Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

11,999 record changes · 5,026 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
Counted changes, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Tue 9 Jun 2026· 2 record changes · 15 advisory changes
2026-06-09CVSS base score changedCVE-2026-22895
whole record
qnap
stated at publication 2.2, now states 6.2CVSS v4.0 · base scoreLowMediumDays to revision 81
2026-06-09Record state changedCVE-2026-26957
whole record
GitHub_M
stated at publication PUBLISHED, now states REJECTEDDays to revision 110
2026-06-09published 2021-08-25 to 2022-01-06Advisory fix version moved
crates.ioactix-web
2 bands
stated at publication 0.7.15, now states 0.7.19not dated
2026-06-09published 2022-01-06same kind of change as the line aboveGHSA-9qj6-4rfq-vm84CVE-2018-25024same package and registry as the line abovecriticalsame change as the line abovenot dated
2026-06-09published 2022-01-06same kind of change as the line aboveGHSA-7x36-h62w-vw65CVE-2018-25026same package and registry as the line abovecriticalsame change as the line abovenot dated
2026-06-09published 2022-01-06same kind of change as the line aboveGHSA-fgfm-hqjw-3265CVE-2018-25025same package and registry as the line abovecriticalsame change as the line abovenot dated
2026-06-09published 2021-08-25same kind of change as the line aboveGHSA-w65j-g6c7-g3m4same package and registry as the line abovemoderatesame change as the line abovenot dated
2026-06-09published 2026-06-01Package added to advisoryGHSA-q53q-5r4j-5729CVE-2026-47425moderatenot named as affected when the advisory was published, now names py-rattlerDays to revision 8
2026-06-09published 2026-05-29Advisory severity changedGHSA-j6fm-9rfm-j5hxCVE-2026-41237whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 11
2026-06-09published 2022-05-24Advisory severity changedGHSA-4hm9-844j-jmxpCVE-2019-13117whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 1,477
2026-06-09published 2026-05-12Advisory severity changedGHSA-3636-h3vx-6465CVE-2026-44593whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 27
2026-06-09published 2026-05-15Advisory severity changedGHSA-rmqr-h98c-qg2mwhole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 24
2026-06-09published 2026-02-18 to 2026-05-15Advisory withdrawnwhole advisory2 bandswithdrawn 2026-06-09Days to revision 24 to 112
2026-06-09published 2026-02-18same kind of change as the line aboveGHSA-wgm6-9rvv-3438CVE-2026-26957same package and registry as the line abovemoderatewithdrawn 2026-06-09Days to revision 112
2026-06-09published 2026-05-15same kind of change as the line aboveGHSA-5h62-f8fg-4w7qsame package and registry as the line abovemoderatewithdrawn 2026-06-09Days to revision 24
2026-06-09published 2026-05-15same kind of change as the line aboveGHSA-wj3q-vw2v-3rj3same package and registry as the line abovemoderatewithdrawn 2026-06-09Days to revision 24
2026-06-09published 2026-05-15same kind of change as the line aboveGHSA-9r8r-x3vg-6xh4same package and registry as the line abovemoderatewithdrawn 2026-06-09Days to revision 24
2026-06-09published 2026-05-15same kind of change as the line aboveGHSA-rmqr-h98c-qg2msame package and registry as the line abovehighwithdrawn 2026-06-09Days to revision 24
2026-06-09published 2026-05-15same kind of change as the line aboveGHSA-h36g-93qx-rxgrsame package and registry as the line abovemoderatewithdrawn 2026-06-09Days to revision 24
Mon 8 Jun 2026· 7 record changes · 8 advisory changes
2026-06-08Added to CISA KEVCVE-2026-50751
Check PointSecurity Gateway
CISA KEV
fix due 2026-06-11Not applicable: Added to CISA KEV has no earlier value
2026-06-08Added to CISA KEVCVE-2026-42271
BerriAILiteLLM
CISA KEV
fix due 2026-06-22Not applicable: Added to CISA KEV has no earlier value
2026-06-08Fix version movedCVE-2026-49777
shapedplugin, llcproduct slider pro for woocommerce
Patchstack
stated at publication 3.5.3, now states 3.5.4Release branch starts at 0.Days to revision 3
2026-06-08Product addedCVE-2025-5372not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 339
2026-06-08Product addednot named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportDays to revision 60 to 70
2026-06-08same kind of change as the line aboveCVE-2026-4878same vendor as the line abovesame change as the line aboveDays to revision 60
2026-06-08same kind of change as the line aboveCVE-2026-5119same vendor as the line abovesame change as the line aboveDays to revision 70
2026-06-08Record state changedCVE-2026-50265
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 3
2026-06-08published 2026-05-15Package added to advisoryGHSA-w42g-jj8w-fj77highnot named as affected when the advisory was published, now names thorsten/phpmyfaqDays to revision 24
2026-06-08published 2021-04-13Package added to advisoryGHSA-3pcr-4982-548mmoderatenot named as affected when the advisory was published, now names shopware/shopwarenot dated
2026-06-08published 2025-10-15Package added to advisoryGHSA-6p6v-m64v-jx8qCVE-2025-55039lownot named as affected when the advisory was published, now names pysparkDays to revision 236
2026-06-08published 2026-03-25Package added to advisoryGHSA-7h8w-hj9j-8rjwCVE-2026-33718highnot named as affected when the advisory was published, now names openhands-aiDays to revision 75
2026-06-08published 2022-05-02Advisory severity changedGHSA-f7w7-6pjc-wwm6CVE-2009-3555whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 1,499
2026-06-08published 2026-03-03Advisory severity changedGHSA-p4wh-cr8m-gm6cCVE-2026-22217whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 97
2026-06-08published 2025-10-15Advisory severity changedGHSA-6p6v-m64v-jx8qCVE-2025-55039whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 236
2026-06-08published 2026-05-15Advisory withdrawnGHSA-w42g-jj8w-fj77whole advisoryhighwithdrawn 2026-06-08Days to revision 24
Sat 6 Jun 2026· 1 record change · 1 advisory change
2026-06-06Product addedCVE-2025-7425not named as affected at publication, now names openshift file integrity operator - fio 1Days to revision 331
2026-06-06published 2026-03-18Advisory fix version movedGHSA-rf6x-r45m-xv3wCVE-2026-33053
pypilangflow
high
stated at publication 1.7.2, now states 1.9.0Days to revision 80
Fri 5 Jun 2026· 13 record changes · 4 advisory changes
2026-06-05Added to CISA KEVCVE-2026-28318
SolarWindsServ-U
CISA KEV
fix due 2026-06-19Not applicable: Added to CISA KEV has no earlier value
2026-06-05Fix version movedCVE-2026-32177
microsoftmicrosoft visual studio 2022 version 17.14
stated at publication 17.14.31, now states 17.14.32Release branch starts at 17.14.0.Days to revision 24
2026-06-05Affected range extendedCVE-2024-58135
srimojolicious
CPANSec
stated at publication 9.39, now states 9.45Release branch starts at 7.28.Original value first replaced 2025-05-12; this value first seen 2026-06-05.Days to revision 9
2026-06-05Product addedCVE-2025-5914not named as affected at publication, now names openshift file integrity operator - fio 1Days to revision 360
2026-06-05Product addednot named as affected at publication, now names red hat enterprise linux 6 extended lifecycle support - extensionDays to revision 30 to 42
2026-06-05same kind of change as the line aboveCVE-2026-33999same vendor as the line abovesame change as the line aboveDays to revision 42
2026-06-05same kind of change as the line aboveCVE-2026-34000same vendor as the line abovesame change as the line aboveDays to revision 30
2026-06-05same kind of change as the line aboveCVE-2026-34001same vendor as the line abovesame change as the line aboveDays to revision 42
2026-06-05same kind of change as the line aboveCVE-2026-34002same vendor as the line abovesame change as the line aboveDays to revision 30
2026-06-05same kind of change as the line aboveCVE-2026-34003same vendor as the line abovesame change as the line aboveDays to revision 42
2026-06-05CVSS base score changedCVE-2026-42250
whole record
CERT-PL
stated at publication 5.1, now states 4.8CVSS v4.0 · base scoreMediumMediumDays to revision 8
2026-06-05Record state changed
whole record
TR-CERT
stated at publication PUBLISHED, now states REJECTEDDays to revision 0
2026-06-05same kind of change as the line aboveCVE-2026-6207same vendor as the line abovesame change as the line aboveDays to revision 0
2026-06-05same kind of change as the line aboveCVE-2026-6208same vendor as the line abovesame change as the line aboveDays to revision 0
2026-06-05same kind of change as the line aboveCVE-2026-6209same vendor as the line abovesame change as the line aboveDays to revision 0
2026-06-05published 2023-08-25Package added to advisoryGHSA-q3mw-pvr8-9ggcCVE-2023-41080moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaDays to revision 1,015
2026-06-05published 2021-06-16Package added to advisoryGHSA-j39c-c8hj-x4j3CVE-2021-25122highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyotenot dated
2026-06-05published 2026-04-18Package added to advisoryGHSA-w9r4-94fj-xp69CVE-2026-32690lownot named as affected when the advisory was published, now names apache-airflowDays to revision 48
2026-06-05published 2025-09-24Package added to advisoryGHSA-776q-jw43-fhjxCVE-2025-48459criticalnot named as affected when the advisory was published, now names apache-iotdbDays to revision 254
Thu 4 Jun 2026· 4 record changes
2026-06-04Product addedCVE-2026-22226TPLinknot named as affected at publication, now names archer ax73 v2Days to revision 122
2026-06-042 commitsProduct addednot named as affected at publication, now names red hat openshift container platform 4.13Branches and original-value intervals are stated on each row.Days to revision 66 to 77
2026-06-04same kind of change as the line aboveCVE-2026-5121same vendor as the line abovesame change as the line aboveDays to revision 66
2026-06-04same kind of change as the line aboveCVE-2026-4424same vendor as the line abovesame change as the line aboveDays to revision 77
2026-06-04CVSS base score changedCVE-2025-71316
whole record
cisa-cg
stated at publication 7.8, now states 9.8CVSS v3.1 · base scoreHighCriticalDays to revision 0
Wed 3 Jun 2026· 15 record changes
2026-06-03Added to CISA KEVCVE-2026-45247
MirasvitMirasvit Full Page Cache Warmer
CISA KEV
fix due 2026-06-06Not applicable: Added to CISA KEV has no earlier value
2026-06-03Product addednot named as affected at publication, now names openshift file integrity operator - fio 1Days to revision 352
2026-06-03same kind of change as the line aboveCVE-2025-49794same vendor as the line abovesame change as the line aboveDays to revision 352
2026-06-03same kind of change as the line aboveCVE-2025-49796same vendor as the line abovesame change as the line aboveDays to revision 352
2026-06-03Product addedCVE-2026-5119not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 65
2026-06-03CVSS base score changed
whole record
autodesk
stated at publication 7.1, now states 8.1CVSS v3.1 · base scoreHighHighDays to revision 132
2026-06-03same kind of change as the line aboveCVE-2026-0533same vendor as the line abovesame change as the line aboveDays to revision 132
2026-06-03same kind of change as the line aboveCVE-2026-0534same vendor as the line abovesame change as the line aboveDays to revision 132
2026-06-03same kind of change as the line aboveCVE-2026-0535same vendor as the line abovesame change as the line aboveDays to revision 132
2026-06-03CVSS base score changed
whole record
autodesk
stated at publication 7.8, now states 8.4CVSS v3.1 · base scoreHighHighDays to revision 119
2026-06-03same kind of change as the line aboveCVE-2026-0537same vendor as the line abovesame change as the line aboveDays to revision 119
2026-06-03same kind of change as the line aboveCVE-2026-0538same vendor as the line abovesame change as the line aboveDays to revision 119
2026-06-03same kind of change as the line aboveCVE-2026-0660same vendor as the line abovesame change as the line aboveDays to revision 119
2026-06-03same kind of change as the line aboveCVE-2026-0661same vendor as the line abovesame change as the line aboveDays to revision 119
2026-06-03CVSS base score changed
whole record
autodesk
stated at publication 5.3, now states 5.5CVSS v3.1 · base scoreMediumMediumDays to revision 8
2026-06-03same kind of change as the line aboveCVE-2026-7450same vendor as the line abovesame change as the line aboveDays to revision 8
2026-06-03same kind of change as the line aboveCVE-2026-7453same vendor as the line abovesame change as the line aboveDays to revision 8
2026-06-03CVSS base score changedCVE-2026-4480
whole record
redhat
stated at publication 8.5, now states 9.0CVSS v3.1 · base scoreHighCriticalDays to revision 8
2026-06-03Record state changedCVE-2026-9642
whole record
tenable
stated at publication PUBLISHED, now states REJECTEDDays to revision 8
Tue 2 Jun 2026· 8 record changes
2026-06-02Added to CISA KEVCVE-2022-0492
LinuxKernel
CISA KEV
fix due 2026-06-05Not applicable: Added to CISA KEV has no earlier value
2026-06-02Added to CISA KEVCVE-2025-48595
AndroidFramework
CISA KEV
fix due 2026-06-05Not applicable: Added to CISA KEV has no earlier value
2026-06-02Product addednot named as affected at publication, now names red hat insights proxy 1.5Days to revision 54 to 174
2026-06-02same kind of change as the line aboveCVE-2025-14087same vendor as the line abovesame change as the line aboveDays to revision 174
2026-06-02same kind of change as the line aboveCVE-2025-14512same vendor as the line abovesame change as the line aboveDays to revision 174
2026-06-02same kind of change as the line aboveCVE-2026-2100same vendor as the line abovesame change as the line aboveDays to revision 68
2026-06-02same kind of change as the line aboveCVE-2026-4878same vendor as the line abovesame change as the line aboveDays to revision 54
2026-06-02Product addedCVE-2026-22029GitHub_Mnot named as affected at publication, now names @remix-run/routerDays to revision 144
2026-06-02CVSS base score changedCVE-2025-53345
whole record
Patchstack
stated at publication 6.5, now states 8.8CVSS v3.1 · base scoreMediumHighDays to revision 0
Mon 1 Jun 2026· 6 record changes · 2 advisory changes
2026-06-01Added to CISA KEVCVE-2024-21182
OracleWebLogic Server
CISA KEV
fix due 2026-06-04Not applicable: Added to CISA KEV has no earlier value
2026-06-01Product addedCVE-2026-4324not named as affected at publication, now names red hat satellite 6.19 for rhel 9Days to revision 76
2026-06-01Product addedCVE-2025-11234not named as affected at publication, now names red hat enterprise linux 9.0 update services for sap solutionsDays to revision 241
2026-06-01Product addednot named as affected at publication, now names fast datapath for red hat enterprise linux 10Days to revision 38
2026-06-01same kind of change as the line aboveCVE-2026-5265same vendor as the line abovesame change as the line aboveDays to revision 38
2026-06-01same kind of change as the line aboveCVE-2026-5367same vendor as the line abovesame change as the line aboveDays to revision 38
2026-06-01Record state changedCVE-2025-61081
whole record
mitre
stated at publication PUBLISHED, now states REJECTEDDays to revision 14
2026-06-01published 2026-05-18Package added to advisoryGHSA-v549-xx3c-6pc8moderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server and 1 moreDays to revision 14
2026-06-01published 2026-05-18same kind of change as the line aboveGHSA-v549-xx3c-6pc8CVE-2026-3637same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost-serverDays to revision 14
2026-06-01published 2026-05-18same kind of change as the line aboveGHSA-v549-xx3c-6pc8CVE-2026-3637same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost/server/v8Days to revision 14
Fri 29 May 2026· 8 record changes · 1 advisory change
2026-05-29Added to CISA KEVCVE-2026-0257CISA KEVfix due 2026-06-01Not applicable: Added to CISA KEV has no earlier value
2026-05-29Product addednot named as affected at publication, now names blueplanet 125 nx3 m10Days to revision 17
2026-05-29same kind of change as the line aboveCVE-2025-40946same vendor as the line abovesame change as the line aboveDays to revision 17
2026-05-29same kind of change as the line aboveCVE-2026-41125same vendor as the line abovesame change as the line aboveDays to revision 17
2026-05-29CVSS base score changedCVE-2026-0257
whole record
palo_alto
stated at publication 4.7, now states 7.8CVSS v4.0 · base scoreMediumHighDays to revision 16
2026-05-29CVSS base score changedCVE-2026-9828
whole record
NCSC.ch
stated at publication 1.2, now states 2.9CVSS v4.0 · base scoreLowLowDays to revision 1
2026-05-29Record state changed
whole record
VulnCheck
stated at publication PUBLISHED, now states REJECTEDDays to revision 53
2026-05-29same kind of change as the line aboveCVE-2026-35020same vendor as the line abovesame change as the line aboveDays to revision 53
2026-05-29same kind of change as the line aboveCVE-2026-35021same vendor as the line abovesame change as the line aboveDays to revision 53
2026-05-29same kind of change as the line aboveCVE-2026-35022same vendor as the line abovesame change as the line aboveDays to revision 53
2026-05-29published 2026-04-22Package added to advisoryGHSA-ffq5-qpvf-xq7xCVE-2026-42086moderatenot named as affected when the advisory was published, now names openc3Days to revision 37
Thu 28 May 2026· 20 record changes · 1 advisory change
2026-05-28Ransomware use confirmedCVE-2026-48027
NxNx Console
CISA KEV
stated at publication Unknown, now states KnownDays to revision 1
2026-05-28Ransomware use confirmedCVE-2026-45321
TanStackTanStack
CISA KEV
stated at publication Unknown, now states KnownDays to revision 1
2026-05-28Product addedCVE-2025-5039not named as affected at publication, now names 3ds maxDays to revision 308
2026-05-285 commitsProduct added14 rows, one per record and productnot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update support and 3 moreBranches and original-value intervals are stated on each row.Days to revision 2 to 70
2026-05-28same kind of change as the line aboveCVE-2026-34000same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 23
2026-05-28same kind of change as the line aboveCVE-2026-34002same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 23
2026-05-28same kind of change as the line aboveCVE-2026-33999same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 35
2026-05-28same kind of change as the line aboveCVE-2026-34001same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 35
2026-05-28same kind of change as the line aboveCVE-2026-34003same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 35
2026-05-28same kind of change as the line aboveCVE-2026-34000same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportDays to revision 23
2026-05-28same kind of change as the line aboveCVE-2026-34002same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportDays to revision 23
2026-05-28same kind of change as the line aboveCVE-2026-33999same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportDays to revision 35
6 more rows in this change are not listed here. Open all 14 rows
2026-05-28Product addedCVE-2026-40034VulnChecknot named as affected at publication, now names gix and 1 moreDays to revision 2
2026-05-28same kind of change as the line aboveCVE-2026-40034same vendor as the line abovenot named as affected at publication, now names gixDays to revision 2
2026-05-28same kind of change as the line aboveCVE-2026-40034same vendor as the line abovenot named as affected at publication, now names gix-submoduleDays to revision 2
2026-05-28Record state changedCVE-2026-9818
whole record
OCD
stated at publication PUBLISHED, now states REJECTEDDays to revision 0
2026-05-28published 2026-04-27Advisory withdrawnGHSA-c8g3-x47w-8q7pwhole advisoryhighwithdrawn 2026-05-28Days to revision 31
Wed 27 May 2026· 19 record changes
2026-05-27Added to CISA KEVCVE-2026-48027
NxNx Console
CISA KEV
fix due 2026-06-10Not applicable: Added to CISA KEV has no earlier value
2026-05-27Added to CISA KEVCVE-2026-45321
TanStackTanStack
CISA KEV
fix due 2026-06-10Not applicable: Added to CISA KEV has no earlier value
2026-05-27Added to CISA KEVCVE-2026-8398
DaemonDaemon Tools Lite
CISA KEV
fix due 2026-05-30Not applicable: Added to CISA KEV has no earlier value
2026-05-27Affected range extendedCVE-2026-5718
glenwpcoderdrag and drop multiple file upload for contact form 7
Wordfence
stated at publication 1.3.9.6, now states 1.3.9.7Release branch starts at 0.Days to revision 39
2026-05-27Product addedCVE-2026-9170not named as affected at publication, now names http serverDays to revision 1
2026-05-27Product addednot named as affected at publication, now names red hat update infrastructure 5Days to revision 48 to 168
2026-05-27same kind of change as the line aboveCVE-2025-14087same vendor as the line abovesame change as the line aboveDays to revision 168
2026-05-27same kind of change as the line aboveCVE-2025-14512same vendor as the line abovesame change as the line aboveDays to revision 167
2026-05-27same kind of change as the line aboveCVE-2026-2100same vendor as the line abovesame change as the line aboveDays to revision 62
2026-05-27same kind of change as the line aboveCVE-2026-4878same vendor as the line abovesame change as the line aboveDays to revision 48
2026-05-272 commitsProduct addedCVE-2026-7374not named as affected at publication, now names red hat container native virtualization 4.21 and 7 moreBranches and original-value intervals are stated on each row.Days to revision 1
2026-05-27same kind of change as the line aboveCVE-2026-7374same vendor as the line abovenot named as affected at publication, now names red hat container native virtualization 4.21Days to revision 1
2026-05-27same kind of change as the line aboveCVE-2026-7374same vendor as the line abovenot named as affected at publication, now names red hat container native virtualization 4.12Days to revision 1
2026-05-27same kind of change as the line aboveCVE-2026-7374same vendor as the line abovenot named as affected at publication, now names red hat container native virtualization 4.13Days to revision 1
2026-05-27same kind of change as the line aboveCVE-2026-7374same vendor as the line abovenot named as affected at publication, now names red hat container native virtualization 4.14Days to revision 1
2026-05-27same kind of change as the line aboveCVE-2026-7374same vendor as the line abovenot named as affected at publication, now names red hat container native virtualization 4.15Days to revision 1
2026-05-27same kind of change as the line aboveCVE-2026-7374same vendor as the line abovenot named as affected at publication, now names red hat container native virtualization 4.16Days to revision 1
2026-05-27same kind of change as the line aboveCVE-2026-7374same vendor as the line abovenot named as affected at publication, now names red hat container native virtualization 4.17Days to revision 1
2026-05-27same kind of change as the line aboveCVE-2026-7374same vendor as the line abovenot named as affected at publication, now names red hat container native virtualization 4.18Days to revision 1
2026-05-27CVSS base score changedCVE-2026-48999
whole record
zte
stated at publication 5.3, now states 5.7CVSS v3.1 · base scoreMediumMediumDays to revision 0
2026-05-27CVSS base score changedCVE-2026-49000
whole record
zte
stated at publication 5.3, now states 7.0CVSS v3.1 · base scoreMediumHighDays to revision 0
Tue 26 May 2026· 8 record changes
2026-05-26Added to CISA KEVCVE-2026-48172
LiteSpeedcPanel Plugin
CISA KEV
fix due 2026-05-29Not applicable: Added to CISA KEV has no earlier value
2026-05-26Affected range extendedCVE-2025-68648
fortinetfortianalyzer cloud
stated at publication 7.0.15, now states 7.0.16Release branch starts at 7.0.1.Days to revision 77
2026-05-26Product addedCVE-2025-23260not named as affected at publication, now names ais operatorDays to revision 336
2026-05-262 commitsProduct addedCVE-2026-4887not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update support and 1 moreBranches and original-value intervals are stated on each row.Days to revision 61
2026-05-26same kind of change as the line aboveCVE-2026-4887same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 61
2026-05-26same kind of change as the line aboveCVE-2026-4887same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportDays to revision 61
2026-05-26CVSS base score changedCVE-2026-41947
whole record
VulnCheck
stated at publication 9.1, now states 9.3CVSS v4.0 · base scoreCriticalCriticalDays to revision 8
2026-05-26CVSS base score changedCVE-2026-48132
whole record
checkpoint
stated at publication 7.4, now states 8.1CVSS v3.1 · base scoreHighHighDays to revision 0
2026-05-26CVSS base score changedCVE-2026-48134
whole record
checkpoint
stated at publication 7.6, now states 5.6CVSS v3.1 · base scoreHighMediumDays to revision 0
Fri 22 May 2026· 2 record changes
2026-05-22Added to CISA KEVCVE-2026-9082
DrupalCore
CISA KEV
fix due 2026-05-27Not applicable: Added to CISA KEV has no earlier value
2026-05-22Ransomware use confirmedCVE-2019-15107
WebminWebmin
CISA KEV
stated at publication Unknown, now states KnownDays to revision at least 451
Thu 21 May 2026· 7 record changes
2026-05-21Added to CISA KEVCVE-2025-34291
LangflowLangflow
CISA KEV
fix due 2026-06-04Not applicable: Added to CISA KEV has no earlier value
2026-05-21Added to CISA KEVCVE-2026-34926
Trend MicroApex One
CISA KEV
fix due 2026-06-04Not applicable: Added to CISA KEV has no earlier value
2026-05-21Ransomware use confirmedCVE-2013-0422
OracleJava Runtime Environment (JRE)
CISA KEV
stated at publication Unknown, now states KnownDays to revision at least 450
2026-05-21Fix version movedCVE-2026-48172
litespeed technologiescpanel plugin
mitre
stated at publication 2.4.5, now states 2.4.7Release branch starts at 2.3.same dayDays to revision 1
2026-05-21Product addedCVE-2026-48172mitrenot named as affected at publication, now names whm pluginDays to revision 1
2026-05-21Product addedCVE-2025-67972Patchstacknot named as affected at publication, now names zoho zeptomailDays to revision 90
2026-05-21Product addedCVE-2023-52355not named as affected at publication, now names red hat enterprise linux 10Days to revision 846
Wed 20 May 2026· 4 record changes
2026-05-20Added to CISA KEVCVE-2010-0249
MicrosoftInternet Explorer
CISA KEV
fix due 2026-06-03 · listed 2026-06-03Not applicable: Added to CISA KEV has no earlier value
2026-05-20Added to CISA KEVCVE-2008-4250
MicrosoftWindows
CISA KEV
fix due 2026-06-03Not applicable: Added to CISA KEV has no earlier value
2026-05-20Added to CISA KEVCVE-2009-1537
MicrosoftDirectX
CISA KEV
fix due 2026-06-03Not applicable: Added to CISA KEV has no earlier value
2026-05-20Added to CISA KEVCVE-2009-3459
AdobeAcrobat and Reader
CISA KEV
fix due 2026-06-03Not applicable: Added to CISA KEV has no earlier value

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →