Every change, newest first
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Kind | Record or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together. | Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|---|
| Wed 20 May 2026· 17 record changes · 10 advisory changes | |||||
| 2026-05-20 | Added to CISA KEV | CVE-2010-0806 | MicrosoftInternet Explorer CISA KEV | fix due 2026-06-03 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-05-20 | Added to CISA KEV | MicrosoftDefender | fix due 2026-06-03 | Not applicable: Added to CISA KEV has no earlier value | |
| 2026-05-20 | same kind of change as the line above | CVE-2026-41091 | same vendor as the line above | same change as the line above | Not applicable: Added to CISA KEV has no earlier value |
| 2026-05-20 | same kind of change as the line above | CVE-2026-45498 | same vendor as the line above | same change as the line above | Not applicable: Added to CISA KEV has no earlier value |
| 2026-05-20 | Product added | CVE-2024-49767 | GitHub_M | not named as affected at publication, now names quart | Days to revision 572 |
| 2026-05-203 commits | Product added | 13 rows, one per record and product | not named as affected at publication, now names red hat openshift container platform 4.17 and 3 moreBranches and original-value intervals are stated on each row. | Days to revision 50 to 183 | |
| 2026-05-20 | same kind of change as the line above | CVE-2025-61662 | same vendor as the line above | not named as affected at publication, now names red hat openshift container platform 4.17 | Days to revision 183 |
| 2026-05-20 | same kind of change as the line above | CVE-2026-4111 | same vendor as the line above | not named as affected at publication, now names red hat openshift container platform 4.17 | Days to revision 68 |
| 2026-05-20 | same kind of change as the line above | CVE-2026-4424 | same vendor as the line above | not named as affected at publication, now names red hat ai inference server 3.2 | Days to revision 62 |
| 2026-05-20 | same kind of change as the line above | CVE-2026-4424 | same vendor as the line above | not named as affected at publication, now names red hat openshift container platform 4.17 | Days to revision 62 |
| 2026-05-20 | same kind of change as the line above | CVE-2026-4775 | same vendor as the line above | not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update support | Days to revision 57 |
| 2026-05-20 | same kind of change as the line above | CVE-2026-5121 | same vendor as the line above | not named as affected at publication, now names red hat ai inference server 3.2 | Days to revision 51 |
| 2026-05-20 | same kind of change as the line above | CVE-2026-5121 | same vendor as the line above | not named as affected at publication, now names red hat openshift container platform 4.17 | Days to revision 51 |
| 2026-05-20 | same kind of change as the line above | CVE-2026-5201 | same vendor as the line above | not named as affected at publication, now names red hat ai inference server 3.2 | Days to revision 50 |
| 5 more rows in this change are not listed here. Open all 13 rows → | |||||
| 2026-05-20published 2024-10-09 | Advisory fix version moved | GHSA-pfr9-2p92-qrhq | crates.iodbn moderate | stated at publication 0.22.0, now states 0.22.1 | Days to revision 587 |
| 2026-05-20published 2023-06-14 | Package added to advisory | GHSA-5wfc-hjrc-gq87CVE-2023-34620 | high | not named as affected when the advisory was published, now names github.com/hjson/hjson-go/v4 | Days to revision 1,071 |
| 2026-05-20published 2023-06-14 | Package added to advisory | GHSA-5wfc-hjrc-gq87CVE-2023-34620 | high | not named as affected when the advisory was published, now names laktak/hjson | Days to revision 1,071 |
| 2026-05-20published 2020-06-15 to 2026-04-09 | Package added to advisory | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Days to revision 41 | |
| 2026-05-20published 2026-04-09 | same kind of change as the line above | GHSA-69cc-cv78-qc8gCVE-2026-29129 | same package registry as the line abovehigh | same change as the line above | Days to revision 41 |
| 2026-05-20published 2020-06-15 | same kind of change as the line above | GHSA-qcxh-w3j9-58qrCVE-2019-0199 | same package registry as the line abovehigh | same change as the line above | not dated |
| 2026-05-20published 2026-04-09 | Package added to advisory | 2 bands | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote-ffm | Days to revision 40 to 41 | |
| 2026-05-20published 2026-04-09 | same kind of change as the line above | GHSA-95jq-rwvf-vjx4CVE-2026-29145 | same package registry as the line abovecritical | same change as the line above | Days to revision 41 |
| 2026-05-20published 2026-04-09 | same kind of change as the line above | GHSA-24j9-x2wg-9qv6CVE-2026-34500 | same package registry as the line abovemoderate | same change as the line above | Days to revision 40 |
| 2026-05-20published 2024-12-17 | Package added to advisory | GHSA-653p-vg55-5652CVE-2024-54677 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat | Days to revision 519 |
| 2026-05-20published 2026-03-31 | Package added to advisory | GHSA-rvhj-8chj-8v3cCVE-2026-0596 | critical | not named as affected when the advisory was published, now names mlflow | Days to revision 49 |
| 2026-05-20published 2026-04-16 | Advisory severity changed | GHSA-v92g-xgxw-vvmmCVE-2026-41205 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 33 |
| Mon 18 May 2026· 2 record changes | |||||
| 2026-05-18 | Product added | CVE-2026-8149 | bcorg | not named as affected at publication, now names bc-lts | Days to revision 11 |
| 2026-05-18 | Record state changed | CVE-2026-4663 | whole record Wordfence | stated at publication PUBLISHED, now states REJECTED | Days to revision 6 |
| Fri 15 May 2026· 2 record changes | |||||
| 2026-05-15 | Added to CISA KEV | CVE-2026-42897 | MicrosoftMicrosoft CISA KEV | fix due 2026-05-29 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-05-15 | Product added | CVE-2026-40379 | not named as affected at publication, now names microsoft entra | Days to revision 3 | |
| Thu 14 May 2026· 10 record changes · 5 advisory changes | |||||
| 2026-05-14 | Added to CISA KEV | CVE-2026-20182 | CiscoCatalyst SD-WAN CISA KEV | fix due 2026-05-17 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-05-14 | Ransomware use confirmed | CVE-2024-1708 | ConnectWiseScreenConnect CISA KEV | stated at publication Unknown, now states Known | Days to revision 16 |
| 2026-05-14 | Ransomware use confirmed | SimpleHelp SimpleHelp | stated at publication Unknown, now states Known | Days to revision 20 | |
| 2026-05-14 | same kind of change as the line above | CVE-2024-57728 | same vendor as the line above | same change as the line above | Days to revision 20 |
| 2026-05-14 | same kind of change as the line above | CVE-2024-57726 | same vendor as the line above | same change as the line above | Days to revision 20 |
| 2026-05-14 | Product added | CVE-2026-35433 | not named as affected at publication, now names microsoft .net framework 3.5 and 4 more | Days to revision 2 | |
| 2026-05-14 | same kind of change as the line above | CVE-2026-35433 | same vendor as the line above | not named as affected at publication, now names microsoft .net framework 3.5 | Days to revision 2 |
| 2026-05-14 | same kind of change as the line above | CVE-2026-35433 | same vendor as the line above | not named as affected at publication, now names microsoft .net framework 3.5 and 4.7.2 | Days to revision 2 |
| 2026-05-14 | same kind of change as the line above | CVE-2026-35433 | same vendor as the line above | not named as affected at publication, now names microsoft .net framework 3.5 and 4.8 | Days to revision 2 |
| 2026-05-14 | same kind of change as the line above | CVE-2026-35433 | same vendor as the line above | not named as affected at publication, now names microsoft .net framework 3.5 and 4.8.1 | Days to revision 2 |
| 2026-05-14 | same kind of change as the line above | CVE-2026-35433 | same vendor as the line above | not named as affected at publication, now names microsoft .net framework 4.8 | Days to revision 2 |
| 2026-05-14 | CVSS base score changed | CVE-2026-20188 | whole record cisco | stated at publication 7.5, now states 0.0CVSS v3.1 · base scoreHighNone | Days to revision 8 |
| 2026-05-14published 2022-05-17 | Advisory fix version moved | GHSA-4j5j-58j7-6c3wCVE-2014-9706 | pypidulwich critical | stated at publication 0.9.9, now states 0.9.10 | Days to revision 1,459 |
| 2026-05-14published 2024-12-02 | Package added to advisory | GHSA-4cx5-89vm-833x | low | not named as affected when the advisory was published, now names org.verapdf:library and 2 more | Days to revision 528 |
| 2026-05-14published 2024-12-02 | same kind of change as the line above | GHSA-4cx5-89vm-833xCVE-2024-52800 | same package registry as the line abovelow | not named as affected when the advisory was published, now names org.verapdf:library | Days to revision 528 |
| 2026-05-14published 2024-12-02 | same kind of change as the line above | GHSA-4cx5-89vm-833xCVE-2024-52800 | same package registry as the line abovelow | not named as affected when the advisory was published, now names org.verapdf:library-arlington | Days to revision 528 |
| 2026-05-14published 2024-12-02 | same kind of change as the line above | GHSA-4cx5-89vm-833xCVE-2024-52800 | same package registry as the line abovelow | not named as affected when the advisory was published, now names org.verapdf:library-jakarta | Days to revision 528 |
| 2026-05-14published 2022-05-14 | Advisory withdrawn | GHSA-9848-v244-962pCVE-2012-1007 | whole advisorymoderate | withdrawn 2026-05-14 | Days to revision 1,461 |
| Wed 13 May 2026· 37 record changes · 1 advisory change | |||||
| 2026-05-13 | Fix version moved | microsoftmicrosoft dynamics 365 (on-premises) version 9.1 | stated at publication 9.1.44.15, now states 9.1.45.11Release branch starts at 9.0.same day | Days to revision 1 | |
| 2026-05-13 | same kind of change as the line above | CVE-2026-42898 | same vendor as the line above | same change as the line aboveRelease branch starts at 9.0.same day | Days to revision 1 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-42833 | same vendor as the line above | same change as the line aboveRelease branch starts at 9.0.same day | Days to revision 1 |
| 2026-05-13 | Product added | not named as affected at publication, now names safari | Days to revision 2 | ||
| 2026-05-13 | same kind of change as the line above | CVE-2026-28847 | same vendor as the line above | same change as the line above | Days to revision 2 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-28883 | same vendor as the line above | same change as the line above | Days to revision 2 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-28901 | same vendor as the line above | same change as the line above | Days to revision 2 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-28902 | same vendor as the line above | same change as the line above | Days to revision 2 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-28903 | same vendor as the line above | same change as the line above | Days to revision 2 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-28904 | same vendor as the line above | same change as the line above | Days to revision 2 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-28905 | same vendor as the line above | same change as the line above | Days to revision 2 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-28907 | same vendor as the line above | same change as the line above | Days to revision 2 |
| 13 more rows in this change are not listed here. Open all 21 rows → | |||||
| 2026-05-132 commits | Product added | 8 rows, one per record and product | not named as affected at publication, now names red hat openshift container platform 4.15 and 1 moreBranches and original-value intervals are stated on each row. | Days to revision 44 to 176 | |
| 2026-05-13 | same kind of change as the line above | CVE-2025-61662 | same vendor as the line above | not named as affected at publication, now names red hat openshift container platform 4.15 | Days to revision 176 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-4111 | same vendor as the line above | not named as affected at publication, now names red hat openshift container platform 4.15 | Days to revision 61 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-4424 | same vendor as the line above | not named as affected at publication, now names red hat openshift container platform 4.15 | Days to revision 55 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-5121 | same vendor as the line above | not named as affected at publication, now names red hat openshift container platform 4.15 | Days to revision 44 |
| 2026-05-13 | same kind of change as the line above | CVE-2025-61662 | same vendor as the line above | not named as affected at publication, now names red hat openshift container platform 4.14 | Days to revision 176 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-4111 | same vendor as the line above | not named as affected at publication, now names red hat openshift container platform 4.14 | Days to revision 61 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-4424 | same vendor as the line above | not named as affected at publication, now names red hat openshift container platform 4.14 | Days to revision 55 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-5121 | same vendor as the line above | not named as affected at publication, now names red hat openshift container platform 4.14 | Days to revision 44 |
| 2026-05-13 | CVSS base score changed | whole record adobe | stated at publication 5.5, now states 7.8CVSS v3.1 · base scoreMediumHigh | Days to revision 1 | |
| 2026-05-13 | same kind of change as the line above | CVE-2026-34683 | same vendor as the line above | same change as the line above | Days to revision 1 |
| 2026-05-13 | same kind of change as the line above | CVE-2026-34684 | same vendor as the line above | same change as the line above | Days to revision 1 |
| 2026-05-13 | CVSS base score changed | CVE-2026-44113 | whole record VulnCheck | stated at publication 6.0, now states 8.3CVSS v4.0 · base scoreMediumHigh | Days to revision 7 |
| 2026-05-13 | CVSS base score changed | CVE-2025-15101 | whole record ASUS | stated at publication 8.5, now states 8.6CVSS v4.0 · base scoreHighHigh | Days to revision 48 |
| 2026-05-13 | KEV required action changed | CVE-2026-0300 | Palo Alto NetworksPAN-OS CISA KEV | stated at publication Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required., now states Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch. | Days to revision 7 |
| 2026-05-13 | Record state changed | CVE-2026-8449 | whole record VulnCheck | stated at publication PUBLISHED, now states REJECTED | Days to revision 1 |
| 2026-05-13published 2026-05-05 | Advisory severity changed | GHSA-wv26-88m5-6h59CVE-2026-42875 | whole advisorymoderate | stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version. | Days to revision 8 |
| Tue 12 May 2026· 81 record changes · 5 advisory changes | |||||
| 2026-05-12 | Affected range extended | CVE-2025-65084 | ashlar-vellum5 products icscert | stated at publication 12.6.1204.207, now states 12.6.1204.216Release branch starts at 0. | Days to revision 168 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-65084 | same vendor as the line above | same change as the line aboveRelease branch starts at 0. | Days to revision 168 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-65084 | same vendor as the line above | same change as the line aboveRelease branch starts at 0. | Days to revision 168 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-65084 | same vendor as the line above | same change as the line aboveRelease branch starts at 0. | Days to revision 168 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-65084 | same vendor as the line above | same change as the line aboveRelease branch starts at 0. | Days to revision 168 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-65084 | same vendor as the line above | same change as the line aboveRelease branch starts at 0. | Days to revision 168 |
| 2026-05-12 | Affected range extended | CVE-2025-65085 | ashlar-vellum5 products icscert | stated at publication 12.6.1204.207, now states 12.6.1204.216Release branch starts at 0. | Days to revision 168 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-65085 | same vendor as the line above | same change as the line aboveRelease branch starts at 0. | Days to revision 168 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-65085 | same vendor as the line above | same change as the line aboveRelease branch starts at 0. | Days to revision 168 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-65085 | same vendor as the line above | same change as the line aboveRelease branch starts at 0. | Days to revision 168 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-65085 | same vendor as the line above | same change as the line aboveRelease branch starts at 0. | Days to revision 168 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-65085 | same vendor as the line above | same change as the line aboveRelease branch starts at 0. | Days to revision 168 |
| 2026-05-12 | Affected range extended | CVE-2025-62631 | fortinetfortios | stated at publication 7.2.11, now states 7.2.13Release branch starts at 7.2.0. | Days to revision 154 |
| 2026-05-12 | Product added | CVE-2026-25836 | not named as affected at publication, now names fortisandbox paas | Days to revision 63 | |
| 2026-05-12 | Product added | CVE-2025-23384 | not named as affected at publication, now names scalance sc622-2c and 5 more | Days to revision 427 | |
| 2026-05-12 | same kind of change as the line above | CVE-2025-23384 | same vendor as the line above | not named as affected at publication, now names scalance sc622-2c | Days to revision 427 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-23384 | same vendor as the line above | not named as affected at publication, now names scalance sc626-2c | Days to revision 427 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-23384 | same vendor as the line above | not named as affected at publication, now names scalance sc632-2c | Days to revision 427 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-23384 | same vendor as the line above | not named as affected at publication, now names scalance sc636-2c | Days to revision 427 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-23384 | same vendor as the line above | not named as affected at publication, now names scalance sc642-2c | Days to revision 427 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-23384 | same vendor as the line above | not named as affected at publication, now names scalance sc646-2c | Days to revision 427 |
| 2026-05-12 | Product added | CVE-2025-40943 | not named as affected at publication, now names simatic et 200sp open controller cpu 1515sp pc3 v4 cpus | Days to revision 63 | |
| 2026-05-12 | Product added | not named as affected at publication, now names red hat ai inference server 3.3 | Days to revision 42 to 54 | ||
| 2026-05-12 | same kind of change as the line above | CVE-2026-4424 | same vendor as the line above | same change as the line above | Days to revision 54 |
| 2026-05-12 | same kind of change as the line above | CVE-2026-5121 | same vendor as the line above | same change as the line above | Days to revision 43 |
| 2026-05-12 | same kind of change as the line above | CVE-2026-5201 | same vendor as the line above | same change as the line above | Days to revision 42 |
| 2026-05-12 | Product added | 48 rows, one per record and product | jpcert | not named as affected at publication, now names wmc-2lx-b and 22 more | Days to revision 98 to 998 |
| 2026-05-12 | same kind of change as the line above | CVE-2023-39454 | same vendor as the line above | not named as affected at publication, now names wmc-2lx-b | Days to revision 998 |
| 2026-05-12 | same kind of change as the line above | CVE-2023-39454 | same vendor as the line above | not named as affected at publication, now names wmc-2lx2-b | Days to revision 998 |
| 2026-05-12 | same kind of change as the line above | CVE-2023-39454 | same vendor as the line above | not named as affected at publication, now names wmc-x1800gst-b | Days to revision 998 |
| 2026-05-12 | same kind of change as the line above | CVE-2023-39454 | same vendor as the line above | not named as affected at publication, now names wmc-x1800gst2-b | Days to revision 998 |
| 2026-05-12 | same kind of change as the line above | CVE-2023-39454 | same vendor as the line above | not named as affected at publication, now names wrc-x3000gs3-b | Days to revision 998 |
| 2026-05-12 | same kind of change as the line above | CVE-2023-39454 | same vendor as the line above | not named as affected at publication, now names wrc-x3000gs3a-b | Days to revision 998 |
| 2026-05-12 | same kind of change as the line above | CVE-2023-39454 | same vendor as the line above | not named as affected at publication, now names wsc-x1800gs-b | Days to revision 998 |
| 2026-05-12 | same kind of change as the line above | CVE-2023-39454 | same vendor as the line above | not named as affected at publication, now names wsc-x1800gs2-b | Days to revision 998 |
| 40 more rows in this change are not listed here. Open all 48 rows → | |||||
| 2026-05-12 | Product added | not named as affected at publication, now names tdc-x401gl | Days to revision 379 to 522 | ||
| 2026-05-12 | same kind of change as the line above | CVE-2024-10771 | same vendor as the line above | same change as the line above | Days to revision 522 |
| 2026-05-12 | same kind of change as the line above | CVE-2025-32471 | same vendor as the line above | same change as the line above | Days to revision 379 |
| 2026-05-12 | CVSS base score changed | CVE-2026-29204 | whole record hackerone | stated at publication 10.0, now states 9.1CVSS v3.1 · base scoreCriticalCritical | Days to revision 0 |
| 2026-05-12 | CVSS base score changed | CVE-2023-53878 | whole record VulnCheck | stated at publication 7.3, now states 6.9CVSS v4.0 · base scoreHighMedium | Days to revision 148 |
| 2026-05-12 | CVSS base score changed | CVE-2023-53879 | whole record VulnCheck | stated at publication 5.3, now states 6.7CVSS v4.0 · base scoreMediumMedium | Days to revision 148 |
| 2026-05-12 | CVSS base score changed | whole record VulnCheck | stated at publication 7.2, now states 8.6CVSS v4.0 · base scoreHighHigh | Days to revision 148 | |
| 2026-05-12 | same kind of change as the line above | CVE-2023-53883 | same vendor as the line above | same change as the line above | Days to revision 148 |
| 2026-05-12 | same kind of change as the line above | CVE-2023-53885 | same vendor as the line above | same change as the line above | Days to revision 148 |
| 2026-05-12 | same kind of change as the line above | CVE-2023-53888 | same vendor as the line above | same change as the line above | Days to revision 148 |
| 2026-05-12 | same kind of change as the line above | CVE-2023-53889 | same vendor as the line above | same change as the line above | Days to revision 148 |
| 2026-05-12 | CVSS base score changed | CVE-2023-53886 | whole record VulnCheck | stated at publication 5.7, now states 5.1CVSS v4.0 · base scoreMediumMedium | Days to revision 148 |
| 2026-05-12 | Record state changed | CVE-2026-22920 | whole record SICK AG | stated at publication PUBLISHED, now states REJECTED | Days to revision 117 |
| 2026-05-12published 2026-05-04 | Advisory severity changed | GHSA-wppj-c6mr-83jjCVE-2026-44112 | whole advisorymoderate | stated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 8 |
| 2026-05-12published 2026-04-25 | Advisory severity changed | GHSA-c4qg-j8jg-42q5CVE-2026-44117 | whole advisorymoderate | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 17 |
| 2026-05-12published 2026-04-25 | Advisory severity changed | GHSA-hxvm-xjvf-93f3CVE-2026-44114 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 17 |
| 2026-05-12published 2026-04-17 | Advisory severity changed | GHSA-xmxx-7p24-h892CVE-2026-43585 | whole advisorycritical | stated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 25 |
| 2026-05-12published 2026-04-13 | Advisory withdrawn | GHSA-rp7w-624x-95qv | whole advisorymoderate | withdrawn 2026-05-12 | Days to revision 29 |
| Mon 11 May 2026· 12 record changes · 1 advisory change | |||||
| 2026-05-11 | Fix version moved | CVE-2026-21523 | microsoftvisual studio code | stated at publication 1.109.2, now states 1.110.1Release branch starts at 1.0.0. | Days to revision 90 |
| 2026-05-11 | Fix version moved | CVE-2026-20841 | microsoftwindows notepad | stated at publication 11.2510, now states 11.2512.26.0Release branch starts at 11.0.0.Original value first replaced 2026-03-12; this value first seen 2026-05-11. | Days to revision 30 |
| 2026-05-113 commits | Product added | hackerone | not named as affected at publication, now names cpanel (cloudlinux 6, centos 6)Branches and original-value intervals are stated on each row. | Days to revision 3 | |
| 2026-05-11 | same kind of change as the line above | CVE-2026-29201 | same vendor as the line above | same change as the line above | Days to revision 3 |
| 2026-05-11 | same kind of change as the line above | CVE-2026-29203 | same vendor as the line above | same change as the line above | Days to revision 3 |
| 2026-05-11 | same kind of change as the line above | CVE-2026-29202 | same vendor as the line above | same change as the line above | Days to revision 3 |
| 2026-05-11 | Product added | CVE-2026-20657 | not named as affected at publication, now names visionos | Days to revision 48 | |
| 2026-05-11 | Product added | CVE-2026-29202 | hackerone | not named as affected at publication, now names wp squared | Days to revision 3 |
| 2026-05-11 | Product added | CVE-2026-32226 | not named as affected at publication, now names microsoft .net framework 4.6.2/4.7/4.7.1/4.7.2 and 2 more | Days to revision 27 | |
| 2026-05-11 | same kind of change as the line above | CVE-2026-32226 | same vendor as the line above | not named as affected at publication, now names microsoft .net framework 4.6.2/4.7/4.7.1/4.7.2 | Days to revision 27 |
| 2026-05-11 | same kind of change as the line above | CVE-2026-32226 | same vendor as the line above | not named as affected at publication, now names microsoft .net framework 4.7.2 | Days to revision 27 |
| 2026-05-11 | same kind of change as the line above | CVE-2026-32226 | same vendor as the line above | not named as affected at publication, now names microsoft .net framework 4.8.1 | Days to revision 27 |
| 2026-05-11 | Product added | not named as affected at publication, now names red hat openshift container platform 4.18 | Days to revision 42 to 53 | ||
| 2026-05-11 | same kind of change as the line above | CVE-2026-4424 | same vendor as the line above | same change as the line above | Days to revision 53 |
| 2026-05-11 | same kind of change as the line above | CVE-2026-5121 | same vendor as the line above | same change as the line above | Days to revision 42 |
| 2026-05-11published 2026-02-03 | Advisory withdrawn | GHSA-2r8f-cf6w-x5vq | whole advisoryhigh | withdrawn 2026-05-11 | Days to revision 97 |
| Sun 10 May 2026· 1 record change | |||||
| 2026-05-10 | CVSS base score changed | CVE-2026-5791 | whole record TR-CERT | stated at publication 9.6, now states 6.5CVSS v3.1 · base scoreCriticalMedium | Days to revision 3 |
| Sat 9 May 2026· 2 record changes | |||||
| 2026-05-09 | Product added | not named as affected at publication, now names red hat openshift container platform 4.12 | Days to revision 40 to 50 | ||
| 2026-05-09 | same kind of change as the line above | CVE-2026-4424 | same vendor as the line above | same change as the line above | Days to revision 50 |
| 2026-05-09 | same kind of change as the line above | CVE-2026-5121 | same vendor as the line above | same change as the line above | Days to revision 40 |
| Fri 8 May 2026· 3 record changes · 15 advisory changes | |||||
| 2026-05-08 | Added to CISA KEV | CVE-2026-42208 | BerriAILiteLLM CISA KEV | fix due 2026-05-11 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-05-08 | Product added | CVE-2026-5588 | bcorg | not named as affected at publication, now names bcpix-lts | Days to revision 23 |
| 2026-05-08 | Record state changed | CVE-2026-7448 | whole record Wordfence | stated at publication PUBLISHED, now states REJECTED | Days to revision 2 |
| 2026-05-08published 2026-05-04 | Advisory severity changed | GHSA-67wx-r9xr-x75xCVE-2026-41648 | whole advisorymoderate | stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version. | Days to revision 4 |
| 2026-05-08published 2026-05-04 to 2026-05-05 | Advisory severity changed | whole advisoryhigh | stated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same. | Days to revision 3 to 4 | |
| 2026-05-08published 2026-05-04 | same kind of change as the line above | GHSA-4m88-wxj4-9qj6CVE-2026-40251 | same package and registry as the line abovehigh | same change as the line above | Days to revision 4 |
| 2026-05-08published 2026-05-04 | same kind of change as the line above | GHSA-r7w7-mmxr-47r9CVE-2026-40197 | same package and registry as the line abovehigh | same change as the line above | Days to revision 4 |
| 2026-05-08published 2026-05-04 | same kind of change as the line above | GHSA-gc7j-g665-rxr9CVE-2026-40195 | same package and registry as the line abovehigh | same change as the line above | Days to revision 4 |
| 2026-05-08published 2026-05-05 | same kind of change as the line above | GHSA-5mrq-x3x5-8v8fCVE-2026-40934 | same package and registry as the line abovehigh | same change as the line above | Days to revision 3 |
| 2026-05-08published 2026-05-04 | Advisory severity changed | GHSA-78fc-9688-w8xwCVE-2026-40076 | whole advisorycritical | stated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same. | Days to revision 4 |
| 2026-05-08published 2026-03-31 to 2026-04-17 | Advisory severity changed | whole advisorymoderate | stated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 20 to 38 | |
| 2026-05-08published 2026-03-31 | same kind of change as the line above | GHSA-5h2w-qmfp-ggp6CVE-2026-41344 | same package and registry as the line abovemoderate | same change as the line above | Days to revision 38 |
| 2026-05-08published 2026-04-17 | same kind of change as the line above | GHSA-mr34-9552-qr95CVE-2026-41389 | same package and registry as the line abovemoderate | same change as the line above | Days to revision 20 |
| 2026-05-08published 2026-04-07 | Advisory severity changed | GHSA-767m-xrhc-fxm7CVE-2026-41359 | whole advisoryhigh | stated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 31 |
| 2026-05-08published 2026-05-05 | Advisory severity changed | GHSA-gwfr-jfjf-92vvCVE-2026-7317 | whole advisorylow | stated at publication HIGH, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 3 |
| 2026-05-08published 2026-04-30 | Advisory severity changed | GHSA-5vh4-rgv7-p9g4CVE-2026-39383 | whole advisorymoderate | stated at publication HIGH, now states MODERATEA CVSS version was added; the existing vectors stayed the same. | Days to revision 8 |
| 2026-05-08published 2026-04-30 | Advisory severity changed | GHSA-5q7p-7jgv-ww56CVE-2026-40280 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHA CVSS version was added; the existing vectors stayed the same. | Days to revision 8 |
| 2026-05-08published 2026-04-29 | Advisory severity changed | GHSA-q4q6-r8wh-5cghCVE-2026-34084 | whole advisorycritical | stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version. | Days to revision 9 |
| 2026-05-08published 2023-11-27 to 2024-03-02 | Advisory withdrawn | whole advisoryhigh | withdrawn 2026-05-08 | Days to revision 798 to 893 | |
| 2026-05-08published 2023-11-27 | same kind of change as the line above | GHSA-jpr7-q523-hx25 | same package and registry as the line abovehigh | withdrawn 2026-05-08 | Days to revision 893 |
| 2026-05-08published 2024-03-02 | same kind of change as the line above | GHSA-jr22-8qgm-4q87 | same package and registry as the line abovehigh | withdrawn 2026-05-08 | Days to revision 798 |
| Thu 7 May 2026· 4 record changes · 8 advisory changes | |||||
| 2026-05-07 | Added to CISA KEV | CVE-2026-6973 | IvantiEndpoint Manager Mobile (EPMM) CISA KEV | fix due 2026-05-10 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-05-072 commits | Product added | not named as affected at publication, now names red hat discovery 2Branches and original-value intervals are stated on each row. | Days to revision 28 to 49 | ||
| 2026-05-07 | same kind of change as the line above | CVE-2026-5121 | same vendor as the line above | same change as the line above | Days to revision 39 |
| 2026-05-07 | same kind of change as the line above | CVE-2026-4424 | same vendor as the line above | same change as the line above | Days to revision 49 |
| 2026-05-07 | same kind of change as the line above | CVE-2026-4878 | same vendor as the line above | same change as the line above | Days to revision 28 |
| 2026-05-07published 2025-07-11 to 2025-08-08 | Package added to advisory | 2 bands | not named as affected when the advisory was published, now names github.com/pytorch/executorch | Days to revision 273 to 300 | |
| 2026-05-07published 2025-08-08 | same kind of change as the line above | GHSA-hj95-mhgf-jxc4CVE-2025-30404 | same package registry as the line abovecritical | same change as the line above | Days to revision 273 |
| 2026-05-07published 2025-08-08 | same kind of change as the line above | GHSA-xc7w-r669-48pfCVE-2025-54951 | same package registry as the line abovecritical | same change as the line above | Days to revision 273 |
| 2026-05-07published 2025-08-08 | same kind of change as the line above | GHSA-84m3-f99p-cqx5CVE-2025-30405 | same package registry as the line abovecritical | same change as the line above | Days to revision 273 |
| 2026-05-07published 2025-08-08 | same kind of change as the line above | GHSA-9m39-3mf3-xwchCVE-2025-54949 | same package registry as the line abovecritical | same change as the line above | Days to revision 273 |
| 2026-05-07published 2025-08-08 | same kind of change as the line above | GHSA-f9hx-c6jf-3qxmCVE-2025-54950 | same package registry as the line abovecritical | same change as the line above | Days to revision 273 |
| 2026-05-07published 2025-07-11 | same kind of change as the line above | GHSA-h952-963h-rv99CVE-2025-30402 | same package registry as the line abovehigh | same change as the line above | Days to revision 300 |
| 2026-05-07published 2026-03-16 | Package added to advisory | GHSA-6jj5-j4j8-8473CVE-2026-28499 | moderate | not named as affected when the advisory was published, now names github.com/vapor/leaf-kit | Days to revision 52 |
| 2026-05-07published 2026-05-07 | Advisory withdrawn | GHSA-j7w6-vpvq-j3gmCVE-2026-44827 | whole advisoryhigh | withdrawn 2026-05-07 | Days to revision 0 |
| Wed 6 May 2026· 5 record changes · 22 advisory changes | |||||
| 2026-05-06 | Added to CISA KEV | CVE-2026-0300 | Palo Alto NetworksPAN-OS CISA KEV | fix due 2026-05-09 | Not applicable: Added to CISA KEV has no earlier value |
| 2026-05-06 | Product added | 4 rows, one per record and product | not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update support and 1 more | Days to revision 35 | |
| 2026-05-06 | same kind of change as the line above | CVE-2026-35091 | same vendor as the line above | not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update support | Days to revision 35 |
| 2026-05-06 | same kind of change as the line above | CVE-2026-35091 | same vendor as the line above | not named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update support | Days to revision 35 |
| 2026-05-06 | same kind of change as the line above | CVE-2026-35092 | same vendor as the line above | not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update support | Days to revision 35 |
| 2026-05-06 | same kind of change as the line above | CVE-2026-35092 | same vendor as the line above | not named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update support | Days to revision 35 |
| 2026-05-06published 2026-04-18 | Advisory fix version moved | GHSA-8m29-fpq5-89jjCVE-2026-41583 | crates.iozebra-script critical | stated at publication 5.0.1, now states 5.0.2 | Days to revision 19 |
| 2026-05-06published 2025-11-13 | Package added to advisory | GHSA-7wq2-32h4-9hc9 | high | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/auth-helpers and 8 more | Days to revision 174 |
| 2026-05-06published 2025-11-13 | same kind of change as the line above | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/auth-helpers | Days to revision 174 |
| 2026-05-06published 2025-11-13 | same kind of change as the line above | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/aws-secrets-manager | Days to revision 174 |
| 2026-05-06published 2025-11-13 | same kind of change as the line above | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/federated-auth | Days to revision 174 |
| 2026-05-06published 2025-11-13 | same kind of change as the line above | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/iam | Days to revision 174 |
| 2026-05-06published 2025-11-13 | same kind of change as the line above | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/mysql-driver | Days to revision 174 |
| 2026-05-06published 2025-11-13 | same kind of change as the line above | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/okta | Days to revision 174 |
| 2026-05-06published 2025-11-13 | same kind of change as the line above | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/otlp | Days to revision 174 |
| 2026-05-06published 2025-11-13 | same kind of change as the line above | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/pgx-driver | Days to revision 174 |
| 1 more row in this change is not listed here. Open all 9 rows → | |||||
| 2026-05-06published 2026-04-03 | Advisory severity changed | whole advisorylow | stated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 34 | |
| 2026-05-06published 2026-04-03 | same kind of change as the line above | GHSA-6336-qqw9-v6x6CVE-2026-41341 | same package and registry as the line abovelow | same change as the line above | Days to revision 34 |
| 2026-05-06published 2026-04-03 | same kind of change as the line above | GHSA-rvvf-6vh3-9j43CVE-2026-41348 | same package and registry as the line abovelow | same change as the line above | Days to revision 34 |
| 2026-05-06published 2026-04-03 | same kind of change as the line above | GHSA-mhr7-2xmv-4c4qCVE-2026-41347 | same package and registry as the line abovelow | same change as the line above | Days to revision 34 |
| 2026-05-06published 2026-04-02 to 2026-04-03 | Advisory severity changed | whole advisorymoderate | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 34 | |
| 2026-05-06published 2026-04-03 | same kind of change as the line above | GHSA-37v6-fxx8-xjmxCVE-2026-41351 | same package and registry as the line abovemoderate | same change as the line above | Days to revision 34 |
| 2026-05-06published 2026-04-02 | same kind of change as the line above | GHSA-89r3-6x4j-v7wfCVE-2026-41337 | same package and registry as the line abovemoderate | same change as the line above | Days to revision 34 |
| 2026-05-06published 2026-04-02 to 2026-04-03 | Advisory severity changed | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 34 | |
| 2026-05-06published 2026-04-03 | same kind of change as the line above | GHSA-cg7q-fg22-4g98CVE-2026-41369 | same package and registry as the line abovehigh | same change as the line above | Days to revision 34 |
| 2026-05-06published 2026-04-02 | same kind of change as the line above | GHSA-fv94-qvg8-xqpwCVE-2026-41364 | same package and registry as the line abovehigh | same change as the line above | Days to revision 34 |
| 2026-05-06published 2026-04-03 | Advisory severity changed | GHSA-p464-m8x6-vhv8CVE-2026-41405 | whole advisoryhigh | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | Days to revision 33 |
| 2026-05-06published 2026-03-31 | Advisory severity changed | GHSA-j7p2-qcwm-94v4CVE-2026-41387 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHA CVSS version was added; the existing vectors stayed the same. | Days to revision 35 |
| 2026-05-06published 2024-03-02 to 2026-05-06 | Advisory withdrawn | whole advisoryhigh | withdrawn 2026-05-06 | Days to revision 0 to 796 | |
| 2026-05-06published 2026-01-15 | same kind of change as the line above | GHSA-xfhx-r7ww-5995 | same package and registry as the line abovehigh | withdrawn 2026-05-06 | Days to revision 111 |
| 2026-05-06published 2026-05-06 | same kind of change as the line above | GHSA-hjph-f4mc-wx4c | same package and registry as the line abovehigh | withdrawn 2026-05-06 | Days to revision 0 |
| 2026-05-06published 2024-03-02 | same kind of change as the line above | GHSA-hg35-mp25-qf6h | same package and registry as the line abovehigh | withdrawn 2026-05-06 | Days to revision 796 |
| Tue 5 May 2026· 5 record changes · 8 advisory changes | |||||
| 2026-05-05 | Ransomware use confirmed | CVE-2026-41940 | WebProscPanel & WHM and WP2 (WordPress Squared) CISA KEV | stated at publication Unknown, now states Known | Days to revision 5 |
| 2026-05-052 commits | Product added | not named as affected at publication, now names rhel-8 based middleware containersBranches and original-value intervals are stated on each row. | Days to revision 36 to 99 | ||
| 2026-05-05 | same kind of change as the line above | CVE-2025-9820 | same vendor as the line above | same change as the line above | Days to revision 99 |
| 2026-05-05 | same kind of change as the line above | CVE-2025-14831 | same vendor as the line above | same change as the line above | Days to revision 85 |
| 2026-05-05 | same kind of change as the line above | CVE-2026-4424 | same vendor as the line above | same change as the line above | Days to revision 47 |
| 2026-05-05 | same kind of change as the line above | CVE-2026-5121 | same vendor as the line above | same change as the line above | Days to revision 36 |
| 2026-05-05published 2025-05-27 | Advisory fix version moved | GHSA-8r88-6cj9-9fh5CVE-2025-48370 | npm@supabase/auth-js low | stated at publication 2.69.1, now states 2.70.0 | Days to revision 343 |
| 2026-05-05published 2025-09-03 | Package added to advisory | GHSA-qww7-89xh-x7m7CVE-2025-55747 | critical | not named as affected when the advisory was published, now names org.xwiki.platform:xwiki-platform-webjars | Days to revision 244 |
| 2026-05-05published 2026-04-18 | Advisory severity changed | GHSA-6ffj-2wg2-w45jCVE-2026-25917 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 17 |
| 2026-05-05published 2026-04-23 | Advisory severity changed | GHSA-q2pw-xx38-p64jCVE-2026-29051 | whole advisorylow | stated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 12 |
| 2026-05-05published 2026-04-15 to 2026-04-23 | Advisory severity changed | whole advisorycritical | stated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 12 to 20 | |
| 2026-05-05published 2026-04-23 | same kind of change as the line above | GHSA-9mv3-2cwr-p262CVE-2026-40372 | same package and registry as the line abovecritical | same change as the line above | Days to revision 12 |
| 2026-05-05published 2026-04-15 | same kind of change as the line above | GHSA-hv5g-26jg-pc45CVE-2026-6290 | same package and registry as the line abovecritical | same change as the line above | Days to revision 20 |
| 2026-05-05published 2026-04-10 | Advisory severity changed | GHSA-2rhw-gw3f-477jCVE-2026-40306 | whole advisorymoderate | stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version. | Days to revision 25 |
| 2026-05-05published 2026-04-02 | Advisory severity changed | GHSA-v569-hp3g-36wrCVE-2026-34230 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 33 |
Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.
Data sources and quality
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →