Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

11,999 record changes · 5,026 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
Counted changes, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Wed 20 May 2026· 17 record changes · 10 advisory changes
2026-05-20Added to CISA KEVCVE-2010-0806
MicrosoftInternet Explorer
CISA KEV
fix due 2026-06-03Not applicable: Added to CISA KEV has no earlier value
2026-05-20Added to CISA KEV
MicrosoftDefender
fix due 2026-06-03Not applicable: Added to CISA KEV has no earlier value
2026-05-20same kind of change as the line aboveCVE-2026-41091same vendor as the line abovesame change as the line aboveNot applicable: Added to CISA KEV has no earlier value
2026-05-20same kind of change as the line aboveCVE-2026-45498same vendor as the line abovesame change as the line aboveNot applicable: Added to CISA KEV has no earlier value
2026-05-20Product addedCVE-2024-49767GitHub_Mnot named as affected at publication, now names quartDays to revision 572
2026-05-203 commitsProduct added13 rows, one per record and productnot named as affected at publication, now names red hat openshift container platform 4.17 and 3 moreBranches and original-value intervals are stated on each row.Days to revision 50 to 183
2026-05-20same kind of change as the line aboveCVE-2025-61662same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.17Days to revision 183
2026-05-20same kind of change as the line aboveCVE-2026-4111same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.17Days to revision 68
2026-05-20same kind of change as the line aboveCVE-2026-4424same vendor as the line abovenot named as affected at publication, now names red hat ai inference server 3.2Days to revision 62
2026-05-20same kind of change as the line aboveCVE-2026-4424same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.17Days to revision 62
2026-05-20same kind of change as the line aboveCVE-2026-4775same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 57
2026-05-20same kind of change as the line aboveCVE-2026-5121same vendor as the line abovenot named as affected at publication, now names red hat ai inference server 3.2Days to revision 51
2026-05-20same kind of change as the line aboveCVE-2026-5121same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.17Days to revision 51
2026-05-20same kind of change as the line aboveCVE-2026-5201same vendor as the line abovenot named as affected at publication, now names red hat ai inference server 3.2Days to revision 50
5 more rows in this change are not listed here. Open all 13 rows
2026-05-20published 2024-10-09Advisory fix version movedGHSA-pfr9-2p92-qrhqmoderatestated at publication 0.22.0, now states 0.22.1Days to revision 587
2026-05-20published 2023-06-14Package added to advisoryGHSA-5wfc-hjrc-gq87CVE-2023-34620highnot named as affected when the advisory was published, now names github.com/hjson/hjson-go/v4Days to revision 1,071
2026-05-20published 2023-06-14Package added to advisoryGHSA-5wfc-hjrc-gq87CVE-2023-34620highnot named as affected when the advisory was published, now names laktak/hjsonDays to revision 1,071
2026-05-20published 2020-06-15 to 2026-04-09Package added to advisoryhighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 41
2026-05-20published 2026-04-09same kind of change as the line aboveGHSA-69cc-cv78-qc8gCVE-2026-29129same package registry as the line abovehighsame change as the line aboveDays to revision 41
2026-05-20published 2020-06-15same kind of change as the line aboveGHSA-qcxh-w3j9-58qrCVE-2019-0199same package registry as the line abovehighsame change as the line abovenot dated
2026-05-20published 2026-04-09Package added to advisory2 bandsnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote-ffmDays to revision 40 to 41
2026-05-20published 2026-04-09same kind of change as the line aboveGHSA-95jq-rwvf-vjx4CVE-2026-29145same package registry as the line abovecriticalsame change as the line aboveDays to revision 41
2026-05-20published 2026-04-09same kind of change as the line aboveGHSA-24j9-x2wg-9qv6CVE-2026-34500same package registry as the line abovemoderatesame change as the line aboveDays to revision 40
2026-05-20published 2024-12-17Package added to advisoryGHSA-653p-vg55-5652CVE-2024-54677moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcatDays to revision 519
2026-05-20published 2026-03-31Package added to advisoryGHSA-rvhj-8chj-8v3cCVE-2026-0596criticalnot named as affected when the advisory was published, now names mlflowDays to revision 49
2026-05-20published 2026-04-16Advisory severity changedGHSA-v92g-xgxw-vvmmCVE-2026-41205whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 33
Mon 18 May 2026· 2 record changes
2026-05-18Product addedCVE-2026-8149bcorgnot named as affected at publication, now names bc-ltsDays to revision 11
2026-05-18Record state changedCVE-2026-4663
whole record
Wordfence
stated at publication PUBLISHED, now states REJECTEDDays to revision 6
Fri 15 May 2026· 2 record changes
2026-05-15Added to CISA KEVCVE-2026-42897
MicrosoftMicrosoft
CISA KEV
fix due 2026-05-29Not applicable: Added to CISA KEV has no earlier value
2026-05-15Product addedCVE-2026-40379not named as affected at publication, now names microsoft entraDays to revision 3
Thu 14 May 2026· 10 record changes · 5 advisory changes
2026-05-14Added to CISA KEVCVE-2026-20182
CiscoCatalyst SD-WAN
CISA KEV
fix due 2026-05-17Not applicable: Added to CISA KEV has no earlier value
2026-05-14Ransomware use confirmedCVE-2024-1708
ConnectWiseScreenConnect
CISA KEV
stated at publication Unknown, now states KnownDays to revision 16
2026-05-14Ransomware use confirmed
SimpleHelp SimpleHelp
stated at publication Unknown, now states KnownDays to revision 20
2026-05-14same kind of change as the line aboveCVE-2024-57728same vendor as the line abovesame change as the line aboveDays to revision 20
2026-05-14same kind of change as the line aboveCVE-2024-57726same vendor as the line abovesame change as the line aboveDays to revision 20
2026-05-14Product addedCVE-2026-35433not named as affected at publication, now names microsoft .net framework 3.5 and 4 moreDays to revision 2
2026-05-14same kind of change as the line aboveCVE-2026-35433same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5Days to revision 2
2026-05-14same kind of change as the line aboveCVE-2026-35433same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5 and 4.7.2Days to revision 2
2026-05-14same kind of change as the line aboveCVE-2026-35433same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5 and 4.8Days to revision 2
2026-05-14same kind of change as the line aboveCVE-2026-35433same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 3.5 and 4.8.1Days to revision 2
2026-05-14same kind of change as the line aboveCVE-2026-35433same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 4.8Days to revision 2
2026-05-14CVSS base score changedCVE-2026-20188
whole record
cisco
stated at publication 7.5, now states 0.0CVSS v3.1 · base scoreHighNoneDays to revision 8
2026-05-14published 2022-05-17Advisory fix version movedGHSA-4j5j-58j7-6c3wCVE-2014-9706
pypidulwich
critical
stated at publication 0.9.9, now states 0.9.10Days to revision 1,459
2026-05-14published 2024-12-02Package added to advisoryGHSA-4cx5-89vm-833xlownot named as affected when the advisory was published, now names org.verapdf:library and 2 moreDays to revision 528
2026-05-14published 2024-12-02same kind of change as the line aboveGHSA-4cx5-89vm-833xCVE-2024-52800same package registry as the line abovelownot named as affected when the advisory was published, now names org.verapdf:libraryDays to revision 528
2026-05-14published 2024-12-02same kind of change as the line aboveGHSA-4cx5-89vm-833xCVE-2024-52800same package registry as the line abovelownot named as affected when the advisory was published, now names org.verapdf:library-arlingtonDays to revision 528
2026-05-14published 2024-12-02same kind of change as the line aboveGHSA-4cx5-89vm-833xCVE-2024-52800same package registry as the line abovelownot named as affected when the advisory was published, now names org.verapdf:library-jakartaDays to revision 528
2026-05-14published 2022-05-14Advisory withdrawnGHSA-9848-v244-962pCVE-2012-1007whole advisorymoderatewithdrawn 2026-05-14Days to revision 1,461
Wed 13 May 2026· 37 record changes · 1 advisory change
2026-05-13Fix version moved
microsoftmicrosoft dynamics 365 (on-premises) version 9.1
stated at publication 9.1.44.15, now states 9.1.45.11Release branch starts at 9.0.same dayDays to revision 1
2026-05-13same kind of change as the line aboveCVE-2026-42898same vendor as the line abovesame change as the line aboveRelease branch starts at 9.0.same dayDays to revision 1
2026-05-13same kind of change as the line aboveCVE-2026-42833same vendor as the line abovesame change as the line aboveRelease branch starts at 9.0.same dayDays to revision 1
2026-05-13Product addednot named as affected at publication, now names safariDays to revision 2
2026-05-13same kind of change as the line aboveCVE-2026-28847same vendor as the line abovesame change as the line aboveDays to revision 2
2026-05-13same kind of change as the line aboveCVE-2026-28883same vendor as the line abovesame change as the line aboveDays to revision 2
2026-05-13same kind of change as the line aboveCVE-2026-28901same vendor as the line abovesame change as the line aboveDays to revision 2
2026-05-13same kind of change as the line aboveCVE-2026-28902same vendor as the line abovesame change as the line aboveDays to revision 2
2026-05-13same kind of change as the line aboveCVE-2026-28903same vendor as the line abovesame change as the line aboveDays to revision 2
2026-05-13same kind of change as the line aboveCVE-2026-28904same vendor as the line abovesame change as the line aboveDays to revision 2
2026-05-13same kind of change as the line aboveCVE-2026-28905same vendor as the line abovesame change as the line aboveDays to revision 2
2026-05-13same kind of change as the line aboveCVE-2026-28907same vendor as the line abovesame change as the line aboveDays to revision 2
13 more rows in this change are not listed here. Open all 21 rows
2026-05-132 commitsProduct added8 rows, one per record and productnot named as affected at publication, now names red hat openshift container platform 4.15 and 1 moreBranches and original-value intervals are stated on each row.Days to revision 44 to 176
2026-05-13same kind of change as the line aboveCVE-2025-61662same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.15Days to revision 176
2026-05-13same kind of change as the line aboveCVE-2026-4111same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.15Days to revision 61
2026-05-13same kind of change as the line aboveCVE-2026-4424same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.15Days to revision 55
2026-05-13same kind of change as the line aboveCVE-2026-5121same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.15Days to revision 44
2026-05-13same kind of change as the line aboveCVE-2025-61662same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.14Days to revision 176
2026-05-13same kind of change as the line aboveCVE-2026-4111same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.14Days to revision 61
2026-05-13same kind of change as the line aboveCVE-2026-4424same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.14Days to revision 55
2026-05-13same kind of change as the line aboveCVE-2026-5121same vendor as the line abovenot named as affected at publication, now names red hat openshift container platform 4.14Days to revision 44
2026-05-13CVSS base score changed
whole record
adobe
stated at publication 5.5, now states 7.8CVSS v3.1 · base scoreMediumHighDays to revision 1
2026-05-13same kind of change as the line aboveCVE-2026-34683same vendor as the line abovesame change as the line aboveDays to revision 1
2026-05-13same kind of change as the line aboveCVE-2026-34684same vendor as the line abovesame change as the line aboveDays to revision 1
2026-05-13CVSS base score changedCVE-2026-44113
whole record
VulnCheck
stated at publication 6.0, now states 8.3CVSS v4.0 · base scoreMediumHighDays to revision 7
2026-05-13CVSS base score changedCVE-2025-15101
whole record
ASUS
stated at publication 8.5, now states 8.6CVSS v4.0 · base scoreHighHighDays to revision 48
2026-05-13KEV required action changedCVE-2026-0300CISA KEVstated at publication Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required., now states Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.Days to revision 7
2026-05-13Record state changedCVE-2026-8449
whole record
VulnCheck
stated at publication PUBLISHED, now states REJECTEDDays to revision 1
2026-05-13published 2026-05-05Advisory severity changedGHSA-wv26-88m5-6h59CVE-2026-42875whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 8
Tue 12 May 2026· 81 record changes · 5 advisory changes
2026-05-12Affected range extendedCVE-2025-65084
ashlar-vellum5 products
icscert
stated at publication 12.6.1204.207, now states 12.6.1204.216Release branch starts at 0.Days to revision 168
2026-05-12same kind of change as the line aboveCVE-2025-65084same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Days to revision 168
2026-05-12same kind of change as the line aboveCVE-2025-65084same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Days to revision 168
2026-05-12same kind of change as the line aboveCVE-2025-65084same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Days to revision 168
2026-05-12same kind of change as the line aboveCVE-2025-65084same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Days to revision 168
2026-05-12same kind of change as the line aboveCVE-2025-65084same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Days to revision 168
2026-05-12Affected range extendedCVE-2025-65085
ashlar-vellum5 products
icscert
stated at publication 12.6.1204.207, now states 12.6.1204.216Release branch starts at 0.Days to revision 168
2026-05-12same kind of change as the line aboveCVE-2025-65085same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Days to revision 168
2026-05-12same kind of change as the line aboveCVE-2025-65085same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Days to revision 168
2026-05-12same kind of change as the line aboveCVE-2025-65085same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Days to revision 168
2026-05-12same kind of change as the line aboveCVE-2025-65085same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Days to revision 168
2026-05-12same kind of change as the line aboveCVE-2025-65085same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Days to revision 168
2026-05-12Affected range extendedCVE-2025-62631
fortinetfortios
stated at publication 7.2.11, now states 7.2.13Release branch starts at 7.2.0.Days to revision 154
2026-05-12Product addedCVE-2026-25836not named as affected at publication, now names fortisandbox paasDays to revision 63
2026-05-12Product addedCVE-2025-23384not named as affected at publication, now names scalance sc622-2c and 5 moreDays to revision 427
2026-05-12same kind of change as the line aboveCVE-2025-23384same vendor as the line abovenot named as affected at publication, now names scalance sc622-2cDays to revision 427
2026-05-12same kind of change as the line aboveCVE-2025-23384same vendor as the line abovenot named as affected at publication, now names scalance sc626-2cDays to revision 427
2026-05-12same kind of change as the line aboveCVE-2025-23384same vendor as the line abovenot named as affected at publication, now names scalance sc632-2cDays to revision 427
2026-05-12same kind of change as the line aboveCVE-2025-23384same vendor as the line abovenot named as affected at publication, now names scalance sc636-2cDays to revision 427
2026-05-12same kind of change as the line aboveCVE-2025-23384same vendor as the line abovenot named as affected at publication, now names scalance sc642-2cDays to revision 427
2026-05-12same kind of change as the line aboveCVE-2025-23384same vendor as the line abovenot named as affected at publication, now names scalance sc646-2cDays to revision 427
2026-05-12Product addedCVE-2025-40943not named as affected at publication, now names simatic et 200sp open controller cpu 1515sp pc3 v4 cpusDays to revision 63
2026-05-12Product addednot named as affected at publication, now names red hat ai inference server 3.3Days to revision 42 to 54
2026-05-12same kind of change as the line aboveCVE-2026-4424same vendor as the line abovesame change as the line aboveDays to revision 54
2026-05-12same kind of change as the line aboveCVE-2026-5121same vendor as the line abovesame change as the line aboveDays to revision 43
2026-05-12same kind of change as the line aboveCVE-2026-5201same vendor as the line abovesame change as the line aboveDays to revision 42
2026-05-12Product added48 rows, one per record and productjpcertnot named as affected at publication, now names wmc-2lx-b and 22 moreDays to revision 98 to 998
2026-05-12same kind of change as the line aboveCVE-2023-39454same vendor as the line abovenot named as affected at publication, now names wmc-2lx-bDays to revision 998
2026-05-12same kind of change as the line aboveCVE-2023-39454same vendor as the line abovenot named as affected at publication, now names wmc-2lx2-bDays to revision 998
2026-05-12same kind of change as the line aboveCVE-2023-39454same vendor as the line abovenot named as affected at publication, now names wmc-x1800gst-bDays to revision 998
2026-05-12same kind of change as the line aboveCVE-2023-39454same vendor as the line abovenot named as affected at publication, now names wmc-x1800gst2-bDays to revision 998
2026-05-12same kind of change as the line aboveCVE-2023-39454same vendor as the line abovenot named as affected at publication, now names wrc-x3000gs3-bDays to revision 998
2026-05-12same kind of change as the line aboveCVE-2023-39454same vendor as the line abovenot named as affected at publication, now names wrc-x3000gs3a-bDays to revision 998
2026-05-12same kind of change as the line aboveCVE-2023-39454same vendor as the line abovenot named as affected at publication, now names wsc-x1800gs-bDays to revision 998
2026-05-12same kind of change as the line aboveCVE-2023-39454same vendor as the line abovenot named as affected at publication, now names wsc-x1800gs2-bDays to revision 998
40 more rows in this change are not listed here. Open all 48 rows
2026-05-12Product addednot named as affected at publication, now names tdc-x401glDays to revision 379 to 522
2026-05-12same kind of change as the line aboveCVE-2024-10771same vendor as the line abovesame change as the line aboveDays to revision 522
2026-05-12same kind of change as the line aboveCVE-2025-32471same vendor as the line abovesame change as the line aboveDays to revision 379
2026-05-12CVSS base score changedCVE-2026-29204
whole record
hackerone
stated at publication 10.0, now states 9.1CVSS v3.1 · base scoreCriticalCriticalDays to revision 0
2026-05-12CVSS base score changedCVE-2023-53878
whole record
VulnCheck
stated at publication 7.3, now states 6.9CVSS v4.0 · base scoreHighMediumDays to revision 148
2026-05-12CVSS base score changedCVE-2023-53879
whole record
VulnCheck
stated at publication 5.3, now states 6.7CVSS v4.0 · base scoreMediumMediumDays to revision 148
2026-05-12CVSS base score changed
whole record
VulnCheck
stated at publication 7.2, now states 8.6CVSS v4.0 · base scoreHighHighDays to revision 148
2026-05-12same kind of change as the line aboveCVE-2023-53883same vendor as the line abovesame change as the line aboveDays to revision 148
2026-05-12same kind of change as the line aboveCVE-2023-53885same vendor as the line abovesame change as the line aboveDays to revision 148
2026-05-12same kind of change as the line aboveCVE-2023-53888same vendor as the line abovesame change as the line aboveDays to revision 148
2026-05-12same kind of change as the line aboveCVE-2023-53889same vendor as the line abovesame change as the line aboveDays to revision 148
2026-05-12CVSS base score changedCVE-2023-53886
whole record
VulnCheck
stated at publication 5.7, now states 5.1CVSS v4.0 · base scoreMediumMediumDays to revision 148
2026-05-12Record state changedCVE-2026-22920
whole record
SICK AG
stated at publication PUBLISHED, now states REJECTEDDays to revision 117
2026-05-12published 2026-05-04Advisory severity changedGHSA-wppj-c6mr-83jjCVE-2026-44112whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2026-05-12published 2026-04-25Advisory severity changedGHSA-c4qg-j8jg-42q5CVE-2026-44117whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 17
2026-05-12published 2026-04-25Advisory severity changedGHSA-hxvm-xjvf-93f3CVE-2026-44114whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 17
2026-05-12published 2026-04-17Advisory severity changedGHSA-xmxx-7p24-h892CVE-2026-43585whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 25
2026-05-12published 2026-04-13Advisory withdrawnGHSA-rp7w-624x-95qvwhole advisorymoderatewithdrawn 2026-05-12Days to revision 29
Mon 11 May 2026· 12 record changes · 1 advisory change
2026-05-11Fix version movedCVE-2026-21523
microsoftvisual studio code
stated at publication 1.109.2, now states 1.110.1Release branch starts at 1.0.0.Days to revision 90
2026-05-11Fix version movedCVE-2026-20841
microsoftwindows notepad
stated at publication 11.2510, now states 11.2512.26.0Release branch starts at 11.0.0.Original value first replaced 2026-03-12; this value first seen 2026-05-11.Days to revision 30
2026-05-113 commitsProduct addedhackeronenot named as affected at publication, now names cpanel (cloudlinux 6, centos 6)Branches and original-value intervals are stated on each row.Days to revision 3
2026-05-11same kind of change as the line aboveCVE-2026-29201same vendor as the line abovesame change as the line aboveDays to revision 3
2026-05-11same kind of change as the line aboveCVE-2026-29203same vendor as the line abovesame change as the line aboveDays to revision 3
2026-05-11same kind of change as the line aboveCVE-2026-29202same vendor as the line abovesame change as the line aboveDays to revision 3
2026-05-11Product addedCVE-2026-20657not named as affected at publication, now names visionosDays to revision 48
2026-05-11Product addedCVE-2026-29202hackeronenot named as affected at publication, now names wp squaredDays to revision 3
2026-05-11Product addedCVE-2026-32226not named as affected at publication, now names microsoft .net framework 4.6.2/4.7/4.7.1/4.7.2 and 2 moreDays to revision 27
2026-05-11same kind of change as the line aboveCVE-2026-32226same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 4.6.2/4.7/4.7.1/4.7.2Days to revision 27
2026-05-11same kind of change as the line aboveCVE-2026-32226same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 4.7.2Days to revision 27
2026-05-11same kind of change as the line aboveCVE-2026-32226same vendor as the line abovenot named as affected at publication, now names microsoft .net framework 4.8.1Days to revision 27
2026-05-11Product addednot named as affected at publication, now names red hat openshift container platform 4.18Days to revision 42 to 53
2026-05-11same kind of change as the line aboveCVE-2026-4424same vendor as the line abovesame change as the line aboveDays to revision 53
2026-05-11same kind of change as the line aboveCVE-2026-5121same vendor as the line abovesame change as the line aboveDays to revision 42
2026-05-11published 2026-02-03Advisory withdrawnGHSA-2r8f-cf6w-x5vqwhole advisoryhighwithdrawn 2026-05-11Days to revision 97
Sun 10 May 2026· 1 record change
2026-05-10CVSS base score changedCVE-2026-5791
whole record
TR-CERT
stated at publication 9.6, now states 6.5CVSS v3.1 · base scoreCriticalMediumDays to revision 3
Sat 9 May 2026· 2 record changes
2026-05-09Product addednot named as affected at publication, now names red hat openshift container platform 4.12Days to revision 40 to 50
2026-05-09same kind of change as the line aboveCVE-2026-4424same vendor as the line abovesame change as the line aboveDays to revision 50
2026-05-09same kind of change as the line aboveCVE-2026-5121same vendor as the line abovesame change as the line aboveDays to revision 40
Fri 8 May 2026· 3 record changes · 15 advisory changes
2026-05-08Added to CISA KEVCVE-2026-42208
BerriAILiteLLM
CISA KEV
fix due 2026-05-11Not applicable: Added to CISA KEV has no earlier value
2026-05-08Product addedCVE-2026-5588bcorgnot named as affected at publication, now names bcpix-ltsDays to revision 23
2026-05-08Record state changedCVE-2026-7448
whole record
Wordfence
stated at publication PUBLISHED, now states REJECTEDDays to revision 2
2026-05-08published 2026-05-04Advisory severity changedGHSA-67wx-r9xr-x75xCVE-2026-41648whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 4
2026-05-08published 2026-05-04 to 2026-05-05Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.Days to revision 3 to 4
2026-05-08published 2026-05-04same kind of change as the line aboveGHSA-4m88-wxj4-9qj6CVE-2026-40251same package and registry as the line abovehighsame change as the line aboveDays to revision 4
2026-05-08published 2026-05-04same kind of change as the line aboveGHSA-r7w7-mmxr-47r9CVE-2026-40197same package and registry as the line abovehighsame change as the line aboveDays to revision 4
2026-05-08published 2026-05-04same kind of change as the line aboveGHSA-gc7j-g665-rxr9CVE-2026-40195same package and registry as the line abovehighsame change as the line aboveDays to revision 4
2026-05-08published 2026-05-05same kind of change as the line aboveGHSA-5mrq-x3x5-8v8fCVE-2026-40934same package and registry as the line abovehighsame change as the line aboveDays to revision 3
2026-05-08published 2026-05-04Advisory severity changedGHSA-78fc-9688-w8xwCVE-2026-40076whole advisorycriticalstated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.Days to revision 4
2026-05-08published 2026-03-31 to 2026-04-17Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 20 to 38
2026-05-08published 2026-03-31same kind of change as the line aboveGHSA-5h2w-qmfp-ggp6CVE-2026-41344same package and registry as the line abovemoderatesame change as the line aboveDays to revision 38
2026-05-08published 2026-04-17same kind of change as the line aboveGHSA-mr34-9552-qr95CVE-2026-41389same package and registry as the line abovemoderatesame change as the line aboveDays to revision 20
2026-05-08published 2026-04-07Advisory severity changedGHSA-767m-xrhc-fxm7CVE-2026-41359whole advisoryhighstated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 31
2026-05-08published 2026-05-05Advisory severity changedGHSA-gwfr-jfjf-92vvCVE-2026-7317whole advisorylowstated at publication HIGH, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 3
2026-05-08published 2026-04-30Advisory severity changedGHSA-5vh4-rgv7-p9g4CVE-2026-39383whole advisorymoderatestated at publication HIGH, now states MODERATEA CVSS version was added; the existing vectors stayed the same.Days to revision 8
2026-05-08published 2026-04-30Advisory severity changedGHSA-5q7p-7jgv-ww56CVE-2026-40280whole advisoryhighstated at publication CRITICAL, now states HIGHA CVSS version was added; the existing vectors stayed the same.Days to revision 8
2026-05-08published 2026-04-29Advisory severity changedGHSA-q4q6-r8wh-5cghCVE-2026-34084whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9
2026-05-08published 2023-11-27 to 2024-03-02Advisory withdrawnwhole advisoryhighwithdrawn 2026-05-08Days to revision 798 to 893
2026-05-08published 2023-11-27same kind of change as the line aboveGHSA-jpr7-q523-hx25same package and registry as the line abovehighwithdrawn 2026-05-08Days to revision 893
2026-05-08published 2024-03-02same kind of change as the line aboveGHSA-jr22-8qgm-4q87same package and registry as the line abovehighwithdrawn 2026-05-08Days to revision 798
Thu 7 May 2026· 4 record changes · 8 advisory changes
2026-05-07Added to CISA KEVCVE-2026-6973
IvantiEndpoint Manager Mobile (EPMM)
CISA KEV
fix due 2026-05-10Not applicable: Added to CISA KEV has no earlier value
2026-05-072 commitsProduct addednot named as affected at publication, now names red hat discovery 2Branches and original-value intervals are stated on each row.Days to revision 28 to 49
2026-05-07same kind of change as the line aboveCVE-2026-5121same vendor as the line abovesame change as the line aboveDays to revision 39
2026-05-07same kind of change as the line aboveCVE-2026-4424same vendor as the line abovesame change as the line aboveDays to revision 49
2026-05-07same kind of change as the line aboveCVE-2026-4878same vendor as the line abovesame change as the line aboveDays to revision 28
2026-05-07published 2025-07-11 to 2025-08-08Package added to advisory2 bandsnot named as affected when the advisory was published, now names github.com/pytorch/executorchDays to revision 273 to 300
2026-05-07published 2025-08-08same kind of change as the line aboveGHSA-hj95-mhgf-jxc4CVE-2025-30404same package registry as the line abovecriticalsame change as the line aboveDays to revision 273
2026-05-07published 2025-08-08same kind of change as the line aboveGHSA-xc7w-r669-48pfCVE-2025-54951same package registry as the line abovecriticalsame change as the line aboveDays to revision 273
2026-05-07published 2025-08-08same kind of change as the line aboveGHSA-84m3-f99p-cqx5CVE-2025-30405same package registry as the line abovecriticalsame change as the line aboveDays to revision 273
2026-05-07published 2025-08-08same kind of change as the line aboveGHSA-9m39-3mf3-xwchCVE-2025-54949same package registry as the line abovecriticalsame change as the line aboveDays to revision 273
2026-05-07published 2025-08-08same kind of change as the line aboveGHSA-f9hx-c6jf-3qxmCVE-2025-54950same package registry as the line abovecriticalsame change as the line aboveDays to revision 273
2026-05-07published 2025-07-11same kind of change as the line aboveGHSA-h952-963h-rv99CVE-2025-30402same package registry as the line abovehighsame change as the line aboveDays to revision 300
2026-05-07published 2026-03-16Package added to advisoryGHSA-6jj5-j4j8-8473CVE-2026-28499moderatenot named as affected when the advisory was published, now names github.com/vapor/leaf-kitDays to revision 52
2026-05-07published 2026-05-07Advisory withdrawnGHSA-j7w6-vpvq-j3gmCVE-2026-44827whole advisoryhighwithdrawn 2026-05-07Days to revision 0
Wed 6 May 2026· 5 record changes · 22 advisory changes
2026-05-06Added to CISA KEVCVE-2026-0300CISA KEVfix due 2026-05-09Not applicable: Added to CISA KEV has no earlier value
2026-05-06Product added4 rows, one per record and productnot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update support and 1 moreDays to revision 35
2026-05-06same kind of change as the line aboveCVE-2026-35091same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 35
2026-05-06same kind of change as the line aboveCVE-2026-35091same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportDays to revision 35
2026-05-06same kind of change as the line aboveCVE-2026-35092same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 35
2026-05-06same kind of change as the line aboveCVE-2026-35092same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 8.6 advanced mission critical update supportDays to revision 35
2026-05-06published 2026-04-18Advisory fix version movedGHSA-8m29-fpq5-89jjCVE-2026-41583
crates.iozebra-script
critical
stated at publication 5.0.1, now states 5.0.2Days to revision 19
2026-05-06published 2025-11-13Package added to advisoryGHSA-7wq2-32h4-9hc9highnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/auth-helpers and 8 moreDays to revision 174
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/auth-helpersDays to revision 174
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/aws-secrets-managerDays to revision 174
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/federated-authDays to revision 174
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/iamDays to revision 174
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/mysql-driverDays to revision 174
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/oktaDays to revision 174
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/otlpDays to revision 174
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/pgx-driverDays to revision 174
1 more row in this change is not listed here. Open all 9 rows
2026-05-06published 2026-04-03Advisory severity changedwhole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 34
2026-05-06published 2026-04-03same kind of change as the line aboveGHSA-6336-qqw9-v6x6CVE-2026-41341same package and registry as the line abovelowsame change as the line aboveDays to revision 34
2026-05-06published 2026-04-03same kind of change as the line aboveGHSA-rvvf-6vh3-9j43CVE-2026-41348same package and registry as the line abovelowsame change as the line aboveDays to revision 34
2026-05-06published 2026-04-03same kind of change as the line aboveGHSA-mhr7-2xmv-4c4qCVE-2026-41347same package and registry as the line abovelowsame change as the line aboveDays to revision 34
2026-05-06published 2026-04-02 to 2026-04-03Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 34
2026-05-06published 2026-04-03same kind of change as the line aboveGHSA-37v6-fxx8-xjmxCVE-2026-41351same package and registry as the line abovemoderatesame change as the line aboveDays to revision 34
2026-05-06published 2026-04-02same kind of change as the line aboveGHSA-89r3-6x4j-v7wfCVE-2026-41337same package and registry as the line abovemoderatesame change as the line aboveDays to revision 34
2026-05-06published 2026-04-02 to 2026-04-03Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 34
2026-05-06published 2026-04-03same kind of change as the line aboveGHSA-cg7q-fg22-4g98CVE-2026-41369same package and registry as the line abovehighsame change as the line aboveDays to revision 34
2026-05-06published 2026-04-02same kind of change as the line aboveGHSA-fv94-qvg8-xqpwCVE-2026-41364same package and registry as the line abovehighsame change as the line aboveDays to revision 34
2026-05-06published 2026-04-03Advisory severity changedGHSA-p464-m8x6-vhv8CVE-2026-41405whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 33
2026-05-06published 2026-03-31Advisory severity changedGHSA-j7p2-qcwm-94v4CVE-2026-41387whole advisoryhighstated at publication CRITICAL, now states HIGHA CVSS version was added; the existing vectors stayed the same.Days to revision 35
2026-05-06published 2024-03-02 to 2026-05-06Advisory withdrawnwhole advisoryhighwithdrawn 2026-05-06Days to revision 0 to 796
2026-05-06published 2026-01-15same kind of change as the line aboveGHSA-xfhx-r7ww-5995same package and registry as the line abovehighwithdrawn 2026-05-06Days to revision 111
2026-05-06published 2026-05-06same kind of change as the line aboveGHSA-hjph-f4mc-wx4csame package and registry as the line abovehighwithdrawn 2026-05-06Days to revision 0
2026-05-06published 2024-03-02same kind of change as the line aboveGHSA-hg35-mp25-qf6hsame package and registry as the line abovehighwithdrawn 2026-05-06Days to revision 796
Tue 5 May 2026· 5 record changes · 8 advisory changes
2026-05-05Ransomware use confirmedCVE-2026-41940
WebProscPanel & WHM and WP2 (WordPress Squared)
CISA KEV
stated at publication Unknown, now states KnownDays to revision 5
2026-05-052 commitsProduct addednot named as affected at publication, now names rhel-8 based middleware containersBranches and original-value intervals are stated on each row.Days to revision 36 to 99
2026-05-05same kind of change as the line aboveCVE-2025-9820same vendor as the line abovesame change as the line aboveDays to revision 99
2026-05-05same kind of change as the line aboveCVE-2025-14831same vendor as the line abovesame change as the line aboveDays to revision 85
2026-05-05same kind of change as the line aboveCVE-2026-4424same vendor as the line abovesame change as the line aboveDays to revision 47
2026-05-05same kind of change as the line aboveCVE-2026-5121same vendor as the line abovesame change as the line aboveDays to revision 36
2026-05-05published 2025-05-27Advisory fix version movedGHSA-8r88-6cj9-9fh5CVE-2025-48370
npm@supabase/auth-js
low
stated at publication 2.69.1, now states 2.70.0Days to revision 343
2026-05-05published 2025-09-03Package added to advisoryGHSA-qww7-89xh-x7m7CVE-2025-55747criticalnot named as affected when the advisory was published, now names org.xwiki.platform:xwiki-platform-webjarsDays to revision 244
2026-05-05published 2026-04-18Advisory severity changedGHSA-6ffj-2wg2-w45jCVE-2026-25917whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 17
2026-05-05published 2026-04-23Advisory severity changedGHSA-q2pw-xx38-p64jCVE-2026-29051whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 12
2026-05-05published 2026-04-15 to 2026-04-23Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 12 to 20
2026-05-05published 2026-04-23same kind of change as the line aboveGHSA-9mv3-2cwr-p262CVE-2026-40372same package and registry as the line abovecriticalsame change as the line aboveDays to revision 12
2026-05-05published 2026-04-15same kind of change as the line aboveGHSA-hv5g-26jg-pc45CVE-2026-6290same package and registry as the line abovecriticalsame change as the line aboveDays to revision 20
2026-05-05published 2026-04-10Advisory severity changedGHSA-2rhw-gw3f-477jCVE-2026-40306whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 25
2026-05-05published 2026-04-02Advisory severity changedGHSA-v569-hp3g-36wrCVE-2026-34230whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 33

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →