Skip to content

Compare published base scores

The publisher of a CVE record and a second scorer, CISA-ADP (CISA's authorised data publisher) or Red Hat SADP (Red Hat's own), scored the same flaw and got different answers. Nothing here changed: both scores are live right now.

A scanner shows you the second scorer’s number. The vendor’s advisory shows you theirs. The two follow different scoring guidance, and you act on whichever one you happened to see.

47 records

meet the reporting rule: a gap of at least one point, or a different severity band. 39 of them land in different severity bands; 219 carry two comparable scores.

Counted in records, and never added to any figure about records that changed. The second scorer put it higher in 22 of the 39 band crossings; the vendor was higher in 17. By scorer: Red Hat SADP scored 126 records twice with 1 band crossing; CISA-ADP scored 93 records twice with 38 band crossings. Not 7.4 against 7.6: Medium against Critical, which is a different ticket. 169,256 records were examined, every in-scope record in the catalog; most carry one score or none.

Score disagreements that meet the reporting rule

47 records · widest gap first

Both scores are compared under the same CVSS version. A record the vendor scored under v3.1 and an analyst scored under v4.0 is two scoring systems, not a disagreement, and is not listed here. This table includes gaps of at least one point, plus every severity-band crossing even when the gap is smaller. The population counts also retain smaller differences.

Same-version score gaps of at least one point, and all severity-band crossings, widest gap first.
CVE recordPublisherPublisher’s scoreScored again byTheir scoreGap
CVE-2025-43712mitre2.9 LowCISA-ADP8.0 High5.1higher
CVE-2024-55089mitre4.1 MediumCISA-ADP9.1 Critical5.0higher
CVE-2025-69873mitre2.9 LowCISA-ADP7.5 High4.6higher
CVE-2024-6163Checkmk5.3 MediumCISA-ADP9.8 Critical4.5higher
CVE-2026-29201hackerone8.6 HighCISA-ADP4.3 Medium4.3lower
CVE-2024-56430mitre2.9 LowCISA-ADP6.5 Medium3.6higher
CVE-2023-2094VulDB6.3 MediumCISA-ADP9.8 Critical3.5higher
CVE-2023-2245VulDB6.3 MediumCISA-ADP9.8 Critical3.5higher
CVE-2023-2660VulDB6.3 MediumCISA-ADP9.8 Critical3.5higher
CVE-2023-2682VulDB6.3 MediumCISA-ADP9.8 Critical3.5higher
CVE-2026-21639hackerone8.8 HighCISA-ADP5.4 Medium3.4lower
CVE-2023-2473VulDB4.3 MediumCISA-ADP7.5 High3.2higher
CVE-2023-26234mitre6.6 MediumCISA-ADP9.8 Critical3.2higher
CVE-2026-26477mitre4.3 MediumCISA-ADP7.5 High3.2higher
CVE-2026-60137WPScan5.9 MediumCISA-ADP9.1 Critical3.2higher
CVE-2023-32070GitHub_M9.1 CriticalCISA-ADP6.1 Medium3.0lower
CVE-2023-2521VulDB3.5 LowCISA-ADP6.1 Medium2.6higher
CVE-2023-2241VulDB5.3 MediumCISA-ADP7.8 High2.5higher
CVE-2025-69720mitre7.3 HighCISA-ADP9.8 Critical2.5higher
CVE-2023-30550GitHub_M6.8 MediumCISA-ADP4.5 Medium2.3lower
CVE-2026-63030WPScan9.8 CriticalCISA-ADP7.5 High2.3lower
CVE-2026-70369TuranSec8.8 HighCISA-ADP6.5 Medium2.3lower
CVE-2026-70370TuranSec8.8 HighCISA-ADP6.5 Medium2.3lower
CVE-2026-70371TuranSec8.8 HighCISA-ADP6.5 Medium2.3lower
CVE-2026-70372TuranSec8.8 HighCISA-ADP6.5 Medium2.3lower
CVE-2026-70373TuranSec8.8 HighCISA-ADP6.5 Medium2.3lower
CVE-2025-57176mitre6.5 MediumCISA-ADP4.3 Medium2.2lower
CVE-2023-2646VulDB4.5 MediumCISA-ADP6.5 Medium2.0higher
CVE-2025-60344mitre8.6 HighCISA-ADP6.6 Medium2.0lower
CVE-2024-52531mitre6.5 MediumCISA-ADP8.4 High1.9higher
CVE-2023-26125snyk5.6 MediumCISA-ADP7.3 High1.7higher
CVE-2023-30639mitre7.1 HighCISA-ADP5.4 Medium1.7lower
CVE-2024-8914Wordfence7.2 HighCISA-ADP5.5 Medium1.7lower
CVE-2026-6478PostgreSQL6.5 MediumRed Hat SADP8.2 High1.7higher
CVE-2023-31146GitHub_M7.5 HighCISA-ADP9.1 Critical1.6higher
CVE-2025-29628mitre9.4 CriticalCISA-ADP8.1 High1.3lower
CVE-2023-25013mitre8.6 HighCISA-ADP7.5 High1.1lower
CVE-2023-26114snyk8.2 HighCISA-ADP9.3 Critical1.1higher
CVE-2023-31207Tribe294.4 MediumCISA-ADP5.5 Medium1.1higher
CVE-2023-27035mitre6.5 MediumCISA-ADP7.5 High1.0higher
CVE-2023-30611GitHub_M4.3 MediumCISA-ADP5.3 Medium1.0higher
CVE-2025-59489mitre7.4 HighCISA-ADP8.4 High1.0higher
CVE-2026-58049VulnCheck8.6 HighRed Hat SADP7.6 High1.0lower
CVE-2025-50891mitre7.2 HighCISA-ADP6.5 Medium0.7lower
CVE-2025-59033mitre7.4 HighCISA-ADP6.7 Medium0.7lower
CVE-2025-29629mitre9.1 CriticalCISA-ADP8.8 High0.3lower
CVE-2025-50989mitre9.1 CriticalCISA-ADP8.8 High0.3lower

Not drift. Where a record's CNA and a second scorer (CISA-ADP, scoring under the Vulnrichment guidance; redhat-SADP, Red Hat scoring for its own distribution) both stated a base score on the same CVSS version and matching assessment context, and reached different answers in the snapshot. Ambiguous or differing contexts are excluded. The two follow different scoring guidance, so a gap is a difference of judgement, not a correction. Counted in records and never added to any drift figure.

A CVE record can carry the publisher’s own score and, separately, a score from an authorised data publisher: CISA-ADP, scoring under the Vulnrichment guidance, or Red Hat SADP, scoring for its own distribution. This page compares those two. It does not compare a record against its own past, which is what every other page here does.

Not counted: with anything else on this site. These are records where two parties disagree today, not records that changed, so adding this figure to a drift total would be adding two different things.

Not checked: a record carries the second score only where CISA-ADP or Red Hat SADP chose to score it, and most records carry one score or none. A record absent here may simply never have been scored twice.

As of the 2026-09-07 snapshot. How this is measured →

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

Shipped snapshot computed 2026-09-07 from catalog commit 1f78fd2580c1. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.