Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

3,930 record edits refused · 339 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
ChangedSourceRows

These rows are not counted anywhere on this site. Checked and refused means we compared this change and then rejected it: the false positive filter for this kind of change judged it to be a false positive rather than a real change. The row is shown so you can check the filter and disagree with us, and it is counted in no figure on this site. No advisory change is here: the advisory engine counts the 2,291 version pairs its filters refused by class rather than writing them out one by one, so this view holds CVE and KEV changes only.

Rows we checked and refused, counted nowhere, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Thu 16 Feb 2023· 2 changes
2023-02-16published 2021-05-18Package added to advisoryhighnot named as affected when the advisory was published, now names github.com/unknwon/caeDuration unknown
2023-02-16published 2021-05-18same kind of change as the line aboveGHSA-vpx7-vm66-qx8rCVE-2020-7664same package registry as the line abovehighsame change as the line aboveDuration unknown
2023-02-16published 2021-05-18same kind of change as the line aboveGHSA-88jf-7rch-32qcCVE-2020-7668same package registry as the line abovehighsame change as the line aboveDuration unknown
Wed 15 Feb 2023· 6 changes
2023-02-15published 2022-10-07Package added to advisoryGHSA-p658-8693-mhvgCVE-2021-21271moderatenot named as affected when the advisory was published, now names github.com/tendermint/tendermintDuration unknown
2023-02-15published 2023-02-08Package added to advisoryGHSA-mv6w-j4xc-qpfwCVE-2023-25163moderatenot named as affected when the advisory was published, now names github.com/argoproj/argo-cd/v2Time to revision 7 days
2023-02-15published 2022-05-24 to 2022-05-25Package added to advisory2 bandsnot named as affected when the advisory was published, now names github.com/pion/dtls/v2Duration unknown
2023-02-15published 2022-05-25same kind of change as the line aboveGHSA-w45j-f832-hxvhCVE-2022-29222same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2023-02-15published 2022-05-24same kind of change as the line aboveGHSA-cm8f-h6j3-p25cCVE-2022-29190same package registry as the line abovehighsame change as the line aboveDuration unknown
2023-02-15published 2022-05-24same kind of change as the line aboveGHSA-cx94-mrg9-rq4jCVE-2022-29189same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2023-02-15published 2022-02-16Package added to advisoryGHSA-cg3q-j54f-5p7pCVE-2022-21698highnot named as affected when the advisory was published, now names github.com/prometheus/client_golangDuration unknown
Tue 14 Feb 2023· 20 changes
2023-02-14published 2021-05-18 to 2023-01-05Package added to advisory20 rows, one per advisory and package4 bandsnot named as affected when the advisory was published, now names github.com/ipld/go-ipld-prime and 17 moreTime to revision 40 to 85 days
2023-02-14published 2023-01-05same kind of change as the line aboveGHSA-c653-6hhg-9x92CVE-2023-22460same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/ipld/go-ipld-primeTime to revision 40 days
2023-02-14published 2022-11-21same kind of change as the line aboveGHSA-pp3f-xrw5-q5j4CVE-2022-41920same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/duke-git/lancetTime to revision 85 days
2023-02-14published 2022-11-21same kind of change as the line aboveGHSA-pp3f-xrw5-q5j4CVE-2022-41920same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/duke-git/lancet/v2Time to revision 85 days
2023-02-14published 2022-11-21same kind of change as the line aboveGHSA-6cqj-6969-p57xCVE-2022-39199same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/codenotary/immudbTime to revision 85 days
2023-02-14published 2022-11-21same kind of change as the line aboveGHSA-672p-m5jq-mrh8CVE-2022-36111same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/codenotary/immudbTime to revision 85 days
2023-02-14published 2022-06-03same kind of change as the line aboveGHSA-9w9f-6mg8-jp7wCVE-2022-31022same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/blevesearch/bleve/v2Duration unknown
2023-02-14published 2022-01-06same kind of change as the line aboveGHSA-jcxc-rh6w-wf49CVE-2021-23772same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/kataras/irisDuration unknown
2023-02-14published 2021-06-23same kind of change as the line aboveGHSA-qj26-7grj-whg3CVE-2018-6558same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/google/fscryptDuration unknown
12 more rows in this change are not listed here. Open all 20 rows
Mon 13 Feb 2023· 3 changes
2023-02-13published 2021-05-27Package added to advisoryGHSA-fh74-hm69-rqjwCVE-2019-19921moderatenot named as affected when the advisory was published, now names github.com/opencontainers/runcDuration unknown
2023-02-13published 2023-02-07Package added to advisorymoderatenot named as affected when the advisory was published, now names github.com/pion/dtls/v2Time to revision 6 days
2023-02-13published 2023-02-07same kind of change as the line aboveGHSA-4xgv-j62q-h3rjsame package registry as the line abovemoderatesame change as the line aboveTime to revision 6 days
2023-02-13published 2023-02-07same kind of change as the line aboveGHSA-hxp2-xqf3-v83hsame package registry as the line abovemoderatesame change as the line aboveTime to revision 6 days
Thu 9 Feb 2023· 14 changes
2023-02-09published 2022-02-11 to 2022-07-06Package added to advisory14 rows, one per advisory and package2 bandsnot named as affected when the advisory was published, now names github.com/hashicorp/go-getter/gcs/v2 and 4 moreDuration unknown
2023-02-09published 2022-05-26same kind of change as the line aboveGHSA-28r2-q6m8-9hpxCVE-2022-30323same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/hashicorp/go-getter/gcs/v2Duration unknown
2023-02-09published 2022-05-26same kind of change as the line aboveGHSA-28r2-q6m8-9hpxCVE-2022-30323same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/hashicorp/go-getter/s3/v2Duration unknown
2023-02-09published 2022-05-26same kind of change as the line aboveGHSA-28r2-q6m8-9hpxCVE-2022-30323same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/hashicorp/go-getter/v2Duration unknown
2023-02-09published 2022-05-26same kind of change as the line aboveGHSA-cjr4-fv6c-f3mvCVE-2022-30322same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/hashicorp/go-getter/gcs/v2Duration unknown
2023-02-09published 2022-05-26same kind of change as the line aboveGHSA-cjr4-fv6c-f3mvCVE-2022-30322same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/hashicorp/go-getter/s3/v2Duration unknown
2023-02-09published 2022-05-26same kind of change as the line aboveGHSA-cjr4-fv6c-f3mvCVE-2022-30322same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/hashicorp/go-getter/v2Duration unknown
2023-02-09published 2022-05-26same kind of change as the line aboveGHSA-fcgg-rvwg-jv58CVE-2022-30321same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/hashicorp/go-getter/gcs/v2Duration unknown
2023-02-09published 2022-05-26same kind of change as the line aboveGHSA-fcgg-rvwg-jv58CVE-2022-30321same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/hashicorp/go-getter/s3/v2Duration unknown
6 more rows in this change are not listed here. Open all 14 rows
Tue 7 Feb 2023· 1 change
2023-02-07published 2021-05-18Package added to advisoryGHSA-w73w-5m7g-f7qcCVE-2020-26160highnot named as affected when the advisory was published, now names github.com/dgrijalva/jwt-go/v4Duration unknown
Thu 2 Feb 2023· 1 change
2023-02-02published 2023-02-02Package added to advisoryGHSA-pgvh-p3g4-86jwCVE-2023-25313criticalnot named as affected when the advisory was published, now names wwbn/avideoTime to revision 1 days
Thu 4 Aug 2022· 2 changes
2022-08-04published 2022-02-11Package added to advisoryGHSA-6qq8-5wq3-86rpmoderatenot named as affected when the advisory was published, now names github.com/traefik/traefik/api and 1 moreTime to revision 174 days
2022-08-04published 2022-02-11same kind of change as the line aboveGHSA-6qq8-5wq3-86rpCVE-2020-15129same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/traefik/traefik/apiTime to revision 174 days
2022-08-04published 2022-02-11same kind of change as the line aboveGHSA-6qq8-5wq3-86rpCVE-2020-15129same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/traefik/traefik/v2/pkg/apiTime to revision 174 days
Tue 2 Aug 2022· 1 change
2022-08-02published 2022-07-23Package added to advisoryGHSA-xg72-6c83-ghh4CVE-2022-2495moderatenot named as affected when the advisory was published, now names microweber/microweberTime to revision 11 days
Fri 29 Jul 2022· 1 change
2022-07-29published 2022-02-11Package added to advisoryGHSA-6qq8-5wq3-86rpCVE-2020-15129moderatenot named as affected when the advisory was published, now names github.com/containous/traefikTime to revision 168 days
Mon 18 Jul 2022· 1 change
2022-07-18published 2021-08-30Package added to advisoryGHSA-23fq-q7hc-993rCVE-2021-38553criticalnot named as affected when the advisory was published, now names github.com/hashicorp/vaultTime to revision 322 days
Sat 16 Jul 2022· 3 changes
2022-07-16published 2022-02-15Package added to advisoryGHSA-5x92-p4p5-33c4CVE-2020-28348moderatenot named as affected when the advisory was published, now names github.com/hashicorp/nomadTime to revision 151 days
2022-07-16published 2022-02-11Package added to advisoryGHSA-fqfh-778m-2v32moderatenot named as affected when the advisory was published, now names github.com/cli/cliTime to revision 154 days
2022-07-16published 2022-02-15Package added to advisoryGHSA-5wmg-j84w-4jj4CVE-2018-1002207moderatenot named as affected when the advisory was published, now names github.com/mholt/archiverTime to revision 151 days
Wed 29 Jun 2022· 1 change
2022-06-29published 2022-06-16Package added to advisoryGHSA-q874-g24w-4q9gCVE-2022-29241highnot named as affected when the advisory was published, now names jupyter-serverTime to revision 13 days
Fri 10 Jun 2022· 1 change
2022-06-10published 2022-05-25Package added to advisoryGHSA-hj57-j5cw-2mwpCVE-2022-1706moderatenot named as affected when the advisory was published, now names github.com/coreos/ignition/v2Time to revision 15 days
Tue 29 Mar 2022· 1 change
2022-03-29published 2022-03-25Package added to advisoryGHSA-p737-p57g-4cprCVE-2022-24757highnot named as affected when the advisory was published, now names jupyter-serverTime to revision 4 days
Wed 2 Mar 2022· 2 changes
2022-03-02published 2021-11-18Package added to advisoryGHSA-5629-8855-gf4gcriticalnot named as affected when the advisory was published, now names solidus_coreTime to revision 104 days
2022-03-02published 2021-11-03Package added to advisoryGHSA-x24j-87x9-jvv5CVE-2021-25973moderatenot named as affected when the advisory was published, now names publify_coreTime to revision 119 days
Sat 26 Feb 2022· 1 change
2022-02-26published 2022-02-24Package added to advisoryGHSA-4cxw-hq44-r344CVE-2021-4070criticalnot named as affected when the advisory was published, now names github.com/v2fly/v2ray-coreTime to revision 2 days

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

What this page cannot see

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Paste your closed CVE tickets and see which of these changes hit them →