Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

11,999 record changes · 5,026 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
Counted changes, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Wed 22 Jul 2026· 22 changes
2026-07-22Product addedCVE-2026-47304not named as affected at publication, now names .net 10.0 and 2 moreTime to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-47304same vendor as the line abovenot named as affected at publication, now names .net 10.0Time to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-47304same vendor as the line abovenot named as affected at publication, now names .net 8.0Time to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-47304same vendor as the line abovenot named as affected at publication, now names .net 9.0Time to revision 8 days
2026-07-22Product addednot named as affected at publication, now names microsoft .net framework 4.8.1Time to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-47304same vendor as the line abovesame change as the line aboveTime to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-50304same vendor as the line abovesame change as the line aboveTime to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-50324same vendor as the line abovesame change as the line aboveTime to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-50355same vendor as the line abovesame change as the line aboveTime to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-50368same vendor as the line abovesame change as the line aboveTime to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-50411same vendor as the line abovesame change as the line aboveTime to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-50525same vendor as the line abovesame change as the line aboveTime to revision 8 days
2026-07-22same kind of change as the line aboveCVE-2026-50647same vendor as the line abovesame change as the line aboveTime to revision 8 days
4 more rows in this change are not listed here. Open all 12 rows
2026-07-222 commitsProduct addednot named as affected at publication, now names red hat openshift container platform 4.19Branches and original-value intervals are stated on each row.Time to revision 57 to 76 days
2026-07-22same kind of change as the line aboveCVE-2026-42011same vendor as the line abovesame change as the line aboveTime to revision 76 days
2026-07-22same kind of change as the line aboveCVE-2026-42013same vendor as the line abovesame change as the line aboveTime to revision 57 days
2026-07-22same kind of change as the line aboveCVE-2026-5260same vendor as the line abovesame change as the line aboveTime to revision 57 days
2026-07-22same kind of change as the line aboveCVE-2026-42009same vendor as the line abovesame change as the line aboveTime to revision 65 days
2026-07-22same kind of change as the line aboveCVE-2026-42010same vendor as the line abovesame change as the line aboveTime to revision 76 days
2026-07-22Product addedCVE-2026-56208not named as affected at publication, now names red hat enterprise linux 8Time to revision 33 days
2026-07-22CVSS base score changedCVE-2026-7253
whole record
ibm
stated at publication 5.3, now states 6.0CVSS v3.1 · base scoreMediumMediumTime to revision 30 days
Tue 21 Jul 2026· 30 changes
2026-07-21Added to CISA KEV
WordPressCore
fix due 2026-08-04Duration unknown
2026-07-21same kind of change as the line aboveCVE-2026-60137same vendor as the line abovesame change as the line aboveDuration unknown
2026-07-21same kind of change as the line aboveCVE-2026-63030same vendor as the line abovesame change as the line aboveDuration unknown
2026-07-21Added to CISA KEVCVE-2026-0770
LangflowLangflow
CISA KEV
fix due 2026-07-24Duration unknown
2026-07-21Added to CISA KEVCVE-2021-27137
DD-WRTDD-WRT
CISA KEV
fix due 2026-07-24Duration unknown
2026-07-21Ransomware use confirmedCVE-2026-0257CISA KEVstated at publication Unknown, now states KnownTime to revision 53 days
2026-07-21Fix version movedCVE-2026-64824
home-assistanthome assistant core
VulnCheck
stated at publication 2026.6.0, now states 2026.7.0Release branch starts at 0.same dayTime to revision 0 days
2026-07-21Product addedCVE-2026-47304not named as affected at publication, now names microsoft visual studio 2017 version 15.9 (includes 15.0 - 15.8) and 2 moreTime to revision 7 days
2026-07-21same kind of change as the line aboveCVE-2026-47304same vendor as the line abovenot named as affected at publication, now names microsoft visual studio 2017 version 15.9 (includes 15.0 - 15.8)Time to revision 7 days
2026-07-21same kind of change as the line aboveCVE-2026-47304same vendor as the line abovenot named as affected at publication, now names microsoft visual studio 2019 version 16.11 (includes 16.0 - 16.10)Time to revision 7 days
2026-07-21same kind of change as the line aboveCVE-2026-47304same vendor as the line abovenot named as affected at publication, now names microsoft visual studio 2026 version 18.5Time to revision 7 days
2026-07-21Product addednot named as affected at publication, now names red hat enterprise linux ai 3.5 for rhel 9Time to revision 32 days
2026-07-21same kind of change as the line aboveCVE-2026-56208same vendor as the line abovesame change as the line aboveTime to revision 32 days
2026-07-21same kind of change as the line aboveCVE-2026-56209same vendor as the line abovesame change as the line aboveTime to revision 32 days
2026-07-21same kind of change as the line aboveCVE-2026-56210same vendor as the line abovesame change as the line aboveTime to revision 32 days
2026-07-21same kind of change as the line aboveCVE-2026-56211same vendor as the line abovesame change as the line aboveTime to revision 32 days
2026-07-21Product addedCVE-2026-16118redhatnot named as affected at publication, now names xdgmimeTime to revision 4 days
2026-07-21Product addedCVE-2025-57847not named as affected at publication, now names red hat ansible automation platform 2.5Time to revision 104 days
2026-07-21Product addedCVE-2026-12701not named as affected at publication, now names red hat ansible automation platform 2.6 and 1 moreTime to revision 1 days
2026-07-21same kind of change as the line aboveCVE-2026-12701same vendor as the line abovenot named as affected at publication, now names red hat ansible automation platform 2.6Time to revision 1 days
2026-07-21same kind of change as the line aboveCVE-2026-12701same vendor as the line abovenot named as affected at publication, now names red hat ansible automation platform 2.7Time to revision 1 days
2026-07-21CVSS base score changedCVE-2026-48356
whole record
adobe
stated at publication 9.6, now states 9.3CVSS v3.1 · base scoreCriticalCriticalTime to revision 7 days
2026-07-21Record state changed
whole record
GitHub_M
stated at publication PUBLISHED, now states REJECTEDTime to revision 1 days
2026-07-21same kind of change as the line aboveCVE-2026-44507same vendor as the line abovesame change as the line aboveTime to revision 1 days
2026-07-21same kind of change as the line aboveCVE-2026-44508same vendor as the line abovesame change as the line aboveTime to revision 1 days
2026-07-21same kind of change as the line aboveCVE-2026-44509same vendor as the line abovesame change as the line aboveTime to revision 1 days
2026-07-21same kind of change as the line aboveCVE-2026-44510same vendor as the line abovesame change as the line aboveTime to revision 1 days
2026-07-21Record state changedCVE-2024-47220
whole record
mitre
stated at publication PUBLISHED, now states REJECTEDTime to revision 668 days
2026-07-21published 2026-05-07Package added to advisoryGHSA-g924-cjx7-2rjwCVE-2026-42597moderatenot named as affected when the advisory was published, now names github.com/gotenberg/gotenberg/v7Time to revision 76 days
2026-07-21published 2026-04-14Package added to advisoryGHSA-2hx3-vp6r-mg3fhighnot named as affected when the advisory was published, now names microsoft.openapi.kiota and 1 moreTime to revision 98 days
2026-07-21published 2026-04-14same kind of change as the line aboveGHSA-2hx3-vp6r-mg3fCVE-2026-41134same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.openapi.kiotaTime to revision 98 days
2026-07-21published 2026-04-14same kind of change as the line aboveGHSA-2hx3-vp6r-mg3fCVE-2026-41134same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.openapi.kiota.builderTime to revision 98 days
2026-07-21published 2025-08-26Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 329 to 329 days
2026-07-21published 2025-08-26same kind of change as the line aboveGHSA-xp4f-hrf8-rxw7CVE-2025-71344same package and registry as the line abovehighsame change as the line aboveTime to revision 329 days
2026-07-21published 2025-08-26same kind of change as the line aboveGHSA-3vg9-h568-4w9mCVE-2025-71354same package and registry as the line abovehighsame change as the line aboveTime to revision 329 days
2026-07-21published 2026-06-23Advisory severity changedGHSA-vcm5-gvmp-78mpCVE-2026-52807whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Time to revision 28 days
2026-07-21published 2026-06-22Advisory severity changedGHSA-c4v7-xg93-qf8gCVE-2026-47267whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 29 days
Mon 20 Jul 2026· 17 changes
2026-07-20Affected range extendedCVE-2026-57956
signozsignoz
VulnCheck
stated at publication 0.130.1, now states 0.133.0Release branch starts at 0.Time to revision 21 days
2026-07-20Affected range extended
sankonet::bittorrent
CPANSec
stated at publication 2.0.1, now states 2.1.0Release branch starts at 0.Time to revision 20 days
2026-07-20same kind of change as the line aboveCVE-2026-57080same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Time to revision 20 days
2026-07-20same kind of change as the line aboveCVE-2026-57081same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Time to revision 20 days
2026-07-203 commitsProduct added11 rows, one per record and productnot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update support and 7 moreBranches and original-value intervals are stated on each row.Time to revision 0 to 46 days
2026-07-20same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportTime to revision 34 days
2026-07-20same kind of change as the line aboveCVE-2026-10649same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportTime to revision 34 days
2026-07-20same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names red hat ansible automation platform 2.6 for rhel 10Time to revision 46 days
2026-07-20same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names red hat ansible automation platform 2.6 for rhel 9Time to revision 46 days
2026-07-20same kind of change as the line aboveCVE-2026-12701same vendor as the line abovenot named as affected at publication, now names red hat ansible automation platform 2.6 for rhel 9Time to revision 0 days
2026-07-20same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names red hat ansible automation platform 2.5 for rhel 8Time to revision 46 days
2026-07-20same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names red hat ansible automation platform 2.5 for rhel 9Time to revision 46 days
2026-07-20same kind of change as the line aboveCVE-2026-12701same vendor as the line abovenot named as affected at publication, now names red hat ansible automation platform 2.5 for rhel 8Time to revision 0 days
3 more rows in this change are not listed here. Open all 11 rows
2026-07-20CVSS base score changedCVE-2026-34632
whole record
adobe
stated at publication 8.2, now states 8.6CVSS v3.1 · base scoreHighHighTime to revision 96 days
2026-07-20published 2025-08-26Advisory severity changedGHSA-8r4j-24qv-fmq9CVE-2025-71361whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 328 days
2026-07-20published 2026-06-05Advisory severity changedGHSA-jr54-jwhj-55gpCVE-2026-47380whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Time to revision 45 days
Sat 18 Jul 2026· 2 changes
2026-07-18CVSS base score changedCVE-2026-57857
whole record
VulnCheck
stated at publication 7.2, now states 5.1CVSS v4.0 · base scoreHighMediumTime to revision 0 days
2026-07-18published 2025-08-26Advisory severity changedGHSA-6w4w-5w54-rjvrCVE-2025-71358whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 326 days
Fri 17 Jul 2026· 1 change
2026-07-17CVSS base score changedCVE-2026-7189
whole record
TR-CERT
stated at publication 8.2, now states 7.5CVSS v3.1 · base scoreHighHighTime to revision 0 days
Thu 16 Jul 2026· 72 changes
2026-07-16Added to CISA KEVCVE-2026-58644
MicrosoftSharePoint
CISA KEV
fix due 2026-07-19Duration unknown
2026-07-16Added to CISA KEV
FortinetFortiSandbox
fix due 2026-07-19Duration unknown
2026-07-16same kind of change as the line aboveCVE-2026-25089same vendor as the line abovesame change as the line aboveDuration unknown
2026-07-16same kind of change as the line aboveCVE-2026-39808same vendor as the line abovesame change as the line aboveDuration unknown
2026-07-16Affected range extendedCVE-2026-59840
fortinetfortios
stated at publication 7.6.2, now states 7.6.3Release branch starts at 7.6.0.Time to revision 2 days
2026-07-16Product added42 rows, one per record and productnot named as affected at publication, now names microsoft .net framework 3.5 and 4.7.2 and 5 moreTime to revision 2 days
2026-07-16same kind of change as the line aboveCVE-2026-50304same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5 and 4.7.2Time to revision 2 days
2026-07-16same kind of change as the line aboveCVE-2026-50304same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5 and 4.8Time to revision 2 days
2026-07-16same kind of change as the line aboveCVE-2026-50304same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5 and 4.8.1Time to revision 2 days
2026-07-16same kind of change as the line aboveCVE-2026-50304same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 4.6.2/4.7/4.7.1/4.7.2Time to revision 2 days
2026-07-16same kind of change as the line aboveCVE-2026-50304same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 4.8Time to revision 2 days
2026-07-16same kind of change as the line aboveCVE-2026-50324same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5 and 4.7.2Time to revision 2 days
2026-07-16same kind of change as the line aboveCVE-2026-50324same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5 and 4.8Time to revision 2 days
2026-07-16same kind of change as the line aboveCVE-2026-50324same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5 and 4.8.1Time to revision 2 days
34 more rows in this change are not listed here. Open all 42 rows
2026-07-16Product addedCVE-2026-4601
vendor not named
snyk
not named as affected at publication, now names org.webjars.npm:jsrsasignTime to revision 116 days
2026-07-16Product addedCVE-2026-10840not named as affected at publication, now names red hat openshift builds 1.8.1Time to revision 42 days
2026-07-16Product addedCVE-2024-8751SICK AGnot named as affected at publication, now names flps and 15 moreTime to revision 672 days
2026-07-16same kind of change as the line aboveCVE-2024-8751same vendor as the line abovenot named as affected at publication, now names flpsTime to revision 672 days
2026-07-16same kind of change as the line aboveCVE-2024-8751same vendor as the line abovenot named as affected at publication, now names gm32Time to revision 672 days
2026-07-16same kind of change as the line aboveCVE-2024-8751same vendor as the line abovenot named as affected at publication, now names gms800Time to revision 672 days
2026-07-16same kind of change as the line aboveCVE-2024-8751same vendor as the line abovenot named as affected at publication, now names gms800 fidorTime to revision 672 days
2026-07-16same kind of change as the line aboveCVE-2024-8751same vendor as the line abovenot named as affected at publication, now names marsic200Time to revision 672 days
2026-07-16same kind of change as the line aboveCVE-2024-8751same vendor as the line abovenot named as affected at publication, now names marsic280Time to revision 672 days
2026-07-16same kind of change as the line aboveCVE-2024-8751same vendor as the line abovenot named as affected at publication, now names marsic300Time to revision 672 days
2026-07-16same kind of change as the line aboveCVE-2024-8751same vendor as the line abovenot named as affected at publication, now names mcs100ftTime to revision 672 days
8 more rows in this change are not listed here. Open all 16 rows
2026-07-16Record state changedCVE-2026-6685
whole record
runZero
stated at publication PUBLISHED, now states REJECTEDTime to revision 15 days
2026-07-16Record state changed
whole record
@huntr_ai
stated at publication PUBLISHED, now states REJECTEDTime to revision 483 to 645 days
2026-07-16same kind of change as the line aboveCVE-2024-7033same vendor as the line abovesame change as the line aboveTime to revision 483 days
2026-07-16same kind of change as the line aboveCVE-2024-7034same vendor as the line abovesame change as the line aboveTime to revision 483 days
2026-07-16same kind of change as the line aboveCVE-2024-7038same vendor as the line abovesame change as the line aboveTime to revision 645 days
2026-07-16same kind of change as the line aboveCVE-2024-7039same vendor as the line abovesame change as the line aboveTime to revision 483 days
2026-07-16same kind of change as the line aboveCVE-2024-7040same vendor as the line abovesame change as the line aboveTime to revision 483 days
2026-07-16same kind of change as the line aboveCVE-2024-7959same vendor as the line abovesame change as the line aboveTime to revision 483 days
2026-07-16published 2024-05-30Package added to advisoryGHSA-22q7-cg4r-p9mxmoderatenot named as affected when the advisory was published, now names typo3/cms-fluidTime to revision 777 days
Wed 15 Jul 2026· 43 changes
2026-07-15Added to CISA KEVCVE-2026-46817
OracleE-Business Suite
CISA KEV
fix due 2026-07-18Duration unknown
2026-07-15Added to CISA KEVCVE-2023-4346
KNX AssociationKNX Protocol Connection Authorization Option 1
CISA KEV
fix due 2026-07-29Duration unknown
2026-07-15Affected range extended
adobeadobe experience manager 6.5
stated at publication 6.5.24, now states 6.5.25Release branch starts at 0.Time to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-48254same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Time to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-48257same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Time to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-48255same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Time to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-48252same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Time to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-48262same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Time to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-48253same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Time to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-48261same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Time to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-48355same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Time to revision 1 days
5 more rows in this change are not listed here. Open all 13 rows
2026-07-15Product added24 rows, one per record and productnot named as affected at publication, now names microsoft .net framework 3.5 and 5 moreTime to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-47304same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5Time to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-47304same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5 and 4.7.2Time to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-47304same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5 and 4.8Time to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-47304same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5 and 4.8.1Time to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-47304same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 4.6.2/4.7/4.7.1/4.7.2Time to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-47304same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 4.8Time to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-50525same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5Time to revision 1 days
2026-07-15same kind of change as the line aboveCVE-2026-50525same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5 and 4.7.2Time to revision 1 days
16 more rows in this change are not listed here. Open all 24 rows
2026-07-15Product addedCVE-2025-5278not named as affected at publication, now names cost management 4Time to revision 414 days
2026-07-15Record state changedCVE-2026-56401
whole record
VulnCheck
stated at publication PUBLISHED, now states REJECTEDTime to revision 7 days
2026-07-15published 2025-12-01Package added to advisoryGHSA-rcmh-qjqh-p98vCVE-2025-14874highnot named as affected when the advisory was published, now names org.webjars.npm:nodemailerTime to revision 226 days
2026-07-15published 2026-06-12Advisory severity changedGHSA-4px2-pw77-vc85CVE-2026-28898whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 33 days
Tue 14 Jul 2026· 46 changes
2026-07-14Added to CISA KEVCVE-2026-56155
MicrosoftActive Directory Federation Services
CISA KEV
fix due 2026-07-28Duration unknown
2026-07-14Added to CISA KEVCVE-2026-56164
MicrosoftSharePoint Server
CISA KEV
fix due 2026-07-17Duration unknown
2026-07-14Added to CISA KEV
SonicWallSMA1000 Appliances
fix due 2026-07-17Duration unknown
2026-07-14same kind of change as the line aboveCVE-2026-15409same vendor as the line abovesame change as the line aboveDuration unknown
2026-07-14same kind of change as the line aboveCVE-2026-15410same vendor as the line abovesame change as the line aboveDuration unknown
2026-07-14Affected range extendedCVE-2026-34690
adobeafter effects
stated at publication 25.6.4, now states 25.6.5Release branch starts at 0.Time to revision 63 days
2026-07-14Product added36 rows, one per record and productnot named as affected at publication, now names content credentials command-line tool and 2 moreTime to revision 0 days
2026-07-14same kind of change as the line aboveCVE-2026-48287same vendor as the line abovenot named as affected at publication, now names content credentials command-line toolTime to revision 0 days
2026-07-14same kind of change as the line aboveCVE-2026-48287same vendor as the line abovenot named as affected at publication, now names content credentials js sdkTime to revision 0 days
2026-07-14same kind of change as the line aboveCVE-2026-48287same vendor as the line abovenot named as affected at publication, now names content credentials rust sdkTime to revision 0 days
2026-07-14same kind of change as the line aboveCVE-2026-48290same vendor as the line abovenot named as affected at publication, now names content credentials command-line toolTime to revision 0 days
2026-07-14same kind of change as the line aboveCVE-2026-48290same vendor as the line abovenot named as affected at publication, now names content credentials js sdkTime to revision 0 days
2026-07-14same kind of change as the line aboveCVE-2026-48290same vendor as the line abovenot named as affected at publication, now names content credentials rust sdkTime to revision 0 days
2026-07-14same kind of change as the line aboveCVE-2026-48295same vendor as the line abovenot named as affected at publication, now names content credentials command-line toolTime to revision 0 days
2026-07-14same kind of change as the line aboveCVE-2026-48295same vendor as the line abovenot named as affected at publication, now names content credentials js sdkTime to revision 0 days
28 more rows in this change are not listed here. Open all 36 rows
2026-07-14Product addedCVE-2024-21529
vendor not named
snyk
not named as affected at publication, now names org.webjars.npm:dsetTime to revision 671 days
2026-07-14Product addedCVE-2025-12758
vendor not named
snyk
not named as affected at publication, now names org.webjars.npm:validatorTime to revision 229 days
2026-07-14Product addedCVE-2026-7891DIVDnot named as affected at publication, now names mendix runtimeTime to revision 68 days
2026-07-14CVSS base score changedCVE-2026-10642
whole record
zephyr
stated at publication 6.5, now states 4.6CVSS v3.1 · base scoreMediumMediumTime to revision 20 days
2026-07-14Record state changedCVE-2026-38969
whole record
mitre
stated at publication PUBLISHED, now states REJECTEDTime to revision 13 days
Mon 13 Jul 2026· 6 changes
2026-07-13Added to CISA KEVCVE-2008-4128
CiscoIOS
CISA KEV
fix due 2026-07-16Duration unknown
2026-07-13Product addedCVE-2025-15608TPLinknot named as affected at publication, now names ax55 v4 and 1 moreTime to revision 115 days
2026-07-13same kind of change as the line aboveCVE-2025-15608same vendor as the line abovenot named as affected at publication, now names ax55 v4Time to revision 115 days
2026-07-13same kind of change as the line aboveCVE-2025-15608same vendor as the line abovenot named as affected at publication, now names ax55 v4.6Time to revision 115 days
2026-07-13Product addedCVE-2026-21728not named as affected at publication, now names enterprise traces (get)Time to revision 80 days
2026-07-13Product addedCVE-2026-11332not named as affected at publication, now names red hat discovery 2Time to revision 38 days
2026-07-13CVSS base score changedCVE-2026-12257
whole record
INCIBE
stated at publication 5.1, now states 9.3CVSS v4.0 · base scoreMediumCriticalTime to revision 0 days
Fri 10 Jul 2026· 6 changes
2026-07-10Added to CISA KEVCVE-2026-56291
BalbooaForms
CISA KEV
fix due 2026-07-13Duration unknown
2026-07-10Added to CISA KEVCVE-2026-48939
iCagendaiCagenda
CISA KEV
fix due 2026-07-13Duration unknown
2026-07-10Product addedCVE-2026-11332not named as affected at publication, now names red hat enterprise linux 10 and 2 moreTime to revision 35 days
2026-07-10same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 10Time to revision 35 days
2026-07-10same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8Time to revision 35 days
2026-07-10same kind of change as the line aboveCVE-2026-11332same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 9Time to revision 35 days
2026-07-10Record state changedCVE-2026-53166
whole record
Linux
stated at publication PUBLISHED, now states REJECTEDTime to revision 15 days
Thu 9 Jul 2026· 3 changes
2026-07-09Product addedCVE-2026-4878not named as affected at publication, now names red hat openshift container platform 4.17Time to revision 91 days
2026-07-09CVSS base score changedCVE-2026-15308
whole record
PSF
stated at publication 10.0, now states 8.7CVSS v4.0 · base scoreCriticalHighTime to revision 0 days
2026-07-09Record state changedCVE-2026-40500
whole record
VulnCheck
stated at publication PUBLISHED, now states REJECTEDTime to revision 85 days
Wed 8 Jul 2026· 43 changes
2026-07-08Affected range extended
fortinetfortimanager
stated at publication 7.0.13, now states 7.0.16Release branch starts at 7.0.0.Time to revision 538 to 540 days
2026-07-08same kind of change as the line aboveCVE-2024-33503same vendor as the line abovesame change as the line aboveRelease branch starts at 7.0.0.Time to revision 540 days
2026-07-08same kind of change as the line aboveCVE-2024-45331same vendor as the line abovesame change as the line aboveRelease branch starts at 7.0.0.Time to revision 538 days
2026-07-08Affected range extendedCVE-2024-45331
fortinetfortianalyzer
stated at publication 7.0.13, now states 7.0.16Release branch starts at 7.0.0.Time to revision 538 days
2026-07-08Affected range extended
fortinetfortios
stated at publication 7.2.12, now states 7.2.13Release branch starts at 7.2.0.Time to revision 267 days
2026-07-08same kind of change as the line aboveCVE-2025-47890same vendor as the line abovesame change as the line aboveRelease branch starts at 7.2.0.Time to revision 267 days
2026-07-08same kind of change as the line aboveCVE-2025-31366same vendor as the line abovesame change as the line aboveRelease branch starts at 7.2.0.Time to revision 267 days
2026-07-08Affected range extended
fortinetfortiproxy
stated at publication 7.2.15, now states 7.2.16Release branch starts at 7.2.0.Time to revision 267 days
2026-07-08same kind of change as the line aboveCVE-2025-47890same vendor as the line abovesame change as the line aboveRelease branch starts at 7.2.0.Time to revision 267 days
2026-07-08same kind of change as the line aboveCVE-2025-31366same vendor as the line abovesame change as the line aboveRelease branch starts at 7.2.0.Time to revision 267 days
2026-07-08Affected range extended
fortinetfortios
stated at publication 7.0.17, now states 7.0.19Release branch starts at 7.0.0.Original value first replaced 2026-01-14; this value first seen 2026-07-08.Time to revision 92 days
2026-07-08same kind of change as the line aboveCVE-2025-47890same vendor as the line abovesame change as the line aboveRelease branch starts at 7.0.0.Original value first replaced 2026-01-14; this value first seen 2026-07-08.Time to revision 92 days
2026-07-08same kind of change as the line aboveCVE-2025-31366same vendor as the line abovesame change as the line aboveRelease branch starts at 7.0.0.Original value first replaced 2026-01-14; this value first seen 2026-07-08.Time to revision 92 days
2026-07-08Affected range extendedCVE-2025-47890
fortinetfortiproxy
stated at publication 7.4.11, now states 7.4.14Release branch starts at 7.4.0.Original value first replaced 2026-01-14; this value first seen 2026-07-08.Time to revision 92 days
2026-07-08Affected range extended
fortinetfortiproxy
stated at publication 7.0.21, now states 7.0.23Release branch starts at 7.0.0.Original value first replaced 2026-01-14; this value first seen 2026-07-08.Time to revision 92 days
2026-07-08same kind of change as the line aboveCVE-2025-47890same vendor as the line abovesame change as the line aboveRelease branch starts at 7.0.0.Original value first replaced 2026-01-14; this value first seen 2026-07-08.Time to revision 92 days
2026-07-08same kind of change as the line aboveCVE-2025-31366same vendor as the line abovesame change as the line aboveRelease branch starts at 7.0.0.Original value first replaced 2026-01-14; this value first seen 2026-07-08.Time to revision 92 days
2026-07-085 commitsProduct added23 rows, one per record and productnot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update support and 4 moreBranches and original-value intervals are stated on each row.Time to revision 1 to 33 days
2026-07-08same kind of change as the line aboveCVE-2026-50256same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportTime to revision 33 days
2026-07-08same kind of change as the line aboveCVE-2026-50257same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportTime to revision 33 days
2026-07-08same kind of change as the line aboveCVE-2026-50258same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportTime to revision 33 days
2026-07-08same kind of change as the line aboveCVE-2026-50259same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportTime to revision 33 days
2026-07-08same kind of change as the line aboveCVE-2026-50260same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportTime to revision 33 days
2026-07-08same kind of change as the line aboveCVE-2026-50261same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportTime to revision 33 days
2026-07-08same kind of change as the line aboveCVE-2026-50262same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportTime to revision 33 days
2026-07-08same kind of change as the line aboveCVE-2026-50263same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportTime to revision 33 days
15 more rows in this change are not listed here. Open all 23 rows
2026-07-08Product addednot named as affected at publication, now names fortimanager cloudTime to revision 540 days
2026-07-08same kind of change as the line aboveCVE-2024-33503same vendor as the line abovesame change as the line aboveTime to revision 540 days
2026-07-08same kind of change as the line aboveCVE-2024-35276same vendor as the line abovesame change as the line aboveTime to revision 540 days
2026-07-08Product addednot named as affected at publication, now names fortianalyzer cloudTime to revision 538 to 540 days
2026-07-08same kind of change as the line aboveCVE-2024-35276same vendor as the line abovesame change as the line aboveTime to revision 540 days
2026-07-08same kind of change as the line aboveCVE-2024-45331same vendor as the line abovesame change as the line aboveTime to revision 538 days
2026-07-08Product addedCVE-2026-11610redhatnot named as affected at publication, now names 389-ds-baseTime to revision 1 days
2026-07-08Product addedCVE-2023-42789not named as affected at publication, now names fortisaseTime to revision 848 days
2026-07-08CVSS base score changedCVE-2026-60104
whole record
VulnCheck
stated at publication 8.5, now states 9.3CVSS v4.0 · base scoreHighCriticalTime to revision 0 days
2026-07-08CVSS base score changedCVE-2026-9182
whole record
Esri
stated at publication 5.3, now states 9.8CVSS v3.1 · base scoreMediumCriticalTime to revision 2 days
Tue 7 Jul 2026· 24 changes
2026-07-07Added to CISA KEVCVE-2026-48908
JoomShaperSP Page Builder
CISA KEV
fix due 2026-07-10Duration unknown
2026-07-07Added to CISA KEVCVE-2026-55255
LangflowLangflow
CISA KEV
fix due 2026-07-10Duration unknown
2026-07-07Added to CISA KEVCVE-2026-56290
JoomlackPage Builder
CISA KEV
fix due 2026-07-10Duration unknown
2026-07-07Added to CISA KEVCVE-2026-48282
AdobeColdFusion
CISA KEV
fix due 2026-07-10Duration unknown
2026-07-07Ransomware use confirmedCVE-2025-3248
LangflowLangflow
CISA KEV
stated at publication Unknown, now states KnownTime to revision 428 days
2026-07-074 commitsProduct added12 rows, one per record and productnot named as affected at publication, now names red hat directory server 12.4 e4s for rhel 9 and 6 moreBranches and original-value intervals are stated on each row.Time to revision 0 to 61 days
2026-07-07same kind of change as the line aboveCVE-2026-11610same vendor as the line abovenot named as affected at publication, now names red hat directory server 12.4 e4s for rhel 9Time to revision 0 days
2026-07-07same kind of change as the line aboveCVE-2026-11774same vendor as the line abovenot named as affected at publication, now names red hat directory server 12.4 e4s for rhel 9Time to revision 26 days
2026-07-07same kind of change as the line aboveCVE-2026-42009same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.20Time to revision 50 days
2026-07-07same kind of change as the line aboveCVE-2026-42010same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.20Time to revision 61 days
2026-07-07same kind of change as the line aboveCVE-2026-9165same vendor as the line abovenot named as affected at publication, now names red hat advanced cluster security for kubernetes 4.11Time to revision 1 days
2026-07-07same kind of change as the line aboveCVE-2026-42009same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.21Time to revision 50 days
2026-07-07same kind of change as the line aboveCVE-2026-42010same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.21Time to revision 61 days
2026-07-07same kind of change as the line aboveCVE-2026-11610same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportTime to revision 0 days
4 more rows in this change are not listed here. Open all 12 rows
2026-07-07Product addedCVE-2026-12866
vendor not named
snyk
not named as affected at publication, now names org.webjars.npm:expr-evalTime to revision 15 days
2026-07-07Product addedCVE-2025-49795redhatnot named as affected at publication, now names libxml2Time to revision 386 days
2026-07-07Product addedCVE-2026-12491redhatnot named as affected at publication, now names vllmTime to revision 20 days
2026-07-07CVSS base score changedCVE-2026-55255
whole record
GitHub_M
stated at publication 9.9, now states 8.4CVSS v3.1 · base scoreCriticalHighTime to revision 14 days
2026-07-07Record state changedCVE-2026-3260
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDTime to revision 106 days
2026-07-07published 2026-05-08Package added to advisoryGHSA-mx76-r943-rf8gCVE-2026-8149moderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-lts8onTime to revision 61 days
2026-07-07published 2026-06-19Advisory severity changedGHSA-qrpv-q767-xqq2CVE-2026-55255whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 18 days
Mon 6 Jul 2026· 1 change
2026-07-06Product addedCVE-2026-2100redhatnot named as affected at publication, now names p11-kitTime to revision 102 days

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

What this page cannot see

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Paste your closed CVE tickets and see which of these changes hit them →