There is more logic to it. We try to detect if you use ubuntu/debian and suggest those updates. From the moment we know the exploits, we show them. Probably you're talking about PHP? For PHP 5.5.25 there are the following exploits CVE-2015-3414, CVE-2015-3415, CVE-2015-3416, CVE-2015-2325, CVE-2015-2326 and CVE-2015-3152. But none of them have information yet. (see
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3152) So as soon as they are disclosed, the exploits will automatically be shown (within 5 minutes)