Security advisories are the one release category where timing is the whole story. A vulnerability disclosure, the vendor patch that fixes it, and the first evidence of exploitation in the wild are three separate events, sometimes days apart and occasionally in the wrong order. What you need is not a list of vulnerabilities but a timeline of them.

Volume is the practical problem. Tens of thousands of vulnerabilities are published each year and the overwhelming majority will never affect you. The useful filter is not severity score alone — it is whether the flaw affects software you actually run, whether a patch exists, and whether anyone is known to be exploiting it. A medium-severity flaw under active exploitation matters more than a critical-severity one that is theoretical.

What this category tracks

Vulnerability disclosures
Newly published advisories with their identifiers, affected products and severity ratings.
Known exploited vulnerabilities
Additions to public catalogues of flaws confirmed as being exploited, with any attached remediation dates.
Vendor security releases
Patches and out-of-band releases issued specifically to close a disclosed vulnerability.
National and sector advisories
Alerts published by national cyber agencies and sector-specific bodies.

What matters most here

Severity scores are a starting point, not an answer. A score describes how bad exploitation would be under assumed conditions; it does not know whether the affected component is exposed in your environment, whether a mitigation is already in place, or whether anyone has written an exploit. Confirmed exploitation is the signal that reliably changes priority, which is why catalogue additions are recorded as critical regardless of the underlying score.

Where this data comes from

  • National cyber agency advisory feeds
  • Public known-exploited-vulnerability catalogues
  • Vendor security bulletins and patch announcements
  • Coordinated disclosure notices from maintainers

Every indexed entry links to its primary source. See our editorial and sourcing policy for what we verify and what we do not.

Common questions

Is this a substitute for a vulnerability scanner?

No. A scanner tells you what you are running and where it is exposed. This is a chronological record of what has been published and when. The two answer different questions and the scanner is the one that knows about your environment.

Why do some advisories appear without a patch?

Because disclosure and remediation are not simultaneous. An advisory published before a fix exists is still worth recording — often with a workaround — and the patch is filed as a separate later event linked to the same identifier.

Tracked releases in Security & CVEs

The live release list for this category loads below.

Guides covering this area

More in Technology