Frequently asked questions
Recent updates
All updatesVulnerability pages covering hundreds of products or versions now show the most relevant entries first, with the full list one click away. Those pages load faster and are much easier to scan.
A vulnerability that appears in more than one of our sources could be stored as several separate records, so monitoring it could alert you about the same vulnerability more than once. Sources are now matched together properly, so each vulnerability is recorded once and alerts once.
The vulnerabilities already split this way have now been merged, so the duplicates are gone.
Vulnerability pages show a plain-English name alongside every CWE weakness classification. Previously most of them appeared as a bare code with no explanation.
The "What to do" box no longer suggests a version number when a vulnerability affects many vendors and the underlying record does not actually name a fix. In those cases it now points you to the vendor advisories instead of guessing.
Alert emails also stop re-sending for older vulnerabilities when only background scoring data changed, and any alert that is an update to something you have already seen is now labelled as an update rather than as new.
Some advisories from feeds that publish little detail had summaries that described the wrong software. Every affected record has been rebuilt from the underlying advisory data, and the summaries now stay blank rather than guess when there is genuinely nothing to describe.