffice
CISA KEV
fix due 2026-04-28Not applicable: Added to CISA KEV has no earlier value
2026-04-14Added to CISA KEVCVE-2026-32201
MicrosoftSharePoint Server
CISA KEV
fix due 2026-04-28Not applicable: Added to CISA KEV has no earlier value
2026-04-14Product addedCVE-2026-22719not named as affected at publication, now names vmware cloud foundation operationsDays to revision 48
2026-04-142 commitsProduct addednot named as affected at publication, now names red hat hardened imagesBranches and original-value intervals are stated on each row.Days to revision 278 to 306
2026-04-14same kind of change as the line aboveCVE-2025-32988same vendor as the line abovesame change as the line aboveDays to revision 278
2026-04-14same kind of change as the line aboveCVE-2025-32989same vendor as the line abovesame change as the line aboveDays to revision 278
2026-04-14same kind of change as the line aboveCVE-2025-32990same vendor as the line abovesame change as the line aboveDays to revision 278
2026-04-14same kind of change as the line aboveCVE-2025-6170same vendor as the line abovesame change as the line aboveDays to revision 302
2026-04-14same kind of change as the line aboveCVE-2025-7424same vendor as the line abovesame change as the line aboveDays to revision 278
2026-04-14same kind of change as the line aboveCVE-2025-7425same vendor as the line abovesame change as the line aboveDays to revision 278
2026-04-14same kind of change as the line aboveCVE-2025-49794same vendor as the line abovesame change as the line aboveDays to revision 302
2026-04-14same kind of change as the line aboveCVE-2025-49795same vendor as the line abovesame change as the line aboveDays to revision 302
2 more rows in this change are not listed here. Open all 10 rows
2026-04-14Product addedCVE-2023-44373not named as affected at publication, now names scalance w721-1 rj45 and 27 moreDays to revision 882
2026-04-14same kind of change as the line aboveCVE-2023-44373same vendor as the line abovenot named as affected at publication, now names scalance w721-1 rj45Days to revision 882
2026-04-14same kind of change as the line aboveCVE-2023-44373same vendor as the line abovenot named as affected at publication, now names scalance w722-1 rj45Days to revision 882
2026-04-14same kind of change as the line aboveCVE-2023-44373same vendor as the line abovenot named as affected at publication, now names scalance w734-1 rj45Days to revision 882
2026-04-14same kind of change as the line aboveCVE-2023-44373same vendor as the line abovenot named as affected at publication, now names scalance w734-1 rj45 (usa)Days to revision 882
2026-04-14same kind of change as the line aboveCVE-2023-44373same vendor as the line abovenot named as affected at publication, now names scalance w738-1 m12Days to revision 882
2026-04-14same kind of change as the line aboveCVE-2023-44373same vendor as the line abovenot named as affected at publication, now names scalance w748-1 m12Days to revision 882
2026-04-14same kind of change as the line aboveCVE-2023-44373same vendor as the line abovenot named as affected at publication, now names scalance w748-1 rj45Days to revision 882
2026-04-14same kind of change as the line aboveCVE-2023-44373same vendor as the line abovenot named as affected at publication, now names scalance w761-1 rj45Days to revision 882
20 more rows in this change are not listed here. Open all 28 rows
2026-04-14Product addedCVE-2025-40571not named as affected at publication, now names mendix oidc sso v4.2 (mendix 10 compatible) and 1 moreDays to revision 336
2026-04-14same kind of change as the line aboveCVE-2025-40571same vendor as the line abovenot named as affected at publication, now names mendix oidc sso v4.2 (mendix 10 compatible)Days to revision 336
2026-04-14same kind of change as the line aboveCVE-2025-40571same vendor as the line abovenot named as affected at publication, now names mendix oidc sso v4.3 (mendix 10 compatible)Days to revision 336
2026-04-14CVSS base score changedCVE-2026-32146
whole record
EEF
stated at publication 6.2, now states 8.3CVSS v4.0 · base scoreMediumHighDays to revision 3
2026-04-14published 2026-03-30 to 2026-04-08Advisory withdrawnwhole advisory2 bandswithdrawn 2026-04-14Days to revision 5 to 15
2026-04-14published 2026-03-30same kind of change as the line aboveGHSA-qqrv-2hch-83q4same package and registry as the line abovemoderatewithdrawn 2026-04-14Days to revision 15
2026-04-14published 2026-04-08same kind of change as the line aboveGHSA-gc59-r5jq-98qwsame package and registry as the line abovehighwithdrawn 2026-04-14Days to revision 5
Mon 13 Apr 2026· 25 record changes
2026-04-13Added to CISA KEVCVE-2012-1854
MicrosoftVisual Basic for Applications (VBA)
CISA KEV
fix due 2026-04-27Not applicable: Added to CISA KEV has no earlier value
2026-04-13Added to CISA KEV
MicrosoftWindows
fix due 2026-04-27Not applicable: Added to CISA KEV has no earlier value
2026-04-13same kind of change as the line aboveCVE-2025-60710same vendor as the line abovesame change as the line aboveNot applicable: Added to CISA KEV has no earlier value
2026-04-13same kind of change as the line aboveCVE-2023-36424same vendor as the line abovesame change as the line aboveNot applicable: Added to CISA KEV has no earlier value
2026-04-13Added to CISA KEVCVE-2023-21529
MicrosoftExchange Server
CISA KEV
fix due 2026-04-27Not applicable: Added to CISA KEV has no earlier value
2026-04-13Added to CISA KEVCVE-2020-9715
AdobeAcrobat
CISA KEV
fix due 2026-04-27Not applicable: Added to CISA KEV has no earlier value
2026-04-13Added to CISA KEVCVE-2026-21643
FortinetFortiClient EMS
CISA KEV
fix due 2026-04-16Not applicable: Added to CISA KEV has no earlier value
2026-04-13Added to CISA KEVCVE-2026-34621
AdobeAcrobat and Reader
CISA KEV
fix due 2026-04-27Not applicable: Added to CISA KEV has no earlier value
2026-04-13Product addedCVE-2024-1573Mitsubishinot named as affected at publication, now names analytix and 3 moreDays to revision 649
2026-04-13same kind of change as the line aboveCVE-2024-1573same vendor as the line abovenot named as affected at publication, now names analytixDays to revision 649
2026-04-13same kind of change as the line aboveCVE-2024-1573same vendor as the line abovenot named as affected at publication, now names hyper historianDays to revision 649
2026-04-13same kind of change as the line aboveCVE-2024-1573same vendor as the line abovenot named as affected at publication, now names iotworxDays to revision 649
2026-04-13same kind of change as the line aboveCVE-2024-1573same vendor as the line abovenot named as affected at publication, now names mobilehmiDays to revision 649
2026-04-13Product addedCVE-2024-1573Mitsubishinot named as affected at publication, now names analytix and 3 moreDays to revision 649
2026-04-13same kind of change as the line aboveCVE-2024-1573same vendor as the line abovenot named as affected at publication, now names analytixDays to revision 649
2026-04-13same kind of change as the line aboveCVE-2024-1573same vendor as the line abovenot named as affected at publication, now names hyper historianDays to revision 649
2026-04-13same kind of change as the line aboveCVE-2024-1573same vendor as the line abovenot named as affected at publication, now names iotworxDays to revision 649
2026-04-13same kind of change as the line aboveCVE-2024-1573same vendor as the line abovenot named as affected at publication, now names mobilehmiDays to revision 649
2026-04-134 commitsProduct addednot named as affected at publication, now names red hat hardened imagesBranches and original-value intervals are stated on each row.Days to revision 77 to 220
2026-04-13same kind of change as the line aboveCVE-2025-10911same vendor as the line abovesame change as the line aboveDays to revision 200
2026-04-13same kind of change as the line aboveCVE-2025-9566same vendor as the line abovesame change as the line aboveDays to revision 220
2026-04-13same kind of change as the line aboveCVE-2025-9820same vendor as the line abovesame change as the line aboveDays to revision 77
2026-04-13same kind of change as the line aboveCVE-2025-9900same vendor as the line abovesame change as the line aboveDays to revision 202
2026-04-13same kind of change as the line aboveCVE-2025-11731same vendor as the line abovesame change as the line aboveDays to revision 182
2026-04-13same kind of change as the line aboveCVE-2025-13601same vendor as the line abovesame change as the line aboveDays to revision 138
2026-04-13same kind of change as the line aboveCVE-2025-14512same vendor as the line abovesame change as the line aboveDays to revision 123
2026-04-13same kind of change as the line aboveCVE-2025-14087same vendor as the line abovesame change as the line aboveDays to revision 124
1 more row in this change is not listed here. Open all 9 rows
2026-04-13Product addedCVE-2026-25204samsung.tv_appliancenot named as affected at publication, now names escargotDays to revision 0

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →