Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

2,159 changes · newest first · grouped by dayCSVJSONRSS

SinceClear the filter
ChangedSourceRows
Counted changes published by redhat, newest first, one line per change to a CVE record, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord, Which record was edited, by its CVE id, or how many records one collapsed line stands on.Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Sat 30 Dec 2023· 1 record change
2023-12-30Product addedCVE-2023-5408not named as affected at publication, now names red hat openshift container platform 4.14Days to revision 58
Thu 14 Dec 2023· 1 record change
2023-12-14Product addedCVE-2023-6563not named as affected at publication, now names rhel-8 based middleware containersDays to revision 0
Wed 13 Dec 2023· 3 record changes
2023-12-13Product addedCVE-2023-39417not named as affected at publication, now names red hat software collections for red hat enterprise linux 7Days to revision 124
2023-12-13Product addedCVE-2023-5868not named as affected at publication, now names red hat software collections for red hat enterprise linux 7Days to revision 3
2023-12-13Product addedCVE-2023-5870not named as affected at publication, now names red hat software collections for red hat enterprise linux 7Days to revision 3
Tue 12 Dec 2023· 3 record changes
2023-12-12Product addedCVE-2023-5557not named as affected at publication, now names red hat enterprise linux 8.2 advanced update supportDays to revision 61
2023-12-12Product addedCVE-2023-5557not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 61
2023-12-12CVSS base score changedCVE-2023-5824
whole record
redhat
stated at publication 9.6, now states 7.5CVSS v3.1 · base scoreCriticalHighDays to revision 39
Mon 11 Dec 2023· 1 record change
2023-12-11CVSS base score changedCVE-2023-5981
whole record
redhat
stated at publication 7.4, now states 5.9CVSS v3.1 · base scoreHighMediumDays to revision 13
Sun 10 Dec 2023· 1 record change
2023-12-10CVSS base score changedCVE-2023-5156
whole record
redhat
stated at publication 3.7, now states 7.5CVSS v3.1 · base scoreLowHighOriginal value first replaced 2023-10-02; this value first seen 2023-12-10.Days to revision 7
Fri 8 Dec 2023· 2 record changes
2023-12-08Product addedCVE-2023-3164
vendor not named
redhat
not named as affected at publication, now names libtiffDays to revision 36
2023-12-08CVSS base score changedCVE-2023-3164
whole record
redhat
stated at publication 4.4, now states 5.5CVSS v3.1 · base scoreMediumMediumDays to revision 36
Thu 7 Dec 2023· 1 record change
2023-12-07Product addedCVE-2023-39417not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 118
Wed 6 Dec 2023· 2 record changes
2023-12-06Product addedCVE-2023-39417not named as affected at publication, now names red hat enterprise linux 8.2 advanced update supportDays to revision 117
2023-12-06CVSS base score changedCVE-2023-4459
whole record
redhat
stated at publication 6.5, now states 5.5CVSS v3.1 · base scoreMediumMediumDays to revision 106
Fri 1 Dec 2023· 1 record change
2023-12-01CVSS base score changedCVE-2023-4237
whole record
redhat
stated at publication 6.5, now states 7.3CVSS v3.1 · base scoreMediumHighDays to revision 58
Wed 29 Nov 2023· 3 record changes
2023-11-29Product addedCVE-2023-46847not named as affected at publication, now names red hat enterprise linux 7.6 advanced update supportDays to revision 26
2023-11-29Product addedCVE-2023-46847not named as affected at publication, now names red hat enterprise linux 7.7 advanced update supportDays to revision 26
2023-11-29Product addedCVE-2023-5408not named as affected at publication, now names red hat openshift container platform 4.11Days to revision 27
Tue 28 Nov 2023· 2 record changes
2023-11-28Product addedCVE-2023-5178not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 27
2023-11-28Product addedCVE-2023-5367not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 34
Tue 21 Nov 2023· 7 record changes
2023-11-21Product addedCVE-2023-3961not named as affected at publication, now names red hat virtualization 4 for red hat enterprise linux 8Days to revision 18
2023-11-21Product addedCVE-2023-42669not named as affected at publication, now names red hat virtualization 4 for red hat enterprise linux 8Days to revision 15
2023-11-21Product addedCVE-2023-4091not named as affected at publication, now names red hat virtualization 4 for red hat enterprise linux 8Days to revision 18
2023-11-21Product addedCVE-2023-4806not named as affected at publication, now names red hat virtualization 4 for red hat enterprise linux 8Days to revision 64
2023-11-21Product addedCVE-2023-4813not named as affected at publication, now names red hat virtualization 4 for red hat enterprise linux 8Days to revision 70
2023-11-21Product addedCVE-2023-4004not named as affected at publication, now names red hat enterprise linux 8.2 advanced update supportDays to revision 113
2023-11-21Product addedCVE-2023-5367not named as affected at publication, now names red hat enterprise linux 8.2 advanced update supportDays to revision 27
Mon 20 Nov 2023· 1 record change
2023-11-20CVSS base score changedCVE-2023-46847
whole record
redhat
stated at publication 9.9, now states 8.6CVSS v3.1 · base scoreCriticalHighDays to revision 17
Thu 16 Nov 2023· 1 record change
2023-11-16Product addedCVE-2023-5408not named as affected at publication, now names red hat openshift container platform 4.12Days to revision 15
Tue 14 Nov 2023· 1 record change
2023-11-14Record state changedCVE-2023-4128
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 96
Sat 11 Nov 2023· 1 record change
2023-11-11CVSS base score changedCVE-2023-5408
whole record
redhat
stated at publication 8.2, now states 7.2CVSS v3.1 · base scoreHighHighDays to revision 10
Fri 10 Nov 2023· 1 record change
2023-11-10CVSS base score changedCVE-2023-4586
whole record
redhat
stated at publication 5.3, now states 7.4CVSS v3.1 · base scoreMediumHighDays to revision 37
Thu 9 Nov 2023· 1 record change
2023-11-09Product addedCVE-2023-5157not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 44
Wed 8 Nov 2023· 5 record changes
2023-11-08Product addedCVE-2023-3972not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 7
2023-11-08Product addedCVE-2023-46846not named as affected at publication, now names red hat enterprise linux 8.2 advanced update supportDays to revision 5
2023-11-08Product addedCVE-2023-46846not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 5
2023-11-08Product addedCVE-2023-46847not named as affected at publication, now names red hat enterprise linux 8.2 advanced update supportDays to revision 5
2023-11-08Product addedCVE-2023-46847not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 5
Fri 3 Nov 2023· 1 record change
2023-11-03CVSS base score changedCVE-2023-5380
whole record
redhat
stated at publication 5.1, now states 4.7CVSS v3.1 · base scoreMediumMediumDays to revision 9
Thu 2 Nov 2023· 1 record change
2023-11-02Product addedCVE-2023-3972not named as affected at publication, now names red hat enterprise linux 8.2 advanced update supportDays to revision 1
Wed 25 Oct 2023· 1 record change
2023-10-25Product addedCVE-2023-4853not named as affected at publication, now names rhel-8 based middleware containersDays to revision 35
Mon 23 Oct 2023· 1 record change
2023-10-23CVSS base score changedCVE-2023-39193
whole record
redhat
stated at publication 5.1, now states 6.1CVSS v3.1 · base scoreMediumMediumDays to revision 14
Tue 10 Oct 2023· 1 record change
2023-10-10Product addedCVE-2023-4004not named as affected at publication, now names red hat virtualization 4 for red hat enterprise linux 8Days to revision 71
Thu 28 Sep 2023· 1 record change
2023-09-28CVSS base score changedCVE-2023-3567
whole record
redhat
stated at publication 6.7, now states 7.1CVSS v3.1 · base scoreMediumHighDays to revision 66
Wed 20 Sep 2023· 3 record changes
2023-09-20Product addedCVE-2023-4456not named as affected at publication, now names rhol-5.5-rhel-8Days to revision 30
2023-09-20Product addedCVE-2023-4456not named as affected at publication, now names rhol-5.6-rhel-8Days to revision 30
2023-09-20Record state changedCVE-2023-4881
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 9
Mon 18 Sep 2023· 1 record change
2023-09-18CVSS base score changedCVE-2023-4387
whole record
redhat
stated at publication 6.6, now states 7.1CVSS v3.1 · base scoreMediumHighDays to revision 33
Fri 15 Sep 2023· 1 record change
2023-09-15Record state changedCVE-2023-1576
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 1
Wed 13 Sep 2023· 1 record change
2023-09-13Product addedCVE-2023-4456not named as affected at publication, now names rhol-5.7-rhel-8Days to revision 23
Tue 5 Sep 2023· 1 record change
2023-09-05Product addedCVE-2023-4004not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 36
Thu 10 Aug 2023· 1 record change
2023-08-10Record state changedCVE-2023-4205
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 3
Tue 8 Aug 2023· 1 record change
2023-08-08CVSS base score changedCVE-2023-3618
whole record
redhat
stated at publication 7.5, now states 6.5CVSS v3.1 · base scoreHighMediumDays to revision 27
Tue 1 Aug 2023· 1 record change
2023-08-01Record state changedCVE-2023-3117
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 33
Mon 24 Jul 2023· 3 record changes
2023-07-24Product addedCVE-2023-2908redhatnot named as affected at publication, now names fedoraDays to revision 25
2023-07-24Product addedCVE-2023-3338redhatnot named as affected at publication, now names fedoraDays to revision 25
2023-07-24Product addedCVE-2023-3355redhatnot named as affected at publication, now names fedoraDays to revision 27
Fri 26 May 2023· 1 record change
2023-05-26Record state changedCVE-2023-2004
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 42

Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →