Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

11,999 record changes · 5,026 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
Counted changes, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Fri 19 Jun 2026· 8 record changes
2026-06-19Fix version movedCVE-2026-45852
linuxlinux
stated at publication 5.10.252, now states 5.10.259Release branch starts at 5.10.*.Days to revision 23
2026-06-19Fix version movedCVE-2026-45852
linuxlinux
stated at publication 5.15.202, now states 5.15.210Release branch starts at 5.15.*.Days to revision 23
2026-06-19Fix version movedCVE-2026-45852
linuxlinux
stated at publication 6.1.165, now states 6.1.176Release branch starts at 6.1.*.Days to revision 23
2026-06-19CVSS base score changedCVE-2026-42915
whole record
microsoft
stated at publication 5.7, now states 5.5CVSS v3.1 · base scoreMediumMediumDays to revision 10
2026-06-19CVSS base score changedCVE-2026-56208
whole record
redhat
stated at publication 8.6, now states 7.6CVSS v3.1 · base scoreHighHighDays to revision 0
2026-06-19CVSS base score changedCVE-2026-56209
whole record
redhat
stated at publication 9.1, now states 7.1CVSS v3.1 · base scoreCriticalHighDays to revision 0
2026-06-19CVSS base score changedCVE-2026-56210
whole record
redhat
stated at publication 8.2, now states 7.1CVSS v3.1 · base scoreHighHighDays to revision 0
2026-06-19CVSS base score changedCVE-2026-56211
whole record
redhat
stated at publication 8.1, now states 7.1CVSS v3.1 · base scoreHighHighDays to revision 0
Thu 18 Jun 2026· 5 record changes · 8 advisory changes
2026-06-18Added to CISA KEVCVE-2026-20253
SplunkEnterprise
CISA KEV
fix due 2026-06-21Not applicable: Added to CISA KEV has no earlier value
2026-06-18Product addedCVE-2026-9064not named as affected at publication, now names red hat directory server 13.2Days to revision 30
2026-06-18Product addedCVE-2026-4878not named as affected at publication, now names red hat openshift container platform 4.16Days to revision 70
2026-06-18CVSS base score changedCVE-2026-9591
whole record
Checkmarx
stated at publication 8.3, now states 6.9CVSS v4.0 · base scoreHighMediumDays to revision 1
2026-06-18Record state changedCVE-2025-15603
whole record
VulDB
stated at publication PUBLISHED, now states REJECTEDDays to revision 100
2026-06-18published 2024-01-19Package added to advisoryGHSA-f4qf-m5gf-8jm8CVE-2024-21733moderatenot named as affected when the advisory was published, now names org.apache.tomcat.experimental:tomcat-embed-programmaticDays to revision 881
2026-06-18published 2026-04-09Package added to advisoryGHSA-x4m4-345f-5h5gCVE-2026-34487highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-tribesDays to revision 70
2026-06-18published 2024-11-18Package added to advisoryGHSA-f632-9449-3j4wCVE-2024-52318moderatenot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-jasperDays to revision 577
2026-06-18published 2019-05-30 to 2024-11-18Package added to advisorymoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcatDays to revision 577
2026-06-18published 2024-11-18same kind of change as the line aboveGHSA-f632-9449-3j4wCVE-2024-52318same package registry as the line abovemoderatesame change as the line aboveDays to revision 577
2026-06-18published 2019-05-30same kind of change as the line aboveGHSA-jjpq-gp5q-8q6wCVE-2019-0221same package registry as the line abovemoderatesame change as the line abovenot dated
2026-06-18published 2019-05-30 to 2023-02-20Package added to advisory2 bandsnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaDays to revision 1,214
2026-06-18published 2023-02-20same kind of change as the line aboveGHSA-hfrx-6qgj-fp6cCVE-2023-24998same package registry as the line abovehighsame change as the line aboveDays to revision 1,214
2026-06-18published 2019-05-30same kind of change as the line aboveGHSA-jjpq-gp5q-8q6wCVE-2019-0221same package registry as the line abovemoderatesame change as the line abovenot dated
2026-06-18published 2022-02-10Advisory severity changedGHSA-xp4x-j9vh-c3wfCVE-2019-15609whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
Wed 17 Jun 2026· 22 record changes · 1 advisory change
2026-06-17Fix version movedqnapstated at publication 2.9.0, now states 2.9.1Release branch starts at 2.9.0.Days to revision 7 to 8
2026-06-17same kind of change as the line aboveCVE-2026-26236same vendor as the line abovesame change as the line aboveRelease branch starts at 2.9.0.Days to revision 8
2026-06-17same kind of change as the line aboveCVE-2026-26237same vendor as the line abovesame change as the line aboveRelease branch starts at 2.9.0.Days to revision 7
2026-06-17Product addedCVE-2026-4878not named as affected at publication, now names red hat openshift container platform 4.18Days to revision 69
2026-06-174 commitsProduct addedCVE-2026-9064not named as affected at publication, now names red hat directory server 12.4 e4s for rhel 9 and 3 moreBranches and original-value intervals are stated on each row.Days to revision 28 to 29
2026-06-17same kind of change as the line aboveCVE-2026-9064same vendor as the line abovenot named as affected at publication, now names red hat directory server 12.4 e4s for rhel 9Days to revision 29
2026-06-17same kind of change as the line aboveCVE-2026-9064same vendor as the line abovenot named as affected at publication, now names red hat directory server 12.2 e4s for rhel 9Days to revision 28
2026-06-17same kind of change as the line aboveCVE-2026-9064same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 28
2026-06-17same kind of change as the line aboveCVE-2026-9064same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportDays to revision 28
2026-06-17CVSS base score changedCVE-2026-55202
whole record
VulnCheck
stated at publication 9.3, now states 8.8CVSS v4.0 · base scoreCriticalHighDays to revision 0
2026-06-17CVSS base score changedCVE-2025-62851
whole record
qnap
stated at publication 6.9, now states 4.6CVSS v4.0 · base scoreMediumMediumDays to revision 7
2026-06-17CVSS base score changed
whole record
qnap
stated at publication 5.3, now states 1.3CVSS v4.0 · base scoreMediumLowDays to revision 7
2026-06-17same kind of change as the line aboveCVE-2026-22899same vendor as the line abovesame change as the line aboveDays to revision 7
2026-06-17same kind of change as the line aboveCVE-2026-24720same vendor as the line abovesame change as the line aboveDays to revision 7
2026-06-17same kind of change as the line aboveCVE-2026-26240same vendor as the line abovesame change as the line aboveDays to revision 7
2026-06-17same kind of change as the line aboveCVE-2026-26241same vendor as the line abovesame change as the line aboveDays to revision 7
2026-06-17CVSS base score changedCVE-2026-24724
whole record
qnap
stated at publication 8.6, now states 6.2CVSS v4.0 · base scoreHighMediumDays to revision 7
2026-06-17CVSS base score changed
whole record
qnap
stated at publication 8.7, now states 6.6CVSS v4.0 · base scoreHighMediumDays to revision 7 to 8
2026-06-17same kind of change as the line aboveCVE-2026-26236same vendor as the line abovesame change as the line aboveDays to revision 8
2026-06-17same kind of change as the line aboveCVE-2026-26237same vendor as the line abovesame change as the line aboveDays to revision 7
2026-06-17CVSS base score changedCVE-2026-26239
whole record
qnap
stated at publication 8.7, now states 6.3CVSS v4.0 · base scoreHighMediumDays to revision 7
2026-06-172 commitsRecord state changed
whole record
Linux
stated at publication PUBLISHED, now states REJECTEDBranches and original-value intervals are stated on each row.Days to revision 40 to 303
2026-06-17same kind of change as the line aboveCVE-2026-43122same vendor as the line abovesame change as the line aboveDays to revision 42
2026-06-17same kind of change as the line aboveCVE-2025-38553same vendor as the line abovesame change as the line aboveDays to revision 303
2026-06-17same kind of change as the line aboveCVE-2026-31688same vendor as the line abovesame change as the line aboveDays to revision 51
2026-06-17same kind of change as the line aboveCVE-2026-43422same vendor as the line abovesame change as the line aboveDays to revision 40
2026-06-17same kind of change as the line aboveCVE-2026-43423same vendor as the line abovesame change as the line aboveDays to revision 40
2026-06-17published 2026-06-12Advisory withdrawnGHSA-gv7w-rqvm-qjhrwhole advisoryhighwithdrawn 2026-06-17Days to revision 5
Tue 16 Jun 2026· 22 record changes
2026-06-16Added to CISA KEVCVE-2026-48907
Widget FactoryJoomla Content Editor
CISA KEV
fix due 2026-06-19Not applicable: Added to CISA KEV has no earlier value
2026-06-16Product addedCVE-2026-2604redhatnot named as affected at publication, now names evolution data serverDays to revision 0
2026-06-162 commitsProduct addednot named as affected at publication, now names red hat update infrastructure 5Branches and original-value intervals are stated on each row.Days to revision 1 to 47
2026-06-16same kind of change as the line aboveCVE-2026-3832same vendor as the line abovesame change as the line aboveDays to revision 47
2026-06-16same kind of change as the line aboveCVE-2026-5419same vendor as the line abovesame change as the line aboveDays to revision 15
2026-06-16same kind of change as the line aboveCVE-2026-33845same vendor as the line abovesame change as the line aboveDays to revision 47
2026-06-16same kind of change as the line aboveCVE-2026-33846same vendor as the line abovesame change as the line aboveDays to revision 44
2026-06-16same kind of change as the line aboveCVE-2026-3833same vendor as the line abovesame change as the line aboveDays to revision 47
2026-06-16same kind of change as the line aboveCVE-2026-42009same vendor as the line abovesame change as the line aboveDays to revision 29
2026-06-16same kind of change as the line aboveCVE-2026-42010same vendor as the line abovesame change as the line aboveDays to revision 40
2026-06-16same kind of change as the line aboveCVE-2026-42011same vendor as the line abovesame change as the line aboveDays to revision 40
5 more rows in this change are not listed here. Open all 13 rows
2026-06-16Product addedCVE-2026-20182not named as affected at publication, now names cisco catalyst sd-wan controllerDays to revision 33
2026-06-16CVSS base score changedCVE-2026-6893
whole record
redhat
stated at publication 8.8, now states 7.5CVSS v3.1 · base scoreHighHighDays to revision 6
2026-06-162 commitsRecord state changed
whole record
Chrome
stated at publication PUBLISHED, now states REJECTEDBranches and original-value intervals are stated on each row.Days to revision 5 to 104
2026-06-16same kind of change as the line aboveCVE-2026-5904same vendor as the line abovesame change as the line aboveDays to revision 69
2026-06-16same kind of change as the line aboveCVE-2026-12013same vendor as the line abovesame change as the line aboveDays to revision 5
2026-06-16same kind of change as the line aboveCVE-2026-3539same vendor as the line abovesame change as the line aboveDays to revision 104
2026-06-16same kind of change as the line aboveCVE-2026-7936same vendor as the line abovesame change as the line aboveDays to revision 41
2026-06-16same kind of change as the line aboveCVE-2026-8568same vendor as the line abovesame change as the line aboveDays to revision 33
Mon 15 Jun 2026· 10 record changes
2026-06-15Added to CISA KEVCVE-2026-54420
LiteSpeedcPanel Plugin
CISA KEV
fix due 2026-06-18Not applicable: Added to CISA KEV has no earlier value
2026-06-15Added to CISA KEVCVE-2026-20262
CiscoCatalyst SD-WAN Manager
CISA KEV
fix due 2026-06-29Not applicable: Added to CISA KEV has no earlier value
2026-06-15Fix version moved
microsoftvisual studio code
stated at publication 1.123.1, now states 1.123.2Release branch starts at 1.0.0.Days to revision 6
2026-06-15same kind of change as the line aboveCVE-2026-47287same vendor as the line abovesame change as the line aboveRelease branch starts at 1.0.0.Days to revision 6
2026-06-15same kind of change as the line aboveCVE-2026-47281same vendor as the line abovesame change as the line aboveRelease branch starts at 1.0.0.Days to revision 6
2026-06-15same kind of change as the line aboveCVE-2026-47284same vendor as the line abovesame change as the line aboveRelease branch starts at 1.0.0.Days to revision 6
2026-06-15Product addedCVE-2026-7374not named as affected at publication, now names red hat container native virtualization 4.20Days to revision 20
2026-06-15Product addedCVE-2025-5372not named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportDays to revision 346
2026-06-15Record state changed
whole record
Linux
stated at publication PUBLISHED, now states REJECTEDDays to revision 18 to 19
2026-06-15same kind of change as the line aboveCVE-2026-45992same vendor as the line abovesame change as the line aboveDays to revision 19
2026-06-15same kind of change as the line aboveCVE-2026-46217same vendor as the line abovesame change as the line aboveDays to revision 18
2026-06-15same kind of change as the line aboveCVE-2026-46237same vendor as the line abovesame change as the line aboveDays to revision 18
Sat 13 Jun 2026· 1 record change
2026-06-13Product addedCVE-2026-53833VulnChecknot named as affected at publication, now names openclawDays to revision 1
Fri 12 Jun 2026· 12 record changes · 4 advisory changes
2026-06-12Added to CISA KEVCVE-2026-35273
Oracle PeopleSoft Enterprise PeopleTools
CISA KEV
fix due 2026-06-15Not applicable: Added to CISA KEV has no earlier value
2026-06-12Affected range extended
fortinetfortios
stated at publication 6.2.16, now states 6.2.17Release branch starts at 6.2.0.Days to revision 759
2026-06-12same kind of change as the line aboveCVE-2023-45583same vendor as the line abovesame change as the line aboveRelease branch starts at 6.2.0.Days to revision 759
2026-06-12same kind of change as the line aboveCVE-2023-36640same vendor as the line abovesame change as the line aboveRelease branch starts at 6.2.0.Days to revision 759
2026-06-12Affected range extendedCVE-2023-45583
fortinetfortios
stated at publication 6.4.15, now states 6.4.16Release branch starts at 6.4.0.Days to revision 759
2026-06-12Product addedCVE-2025-10101NLOKnot named as affected at publication, now names avast oneDays to revision 193
2026-06-12Product addedCVE-2026-20245not named as affected at publication, now names cisco catalyst sd-wan controllerDays to revision 8
2026-06-12CVSS base score changedCVE-2025-10101
whole record
NLOK
stated at publication 8.1, now states 7.8CVSS v3.1 · base scoreHighHighDays to revision 193
2026-06-12CVSS base score changedCVE-2025-8351
whole record
NLOK
stated at publication 9.0, now states 7.8CVSS v3.1 · base scoreCriticalHighDays to revision 193
2026-06-12CVSS base score changedCVE-2026-11535
whole record
Vivo
stated at publication 8.7, now states 9.4CVSS v4.0 · base scoreHighCriticalDays to revision 0
2026-06-12CVSS base score changedCVE-2026-11561
whole record
TR-CERT
stated at publication 5.3, now states 9.8CVSS v3.1 · base scoreMediumCriticalDays to revision 1
2026-06-12CVSS base score changedCVE-2026-45171
whole record
palo_alto
stated at publication 9.3, now states 8.7CVSS v4.0 · base scoreCriticalHighDays to revision 0
2026-06-12CVSS base score changedCVE-2025-59382
whole record
qnap
stated at publication 5.1, now states 1.2CVSS v4.0 · base scoreMediumLowDays to revision 2
2026-06-12published 2023-10-10 to 2026-02-17Package added to advisorymoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 115 to 976
2026-06-12published 2023-10-10same kind of change as the line aboveGHSA-r6j3-px5g-cq3xCVE-2023-45648same package registry as the line abovemoderatesame change as the line aboveDays to revision 976
2026-06-12published 2026-02-17same kind of change as the line aboveGHSA-fpj8-gq4v-p354CVE-2025-66614same package registry as the line abovemoderatesame change as the line aboveDays to revision 115
2026-06-12published 2023-10-10Package added to advisoryGHSA-g8pj-r55q-5c2vmoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina and 1 moreDays to revision 976
2026-06-12published 2023-10-10same kind of change as the line aboveGHSA-g8pj-r55q-5c2vCVE-2023-42795same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaDays to revision 976
2026-06-12published 2023-10-10same kind of change as the line aboveGHSA-g8pj-r55q-5c2vCVE-2023-42795same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-utilDays to revision 976
Thu 11 Jun 2026· 3 record changes · 6 advisory changes
2026-06-11Added to CISA KEVCVE-2026-10520
IvantiSentry
CISA KEV
fix due 2026-06-14Not applicable: Added to CISA KEV has no earlier value
2026-06-11Product addedCVE-2026-4878not named as affected at publication, now names red hat openshift container platform 4.15Days to revision 63
2026-06-11Record state changedCVE-2026-27066
whole record
Patchstack
stated at publication PUBLISHED, now states REJECTEDDays to revision 112
2026-06-11published 2026-05-07Package added to advisoryGHSA-2mh5-3cw6-hrrqCVE-2026-40981highnot named as affected when the advisory was published, now names org.springframework.cloud:spring-cloud-config-serverDays to revision 35
2026-06-11published 2022-02-08Package added to advisoryGHSA-m7jv-hq7h-mq7chighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocket and 1 morenot dated
2026-06-11published 2022-02-08same kind of change as the line aboveGHSA-m7jv-hq7h-mq7cCVE-2020-13935same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocketnot dated
2026-06-11published 2022-02-08same kind of change as the line aboveGHSA-m7jv-hq7h-mq7cCVE-2020-13935same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-websocketnot dated
2026-06-11published 2022-02-09Package added to advisoryGHSA-53hp-jpwq-2jgqCVE-2020-11996highnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-corenot dated
2026-06-11published 2023-05-30Advisory severity changedGHSA-mj6p-3pc9-wf5mCVE-2023-2968whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 1,108
2026-06-11published 2024-04-18Advisory severity changedGHSA-jjff-q3q4-5hh8CVE-2024-30564whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 784
Wed 10 Jun 2026· 21 record changes
2026-06-10Fix version moved
microsoftvisual studio code
stated at publication 1.119.1, now states 1.123.2Release branch starts at 1.0.0.Days to revision 1
2026-06-10same kind of change as the line aboveCVE-2026-40376same vendor as the line abovesame change as the line aboveRelease branch starts at 1.0.0.Days to revision 1
2026-06-10same kind of change as the line aboveCVE-2026-48569same vendor as the line abovesame change as the line aboveRelease branch starts at 1.0.0.Days to revision 1
2026-06-10Fix version movedCVE-2026-45482
microsoftmicrosoft visual studio code copilot chat extension
stated at publication 1.123.1, now states 1.123.2Release branch starts at 0.27.0.Days to revision 1
2026-06-10Product addedCVE-2026-4874not named as affected at publication, now names red hat build of keycloak 26.6Days to revision 77
2026-06-102 commitsProduct addednot named as affected at publication, now names rbe970Branches and original-value intervals are stated on each row.Days to revision 1
2026-06-10same kind of change as the line aboveCVE-2026-3088same vendor as the line abovesame change as the line aboveDays to revision 1
2026-06-10same kind of change as the line aboveCVE-2026-0411same vendor as the line abovesame change as the line aboveDays to revision 1
2026-06-10same kind of change as the line aboveCVE-2026-0414same vendor as the line abovesame change as the line aboveDays to revision 1
2026-06-10same kind of change as the line aboveCVE-2026-0415same vendor as the line abovesame change as the line aboveDays to revision 1
2026-06-10Product addedCVE-2026-3088not named as affected at publication, now names rbe971Days to revision 1
2026-06-10Product addednot named as affected at publication, now names red hat ai inference server 3.2Days to revision 62 to 182
2026-06-10same kind of change as the line aboveCVE-2025-14087same vendor as the line abovesame change as the line aboveDays to revision 182
2026-06-10same kind of change as the line aboveCVE-2025-14512same vendor as the line abovesame change as the line aboveDays to revision 182
2026-06-10same kind of change as the line aboveCVE-2026-4775same vendor as the line abovesame change as the line aboveDays to revision 78
2026-06-10same kind of change as the line aboveCVE-2026-4878same vendor as the line abovesame change as the line aboveDays to revision 62
2026-06-10Product addedCVE-2026-4878not named as affected at publication, now names red hat openshift container platform 4.19Days to revision 62
2026-06-10Product addedCVE-2026-8863certccnot named as affected at publication, now names opensuse shimDays to revision 1
2026-06-10Product addedCVE-2026-0413not named as affected at publication, now names rbe370 and 1 moreDays to revision 1
2026-06-10same kind of change as the line aboveCVE-2026-0413same vendor as the line abovenot named as affected at publication, now names rbe370Days to revision 1
2026-06-10same kind of change as the line aboveCVE-2026-0413same vendor as the line abovenot named as affected at publication, now names rbe770Days to revision 1
2026-06-10CVSS base score changedCVE-2023-42456
whole record
GitHub_M
stated at publication 3.1, now states 3.3CVSS v3.1 · base scoreLowLowDays to revision 993
2026-06-10Record state changedCVE-2025-70420
whole record
mitre
stated at publication PUBLISHED, now states REJECTEDDays to revision 51
2026-06-10Record state changedCVE-2026-7930
whole record
Chrome
stated at publication PUBLISHED, now states REJECTEDDays to revision 35
2026-06-10Record state changedCVE-2026-4821
whole record
GitHub_P
stated at publication PUBLISHED, now states REJECTEDDays to revision 49
Tue 9 Jun 2026· 90 record changes
2026-06-09Added to CISA KEVCVE-2026-11645
GoogleChromium V8
CISA KEV
fix due 2026-06-23Not applicable: Added to CISA KEV has no earlier value
2026-06-09Added to CISA KEVCVE-2026-7473
AristaExtensible Operating System
CISA KEV
fix due 2026-06-23Not applicable: Added to CISA KEV has no earlier value
2026-06-09Added to CISA KEVCVE-2026-20245
CiscoCatalyst SD-WAN Manager
CISA KEV
fix due 2026-06-23Not applicable: Added to CISA KEV has no earlier value
2026-06-09Ransomware use confirmedCVE-2026-50751
Check PointSecurity Gateway
CISA KEV
stated at publication Unknown, now states KnownDays to revision 1
2026-06-09Fix version moved
microsoftwindows 10 version 22h2
stated at publication 10.0.19045.7291, now states 10.0.19045.7417Release branch starts at 10.0.19045.0.bulk ×54Days to revision 28
2026-06-09same kind of change as the line aboveCVE-2026-21530same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.19045.0.bulk ×54Days to revision 28
2026-06-09same kind of change as the line aboveCVE-2026-33834same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.19045.0.bulk ×54Days to revision 28
2026-06-09same kind of change as the line aboveCVE-2026-33839same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.19045.0.bulk ×54Days to revision 28
2026-06-09same kind of change as the line aboveCVE-2026-33841same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.19045.0.bulk ×54Days to revision 28
2026-06-09same kind of change as the line aboveCVE-2026-34329same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.19045.0.bulk ×54Days to revision 28
2026-06-09same kind of change as the line aboveCVE-2026-34330same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.19045.0.bulk ×54Days to revision 28
2026-06-09same kind of change as the line aboveCVE-2026-34331same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.19045.0.bulk ×54Days to revision 28
2026-06-09same kind of change as the line aboveCVE-2026-34333same vendor as the line abovesame change as the line aboveRelease branch starts at 10.0.19045.0.bulk ×54Days to revision 28
45 more rows in this change are not listed here. Open all 53 rows
2026-06-09Fix version movedCVE-2026-32175
microsoftmicrosoft visual studio 2022 version 17.14
stated at publication 17.14.31, now states 17.14.32Release branch starts at 17.14.0.bulk ×54Days to revision 28
2026-06-09Affected range extendedCVE-2025-31514
fortinetfortios
stated at publication 7.2.12, now states 7.2.13Release branch starts at 7.2.0.Days to revision 238
2026-06-09Affected range extendedCVE-2025-31514
fortinetfortios
stated at publication 7.4.9, now states 7.4.11Release branch starts at 7.4.0.Days to revision 238
2026-06-09Affected range extendedCVE-2025-31514
fortinetfortiproxy
stated at publication 7.2.15, now states 7.2.16Release branch starts at 7.2.0.Days to revision 238
2026-06-09Affected range extendedCVE-2025-31514
fortinetfortios
stated at publication 7.0.17, now states 7.0.19Release branch starts at 7.0.0.Original value first replaced 2026-01-14; this value first seen 2026-06-09.Days to revision 92
2026-06-09Affected range extendedCVE-2025-31514
fortinetfortiproxy
stated at publication 7.4.11, now states 7.4.13Release branch starts at 7.4.0.Original value first replaced 2026-01-14; this value first seen 2026-06-09.Days to revision 92
2026-06-09Affected range extendedCVE-2025-31514
fortinetfortiproxy
stated at publication 7.0.21, now states 7.0.23Release branch starts at 7.0.0.Original value first replaced 2026-01-14; this value first seen 2026-06-09.Days to revision 92
2026-06-092 commitsProduct added15 rows, one per record and productnot named as affected at publication, now names microsoft excel for android and 10 moreBranches and original-value intervals are stated on each row.Days to revision 28 to 609
2026-06-09same kind of change as the line aboveCVE-2026-41100same vendor as the line abovenot named as affected at publication, now names microsoft excel for androidDays to revision 28
2026-06-09same kind of change as the line aboveCVE-2026-41100same vendor as the line abovenot named as affected at publication, now names microsoft loop for androidDays to revision 28
2026-06-09same kind of change as the line aboveCVE-2026-41100same vendor as the line abovenot named as affected at publication, now names microsoft onenote for androidDays to revision 28
2026-06-09same kind of change as the line aboveCVE-2026-41100same vendor as the line abovenot named as affected at publication, now names microsoft powerpoint for androidDays to revision 28
2026-06-09same kind of change as the line aboveCVE-2026-41100same vendor as the line abovenot named as affected at publication, now names microsoft word for androidDays to revision 28
2026-06-09same kind of change as the line aboveCVE-2024-43582same vendor as the line abovenot named as affected at publication, now names windows 11 version 26h1Days to revision 609
2026-06-09same kind of change as the line aboveCVE-2024-49075same vendor as the line abovenot named as affected at publication, now names windows 11 version 26h1Days to revision 546
2026-06-09same kind of change as the line aboveCVE-2024-49123same vendor as the line abovenot named as affected at publication, now names windows 11 version 26h1Days to revision 546
7 more rows in this change are not listed here. Open all 15 rows
2026-06-09Product addedCVE-2026-8863certccnot named as affected at publication, now names oraclelinux(7.2) shimDays to revision 0
2026-06-09Product addedCVE-2026-4366not named as affected at publication, now names red hat build of keycloak 26.4Days to revision 84
2026-06-09Product addedCVE-2026-24858not named as affected at publication, now names fortinac-fDays to revision 133
2026-06-09Product addedCVE-2025-40936not named as affected at publication, now names simcenter femapDays to revision 204
2026-06-09Product addedCVE-2025-66274qnapnot named as affected at publication, now names qtsDays to revision 118
2026-06-09CVSS base score changedCVE-2026-11429
whole record
Altium
stated at publication 9.4, now states 10.0CVSS v4.0 · base scoreCriticalCriticalDays to revision 4
2026-06-092 commitsCVSS base score changed
whole record
GitHub_M
stated at publication 8.1, now states 8.0CVSS v3.1 · base scoreHighHighBranches and original-value intervals are stated on each row.Days to revision 348
2026-06-09same kind of change as the line aboveCVE-2025-52903same vendor as the line abovesame change as the line aboveDays to revision 348
2026-06-09same kind of change as the line aboveCVE-2025-52904same vendor as the line abovesame change as the line aboveDays to revision 348
2026-06-09CVSS base score changedCVE-2026-10840
whole record
redhat
stated at publication 9.6, now states 7.1CVSS v3.1 · base scoreCriticalHighDays to revision 5
2026-06-09CVSS base score changedCVE-2025-59381
whole record
qnap
stated at publication 4.6, now states 6.9CVSS v4.0 · base scoreMediumMediumDays to revision 158
2026-06-09CVSS base score changedCVE-2025-66274
whole record
qnap
stated at publication 1.2, now states 5.1CVSS v4.0 · base scoreLowMediumDays to revision 118

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →