Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

11,999 record changes · 5,026 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
Counted changes, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Wed 5 Aug 2026· 11 changes
2026-08-05CVSS base score changedCVE-2026-71211
whole record
TuranSec
stated at publication 7.7, now states 7.1CVSS v3.1 · base scoreHighHighTime to revision 0 days
2026-08-05CVSS base score changedCVE-2026-71213
whole record
TuranSec
stated at publication 8.1, now states 9.1CVSS v3.1 · base scoreHighCriticalTime to revision 0 days
2026-08-05CVSS base score changedCVE-2026-71235
whole record
TuranSec
stated at publication 9.9, now states 8.8CVSS v3.1 · base scoreCriticalHighTime to revision 0 days
2026-08-05CVSS base score changedCVE-2026-71236
whole record
TuranSec
stated at publication 8.0, now states 8.7CVSS v3.1 · base scoreHighHighTime to revision 0 days
2026-08-05CVSS base score changedCVE-2026-71239
whole record
TuranSec
stated at publication 8.8, now states 8.1CVSS v3.1 · base scoreHighHighTime to revision 0 days
2026-08-05CVSS base score changedCVE-2026-71240
whole record
TuranSec
stated at publication 5.4, now states 4.3CVSS v3.1 · base scoreMediumMediumTime to revision 0 days
2026-08-05CVSS base score changedCVE-2026-71244
whole record
TuranSec
stated at publication 7.1, now states 6.5CVSS v3.1 · base scoreHighMediumTime to revision 0 days
2026-08-05CVSS base score changedCVE-2026-71246
whole record
TuranSec
stated at publication 5.7, now states 4.3CVSS v3.1 · base scoreMediumMediumTime to revision 0 days
2026-08-05CVSS base score changedCVE-2026-71254
whole record
TuranSec
stated at publication 9.1, now states 9.8CVSS v3.1 · base scoreCriticalCriticalTime to revision 0 days
2026-08-05CVSS base score changedCVE-2026-71255
whole record
TuranSec
stated at publication 8.2, now states 8.6CVSS v3.1 · base scoreHighHighTime to revision 0 days
2026-08-05CVSS base score changedCVE-2026-71256
whole record
TuranSec
stated at publication 8.1, now states 9.8CVSS v3.1 · base scoreHighCriticalTime to revision 0 days
Tue 4 Aug 2026· 37 changes
2026-08-04Added to CISA KEVCVE-2026-18556
N-ableN-central
CISA KEV
fix due 2026-08-07Duration unknown
2026-08-04Added to CISA KEVCVE-2026-34486
ApacheTomcat
CISA KEV
fix due 2026-08-07Duration unknown
2026-08-04Added to CISA KEVCVE-2026-9198
IBMLangflow
CISA KEV
fix due 2026-08-07Duration unknown
2026-08-04Ransomware use confirmedCVE-2025-26399
SolarWindsWeb Help Desk
CISA KEV
stated at publication Unknown, now states KnownTime to revision 148 days
2026-08-048 commitsProduct added24 rows, one per record and productnot named as affected at publication, now names red hat enterprise linux 6 extended lifecycle support - extension and 12 moreBranches and original-value intervals are stated on each row.Time to revision 4 to 61 days
2026-08-04same kind of change as the line aboveCVE-2026-50256same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 6 extended lifecycle support - extensionTime to revision 61 days
2026-08-04same kind of change as the line aboveCVE-2026-50257same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 6 extended lifecycle support - extensionTime to revision 61 days
2026-08-04same kind of change as the line aboveCVE-2026-50258same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 6 extended lifecycle support - extensionTime to revision 61 days
2026-08-04same kind of change as the line aboveCVE-2026-50259same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 6 extended lifecycle support - extensionTime to revision 61 days
2026-08-04same kind of change as the line aboveCVE-2026-50260same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 6 extended lifecycle support - extensionTime to revision 61 days
2026-08-04same kind of change as the line aboveCVE-2026-50261same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 6 extended lifecycle support - extensionTime to revision 61 days
2026-08-04same kind of change as the line aboveCVE-2026-50262same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 6 extended lifecycle support - extensionTime to revision 61 days
2026-08-04same kind of change as the line aboveCVE-2026-50263same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 6 extended lifecycle support - extensionTime to revision 61 days
16 more rows in this change are not listed here. Open all 24 rows
2026-08-04Product addedCVE-2026-40181GitHub_Mnot named as affected at publication, now names @remix-run/routerTime to revision 63 days
2026-08-04Product addedCVE-2026-0651TPLinknot named as affected at publication, now names tapo c211 v2Time to revision 175 days
2026-08-04CVSS base score changedCVE-2025-61813
whole record
adobe
stated at publication 8.2, now states 7.4CVSS v3.1 · base scoreHighHighTime to revision 238 days
2026-08-04CVSS base score changedCVE-2026-47996
whole record
adobe
stated at publication 7.6, now states 6.8CVSS v3.1 · base scoreHighMediumTime to revision 21 days
2026-08-04CVSS base score changedCVE-2026-48322
whole record
adobe
stated at publication 9.6, now states 9.9CVSS v3.1 · base scoreCriticalCriticalTime to revision 21 days
2026-08-04Record state changedCVE-2026-13325
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDTime to revision 39 days
2026-08-04published 2026-07-28Advisory fix version movedGHSA-6wcc-39rp-hh9pCVE-2026-54658
npm@hypequery/clickhouse
critical
stated at publication 2.0.2, now states 2.5.1Time to revision 7 days
2026-08-04published 2026-06-03Package added to advisoryGHSA-2j2x-hqr9-3h42CVE-2026-40181moderatenot named as affected when the advisory was published, now names @remix-run/routerTime to revision 62 days
2026-08-04published 2026-07-21Package added to advisoryGHSA-w5pg-649r-p6ggCVE-2026-58439highnot named as affected when the advisory was published, now names code.gitea.io/giteaTime to revision 13 days
Mon 3 Aug 2026· 9 changes
2026-08-03Added to CISA KEVCVE-2026-18577
N-ableN-central
CISA KEV
fix due 2026-08-06Duration unknown
2026-08-03Ransomware use confirmed
SonicWallSMA1000 Appliances
stated at publication Unknown, now states KnownTime to revision 20 days
2026-08-03same kind of change as the line aboveCVE-2026-15409same vendor as the line abovesame change as the line aboveTime to revision 20 days
2026-08-03same kind of change as the line aboveCVE-2026-15410same vendor as the line abovesame change as the line aboveTime to revision 20 days
2026-08-03Product addedCVE-2023-52355not named as affected at publication, now names red hat enterprise linux 10.0 extended update supportTime to revision 921 days
2026-08-032 commitsProduct addedCVE-2026-53705not named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update support and 1 moreBranches and original-value intervals are stated on each row.Time to revision 49 days
2026-08-03same kind of change as the line aboveCVE-2026-53705same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportTime to revision 49 days
2026-08-03same kind of change as the line aboveCVE-2026-53705same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportTime to revision 49 days
2026-08-03CVSS base score changedCVE-2026-47296
whole record
microsoft
stated at publication 7.8, now states 7.5CVSS v3.1 · base scoreHighHighTime to revision 20 days
2026-08-03CVSS base score changedCVE-2026-55002
whole record
microsoft
stated at publication 7.8, now states 8.8CVSS v3.1 · base scoreHighHighTime to revision 20 days
2026-08-03Record state changedCVE-2026-13151
whole record
GitLab
stated at publication PUBLISHED, now states REJECTEDTime to revision 26 days
Sun 2 Aug 2026· 4 changes
2026-08-02Affected range extendedCVE-2026-5084
aspeerwebdyne::session
CPANSec
stated at publication 2.075, now states 3.003_704Release branch starts at 0.Time to revision 83 days
2026-08-02Product addedCVE-2026-10840not named as affected at publication, now names red hat openshift builds 1.7.3Time to revision 59 days
2026-08-02Product addedCVE-2026-4878not named as affected at publication, now names red hat openshift distributed tracing 3.9.2Time to revision 115 days
2026-08-02Product addedCVE-2026-16242not named as affected at publication, now names multicluster engine for kubernetes 2.1Time to revision 13 days
Sat 1 Aug 2026· 1 change
2026-08-01Product addedCVE-2024-21536
vendor not named
snyk
not named as affected at publication, now names org.webjars.npm:http-proxy-middlewareTime to revision 651 days
Fri 31 Jul 2026· 61 changes
2026-07-31Product addedCVE-2026-0631TPLinknot named as affected at publication, now names archer axe75 v1Time to revision 179 days
2026-07-313 commitsProduct added6 rows, one per record and productnot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update support and 1 moreBranches and original-value intervals are stated on each row.Time to revision 49 to 66 days
2026-07-31same kind of change as the line aboveCVE-2026-48864same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportTime to revision 66 days
2026-07-31same kind of change as the line aboveCVE-2026-54228same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportTime to revision 49 days
2026-07-31same kind of change as the line aboveCVE-2026-54228same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportTime to revision 49 days
2026-07-31same kind of change as the line aboveCVE-2026-54229same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportTime to revision 49 days
2026-07-31same kind of change as the line aboveCVE-2026-54229same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportTime to revision 49 days
2026-07-31same kind of change as the line aboveCVE-2026-48864same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportTime to revision 66 days
2026-07-312 commitsProduct addedredhatnot named as affected at publication, now names gimpBranches and original-value intervals are stated on each row.Time to revision 4 days
2026-07-31same kind of change as the line aboveCVE-2026-66757same vendor as the line abovesame change as the line aboveTime to revision 4 days
2026-07-31same kind of change as the line aboveCVE-2026-66758same vendor as the line abovesame change as the line aboveTime to revision 4 days
2026-07-31same kind of change as the line aboveCVE-2026-66759same vendor as the line abovesame change as the line aboveTime to revision 4 days
2026-07-31Product addedCVE-2026-66420VulnChecknot named as affected at publication, now names meshcentralTime to revision 1 days
2026-07-31Product addedCVE-2026-16843not named as affected at publication, now names ds-3wg105g-si and 3 moreTime to revision 0 days
2026-07-31same kind of change as the line aboveCVE-2026-16843same vendor as the line abovenot named as affected at publication, now names ds-3wg105g-siTime to revision 0 days
2026-07-31same kind of change as the line aboveCVE-2026-16843same vendor as the line abovenot named as affected at publication, now names ds-3wg105gp-siTime to revision 0 days
2026-07-31same kind of change as the line aboveCVE-2026-16843same vendor as the line abovenot named as affected at publication, now names ds-3wg210gp-siTime to revision 0 days
2026-07-31same kind of change as the line aboveCVE-2026-16843same vendor as the line abovenot named as affected at publication, now names ds-3wg507g-siTime to revision 0 days
2026-07-31Product addedCSAnot named as affected at publication, now names tbcTime to revision 0 days
2026-07-31same kind of change as the line aboveCVE-2026-43829same vendor as the line abovesame change as the line aboveTime to revision 0 days
2026-07-31same kind of change as the line aboveCVE-2026-43830same vendor as the line abovesame change as the line aboveTime to revision 0 days
2026-07-31same kind of change as the line aboveCVE-2026-43831same vendor as the line abovesame change as the line aboveTime to revision 0 days
2026-07-31same kind of change as the line aboveCVE-2026-43832same vendor as the line abovesame change as the line aboveTime to revision 0 days
2026-07-31same kind of change as the line aboveCVE-2026-43833same vendor as the line abovesame change as the line aboveTime to revision 0 days
2026-07-31Record state changedCVE-2026-6552
whole record
GitLab
stated at publication PUBLISHED, now states REJECTEDTime to revision 50 days
2026-07-31Record state changed
whole record
mitre
stated at publication PUBLISHED, now states REJECTEDTime to revision 2 to 5 days
2026-07-31same kind of change as the line aboveCVE-2026-51235same vendor as the line abovesame change as the line aboveTime to revision 5 days
2026-07-31same kind of change as the line aboveCVE-2026-51244same vendor as the line abovesame change as the line aboveTime to revision 5 days
2026-07-31same kind of change as the line aboveCVE-2026-51251same vendor as the line abovesame change as the line aboveTime to revision 4 days
2026-07-31same kind of change as the line aboveCVE-2026-51252same vendor as the line abovesame change as the line aboveTime to revision 4 days
2026-07-31same kind of change as the line aboveCVE-2026-51254same vendor as the line abovesame change as the line aboveTime to revision 4 days
2026-07-31same kind of change as the line aboveCVE-2026-51259same vendor as the line abovesame change as the line aboveTime to revision 4 days
2026-07-31same kind of change as the line aboveCVE-2026-51260same vendor as the line abovesame change as the line aboveTime to revision 4 days
2026-07-31same kind of change as the line aboveCVE-2026-51261same vendor as the line abovesame change as the line aboveTime to revision 4 days
24 more rows in this change are not listed here. Open all 32 rows
2026-07-31Record state changed
whole record
CSA
stated at publication PUBLISHED, now states REJECTEDTime to revision 0 days
2026-07-31same kind of change as the line aboveCVE-2026-6889same vendor as the line abovesame change as the line aboveTime to revision 0 days
2026-07-31same kind of change as the line aboveCVE-2026-6890same vendor as the line abovesame change as the line aboveTime to revision 0 days
2026-07-31published 2026-04-07Advisory fix version movedGHSA-89gg-p5r5-q6r4
pypimonai
high
stated at publication 1.5.2, now states 1.6.0Time to revision 115 days
2026-07-31published 2026-07-21Package added to advisoryGHSA-m4p7-r5rc-7g4jCVE-2026-59884highnot named as affected when the advisory was published, now names pyasn1Time to revision 10 days
2026-07-31published 2026-06-16Advisory severity changedGHSA-8xpq-cjcf-3wh9CVE-2026-49401whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 45 days
2026-07-31published 2023-08-29 to 2026-06-03Advisory withdrawnwhole advisorymoderatewithdrawn 2026-07-31Time to revision 58 to 1,067 days
2026-07-31published 2023-08-29same kind of change as the line aboveGHSA-vmf9-6pcv-xr87CVE-2023-39522same package and registry as the line abovemoderatewithdrawn 2026-07-31Time to revision 1,067 days
2026-07-31published 2026-06-03same kind of change as the line aboveGHSA-v42x-x7jp-845hCVE-2026-6657same package and registry as the line abovemoderatewithdrawn 2026-07-31Time to revision 58 days
2026-07-31published 2026-06-02same kind of change as the line aboveGHSA-gf7q-q4j7-hp7cCVE-2026-5422same package and registry as the line abovemoderatewithdrawn 2026-07-31Time to revision 59 days
Thu 30 Jul 2026· 7 changes
2026-07-30Product addedCVE-2026-16242not named as affected at publication, now names multicluster engine for kubernetes 2.17Time to revision 10 days
2026-07-30Record state changed
whole record
twcert
stated at publication PUBLISHED, now states REJECTEDTime to revision 195 days
2026-07-30same kind of change as the line aboveCVE-2026-1018same vendor as the line abovesame change as the line aboveTime to revision 195 days
2026-07-30same kind of change as the line aboveCVE-2026-1019same vendor as the line abovesame change as the line aboveTime to revision 195 days
2026-07-30same kind of change as the line aboveCVE-2026-1020same vendor as the line abovesame change as the line aboveTime to revision 195 days
2026-07-30same kind of change as the line aboveCVE-2026-1021same vendor as the line abovesame change as the line aboveTime to revision 195 days
2026-07-30published 2025-05-13Package added to advisoryGHSA-qqcr-9jfc-35c4highnot named as affected when the advisory was published, now names oxid-esales/oxideshop-metapackage-ce and 1 moreTime to revision 443 days
2026-07-30published 2025-05-13same kind of change as the line aboveGHSA-qqcr-9jfc-35c4CVE-2024-56526same package registry as the line abovehighnot named as affected when the advisory was published, now names oxid-esales/oxideshop-metapackage-ceTime to revision 443 days
2026-07-30published 2025-05-13same kind of change as the line aboveGHSA-qqcr-9jfc-35c4CVE-2024-56526same package registry as the line abovehighnot named as affected when the advisory was published, now names oxid-esales/smarty-componentTime to revision 443 days
Wed 29 Jul 2026· 11 changes
2026-07-29Added to CISA KEVCVE-2026-20316
CiscoSecure Firewall Management Center (FMC)
CISA KEV
fix due 2026-08-01Duration unknown
2026-07-29Affected range extendedCVE-2024-4944
watchguardmobile vpn with ssl client
stated at publication 12.10, now states 12.10.4Release branch starts at 0.Time to revision 751 days
2026-07-29Product addedCVE-2026-11541not named as affected at publication, now names cics transaction gateway for multiplatformsTime to revision 29 days
2026-07-293 commitsProduct addedCVE-2026-16242not named as affected at publication, now names multicluster engine for kubernetes 2.11 and 3 moreBranches and original-value intervals are stated on each row.Time to revision 9 days
2026-07-29same kind of change as the line aboveCVE-2026-16242same vendor as the line abovenot named as affected at publication, now names multicluster engine for kubernetes 2.11Time to revision 9 days
2026-07-29same kind of change as the line aboveCVE-2026-16242same vendor as the line abovenot named as affected at publication, now names multicluster engine for kubernetes 2.6Time to revision 9 days
2026-07-29same kind of change as the line aboveCVE-2026-16242same vendor as the line abovenot named as affected at publication, now names multicluster engine for kubernetes 2.9Time to revision 9 days
2026-07-29same kind of change as the line aboveCVE-2026-16242same vendor as the line abovenot named as affected at publication, now names multicluster engine for kubernetes 2.8Time to revision 9 days
2026-07-29Product addedCVE-2025-12799not named as affected at publication, now names red hat jboss enterprise application platform 8.1.7.gaTime to revision 22 days
2026-07-29Product addedCVE-2024-21537
vendor not named
snyk
not named as affected at publication, now names org.webjars.npm:lilconfigTime to revision 636 days
2026-07-29CVSS base score changedCVE-2025-4318
whole record
AMZN
stated at publication 9.5, now states 9.0CVSS v4.0 · base scoreCriticalCriticalTime to revision 450 days
2026-07-29Record state changedCVE-2026-62389
whole record
VulnCheck
stated at publication PUBLISHED, now states REJECTEDTime to revision 14 days
Tue 28 Jul 2026· 39 changes
2026-07-28Fix version moved
microsoftmicrosoft exchange server 2016 cumulative update 23
stated at publication 15.01.2507.069, now states 15.01.2507.071Release branch starts at 15.01.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45500same vendor as the line abovesame change as the line aboveRelease branch starts at 15.01.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45501same vendor as the line abovesame change as the line aboveRelease branch starts at 15.01.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45502same vendor as the line abovesame change as the line aboveRelease branch starts at 15.01.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45503same vendor as the line abovesame change as the line aboveRelease branch starts at 15.01.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45504same vendor as the line abovesame change as the line aboveRelease branch starts at 15.01.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45583same vendor as the line abovesame change as the line aboveRelease branch starts at 15.01.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-47631same vendor as the line abovesame change as the line aboveRelease branch starts at 15.01.0.0.Time to revision 49 days
2026-07-28Fix version moved
microsoftmicrosoft exchange server 2019 cumulative update 14
stated at publication 15.02.1544.041, now states 15.02.1544.043Release branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45500same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45501same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45502same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45503same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45504same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45583same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-47631same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28Fix version moved
microsoftmicrosoft exchange server 2019 cumulative update 15
stated at publication 15.02.1748.046, now states 15.02.1748.048Release branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45500same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45501same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45502same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45503same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45504same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45583same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-47631same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28Fix version moved
microsoftmicrosoft exchange server subscription edition rtm
stated at publication 15.02.2562.043, now states 15.02.2562.045Release branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45500same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45501same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45502same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45503same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45504same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-45583same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28same kind of change as the line aboveCVE-2026-47631same vendor as the line abovesame change as the line aboveRelease branch starts at 15.02.0.0.Time to revision 49 days
2026-07-28Affected range extendedCVE-2026-49779
addifytax exempt for woocommerce
Patchstack
stated at publication 1.9.3, now states 1.9.5Release branch starts at 0.Time to revision 26 days
2026-07-28Product addedCVE-2026-16313not named as affected at publication, now names red hat openshift container platform 4Time to revision 0 days
2026-07-28Product addedCVE-2026-12505not named as affected at publication, now names red hat openshift container platform 4.22Time to revision 41 days
2026-07-28Product addednot named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportTime to revision 43 days
2026-07-28same kind of change as the line aboveCVE-2026-52720same vendor as the line abovesame change as the line aboveTime to revision 43 days
2026-07-28same kind of change as the line aboveCVE-2026-52722same vendor as the line abovesame change as the line aboveTime to revision 43 days
2026-07-28Product addedCVE-2026-4258
vendor not named
snyk
not named as affected at publication, now names org.webjars.npm:sjclTime to revision 134 days
2026-07-28Product addednot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportTime to revision 43 days
2026-07-28same kind of change as the line aboveCVE-2026-52720same vendor as the line abovesame change as the line aboveTime to revision 43 days
2026-07-28same kind of change as the line aboveCVE-2026-52722same vendor as the line abovesame change as the line aboveTime to revision 43 days
2026-07-28Product addedCVE-2026-40000not named as affected at publication, now names blade a75 5gTime to revision 1 days
2026-07-28CVSS base score changedCVE-2026-12495
whole record
INCIBE
stated at publication 9.2, now states 5.3CVSS v4.0 · base scoreCriticalMediumTime to revision 1 days
2026-07-28published 2025-08-27Advisory withdrawnGHSA-cxm3-wv7p-598cCVE-2025-10894whole advisorycriticalwithdrawn 2026-07-28Time to revision 335 days
Mon 27 Jul 2026· 105 changes
2026-07-27Added to CISA KEVCVE-2026-16812
AristaVeloCloud Orchestrator
CISA KEV
fix due 2026-07-30Duration unknown
2026-07-27Added to CISA KEVCVE-2025-68686
FortinetFortiOS
CISA KEV
fix due 2026-08-10Duration unknown
2026-07-27Product added98 rows, one per record and productnot named as affected at publication, now names tvos and 2 moreTime to revision 28 days
2026-07-27same kind of change as the line aboveCVE-2026-28979same vendor as the line abovenot named as affected at publication, now names tvosTime to revision 28 days
2026-07-27same kind of change as the line aboveCVE-2026-28979same vendor as the line abovenot named as affected at publication, now names visionosTime to revision 28 days
2026-07-27same kind of change as the line aboveCVE-2026-28979same vendor as the line abovenot named as affected at publication, now names watchosTime to revision 28 days
2026-07-27same kind of change as the line aboveCVE-2026-39868same vendor as the line abovenot named as affected at publication, now names tvosTime to revision 28 days
2026-07-27same kind of change as the line aboveCVE-2026-39868same vendor as the line abovenot named as affected at publication, now names visionosTime to revision 28 days
2026-07-27same kind of change as the line aboveCVE-2026-39868same vendor as the line abovenot named as affected at publication, now names watchosTime to revision 28 days
2026-07-27same kind of change as the line aboveCVE-2026-39872same vendor as the line abovenot named as affected at publication, now names tvosTime to revision 28 days
2026-07-27same kind of change as the line aboveCVE-2026-39872same vendor as the line abovenot named as affected at publication, now names visionosTime to revision 28 days
90 more rows in this change are not listed here. Open all 98 rows
2026-07-272 commitsProduct addednot named as affected at publication, now names red hat discovery 2Branches and original-value intervals are stated on each row.Time to revision 27 to 406 days
2026-07-27same kind of change as the line aboveCVE-2025-6170same vendor as the line abovesame change as the line aboveTime to revision 406 days
2026-07-27same kind of change as the line aboveCVE-2026-48864same vendor as the line abovesame change as the line aboveTime to revision 62 days
2026-07-27same kind of change as the line aboveCVE-2026-58016same vendor as the line abovesame change as the line aboveTime to revision 27 days
2026-07-27Record state changedCVE-2026-41603
whole record
apache
stated at publication PUBLISHED, now states REJECTEDTime to revision 90 days
2026-07-27Record state changedCVE-2026-10517
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDTime to revision 56 days
Sun 26 Jul 2026· 3 changes
2026-07-26Product addedCVE-2026-48561not named as affected at publication, now names microsoft edge copilot for android and 1 moreTime to revision 12 days
2026-07-26same kind of change as the line aboveCVE-2026-48561same vendor as the line abovenot named as affected at publication, now names microsoft edge copilot for androidTime to revision 12 days
2026-07-26same kind of change as the line aboveCVE-2026-48561same vendor as the line abovenot named as affected at publication, now names microsoft edge copilot for iosTime to revision 12 days
2026-07-26Product addedCVE-2025-5278not named as affected at publication, now names red hat openshift distributed tracing 3.10.2Time to revision 424 days
Fri 24 Jul 2026· 9 changes
2026-07-24Ransomware use confirmedCVE-2026-12569
PTCWindchill and FlexPLM
CISA KEV
stated at publication Unknown, now states KnownTime to revision 29 days
2026-07-24Fix version movedCVE-2026-8661
rapid7insightconnect markdown plugin
stated at publication 4.0.0, now states 4.0.2Release branch starts at 4.0.0.Time to revision 28 days
2026-07-24Product addedCVE-2026-16870not named as affected at publication, now names snowflake odbc driver and 1 moreTime to revision 1 days
2026-07-24same kind of change as the line aboveCVE-2026-16870same vendor as the line abovenot named as affected at publication, now names snowflake odbc driverTime to revision 1 days
2026-07-24same kind of change as the line aboveCVE-2026-16870same vendor as the line abovenot named as affected at publication, now names snowflake php pdo driverTime to revision 1 days
2026-07-24Product addedCVE-2026-16768redhatnot named as affected at publication, now names gdk-pixbufTime to revision 1 days
2026-07-24CVSS base score changedCVE-2026-15786
whole record
Wordfence
stated at publication 4.9, now states 4.4CVSS v3.1 · base scoreMediumMediumTime to revision 2 days
2026-07-24Record state changedCVE-2026-58054
whole record
VulnCheck
stated at publication PUBLISHED, now states REJECTEDTime to revision 27 days
2026-07-24Record state changedCVE-2026-1518
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDTime to revision 172 days
2026-07-24published 2026-05-06Package added to advisoryGHSA-rwm7-x88c-3g2pCVE-2026-42577highnot named as affected when the advisory was published, now names io.netty:netty-transport-classes-epollTime to revision 79 days
Thu 23 Jul 2026· 14 changes
2026-07-23Ransomware use confirmedCVE-2021-40438
ApacheApache
CISA KEV
stated at publication Unknown, now states KnownDuration unknown
2026-07-23Product addedCVE-2026-11332not named as affected at publication, now names migration toolkit for applications 8 and 4 moreTime to revision 49 days
2026-07-23same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names migration toolkit for applications 8Time to revision 49 days
2026-07-23same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names migration toolkit for virtualizationTime to revision 49 days
2026-07-23same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names red hat ansible automation platform ansible core 2Time to revision 49 days
2026-07-23same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4Time to revision 49 days
2026-07-23same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names self-service automation portal 2Time to revision 49 days
2026-07-23Product addedCVE-2026-16615redhatnot named as affected at publication, now names librestTime to revision 1 days
2026-07-23Product addednot named as affected at publication, now names red hat update infrastructure 5Time to revision 23 to 422 days
2026-07-23same kind of change as the line aboveCVE-2025-10911same vendor as the line abovesame change as the line aboveTime to revision 301 days
2026-07-23same kind of change as the line aboveCVE-2025-5278same vendor as the line abovesame change as the line aboveTime to revision 422 days
2026-07-23same kind of change as the line aboveCVE-2025-6170same vendor as the line abovesame change as the line aboveTime to revision 402 days
2026-07-23same kind of change as the line aboveCVE-2026-48864same vendor as the line abovesame change as the line aboveTime to revision 58 days
2026-07-23same kind of change as the line aboveCVE-2026-58016same vendor as the line abovesame change as the line aboveTime to revision 23 days
2026-07-23CVSS base score changedCVE-2026-63764
whole record
VulnCheck
stated at publication 9.3, now states 8.6CVSS v3.1 · base scoreCriticalHighTime to revision 2 days
2026-07-23Record state changedCVE-2026-16552
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDTime to revision 1 days
Wed 22 Jul 2026· 15 changes
2026-07-22Added to CISA KEVCVE-2026-16232
Check PointSmartConsole
CISA KEV
fix due 2026-07-25Duration unknown
2026-07-22Added to CISA KEVCVE-2026-50522
MicrosoftSharePoint
CISA KEV
fix due 2026-07-25Duration unknown
2026-07-222 commitsFix version moved
microsoft.net 10.0
stated at publication 10.0.6, now states 10.0.10Branches and original-value intervals are stated on each row.Time to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-50524same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.0.Time to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-50525same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.0.Time to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-50526same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.0.Time to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-50527same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.0.Time to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-50528same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.0.Time to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-50648same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.0.Time to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-50651same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.0.Time to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-50659same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.0.Time to revision 8 days
3 more rows in this change are not listed here. Open all 11 rows
2026-07-22Product addedCVE-2026-7253not named as affected at publication, now names sterling b2b integrator and 1 moreTime to revision 30 days
2026-07-22same kind of change as the line aboveCVE-2026-7253same vendor as the line abovenot named as affected at publication, now names sterling b2b integratorTime to revision 30 days
2026-07-22same kind of change as the line aboveCVE-2026-7253same vendor as the line abovenot named as affected at publication, now names sterling file gatewayTime to revision 30 days

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

What this page cannot see

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Paste your closed CVE tickets and see which of these changes hit them →