Every change, newest first
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Kind | Record or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together. | Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|---|
| Thu 23 Apr 2026· 16 record changes | |||||
| 2026-04-23 | CVSS base score changed | CVE-2025-49410 | whole record Patchstack | stated at publication 6.5, now states 10.0CVSS v3.1 · base scoreMediumCritical | Days to revision 246 |
| 2026-04-23 | CVSS base score changed | CVE-2025-49413 | whole record Patchstack | stated at publication 5.9, now states 7.1CVSS v3.1 · base scoreMediumHighOriginal value first replaced 2026-04-01; this value first seen 2026-04-23. | Days to revision 224 |
| 2026-04-23 | CVSS base score changed | CVE-2025-49426 | whole record Patchstack | stated at publication 4.3, now states 8.1CVSS v3.1 · base scoreMediumHighOriginal value first replaced 2026-04-01; this value first seen 2026-04-23. | Days to revision 224 |
| 2026-04-23 | CVSS base score changed | CVE-2025-49428 | whole record Patchstack | stated at publication 5.9, now states 7.5CVSS v3.1 · base scoreMediumHigh | Days to revision 246 |
| 2026-04-23 | CVSS base score changed | CVE-2025-49436 | whole record Patchstack | stated at publication 6.5, now states 8.1CVSS v3.1 · base scoreMediumHighOriginal value first replaced 2026-04-01; this value first seen 2026-04-23. | Days to revision 224 |
| 2026-04-23 | CVSS base score changed | CVE-2025-49438 | whole record Patchstack | stated at publication 7.2, now states 8.1CVSS v3.1 · base scoreHighHigh | Days to revision 246 |
| 2026-04-23 | CVSS base score changed | CVE-2025-49455 | whole record Patchstack | stated at publication 9.8, now states 9.3CVSS v3.1 · base scoreCriticalCriticalOriginal value first replaced 2026-04-01; this value first seen 2026-04-23. | Days to revision 295 |
| 2026-04-23 | CVSS base score changed | whole record Patchstack | stated at publication 5.9, now states 8.1CVSS v3.1 · base scoreMediumHighOriginal value first replaced 2026-04-01; this value first seen 2026-04-23. | Days to revision 224 | |
| 2026-04-23 | same kind of change as the line above | CVE-2025-49889 | same vendor as the line above | same change as the line aboveOriginal value first replaced 2026-04-01; this value first seen 2026-04-23. | Days to revision 224 |
| 2026-04-23 | same kind of change as the line above | CVE-2025-49892 | same vendor as the line above | same change as the line aboveOriginal value first replaced 2026-04-01; this value first seen 2026-04-23. | Days to revision 224 |
| 2026-04-23 | same kind of change as the line above | CVE-2025-49894 | same vendor as the line above | same change as the line aboveOriginal value first replaced 2026-04-01; this value first seen 2026-04-23. | Days to revision 224 |
| 2026-04-23 | CVSS base score changed | CVE-2025-49891 | whole record Patchstack | stated at publication 5.9, now states 8.5CVSS v3.1 · base scoreMediumHighOriginal value first replaced 2026-04-01; this value first seen 2026-04-23. | Days to revision 224 |
| 2026-04-23 | CVSS base score changed | CVE-2025-49895 | whole record Patchstack | stated at publication 8.8, now states 6.5CVSS v3.1 · base scoreHighMedium | Days to revision 251 |
| 2026-04-23 | CVSS base score changed | CVE-2025-49896 | whole record Patchstack | stated at publication 4.3, now states 5.3CVSS v3.1 · base scoreMediumMedium | Days to revision 246 |
| 2026-04-23 | CVSS base score changed | CVE-2025-49897 | whole record Patchstack | stated at publication 8.5, now states 8.8CVSS v3.1 · base scoreHighHigh | Days to revision 251 |
| 2026-04-23 | CVSS base score changed | CVE-2025-49898 | whole record Patchstack | stated at publication 5.9, now states 7.6CVSS v3.1 · base scoreMediumHigh | Days to revision 251 |
| 2026-04-23 | CVSS base score changed | CVE-2025-62138 | whole record Patchstack | stated at publication 5.3, now states 5.4CVSS v3.1 · base scoreMediumMediumOriginal value first replaced 2026-04-01; this value first seen 2026-04-23. | Days to revision 91 |
| Wed 22 Apr 2026· 19 record changes · 1 advisory change | |||||
| 2026-04-22 | Added to CISA KEV | CVE-2026-33825 | MicrosoftDefender CISA KEV | fix due 2026-05-06 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-22 | Product added | TPLink | not named as affected at publication, now names archer c20 v5 | Days to revision 76 to 280 | |
| 2026-04-22 | same kind of change as the line above | CVE-2025-15551 | same vendor as the line above | same change as the line above | Days to revision 76 |
| 2026-04-22 | same kind of change as the line above | CVE-2025-6982 | same vendor as the line above | same change as the line above | Days to revision 280 |
| 2026-04-22 | same kind of change as the line above | CVE-2026-0834 | same vendor as the line above | same change as the line above | Days to revision 91 |
| 2026-04-22 | Product added | CVE-2026-26171 | not named as affected at publication, now names powershell 7.5 and 1 more | Days to revision 8 | |
| 2026-04-22 | same kind of change as the line above | CVE-2026-26171 | same vendor as the line above | not named as affected at publication, now names powershell 7.5 | Days to revision 8 |
| 2026-04-22 | same kind of change as the line above | CVE-2026-26171 | same vendor as the line above | not named as affected at publication, now names powershell 7.6 | Days to revision 8 |
| 2026-04-22 | Product added | CVE-2026-33471 | GitHub_M | not named as affected at publication, now names nimiq-block | Days to revision 0 |
| 2026-04-22 | Product added | CVE-2026-22191 | VulnCheck | not named as affected at publication, now names sicuroweb (sicuro24) | Days to revision 41 |
| 2026-04-22 | Product added | VulnCheck | not named as affected at publication, now names snmp web pro | Days to revision 41 | |
| 2026-04-22 | same kind of change as the line above | CVE-2026-22192 | same vendor as the line above | same change as the line above | Days to revision 41 |
| 2026-04-22 | same kind of change as the line above | CVE-2026-22199 | same vendor as the line above | same change as the line above | Days to revision 41 |
| 2026-04-22 | Product added | not named as affected at publication, now names red hat insights proxy 1.5 | Days to revision 23 to 40 | ||
| 2026-04-22 | same kind of change as the line above | CVE-2026-4111 | same vendor as the line above | same change as the line above | Days to revision 40 |
| 2026-04-22 | same kind of change as the line above | CVE-2026-4424 | same vendor as the line above | same change as the line above | Days to revision 34 |
| 2026-04-22 | same kind of change as the line above | CVE-2026-5121 | same vendor as the line above | same change as the line above | Days to revision 23 |
| 2026-04-22 | Product added | CVE-2026-4111 | not named as affected at publication, now names red hat openshift container platform 4.18 | Days to revision 40 | |
| 2026-04-22 | Product added | not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update support | Days to revision 23 to 34 | ||
| 2026-04-22 | same kind of change as the line above | CVE-2026-4424 | same vendor as the line above | same change as the line above | Days to revision 34 |
| 2026-04-22 | same kind of change as the line above | CVE-2026-5121 | same vendor as the line above | same change as the line above | Days to revision 23 |
| 2026-04-22 | CVSS base score changed | CVE-2026-41171 | whole record GitHub_M | stated at publication 5.7, now states 7.3CVSS v4.0 · base scoreMediumHigh | Days to revision 0 |
| 2026-04-22 | CVSS base score changed | CVE-2026-0972 | whole record Fortra | stated at publication 7.3, now states 5.4CVSS v3.1 · base scoreHighMedium | Days to revision 1 |
| 2026-04-22 | Record state changed | CVE-2026-5358 | whole record glibc | stated at publication PUBLISHED, now states REJECTED | Days to revision 2 |
| 2026-04-22published 2026-02-19 | Package added to advisory | GHSA-4hfh-fch3-5q7pCVE-2026-27120 | moderate | not named as affected when the advisory was published, now names github.com/vapor/leaf-kit | Days to revision 62 |
| Tue 21 Apr 2026· 29 record changes | |||||
| 2026-04-21 | Ransomware use confirmed | CVE-2023-27351 | PaperCutNG/MF CISA KEV | stated at publication Unknown, now states Known | Days to revision 1 |
| 2026-04-21 | Ransomware use confirmed | CVE-2024-27199 | JetBrainsTeamCity CISA KEV | stated at publication Unknown, now states Known | Days to revision 1 |
| 2026-04-21 | Ransomware use confirmed | CVE-2023-21529 | MicrosoftExchange Server CISA KEV | stated at publication Unknown, now states Known | Days to revision 8 |
| 2026-04-21 | Ransomware use confirmed | CVE-2025-52691 | SmarterToolsSmarterMail CISA KEV | stated at publication Unknown, now states Known | Days to revision 85 |
| 2026-04-21 | Product added | CVE-2026-6443 | Wordfence | not named as affected at publication, now names album and image gallery plus lightbox and 20 more | Days to revision 5 |
| 2026-04-21 | same kind of change as the line above | CVE-2026-6443 | same vendor as the line above | not named as affected at publication, now names album and image gallery plus lightbox | Days to revision 5 |
| 2026-04-21 | same kind of change as the line above | CVE-2026-6443 | same vendor as the line above | not named as affected at publication, now names blog designer – post and widget | Days to revision 5 |
| 2026-04-21 | same kind of change as the line above | CVE-2026-6443 | same vendor as the line above | not named as affected at publication, now names countdown timer ultimate | Days to revision 5 |
| 2026-04-21 | same kind of change as the line above | CVE-2026-6443 | same vendor as the line above | not named as affected at publication, now names featured post creative | Days to revision 5 |
| 2026-04-21 | same kind of change as the line above | CVE-2026-6443 | same vendor as the line above | not named as affected at publication, now names meta slider and carousel with lightbox | Days to revision 5 |
| 2026-04-21 | same kind of change as the line above | CVE-2026-6443 | same vendor as the line above | not named as affected at publication, now names popup maker and popup anything – popup for opt-ins and lead generation conversions | Days to revision 5 |
| 2026-04-21 | same kind of change as the line above | CVE-2026-6443 | same vendor as the line above | not named as affected at publication, now names portfolio and projects | Days to revision 5 |
| 2026-04-21 | same kind of change as the line above | CVE-2026-6443 | same vendor as the line above | not named as affected at publication, now names post grid and filter ultimate | Days to revision 5 |
| 13 more rows in this change are not listed here. Open all 21 rows → | |||||
| 2026-04-21 | Product added | CVE-2026-32203 | not named as affected at publication, now names microsoft visual studio 2026 version 18.4 | Days to revision 7 | |
| 2026-04-21 | Product added | CVE-2026-5588 | bcorg | not named as affected at publication, now names bcpkix-fips | Days to revision 6 |
| 2026-04-21 | CVSS base score changed | CVE-2026-5598 | whole record bcorg | stated at publication 10.0, now states 8.9CVSS v4.0 · base scoreCriticalHigh | Days to revision 6 |
| 2026-04-21 | Record state changed | CVE-2026-39659 | whole record Patchstack | stated at publication PUBLISHED, now states REJECTED | Days to revision 13 |
| Mon 20 Apr 2026· 12 record changes | |||||
| 2026-04-20 | Added to CISA KEV | CVE-2026-20122 | CiscoCatalyst SD-WAN Manger CISA KEV | fix due 2026-04-23 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-20 | Added to CISA KEV | CiscoCatalyst SD-WAN Manager | fix due 2026-04-23 | Not applicable: Added to CISA KEV has no earlier value | |
| 2026-04-20 | same kind of change as the line above | CVE-2026-20133 | same vendor as the line above | same change as the line above | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-20 | same kind of change as the line above | CVE-2026-20128 | same vendor as the line above | same change as the line above | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-20 | Added to CISA KEV | CVE-2025-2749 | KenticoKentico Xperience CISA KEV | fix due 2026-05-04 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-20 | Added to CISA KEV | CVE-2023-27351 | PaperCutNG/MF CISA KEV | fix due 2026-05-04 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-20 | Added to CISA KEV | CVE-2025-48700 | SynacorZimbra Collaboration Suite (ZCS) CISA KEV | fix due 2026-04-23 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-20 | Added to CISA KEV | CVE-2025-32975 | QuestKACE Systems Management Appliance (SMA) CISA KEV | fix due 2026-05-04 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-20 | Added to CISA KEV | CVE-2024-27199 | JetBrainsTeamCity CISA KEV | fix due 2026-05-04 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-20 | Product added | not named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update support | Days to revision 21 to 32 | ||
| 2026-04-20 | same kind of change as the line above | CVE-2026-4424 | same vendor as the line above | same change as the line above | Days to revision 32 |
| 2026-04-20 | same kind of change as the line above | CVE-2026-5121 | same vendor as the line above | same change as the line above | Days to revision 21 |
| 2026-04-20 | CVSS base score changed | whole record INCIBE | stated at publication 9.1, now states 4.7CVSS v3.1 · base scoreCriticalMedium | Days to revision 872 | |
| 2026-04-20 | same kind of change as the line above | CVE-2023-5965 | same vendor as the line above | same change as the line above | Days to revision 872 |
| 2026-04-20 | same kind of change as the line above | CVE-2023-5966 | same vendor as the line above | same change as the line above | Days to revision 872 |
| Sat 18 Apr 2026· 5 advisory changes | |||||
| 2026-04-18published 2026-03-26 | Advisory severity changed | GHSA-mp66-rf4f-mhh8CVE-2026-35622 | whole advisorymoderate | stated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 22 |
| 2026-04-18published 2026-03-26 | Advisory severity changed | GHSA-xhq5-45pm-2gjrCVE-2026-35624 | whole advisorylow | stated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 22 |
| 2026-04-18published 2026-03-29 | Advisory severity changed | GHSA-52q4-3xjc-6778CVE-2026-35617 | whole advisorylow | stated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version. | Days to revision 19 |
| 2026-04-18published 2026-03-29 | Advisory severity changed | GHSA-h4jx-hjr3-fhgcCVE-2026-35645 | whole advisorymoderate | stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version. | Days to revision 19 |
| 2026-04-18published 2026-03-26 | Advisory severity changed | GHSA-7xr2-q9vf-x4r5CVE-2026-35632 | whole advisorymoderate | stated at publication HIGH, now states MODERATEA CVSS version was added; the existing vectors stayed the same. | Days to revision 22 |
| Fri 17 Apr 2026· 11 record changes · 2 advisory changes | |||||
| 2026-04-17 | Fix version moved | CVE-2026-3854 | githubenterprise server GitHub_P | stated at publication 3.14.24, now states 3.14.25Release branch starts at 3.14.0. | Days to revision 38 |
| 2026-04-17 | Fix version moved | CVE-2026-3854 | githubenterprise server GitHub_P | stated at publication 3.15.19, now states 3.15.20Release branch starts at 3.15.0. | Days to revision 38 |
| 2026-04-17 | Fix version moved | CVE-2026-3854 | githubenterprise server GitHub_P | stated at publication 3.16.15, now states 3.16.16Release branch starts at 3.16.0. | Days to revision 38 |
| 2026-04-17 | Fix version moved | CVE-2026-3854 | githubenterprise server GitHub_P | stated at publication 3.17.12, now states 3.17.13Release branch starts at 3.17.0. | Days to revision 38 |
| 2026-04-17 | Fix version moved | CVE-2026-3854 | githubenterprise server GitHub_P | stated at publication 3.18.6, now states 3.18.7Release branch starts at 3.18.0. | Days to revision 38 |
| 2026-04-17 | Fix version moved | CVE-2026-3854 | githubenterprise server GitHub_P | stated at publication 3.19.3, now states 3.19.4Release branch starts at 3.19.0. | Days to revision 38 |
| 2026-04-17 | Product added | hackerone | not named as affected at publication, now names backup and replication | Days to revision 36 | |
| 2026-04-17 | same kind of change as the line above | CVE-2026-21672 | same vendor as the line above | same change as the line above | Days to revision 36 |
| 2026-04-17 | same kind of change as the line above | CVE-2026-21708 | same vendor as the line above | same change as the line above | Days to revision 36 |
| 2026-04-17 | Product added | not named as affected at publication, now names red hat ai inference server 3.3 | Days to revision 35 to 813 | ||
| 2026-04-17 | same kind of change as the line above | CVE-2023-52356 | same vendor as the line above | same change as the line above | Days to revision 813 |
| 2026-04-17 | same kind of change as the line above | CVE-2025-14831 | same vendor as the line above | same change as the line above | Days to revision 67 |
| 2026-04-17 | same kind of change as the line above | CVE-2026-4111 | same vendor as the line above | same change as the line above | Days to revision 35 |
| 2026-04-17published 2022-05-14 | Package added to advisory | GHSA-6r5v-hp32-fjqwCVE-2015-0227 | moderate | not named as affected when the advisory was published, now names wss4j:wss4j | not dated |
| 2026-04-17published 2024-05-03 | Package added to advisory | GHSA-4h8f-2wvx-gg5wCVE-2024-34447 | moderate | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | Days to revision 714 |
| Thu 16 Apr 2026· 63 record changes · 6 advisory changes | |||||
| 2026-04-16 | Added to CISA KEV | CVE-2026-34197 | ApacheActiveMQ CISA KEV | fix due 2026-04-30 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-16 | Affected range extended | CVE-2026-5329 | rapid7velociraptor | stated at publication 0.76.1, now states 0.76.3Release branch starts at 0. | Days to revision 7 |
| 2026-04-16 | Product added | not named as affected at publication, now names red hat enterprise linux 8.2 advanced update support | Days to revision 18 to 28 | ||
| 2026-04-16 | same kind of change as the line above | CVE-2026-4424 | same vendor as the line above | same change as the line above | Days to revision 28 |
| 2026-04-16 | same kind of change as the line above | CVE-2026-5121 | same vendor as the line above | same change as the line above | Days to revision 18 |
| 2026-04-16 | Product added | CVE-2025-36579 | not named as affected at publication, now names inspiron 13 5320 and 53 more | Days to revision 0 | |
| 2026-04-16 | same kind of change as the line above | CVE-2025-36579 | same vendor as the line above | not named as affected at publication, now names inspiron 13 5320 | Days to revision 0 |
| 2026-04-16 | same kind of change as the line above | CVE-2025-36579 | same vendor as the line above | not named as affected at publication, now names inspiron 13 5330 | Days to revision 0 |
| 2026-04-16 | same kind of change as the line above | CVE-2025-36579 | same vendor as the line above | not named as affected at publication, now names inspiron 14 5420 | Days to revision 0 |
| 2026-04-16 | same kind of change as the line above | CVE-2025-36579 | same vendor as the line above | not named as affected at publication, now names inspiron 14 5430 | Days to revision 0 |
| 2026-04-16 | same kind of change as the line above | CVE-2025-36579 | same vendor as the line above | not named as affected at publication, now names inspiron 14 5440 | Days to revision 0 |
| 2026-04-16 | same kind of change as the line above | CVE-2025-36579 | same vendor as the line above | not named as affected at publication, now names inspiron 14 7420 2-in-1 | Days to revision 0 |
| 2026-04-16 | same kind of change as the line above | CVE-2025-36579 | same vendor as the line above | not named as affected at publication, now names inspiron 14 7430 2-in-1 | Days to revision 0 |
| 2026-04-16 | same kind of change as the line above | CVE-2025-36579 | same vendor as the line above | not named as affected at publication, now names inspiron 14 7440 2-in-1 | Days to revision 0 |
| 46 more rows in this change are not listed here. Open all 54 rows → | |||||
| 2026-04-16 | Product added | not named as affected at publication, now names red hat openshift container platform 4.13 | Days to revision 34 to 149 | ||
| 2026-04-16 | same kind of change as the line above | CVE-2025-61662 | same vendor as the line above | same change as the line above | Days to revision 149 |
| 2026-04-16 | same kind of change as the line above | CVE-2026-4111 | same vendor as the line above | same change as the line above | Days to revision 34 |
| 2026-04-16 | Product added | CVE-2025-61662 | not named as affected at publication, now names red hat openshift container platform 4.19 | Days to revision 149 | |
| 2026-04-16 | CVSS base score changed | CVE-2025-62718 | whole record GitHub_M | stated at publication 9.3, now states 6.3CVSS v4.0 · base scoreCriticalMedium | Days to revision 7 |
| 2026-04-16 | CVSS base score changed | CVE-2026-40175 | whole record GitHub_M | stated at publication 10.0, now states 4.8CVSS v3.1 · base scoreCriticalMedium | Days to revision 6 |
| 2026-04-16published 2022-04-22 | Package added to advisory | GHSA-4qqf-hmv6-r6whCVE-2011-2487 | moderate | not named as affected when the advisory was published, now names wss4j:wss4j | not dated |
| 2026-04-16published 2025-07-21 | Package added to advisory | GHSA-9342-92gg-6v29CVE-2025-7962 | moderate | not named as affected when the advisory was published, now names com.sun.mail:jakarta.mail | Days to revision 269 |
| 2026-04-16published 2024-10-04 | Package added to advisory | GHSA-wwcp-26wc-3fxmCVE-2024-47855 | moderate | not named as affected when the advisory was published, now names net.sf.json-lib:json-lib | Days to revision 560 |
| 2026-04-16published 2022-05-13 | Package added to advisory | GHSA-jwwr-fjgh-cv2xCVE-2014-3004 | moderate | not named as affected when the advisory was published, now names castor:castor | not dated |
| 2026-04-16published 2026-04-09 to 2026-04-10 | Advisory severity changed | whole advisorymoderate | stated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 6 to 7 | |
| 2026-04-16published 2026-04-10 | same kind of change as the line above | GHSA-fvcv-3m26-pcqxCVE-2026-40175 | same package and registry as the line abovemoderate | same change as the line above | Days to revision 6 |
| 2026-04-16published 2026-04-09 | same kind of change as the line above | GHSA-3p68-rc4w-qgx5CVE-2025-62718 | same package and registry as the line abovemoderate | same change as the line above | Days to revision 7 |
| Wed 15 Apr 2026· 5 record changes · 6 advisory changes | |||||
| 2026-04-15 | CVSS base score changed | CVE-2026-5588 | whole record bcorg | stated at publication 10.0, now states 6.3CVSS v4.0 · base scoreCriticalMedium | Days to revision 0 |
| 2026-04-15 | CVSS base score changed | CVE-2026-3505 | whole record bcorg | stated at publication 10.0, now states 8.7CVSS v4.0 · base scoreCriticalHigh | Days to revision 0 |
| 2026-04-15 | CVSS base score changed | CVE-2025-14813 | whole record bcorg | stated at publication 9.4, now states 9.3CVSS v4.0 · base scoreCriticalCritical | Days to revision 0 |
| 2026-04-15 | CVSS base score changed | CVE-2026-0636 | whole record bcorg | stated at publication 10.0, now states 5.5CVSS v4.0 · base scoreCriticalMedium | Days to revision 0 |
| 2026-04-15 | Record state changed | CVE-2026-32187 | whole record microsoft | stated at publication PUBLISHED, now states REJECTED | Days to revision 19 |
| 2026-04-15published 2026-04-09 | Advisory fix version moved | GHSA-h468-7pvh-8vr8CVE-2026-29146 | mavenorg.apache.tomcat:tomcat high | stated at publication 11.0.19, now states 11.0.20 | Days to revision 6 |
| 2026-04-15published 2026-04-09 | Package added to advisory | GHSA-8mc5-53m5-3qj2CVE-2026-32990 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Days to revision 6 |
| 2026-04-15published 2026-04-09 | Package added to advisory | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-tribes | Days to revision 6 | |
| 2026-04-15published 2026-04-09 | same kind of change as the line above | GHSA-69r9-qgr7-g2wjCVE-2026-34486 | same package registry as the line abovehigh | same change as the line above | Days to revision 6 |
| 2026-04-15published 2026-04-09 | same kind of change as the line above | GHSA-h468-7pvh-8vr8CVE-2026-29146 | same package registry as the line abovehigh | same change as the line above | Days to revision 6 |
| 2026-04-15published 2026-04-14 | Advisory severity changed | whole advisoryhigh | stated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 1 | |
| 2026-04-15published 2026-04-14 | same kind of change as the line above | GHSA-37gx-xxp4-5rgxCVE-2026-33116 | same package and registry as the line abovehigh | same change as the line above | Days to revision 1 |
| 2026-04-15published 2026-04-14 | same kind of change as the line above | GHSA-w3x6-4m5h-cxqfCVE-2026-26171 | same package and registry as the line abovehigh | same change as the line above | Days to revision 1 |
| Tue 14 Apr 2026· 44 record changes · 2 advisory changes | |||||
| 2026-04-14 | Added to CISA KEV | CVE-2009-0238 | MicrosoftOffice CISA KEV | fix due 2026-04-28 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-14 | Added to CISA KEV | CVE-2026-32201 | MicrosoftSharePoint Server CISA KEV | fix due 2026-04-28 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-14 | Product added | CVE-2026-22719 | not named as affected at publication, now names vmware cloud foundation operations | Days to revision 48 | |
| 2026-04-142 commits | Product added | not named as affected at publication, now names red hat hardened imagesBranches and original-value intervals are stated on each row. | Days to revision 278 to 306 | ||
| 2026-04-14 | same kind of change as the line above | CVE-2025-32988 | same vendor as the line above | same change as the line above | Days to revision 278 |
| 2026-04-14 | same kind of change as the line above | CVE-2025-32989 | same vendor as the line above | same change as the line above | Days to revision 278 |
| 2026-04-14 | same kind of change as the line above | CVE-2025-32990 | same vendor as the line above | same change as the line above | Days to revision 278 |
| 2026-04-14 | same kind of change as the line above | CVE-2025-6170 | same vendor as the line above | same change as the line above | Days to revision 302 |
| 2026-04-14 | same kind of change as the line above | CVE-2025-7424 | same vendor as the line above | same change as the line above | Days to revision 278 |
| 2026-04-14 | same kind of change as the line above | CVE-2025-7425 | same vendor as the line above | same change as the line above | Days to revision 278 |
| 2026-04-14 | same kind of change as the line above | CVE-2025-49794 | same vendor as the line above | same change as the line above | Days to revision 302 |
| 2026-04-14 | same kind of change as the line above | CVE-2025-49795 | same vendor as the line above | same change as the line above | Days to revision 302 |
| 2 more rows in this change are not listed here. Open all 10 rows → | |||||
| 2026-04-14 | Product added | CVE-2023-44373 | not named as affected at publication, now names scalance w721-1 rj45 and 27 more | Days to revision 882 | |
| 2026-04-14 | same kind of change as the line above | CVE-2023-44373 | same vendor as the line above | not named as affected at publication, now names scalance w721-1 rj45 | Days to revision 882 |
| 2026-04-14 | same kind of change as the line above | CVE-2023-44373 | same vendor as the line above | not named as affected at publication, now names scalance w722-1 rj45 | Days to revision 882 |
| 2026-04-14 | same kind of change as the line above | CVE-2023-44373 | same vendor as the line above | not named as affected at publication, now names scalance w734-1 rj45 | Days to revision 882 |
| 2026-04-14 | same kind of change as the line above | CVE-2023-44373 | same vendor as the line above | not named as affected at publication, now names scalance w734-1 rj45 (usa) | Days to revision 882 |
| 2026-04-14 | same kind of change as the line above | CVE-2023-44373 | same vendor as the line above | not named as affected at publication, now names scalance w738-1 m12 | Days to revision 882 |
| 2026-04-14 | same kind of change as the line above | CVE-2023-44373 | same vendor as the line above | not named as affected at publication, now names scalance w748-1 m12 | Days to revision 882 |
| 2026-04-14 | same kind of change as the line above | CVE-2023-44373 | same vendor as the line above | not named as affected at publication, now names scalance w748-1 rj45 | Days to revision 882 |
| 2026-04-14 | same kind of change as the line above | CVE-2023-44373 | same vendor as the line above | not named as affected at publication, now names scalance w761-1 rj45 | Days to revision 882 |
| 20 more rows in this change are not listed here. Open all 28 rows → | |||||
| 2026-04-14 | Product added | CVE-2025-40571 | not named as affected at publication, now names mendix oidc sso v4.2 (mendix 10 compatible) and 1 more | Days to revision 336 | |
| 2026-04-14 | same kind of change as the line above | CVE-2025-40571 | same vendor as the line above | not named as affected at publication, now names mendix oidc sso v4.2 (mendix 10 compatible) | Days to revision 336 |
| 2026-04-14 | same kind of change as the line above | CVE-2025-40571 | same vendor as the line above | not named as affected at publication, now names mendix oidc sso v4.3 (mendix 10 compatible) | Days to revision 336 |
| 2026-04-14 | CVSS base score changed | CVE-2026-32146 | whole record EEF | stated at publication 6.2, now states 8.3CVSS v4.0 · base scoreMediumHigh | Days to revision 3 |
| 2026-04-14published 2026-03-30 to 2026-04-08 | Advisory withdrawn | whole advisory2 bands | withdrawn 2026-04-14 | Days to revision 5 to 15 | |
| 2026-04-14published 2026-03-30 | same kind of change as the line above | GHSA-qqrv-2hch-83q4 | same package and registry as the line abovemoderate | withdrawn 2026-04-14 | Days to revision 15 |
| 2026-04-14published 2026-04-08 | same kind of change as the line above | GHSA-gc59-r5jq-98qw | same package and registry as the line abovehigh | withdrawn 2026-04-14 | Days to revision 5 |
| Mon 13 Apr 2026· 25 record changes | |||||
| 2026-04-13 | Added to CISA KEV | CVE-2012-1854 | MicrosoftVisual Basic for Applications (VBA) CISA KEV | fix due 2026-04-27 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-13 | Added to CISA KEV | MicrosoftWindows | fix due 2026-04-27 | Not applicable: Added to CISA KEV has no earlier value | |
| 2026-04-13 | same kind of change as the line above | CVE-2025-60710 | same vendor as the line above | same change as the line above | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-13 | same kind of change as the line above | CVE-2023-36424 | same vendor as the line above | same change as the line above | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-13 | Added to CISA KEV | CVE-2023-21529 | MicrosoftExchange Server CISA KEV | fix due 2026-04-27 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-13 | Added to CISA KEV | CVE-2020-9715 | AdobeAcrobat CISA KEV | fix due 2026-04-27 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-13 | Added to CISA KEV | CVE-2026-21643 | FortinetFortiClient EMS CISA KEV | fix due 2026-04-16 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-13 | Added to CISA KEV | CVE-2026-34621 | AdobeAcrobat and Reader CISA KEV | fix due 2026-04-27 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-04-13 | Product added | CVE-2024-1573 | Mitsubishi | not named as affected at publication, now names analytix and 3 more | Days to revision 649 |
| 2026-04-13 | same kind of change as the line above | CVE-2024-1573 | same vendor as the line above | not named as affected at publication, now names analytix | Days to revision 649 |
| 2026-04-13 | same kind of change as the line above | CVE-2024-1573 | same vendor as the line above | not named as affected at publication, now names hyper historian | Days to revision 649 |
| 2026-04-13 | same kind of change as the line above | CVE-2024-1573 | same vendor as the line above | not named as affected at publication, now names iotworx | Days to revision 649 |
| 2026-04-13 | same kind of change as the line above | CVE-2024-1573 | same vendor as the line above | not named as affected at publication, now names mobilehmi | Days to revision 649 |
| 2026-04-13 | Product added | CVE-2024-1573 | Mitsubishi | not named as affected at publication, now names analytix and 3 more | Days to revision 649 |
| 2026-04-13 | same kind of change as the line above | CVE-2024-1573 | same vendor as the line above | not named as affected at publication, now names analytix | Days to revision 649 |
| 2026-04-13 | same kind of change as the line above | CVE-2024-1573 | same vendor as the line above | not named as affected at publication, now names hyper historian | Days to revision 649 |
| 2026-04-13 | same kind of change as the line above | CVE-2024-1573 | same vendor as the line above | not named as affected at publication, now names iotworx | Days to revision 649 |
| 2026-04-13 | same kind of change as the line above | CVE-2024-1573 | same vendor as the line above | not named as affected at publication, now names mobilehmi | Days to revision 649 |
| 2026-04-134 commits | Product added | not named as affected at publication, now names red hat hardened imagesBranches and original-value intervals are stated on each row. | Days to revision 77 to 220 | ||
| 2026-04-13 | same kind of change as the line above | CVE-2025-10911 | same vendor as the line above | same change as the line above | Days to revision 200 |
| 2026-04-13 | same kind of change as the line above | CVE-2025-9566 | same vendor as the line above | same change as the line above | Days to revision 220 |
| 2026-04-13 | same kind of change as the line above | CVE-2025-9820 | same vendor as the line above | same change as the line above | Days to revision 77 |
| 2026-04-13 | same kind of change as the line above | CVE-2025-9900 | same vendor as the line above | same change as the line above | Days to revision 202 |
| 2026-04-13 | same kind of change as the line above | CVE-2025-11731 | same vendor as the line above | same change as the line above | Days to revision 182 |
| 2026-04-13 | same kind of change as the line above | CVE-2025-13601 | same vendor as the line above | same change as the line above | Days to revision 138 |
| 2026-04-13 | same kind of change as the line above | CVE-2025-14512 | same vendor as the line above | same change as the line above | Days to revision 123 |
| 2026-04-13 | same kind of change as the line above | CVE-2025-14087 | same vendor as the line above | same change as the line above | Days to revision 124 |
| 1 more row in this change is not listed here. Open all 9 rows → | |||||
| 2026-04-13 | Product added | CVE-2026-25204 | samsung.tv_appliance | not named as affected at publication, now names escargot | Days to revision 0 |
Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.
Data sources and quality
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →