Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

3,930 record edits refused · 339 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
ChangedSourceRows

These rows are not counted anywhere on this site. Checked and refused means we compared this change and then rejected it: the false positive filter for this kind of change judged it to be a false positive rather than a real change. The row is shown so you can check the filter and disagree with us, and it is counted in no figure on this site. No advisory change is here: the advisory engine counts the 2,291 version pairs its filters refused by class rather than writing them out one by one, so this view holds CVE and KEV changes only.

Rows we checked and refused, counted nowhere, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Tue 19 Nov 2024· 1 advisory change
2024-11-19published 2024-11-14Package added to advisoryGHSA-p2h2-3vg9-4p87CVE-2024-52308highnot named as affected when the advisory was published, now names github.com/cli/cliDays to revision 5
Fri 15 Nov 2024· 2 record changes
2024-11-15Affected range extendedCVE-2024-10921
mongodb incmongodb server
mongodb
stated at publication 8.0.3, now states 8.0.3Release branch starts at 8.0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 1
2024-11-15CVSS base score changedCVE-2024-52308
whole record
GitHub_M
stated at publication 8.1, now states 8.0Assessments not comparable · base scoreHighHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Mon 28 Oct 2024· 1 advisory change
2024-10-28published 2020-10-13Package added to advisoryGHSA-j257-jfvv-h3x5CVE-2020-15251moderatenot named as affected when the advisory was published, now names sopel-plugins-channelmgntnot dated
Fri 25 Oct 2024· 1 record change
2024-10-25CVSS base score changedCVE-2024-8036
whole record
ABB
stated at publication 10.0, now states 5.9Assessments not comparable · base scoreCriticalMediumNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Thu 17 Oct 2024· 4 record changes
2024-10-17CVSS base score changedCVE-2024-47130
whole record
icscert
stated at publication 8.7, now states 8.8Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 21
2024-10-17CVSS base score changedCVE-2024-47124
whole record
icscert
stated at publication 2.3, now states 4.3Assessments not comparable · base scoreLowMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 21
2024-10-17CVSS base score changedCVE-2024-47125
whole record
icscert
stated at publication 7.6, now states 8.1Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 21
2024-10-17CVSS base score changedCVE-2024-47127
whole record
icscert
stated at publication 6.0, now states 6.5Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 21
Tue 15 Oct 2024· 15 record changes
2024-10-15Fix version movedCVE-2024-9137
moxa4 products
stated at publication 3.12.1, now states 3.12.1Release branch starts at 0.not counted: Same claim, other operatorDays to revision 1
2024-10-15same kind of change as the line aboveCVE-2024-9137same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2024-10-15same kind of change as the line aboveCVE-2024-9137same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2024-10-15same kind of change as the line aboveCVE-2024-9137same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2024-10-15same kind of change as the line aboveCVE-2024-9137same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2024-10-15Fix version moved
moxanat-102 series
stated at publication 1.0.5, now states 1.0.5Release branch starts at 0.not counted: Same claim, other operatorDays to revision 1
2024-10-15same kind of change as the line aboveCVE-2024-9137same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2024-10-15same kind of change as the line aboveCVE-2024-9139same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2024-10-15Fix version moved
moxaoncell g4302-lte4 series
stated at publication 3.9, now states 3.9Release branch starts at 0.not counted: Same claim, other operatorDays to revision 1
2024-10-15same kind of change as the line aboveCVE-2024-9137same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2024-10-15same kind of change as the line aboveCVE-2024-9139same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2024-10-15Fix version moved
moxatn-4900 series
stated at publication 3.6, now states 3.6Release branch starts at 0.not counted: Same claim, other operatorDays to revision 1
2024-10-15same kind of change as the line aboveCVE-2024-9137same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2024-10-15same kind of change as the line aboveCVE-2024-9139same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2024-10-15Fix version movedCVE-2024-9139
moxa4 products
stated at publication 3.12.1, now states 3.12.1Release branch starts at 0.not counted: Same claim, other operatorDays to revision 1
2024-10-15same kind of change as the line aboveCVE-2024-9139same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2024-10-15same kind of change as the line aboveCVE-2024-9139same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2024-10-15same kind of change as the line aboveCVE-2024-9139same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2024-10-15same kind of change as the line aboveCVE-2024-9139same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lt` rewritten as `lte` on the same or the next release — the same claim under the other operatorDays to revision 1
2024-10-15CVSS base score changedCVE-2023-22644
whole record
suse
stated at publication 3.8, now states 9.4Assessments not comparable · base scoreLowCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 391
Mon 14 Oct 2024· 1 advisory change
2024-10-14published 2024-09-04Package added to advisoryGHSA-7h5p-mmpp-hgmmCVE-2024-43405moderatenot named as affected when the advisory was published, now names github.com/projectdiscovery/nuclei/v3Days to revision 40
Fri 11 Oct 2024· 1 record change
2024-10-11CVSS base score changedCVE-2023-39363
whole record
GitHub_M
stated at publication 5.9, now states 9.1Assessments not comparable · base scoreMediumCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 431
Wed 9 Oct 2024· 2 advisory changes
2024-10-09published 2024-10-01Package added to advisoryGHSA-fhqq-8f65-5xfcCVE-2024-9407moderatenot named as affected when the advisory was published, now names github.com/containers/podmanDays to revision 8
2024-10-09published 2024-10-01Package added to advisoryGHSA-3h3x-2hwv-hr52CVE-2024-9355highnot named as affected when the advisory was published, now names github.com/golang-fips/opensslDays to revision 8
Mon 7 Oct 2024· 1 record change · 1 advisory change
2024-10-07CVSS base score changedCVE-2024-47967
whole record
Solidigm
stated at publication 10.0, now states 4.4Assessments not comparable · base scoreCriticalMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 0
2024-10-07published 2018-07-13Package added to advisoryGHSA-xcp8-hh74-f6mcCVE-2017-2592highnot named as affected when the advisory was published, now names oslo-middlewarenot dated
Tue 1 Oct 2024· 1 record change
2024-10-01CVSS base score changedCVE-2024-45613
whole record
GitHub_M
stated at publication 7.2, now states 5.1Assessments not comparable · base scoreHighMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 6
Thu 26 Sep 2024· 2 record changes
2024-09-26Affected range extended
papercutpapercut ng, papercut mf
stated at publication 23.0.8, now states 23.0.9Release branch starts at 0.not counted: Same claim, other operatorDays to revision 135
2024-09-26same kind of change as the line aboveCVE-2024-3037same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 135
2024-09-26same kind of change as the line aboveCVE-2024-4712same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 135
Fri 20 Sep 2024· 4 record changes
2024-09-20CVSS base score changedCVE-2023-24477
whole record
Nozomi
stated at publication 5.0, now states 7.0Assessments not comparable · base scoreMediumHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 408
2024-09-20CVSS base score changedCVE-2023-2567
whole record
Nozomi
stated at publication 7.6, now states 8.8Assessments not comparable · base scoreHighHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 367
2024-09-202 commitsCVSS base score changed
whole record
Nozomi
stated at publication 7.1, now states 8.8Assessments not comparable · base scoreHighHighBranches and original-value intervals are stated on each row.not counted: CVSS assessments are not comparableDays to revision 408
2024-09-20same kind of change as the line aboveCVE-2023-23574same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 408
2024-09-20same kind of change as the line aboveCVE-2023-22378same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 408
Mon 16 Sep 2024· 7 advisory changes
2024-09-16published 2024-01-31Package added to advisoryGHSA-4pwp-cx67-5cpxCVE-2019-19499moderatenot named as affected when the advisory was published, now names github.com/grafana/grafanaDays to revision 229
2024-09-16published 2024-01-30 to 2024-01-31Package added to advisory3 bandsnot named as affected when the advisory was published, now names github.com/hashicorp/vaultDays to revision 230
2024-09-16published 2024-01-30same kind of change as the line aboveGHSA-m979-w9wj-qfj9CVE-2020-10660same package registry as the line abovemoderatesame change as the line aboveDays to revision 230
2024-09-16published 2024-01-31same kind of change as the line aboveGHSA-4mp7-2m29-gqxfCVE-2020-16251same package registry as the line abovehighsame change as the line aboveDays to revision 230
2024-09-16published 2024-01-30same kind of change as the line aboveGHSA-j6vv-vv26-rh7cCVE-2020-10661same package registry as the line abovecriticalsame change as the line aboveDays to revision 230
2024-09-16published 2024-09-03Package added to advisoryGHSA-g5xx-c4hv-9ccclownot named as affected when the advisory was published, now names github.com/cometbft/cometbftDays to revision 13
2024-09-16published 2024-08-26Package added to advisoryGHSA-cj55-gc7m-wvcqCVE-2024-45258moderatenot named as affected when the advisory was published, now names github.com/imroc/reqDays to revision 22
2024-09-16published 2022-05-13Package added to advisoryGHSA-wp7w-vx86-vj9hCVE-2018-10856highnot named as affected when the advisory was published, now names github.com/containers/podmanDays to revision 858
Wed 11 Sep 2024· 1 advisory change
2024-09-11published 2024-06-10Package added to advisoryGHSA-3mwc-2cj7-gx8cCVE-2024-5389moderatenot named as affected when the advisory was published, now names lunaryDays to revision 94
Tue 10 Sep 2024· 1 record change
2024-09-10CVSS base score changedCVE-2024-21483
whole record
siemens
stated at publication 4.6, now states 5.1Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 182
Mon 9 Sep 2024· 2 record changes
2024-09-09CVSS base score changedCVE-2024-2911
whole record
VulDB
stated at publication 5.0, now states 6.9Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 167
2024-09-09CVSS base score changedCVE-2024-2935
whole record
VulDB
stated at publication 4.0, now states 5.3Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 167
Sat 7 Sep 2024· 3 record changes
2024-09-07Affected range extendedCVE-2024-6923PSFstated at publication 3.13.0rc2, now states 3.13.0rc2Release branch starts at 0.Original value first replaced 2024-08-07; this value first seen 2024-09-07.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 6
2024-09-07Affected range extendedPSFstated at publication 3.13.0, now states 3.13.0rc2Release branch starts at 0.not counted: Same claim, other operatorDays to revision 15 to 18
2024-09-07same kind of change as the line aboveCVE-2024-7592same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 18
2024-09-07same kind of change as the line aboveCVE-2024-8088same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 15
Fri 6 Sep 2024· 1 advisory change
2024-09-06published 2024-09-05Package added to advisoryGHSA-7q74-g774-7x3ghighnot named as affected when the advisory was published, now names github.com/cosmos/interchain-securityDays to revision 1
Thu 5 Sep 2024· 1 record change
2024-09-05CVSS base score changedCVE-2024-5956
whole record
trellix
stated at publication 6.9, now states 6.5Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 0
Sun 25 Aug 2024· 1 record change
2024-08-25CVSS base score changedCVE-2024-1430
whole record
VulDB
stated at publication 4.3, now states 5.3Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 196
Thu 22 Aug 2024· 1 record change
2024-08-22CVSS base score changedCVE-2024-39776
whole record
icscert
stated at publication 7.5, now states 8.7Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 0
Fri 16 Aug 2024· 1 record change
2024-08-16CVSS base score changedCVE-2024-32673
whole record
samsung.tv_appliance
stated at publication 0.0, now states 6.7Assessments not comparable · base scoreNoneMediumNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 44
Wed 14 Aug 2024· 1 advisory change
2024-08-14published 2022-05-24Package added to advisoryGHSA-w7pm-cc4v-f3g8CVE-2020-7961criticalnot named as affected when the advisory was published, now names com.liferay.portal:com.liferay.portal.kernelnot dated
Tue 13 Aug 2024· 2 record changes
2024-08-13CVSS base score changedCVE-2023-44373
whole record
siemens
stated at publication 9.1, now states 9.4Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 273
2024-08-13CVSS base score changedCVE-2024-32637
whole record
siemens
stated at publication 3.3, now states 4.8Assessments not comparable · base scoreLowMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 91
Thu 8 Aug 2024· 3 advisory changes
2024-08-08published 2024-08-08Advisory fix version movedGHSA-rg2q-2jh9-447q
gogithub.com/cosmwasm/wasmvm
moderate
stated at publication 1.5.3, now states 1.5.4Days to revision 0
2024-08-08published 2024-08-08Advisory fix version movedGHSA-rg2q-2jh9-447q
gogithub.com/cosmwasm/wasmvm/v2
moderate
stated at publication 2.0.2, now states 2.0.3Days to revision 0
2024-08-08published 2024-08-08Advisory fix version movedGHSA-rg2q-2jh9-447q
gogithub.com/cosmwasm/wasmvm/v2
moderate
stated at publication 2.1.1, now states 2.1.2Days to revision 0
Wed 7 Aug 2024· 2 advisory changes
2024-08-07published 2024-08-02Package added to advisoryGHSA-rpcc-p8xm-rc6pCVE-2024-3056highnot named as affected when the advisory was published, now names github.com/containers/podmanDays to revision 5
2024-08-07published 2024-07-24Package added to advisoryGHSA-v8wx-v5jq-qhhwCVE-2024-41666moderatenot named as affected when the advisory was published, now names github.com/argoproj/argo-cd/v2Days to revision 14
Tue 6 Aug 2024· 1 record change
2024-08-06CVSS base score changedCVE-2024-5913
whole record
palo_alto
stated at publication 5.4, now states 6.1Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 26
Thu 1 Aug 2024· 3 record changes
2024-08-01Affected range extendedCVE-2024-3219PSFstated at publication 3.13.0b4, now states 3.13.0rc1Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 3
2024-08-01Affected range extendedCVE-2024-37956
vektor,inc.vk all in one expansion unit
Patchstack
stated at publication 9.98.1.0, now states 9.99.1.0Release branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bumpDays to revision 12
2024-08-01CVSS base score changedCVE-2024-7211
whole record
1E
stated at publication 5.0, now states 4.7Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 0
Thu 18 Jul 2024· 1 record change
2024-07-18CVSS base score changedCVE-2024-21586
whole record
juniper
stated at publication 8.7, now states 7.5Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 17
Wed 17 Jul 2024· 1 record change
2024-07-17CVSS base score changedCVE-2024-3735
whole record
VulDB
stated at publication 3.7, now states 6.3Assessments not comparable · base scoreLowMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 95
Thu 11 Jul 2024· 2 record changes
2024-07-11CVSS base score changedCVE-2024-4879
whole record
SN
stated at publication 9.3, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 1
2024-07-11CVSS base score changedCVE-2024-5217
whole record
SN
stated at publication 9.2, now states 9.8Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 1
Tue 9 Jul 2024· 2 record changes · 2 advisory changes
2024-07-09CVSS base score changedCVE-2023-46280
whole record
siemens
stated at publication 6.5, now states 8.2Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 56
2024-07-09CVSS base score changedCVE-2023-50821
whole record
siemens
stated at publication 6.2, now states 6.9Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 91
2024-07-09published 2024-07-05Package added to advisoryGHSA-gxrv-wf35-62w9highnot named as affected when the advisory was published, now names github.com/traefik/traefik/v2 and 1 moreDays to revision 4
2024-07-09published 2024-07-05same kind of change as the line aboveGHSA-gxrv-wf35-62w9CVE-2024-39321same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/traefik/traefik/v2Days to revision 4
2024-07-09published 2024-07-05same kind of change as the line aboveGHSA-gxrv-wf35-62w9CVE-2024-39321same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/traefik/traefik/v3Days to revision 4
Mon 8 Jul 2024· 3 advisory changes
2024-07-08published 2024-02-03Package added to advisory2 bandsnot named as affected when the advisory was published, now names go.etcd.io/etcd/v3Days to revision 157
2024-07-08published 2024-02-03same kind of change as the line aboveGHSA-vjg6-93fv-qv64same package registry as the line abovelowsame change as the line aboveDays to revision 157
2024-07-08published 2024-02-03same kind of change as the line aboveGHSA-pm3m-32r3-7mfhsame package registry as the line abovelowsame change as the line aboveDays to revision 157
2024-07-08published 2024-02-03same kind of change as the line aboveGHSA-j86v-2vjr-fg8fsame package registry as the line abovemoderatesame change as the line aboveDays to revision 157
Fri 21 Jun 2024· 1 record change
2024-06-21CVSS base score changedCVE-2024-6218
whole record
VulDB
stated at publication 6.5, now states 7.5Assessments not comparable · base scoreMediumHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Wed 19 Jun 2024· 1 record change
2024-06-19Fix version movedCVE-2024-0985
vendor not namedpostgresql
PostgreSQL
stated at publication 15.6, now states 16.2Release branch starts at *.Not counted: Another branch advanced. another release branch was added — every branch stated at publication is still stated, so 15.6 still holdsnot dated
Tue 18 Jun 2024· 1 record change
2024-06-18CVSS base score changedCVE-2024-6084
whole record
VulDB
stated at publication 6.5, now states 7.5Assessments not comparable · base scoreMediumHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Mon 17 Jun 2024· 2 record changes
2024-06-17CVSS base score changedCVE-2024-5685
whole record
Checkmarx
stated at publication 8.6, now states 7.6Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 3
2024-06-17CVSS base score changedCVE-2024-6042
whole record
VulDB
stated at publication 6.5, now states 7.5Assessments not comparable · base scoreMediumHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Fri 14 Jun 2024· 3 record changes
2024-06-142 commitsCVSS base score changed
whole record
VulDB
stated at publication 6.5, now states 7.5Assessments not comparable · base scoreMediumHighBranches and original-value intervals are stated on each row.not counted: CVSS assessments are not comparableDays to revision 0
2024-06-14same kind of change as the line aboveCVE-2024-5983same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
2024-06-14same kind of change as the line aboveCVE-2024-5984same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
2024-06-14same kind of change as the line aboveCVE-2024-5976same vendor as the line abovesame change as the line aboveNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Thu 13 Jun 2024· 10 record changes
2024-06-13Affected range extendedPSFstated at publication 3.8.18, now states 3.8.19Release branch starts at 0.not counted: Same claim, other operatorDays to revision 86
2024-06-13same kind of change as the line aboveCVE-2023-6597same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 86
2024-06-13same kind of change as the line aboveCVE-2024-0450same vendor as the line abovesame change as the line aboveRelease branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 86
2024-06-13Affected range extendedPSFstated at publication 3.10.13, now states 3.10.14Release branch starts at 3.10.0.not counted: Same claim, other operatorDays to revision 86
2024-06-13same kind of change as the line aboveCVE-2023-6597same vendor as the line abovesame change as the line aboveRelease branch starts at 3.10.0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 86
2024-06-13same kind of change as the line aboveCVE-2024-0450same vendor as the line abovesame change as the line aboveRelease branch starts at 3.10.0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 86
2024-06-13Affected range extendedPSFstated at publication 3.11.8, now states 3.11.8Branches and original-value intervals are stated on each row.not counted: Same claim, other operatorDays to revision 15
2024-06-13same kind of change as the line aboveCVE-2023-6597same vendor as the line abovesame change as the line aboveRelease branch starts at 3.11.0.Original value first replaced 2024-04-03; this value first seen 2024-06-13.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 15
2024-06-13same kind of change as the line aboveCVE-2024-0450same vendor as the line abovesame change as the line aboveRelease branch starts at 3.11.0.Original value first replaced 2024-04-03; this value first seen 2024-06-13.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 15
2024-06-13Affected range extendedPSFstated at publication 3.9.18, now states 3.9.19Release branch starts at 3.9.0.not counted: Same claim, other operatorDays to revision 86
2024-06-13same kind of change as the line aboveCVE-2023-6597same vendor as the line abovesame change as the line aboveRelease branch starts at 3.9.0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 86
2024-06-13same kind of change as the line aboveCVE-2024-0450same vendor as the line abovesame change as the line aboveRelease branch starts at 3.9.0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 86
2024-06-13Affected range extendedCVE-2024-0450PSFstated at publication 3.12.2, now states 3.12.2Release branch starts at 3.12.0.Original value first replaced 2024-04-03; this value first seen 2024-06-13.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorDays to revision 15
2024-06-13CVSS base score changedCVE-2024-5894
whole record
VulDB
stated at publication 6.5, now states 7.5Assessments not comparable · base scoreMediumHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 1
Wed 12 Jun 2024· 1 record change
2024-06-12CVSS base score changedCVE-2024-4927
whole record
VulDB
stated at publication 6.5, now states 7.5Assessments not comparable · base scoreMediumHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 27
Tue 11 Jun 2024· 14 record changes
2024-06-11CVSS base score changedCVE-2023-38380
whole record
siemens
stated at publication 7.5, now states 8.7Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 182
2024-06-11CVSS base score changedCVE-2023-38532
whole record
siemens
stated at publication 6.6, now states 4.8Assessments not comparable · base scoreMediumMediumNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 308
2024-06-11CVSS base score changedCVE-2023-44321
whole record
siemens
stated at publication 2.7, now states 5.1Assessments not comparable · base scoreLowMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 210
2024-06-11CVSS base score changed
whole record
siemens
stated at publication 6.5, now states 7.1Assessments not comparable · base scoreMediumHighnot counted: CVSS version set changedDays to revision 28 to 119
2024-06-11same kind of change as the line aboveCVE-2023-48363same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 119
2024-06-11same kind of change as the line aboveCVE-2023-48364same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 119
2024-06-11same kind of change as the line aboveCVE-2024-33495same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 28
2024-06-11CVSS base score changed
whole record
siemens
stated at publication 3.3, now states 4.8Assessments not comparable · base scoreLowMediumnot counted: CVSS version set changedDays to revision 28 to 63
2024-06-11same kind of change as the line aboveCVE-2024-26276same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 63
2024-06-11same kind of change as the line aboveCVE-2024-26277same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 63
2024-06-11same kind of change as the line aboveCVE-2024-33583same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 28
2024-06-11CVSS base score changedCVE-2024-31485
whole record
siemens
stated at publication 7.2, now states 8.6Assessments not comparable · base scoreHighHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 28
2024-06-11CVSS base score changedCVE-2024-31486
whole record
siemens
stated at publication 5.3, now states 6.0Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 28
2024-06-11CVSS base score changedCVE-2024-33494
whole record
siemens
stated at publication 6.5, now states 6.9Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 28
2024-06-11CVSS base score changedCVE-2024-33498
whole record
siemens
stated at publication 5.3, now states 6.9Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 28
2024-06-11CVSS base score changedCVE-2024-33499
whole record
siemens
stated at publication 9.1, now states 9.4Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 28
Sat 8 Jun 2024· 1 record change
2024-06-08CVSS base score changedCVE-2024-5745
whole record
VulDB
stated at publication 6.5, now states 7.5Assessments not comparable · base scoreMediumHighNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0
Wed 5 Jun 2024· 2 record changes
2024-06-05Affected range extendedCVE-2023-51416
envialosimpleenvíalosimple
Patchstack
stated at publication 2.3, now states 2.3Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `unaffected_start` on the same or the next release — the same claim under the other operatorDays to revision 71
2024-06-05CVSS base score changedCVE-2024-2197
whole record
icscert
stated at publication 9.1, now states 4.3Assessments not comparable · base scoreCriticalMediumNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 78
Wed 29 May 2024· 3 record changes
2024-05-29Fix version moved
microsoftmicrosoft dynamics 365 (on-premises) version 9.1
stated at publication 9.1.18.xx, now states 9.1.21.05Release branch starts at *.not counted: Release branches rewrittennot dated
2024-05-29same kind of change as the line aboveCVE-2023-36886same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Release branches rewritten. the range layout was rewritten: a branch stated at publication is gone and another appeared, so no branch can be matchednot dated
2024-05-29same kind of change as the line aboveCVE-2023-38164same vendor as the line abovesame change as the line aboveRelease branch starts at *.Not counted: Release branches rewritten. the range layout was rewritten: a branch stated at publication is gone and another appeared, so no branch can be matchednot dated
2024-05-29CVSS base score changedCVE-2024-0569
whole record
VulDB
stated at publication 4.3, now states 5.3Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 134
Tue 28 May 2024· 16 record changes
2024-05-283 commitsCVSS base score changed
whole record
icscert
stated at publication 7.5, now states 8.7Assessments not comparable · base scoreHighHighBranches and original-value intervals are stated on each row.not counted: CVSS version set changedDays to revision 40
2024-05-28same kind of change as the line aboveCVE-2024-1491same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 40
2024-05-28same kind of change as the line aboveCVE-2024-3742same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 40
2024-05-28same kind of change as the line aboveCVE-2024-21872same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 40
2024-05-28same kind of change as the line aboveCVE-2024-22179same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 40
2024-05-28same kind of change as the line aboveCVE-2024-3741same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 40
2024-05-282 commitsCVSS base score changed
whole record
icscert
stated at publication 8.4, now states 8.6Assessments not comparable · base scoreHighHighBranches and original-value intervals are stated on each row.not counted: CVSS version set changedDays to revision 13 to 49
2024-05-28same kind of change as the line aboveCVE-2024-3313same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 49
2024-05-28same kind of change as the line aboveCVE-2024-28042same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13
2024-05-28CVSS base score changedCVE-2024-21846
whole record
icscert
stated at publication 5.3, now states 6.9Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 40
2024-05-28CVSS base score changedCVE-2024-3746
whole record
icscert
stated at publication 5.5, now states 6.8Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 28
2024-05-282 commitsCVSS base score changed
whole record
Nozomi
stated at publication 7.5, now states 8.2Assessments not comparable · base scoreHighHighBranches and original-value intervals are stated on each row.not counted: CVSS version set changedDays to revision 48 to 252
2024-05-28same kind of change as the line aboveCVE-2024-0218same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 48
2024-05-28same kind of change as the line aboveCVE-2023-32649same vendor as the line abovesame change as the line aboveNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 252
2024-05-28CVSS base score changedCVE-2023-22843
whole record
Nozomi
stated at publication 6.4, now states 7.3Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 293
2024-05-28CVSS base score changedCVE-2023-23903
whole record
Nozomi
stated at publication 4.9, now states 6.9Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 293
2024-05-28CVSS base score changedCVE-2023-24015
whole record
Nozomi
stated at publication 4.3, now states 5.3Assessments not comparable · base scoreMediumMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 293
2024-05-28CVSS base score changedCVE-2023-24471
whole record
Nozomi
stated at publication 6.5, now states 7.1Assessments not comparable · base scoreMediumHighNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 293
2024-05-28CVSS base score changedCVE-2023-5937
whole record
Nozomi
stated at publication 3.8, now states 5.2Assessments not comparable · base scoreLowMediumNot counted: CVSS version set changed. no CVSS version was rescored — the maximum moved because a different CVSS version was added or removedDays to revision 13

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →