Security Advisories & CVE Tracking
Published advisories, known-exploited catalogue additions, vendor patches and the remediation deadlines attached to them.
Security advisories are the one release category where timing is the whole story. A vulnerability disclosure, the vendor patch that fixes it, and the first evidence of exploitation in the wild are three separate events, sometimes days apart and occasionally in the wrong order. What you need is not a list of vulnerabilities but a timeline of them.
Volume is the practical problem. Tens of thousands of vulnerabilities are published each year and the overwhelming majority will never affect you. The useful filter is not severity score alone — it is whether the flaw affects software you actually run, whether a patch exists, and whether anyone is known to be exploiting it. A medium-severity flaw under active exploitation matters more than a critical-severity one that is theoretical.
What this category tracks
- Vulnerability disclosures
- Newly published advisories with their identifiers, affected products and severity ratings.
- Known exploited vulnerabilities
- Additions to public catalogues of flaws confirmed as being exploited, with any attached remediation dates.
- Vendor security releases
- Patches and out-of-band releases issued specifically to close a disclosed vulnerability.
- National and sector advisories
- Alerts published by national cyber agencies and sector-specific bodies.
What matters most here
Severity scores are a starting point, not an answer. A score describes how bad exploitation would be under assumed conditions; it does not know whether the affected component is exposed in your environment, whether a mitigation is already in place, or whether anyone has written an exploit. Confirmed exploitation is the signal that reliably changes priority, which is why catalogue additions are recorded as critical regardless of the underlying score.
Where this data comes from
- National cyber agency advisory feeds
- Public known-exploited-vulnerability catalogues
- Vendor security bulletins and patch announcements
- Coordinated disclosure notices from maintainers
Every indexed entry links to its primary source. See our editorial and sourcing policy for what we verify and what we do not.
Common questions
Is this a substitute for a vulnerability scanner?
No. A scanner tells you what you are running and where it is exposed. This is a chronological record of what has been published and when. The two answer different questions and the scanner is the one that knows about your environment.
Why do some advisories appear without a patch?
Because disclosure and remediation are not simultaneous. An advisory published before a fix exists is still worth recording — often with a workaround — and the patch is filed as a separate later event linked to the same identifier.
Tracked releases in Security & CVEs
The live release list for this category loads below.
Guides covering this area
Building a Release Watchlist You Will Actually Read
Most tracking setups fail within a month for the same three reasons. A practical method for choosing what to watch, how to receive it, and what to deliberately ignore.
SecurityTracking Security Advisories Without Drowning in Them
Tens of thousands of vulnerabilities are published every year and almost none of them are yours. A practical method for filtering advisories down to the ones that require action.