Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

2,159 changes · newest first · grouped by dayCSVJSONRSS

SinceClear all
ChangedSourceRows
Counted changes published by redhat, newest first, one line per change to a CVE record, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord, Which record was edited, by its CVE id, or how many records one collapsed line stands on.Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Tue 12 Dec 2023· 1 record change
2023-12-12CVSS base score changedCVE-2023-5824
whole record
redhat
stated at publication 9.6, now states 7.5CVSS v3.1 · base scoreCriticalHighDays to revision 39
Mon 11 Dec 2023· 1 record change
2023-12-11CVSS base score changedCVE-2023-5981
whole record
redhat
stated at publication 7.4, now states 5.9CVSS v3.1 · base scoreHighMediumDays to revision 13
Sun 10 Dec 2023· 1 record change
2023-12-10CVSS base score changedCVE-2023-5156
whole record
redhat
stated at publication 3.7, now states 7.5CVSS v3.1 · base scoreLowHighOriginal value first replaced 2023-10-02; this value first seen 2023-12-10.Days to revision 7
Fri 8 Dec 2023· 2 record changes
2023-12-08Product addedCVE-2023-3164
vendor not named
redhat
not named as affected at publication, now names libtiffDays to revision 36
2023-12-08CVSS base score changedCVE-2023-3164
whole record
redhat
stated at publication 4.4, now states 5.5CVSS v3.1 · base scoreMediumMediumDays to revision 36
Thu 7 Dec 2023· 1 record change
2023-12-07Product addedCVE-2023-39417not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 118
Wed 6 Dec 2023· 2 record changes
2023-12-06Product addedCVE-2023-39417not named as affected at publication, now names red hat enterprise linux 8.2 advanced update supportDays to revision 117
2023-12-06CVSS base score changedCVE-2023-4459
whole record
redhat
stated at publication 6.5, now states 5.5CVSS v3.1 · base scoreMediumMediumDays to revision 106
Fri 1 Dec 2023· 1 record change
2023-12-01CVSS base score changedCVE-2023-4237
whole record
redhat
stated at publication 6.5, now states 7.3CVSS v3.1 · base scoreMediumHighDays to revision 58
Wed 29 Nov 2023· 3 record changes
2023-11-29Product addedCVE-2023-46847not named as affected at publication, now names red hat enterprise linux 7.6 advanced update support and 1 moreDays to revision 26
2023-11-29same kind of change as the line aboveCVE-2023-46847same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 7.6 advanced update supportDays to revision 26
2023-11-29same kind of change as the line aboveCVE-2023-46847same vendor as the line abovenot named as affected at publication, now names red hat enterprise linux 7.7 advanced update supportDays to revision 26
2023-11-29Product addedCVE-2023-5408not named as affected at publication, now names red hat openshift container platform 4.11Days to revision 27
Tue 28 Nov 2023· 2 record changes
2023-11-282 commitsProduct addednot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportBranches and original-value intervals are stated on each row.Days to revision 27 to 34
2023-11-28same kind of change as the line aboveCVE-2023-5178same vendor as the line abovesame change as the line aboveDays to revision 27
2023-11-28same kind of change as the line aboveCVE-2023-5367same vendor as the line abovesame change as the line aboveDays to revision 34
Tue 21 Nov 2023· 7 record changes
2023-11-21Product addednot named as affected at publication, now names red hat virtualization 4 for red hat enterprise linux 8Days to revision 15 to 70
2023-11-21same kind of change as the line aboveCVE-2023-3961same vendor as the line abovesame change as the line aboveDays to revision 18
2023-11-21same kind of change as the line aboveCVE-2023-42669same vendor as the line abovesame change as the line aboveDays to revision 15
2023-11-21same kind of change as the line aboveCVE-2023-4091same vendor as the line abovesame change as the line aboveDays to revision 18
2023-11-21same kind of change as the line aboveCVE-2023-4806same vendor as the line abovesame change as the line aboveDays to revision 64
2023-11-21same kind of change as the line aboveCVE-2023-4813same vendor as the line abovesame change as the line aboveDays to revision 70
2023-11-21Product addednot named as affected at publication, now names red hat enterprise linux 8.2 advanced update supportDays to revision 27 to 113
2023-11-21same kind of change as the line aboveCVE-2023-4004same vendor as the line abovesame change as the line aboveDays to revision 113
2023-11-21same kind of change as the line aboveCVE-2023-5367same vendor as the line abovesame change as the line aboveDays to revision 27
Mon 20 Nov 2023· 1 record change
2023-11-20CVSS base score changedCVE-2023-46847
whole record
redhat
stated at publication 9.9, now states 8.6CVSS v3.1 · base scoreCriticalHighDays to revision 17
Thu 16 Nov 2023· 1 record change
2023-11-16Product addedCVE-2023-5408not named as affected at publication, now names red hat openshift container platform 4.12Days to revision 15
Tue 14 Nov 2023· 1 record change
2023-11-14Record state changedCVE-2023-4128
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 96
Sat 11 Nov 2023· 1 record change
2023-11-11CVSS base score changedCVE-2023-5408
whole record
redhat
stated at publication 8.2, now states 7.2CVSS v3.1 · base scoreHighHighDays to revision 10
Fri 10 Nov 2023· 1 record change
2023-11-10CVSS base score changedCVE-2023-4586
whole record
redhat
stated at publication 5.3, now states 7.4CVSS v3.1 · base scoreMediumHighDays to revision 37
Thu 9 Nov 2023· 1 record change
2023-11-09Product addedCVE-2023-5157not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 44
Wed 8 Nov 2023· 5 record changes
2023-11-08Product addednot named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 5 to 7
2023-11-08same kind of change as the line aboveCVE-2023-3972same vendor as the line abovesame change as the line aboveDays to revision 7
2023-11-08same kind of change as the line aboveCVE-2023-46846same vendor as the line abovesame change as the line aboveDays to revision 5
2023-11-08same kind of change as the line aboveCVE-2023-46847same vendor as the line abovesame change as the line aboveDays to revision 5
2023-11-08Product addednot named as affected at publication, now names red hat enterprise linux 8.2 advanced update supportDays to revision 5
2023-11-08same kind of change as the line aboveCVE-2023-46846same vendor as the line abovesame change as the line aboveDays to revision 5
2023-11-08same kind of change as the line aboveCVE-2023-46847same vendor as the line abovesame change as the line aboveDays to revision 5
Fri 3 Nov 2023· 1 record change
2023-11-03CVSS base score changedCVE-2023-5380
whole record
redhat
stated at publication 5.1, now states 4.7CVSS v3.1 · base scoreMediumMediumDays to revision 9
Thu 2 Nov 2023· 1 record change
2023-11-02Product addedCVE-2023-3972not named as affected at publication, now names red hat enterprise linux 8.2 advanced update supportDays to revision 1
Wed 25 Oct 2023· 1 record change
2023-10-25Product addedCVE-2023-4853not named as affected at publication, now names rhel-8 based middleware containersDays to revision 35
Mon 23 Oct 2023· 1 record change
2023-10-23CVSS base score changedCVE-2023-39193
whole record
redhat
stated at publication 5.1, now states 6.1CVSS v3.1 · base scoreMediumMediumDays to revision 14
Tue 10 Oct 2023· 1 record change
2023-10-10Product addedCVE-2023-4004not named as affected at publication, now names red hat virtualization 4 for red hat enterprise linux 8Days to revision 71
Thu 28 Sep 2023· 1 record change
2023-09-28CVSS base score changedCVE-2023-3567
whole record
redhat
stated at publication 6.7, now states 7.1CVSS v3.1 · base scoreMediumHighDays to revision 66
Wed 20 Sep 2023· 3 record changes
2023-09-20Product addedCVE-2023-4456not named as affected at publication, now names rhol-5.5-rhel-8 and 1 moreDays to revision 30
2023-09-20same kind of change as the line aboveCVE-2023-4456same vendor as the line abovenot named as affected at publication, now names rhol-5.5-rhel-8Days to revision 30
2023-09-20same kind of change as the line aboveCVE-2023-4456same vendor as the line abovenot named as affected at publication, now names rhol-5.6-rhel-8Days to revision 30
2023-09-20Record state changedCVE-2023-4881
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 9
Mon 18 Sep 2023· 1 record change
2023-09-18CVSS base score changedCVE-2023-4387
whole record
redhat
stated at publication 6.6, now states 7.1CVSS v3.1 · base scoreMediumHighDays to revision 33
Fri 15 Sep 2023· 1 record change
2023-09-15Record state changedCVE-2023-1576
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 1
Wed 13 Sep 2023· 1 record change
2023-09-13Product addedCVE-2023-4456not named as affected at publication, now names rhol-5.7-rhel-8Days to revision 23
Tue 5 Sep 2023· 1 record change
2023-09-05Product addedCVE-2023-4004not named as affected at publication, now names red hat enterprise linux 8.4 advanced mission critical update supportDays to revision 36
Thu 10 Aug 2023· 1 record change
2023-08-10Record state changedCVE-2023-4205
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 3
Tue 8 Aug 2023· 1 record change
2023-08-08CVSS base score changedCVE-2023-3618
whole record
redhat
stated at publication 7.5, now states 6.5CVSS v3.1 · base scoreHighMediumDays to revision 27
Tue 1 Aug 2023· 1 record change
2023-08-01Record state changedCVE-2023-3117
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 33
Mon 24 Jul 2023· 3 record changes
2023-07-24Product addedredhatnot named as affected at publication, now names fedoraDays to revision 25 to 27
2023-07-24same kind of change as the line aboveCVE-2023-2908same vendor as the line abovesame change as the line aboveDays to revision 25
2023-07-24same kind of change as the line aboveCVE-2023-3338same vendor as the line abovesame change as the line aboveDays to revision 25
2023-07-24same kind of change as the line aboveCVE-2023-3355same vendor as the line abovesame change as the line aboveDays to revision 27
Fri 26 May 2023· 1 record change
2023-05-26Record state changedCVE-2023-2004
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 42

Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →