Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

11,999 record changes · 5,026 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
ChangedSourceRows
Counted changes, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Thu 28 Apr 2022· 2 advisory changes
2022-04-28published 2022-04-20Advisory severity changedGHSA-fxwj-v664-wv5gCVE-2022-1385whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 9
2022-04-28published 2022-03-31Advisory severity changedGHSA-8m49-2xj8-67v9CVE-2022-27816whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
Wed 27 Apr 2022· 2 advisory changes
2022-04-27published 2021-04-13Advisory fix version movedGHSA-w8h4-vw8f-rvvjCVE-2021-26276
npmconfig-shield
moderate
stated at publication 0.2.2, now states 0.2.3Days to revision 379
2022-04-27published 2021-02-08Advisory severity changedGHSA-cf3w-g86h-35x4CVE-2021-21305whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 443
Tue 26 Apr 2022· 4 advisory changes
2022-04-26published 2021-09-20Advisory severity changedGHSA-93q8-gq69-wqmwCVE-2021-3807whole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 218
2022-04-26published 2018-08-21Advisory severity changedGHSA-cqxw-3p7v-p9grCVE-2016-10345whole advisoryhighstated at publication CRITICAL, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 1,344
2022-04-26published 2021-04-20Advisory severity changedGHSA-gwr8-5j83-483cCVE-2019-14904whole advisoryhighstated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.Days to revision 371
2022-04-26published 2022-02-10Advisory severity changedGHSA-jrg3-qq99-35g7CVE-2018-21234whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 75
Mon 25 Apr 2022· 3 advisory changes
2022-04-25published 2022-04-15Advisory severity changedGHSA-g5mm-vmx4-3rg7CVE-2022-22968whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 11
2022-04-25published 2021-06-23Advisory severity changedGHSA-9qq2-xhmc-h9qrCVE-2018-20321whole advisorymoderatestated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 306
2022-04-25published 2021-05-18Advisory severity changedGHSA-xhg2-rvm8-w2jhCVE-2019-13209whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 342
Fri 22 Apr 2022· 2 advisory changes
2022-04-22published 2021-03-18Advisory severity changedGHSA-hwvv-438r-mhvjCVE-2021-22134whole advisorymoderatestated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 400
2022-04-22published 2021-04-07Advisory severity changedGHSA-244r-fcj3-ghjqCVE-2021-20289whole advisorymoderatestated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 380
Tue 19 Apr 2022· 4 advisory changes
2022-04-19published 2022-04-08Advisory severity changedGHSA-r3r5-jhw6-4634CVE-2022-27818whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 12
2022-04-19published 2022-04-01Advisory severity changedGHSA-qvf8-p83w-v58jCVE-2022-27649whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 18
2022-04-19published 2022-04-01Advisory severity changedGHSA-c3g4-w6cv-6v7hCVE-2022-27651whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 18
2022-04-19published 2022-04-08Advisory severity changedGHSA-gx2c-fvhc-ph4jCVE-2022-26612whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 12
Mon 18 Apr 2022· 5 advisory changes
2022-04-18published 2022-04-01Advisory severity changedGHSA-xw7v-qrhc-jjg2CVE-2021-37517whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 18
2022-04-18published 2022-04-03Advisory severity changedGHSA-74w3-2r77-fw5hCVE-2022-27177whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 16
2022-04-18published 2022-04-07Advisory severity changedGHSA-jm35-h8q2-73mpCVE-2021-43177whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
2022-04-18published 2022-04-02Advisory severity changedGHSA-45hc-r4fj-qj89CVE-2021-44135whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 17
2022-04-18published 2022-04-01Advisory severity changedGHSA-6635-c626-vj4rCVE-2022-21235whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 17
Sun 17 Apr 2022· 1 advisory change
2022-04-17published 2022-04-09Advisory severity changedGHSA-86r3-4gq8-xw8qCVE-2021-43503whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9
Fri 15 Apr 2022· 2 advisory changes
2022-04-15published 2022-04-03Advisory severity changedGHSA-hf55-c445-2w97CVE-2022-21830whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 13
2022-04-15published 2022-04-04Advisory severity changedGHSA-x752-qjv4-c4hcCVE-2022-28368whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 12
Tue 12 Apr 2022· 1 advisory change
2022-04-12published 2021-05-28Package added to advisoryGHSA-g42g-737j-qx6jCVE-2021-25735moderatenot named as affected when the advisory was published, now names k8s.io/kubernetesDays to revision 319
Fri 8 Apr 2022· 4 advisory changes
2022-04-08published 2022-02-25Advisory fix version movedGHSA-q62h-jw38-24vhCVE-2022-24615
mavennet.lingala.zip4j:zip4j
moderate
stated at publication 2.9.0, now states 2.10.0Days to revision 1
2022-04-08published 2021-12-09Advisory severity changedGHSA-qjw2-hr98-qgfhCVE-2020-24750whole advisoryhighstated at publication CRITICAL, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 120
2022-04-08published 2018-12-20Advisory severity changedGHSA-27xw-p8v6-9jjrCVE-2018-15801whole advisoryhighstated at publication CRITICAL, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 1,205
2022-04-08published 2022-03-26Advisory severity changedGHSA-69p3-xp37-f692CVE-2022-0759whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 14
Wed 6 Apr 2022· 3 advisory changes
2022-04-06published 2022-03-31Advisory severity changedGHSA-p4jg-pccf-h82cCVE-2022-27815whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2022-04-06published 2022-04-04Advisory severity changedGHSA-7vrm-3jc8-5wwmwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 2
2022-04-06published 2022-04-03Advisory severity changedGHSA-6v73-fgf6-w5j7CVE-2022-22963whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 4
Tue 5 Apr 2022· 3 advisory changes
2022-04-05published 2021-11-10Advisory severity changedGHSA-5mxh-2qfv-4g7jCVE-2021-3910whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 146
2022-04-05published 2022-03-31Advisory severity changedGHSA-qg5x-66hp-cw5pCVE-2022-25598whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
2022-04-05published 2022-03-29Advisory severity changedGHSA-674v-3g2w-84gxCVE-2021-46433whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
Mon 4 Apr 2022· 4 advisory changes
2022-04-04published 2021-08-13Advisory fix version movedGHSA-4vww-mc66-62m6CVE-2021-33037
mavenorg.apache.tomcat:tomcat
moderate
stated at publication 10.0.6, now states 10.0.7Days to revision 234
2022-04-04published 2021-08-13Advisory fix version movedGHSA-4vww-mc66-62m6CVE-2021-33037
mavenorg.apache.tomcat:tomcat
moderate
stated at publication 8.5.66, now states 8.5.68Days to revision 234
2022-04-04published 2021-08-13Advisory fix version movedGHSA-4vww-mc66-62m6CVE-2021-33037
mavenorg.apache.tomcat:tomcat
moderate
stated at publication 9.0.46, now states 9.0.48Days to revision 234
2022-04-04published 2022-03-18Advisory severity changedGHSA-xvch-5gv4-984hCVE-2021-44906whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 18
Fri 1 Apr 2022· 3 advisory changes
2022-04-01published 2022-03-26Advisory severity changedGHSA-rr8m-29g8-8cgcCVE-2022-1064whole advisoryhighstated at publication CRITICAL, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 7
2022-04-01published 2022-03-26Advisory severity changedGHSA-pv39-qp28-4mghCVE-2021-43090whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2022-04-01published 2019-10-11Advisory severity changedGHSA-p979-4mfw-53vgCVE-2019-16869whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 903
Wed 30 Mar 2022· 5 advisory changes
2022-03-30published 2022-03-23Advisory severity changedGHSA-xr2c-5w89-63pvCVE-2022-26184whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2022-03-30published 2022-03-23Advisory severity changedGHSA-9m87-6fj3-c5xhCVE-2022-26183whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8
2022-03-30published 2022-03-17Advisory severity changedGHSA-32j9-6qqm-mq9gCVE-2022-21164whole advisoryhighstated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 14
2022-03-30published 2022-03-18Advisory severity changedGHSA-vrcc-g6vj-mh5wCVE-2021-42219whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 13
2022-03-30published 2022-03-20Advisory severity changedGHSA-rggc-4g3r-j7ffCVE-2022-26265whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 11
Tue 29 Mar 2022· 5 advisory changes
2022-03-29published 2022-03-15Advisory fix version movedGHSA-rgg3-3wh7-w935CVE-2021-42171
packagisttribalsystems/zenario
critical
stated at publication 9.0.55141, now states 9.0.55143Days to revision 15
2022-03-29published 2022-03-15Advisory fix version movedGHSA-x8wj-cqmp-3wmmCVE-2021-41952
packagisttribalsystems/zenario
moderate
stated at publication 9.0.55141, now states 9.0.55143Days to revision 15
2022-03-29published 2022-03-18Advisory severity changedGHSA-x5m8-2r8v-8f97CVE-2022-25352whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 12
2022-03-29published 2022-03-18Advisory severity changedGHSA-fx95-883v-4q4hCVE-2022-21221whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 12
2022-03-29published 2022-03-18Advisory severity changedGHSA-6956-83fg-5wc5CVE-2022-25354whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 12
Sat 26 Mar 2022· 1 advisory change
2022-03-26published 2022-02-18Advisory fix version movedGHSA-4cpg-3vgw-4877CVE-2022-22912
npmplist
critical
stated at publication 3.0.4, now states 3.0.5Days to revision 34
Tue 22 Mar 2022· 3 advisory changes
2022-03-22published 2022-03-12Advisory fix version movedGHSA-6vx5-cg2p-7g5vCVE-2022-0912
packagistmicroweber/microweber
moderate
stated at publication 1.2.11, now states 1.2.12Days to revision 11
2022-03-22published 2022-03-13Advisory fix version movedGHSA-5fxf-x22x-5q38CVE-2022-0929
packagistmicroweber/microweber
moderate
stated at publication 1.2.11, now states 1.2.12Days to revision 10
2022-03-22published 2022-03-13Advisory severity changedGHSA-3q55-66g3-p8xqCVE-2022-0926whole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 10
Fri 18 Mar 2022· 10 advisory changes
2022-03-18published 2022-03-08Advisory severity changedGHSA-2647-c639-qv2jCVE-2022-0766whole advisorycriticalstated at publication MODERATE, now states CRITICALCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 11
2022-03-18published 2022-03-08Advisory severity changedGHSA-28mg-98xm-q493CVE-2022-0697whole advisorymoderatestated at publication LOW, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 11
2022-03-18published 2022-03-06Advisory severity changedGHSA-r5qj-cvf9-p85hCVE-2022-0845whole advisorycriticalstated at publication HIGH, now states CRITICALCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 13
2022-03-18published 2022-03-05Advisory severity changedGHSA-jvfv-hrrc-6q72CVE-2022-0839whole advisorycriticalstated at publication HIGH, now states CRITICALCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 14
2022-03-18published 2022-03-04Advisory severity changedGHSA-99wh-973f-779pCVE-2022-0265whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 15
2022-03-18published 2022-02-01Advisory severity changedGHSA-4mpj-488r-vh6mCVE-2021-42767whole advisorycriticalstated at publication MODERATE, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 45
2022-03-18published 2022-03-01Advisory severity changedGHSA-r5hc-wm3g-hjw6CVE-2022-0768whole advisorycriticalstated at publication HIGH, now states CRITICALCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 17
2022-03-18published 2022-03-05Advisory severity changedGHSA-vmf7-hmh6-vv57CVE-2022-23328whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 14
2022-03-18published 2022-03-05Advisory severity changedGHSA-pvx3-gm3c-gmprCVE-2022-23327whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 14
2022-03-18published 2022-03-15Advisory severity changedGHSA-6x2m-w449-qwx7CVE-2022-0811whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 3
Thu 17 Mar 2022· 3 advisory changes
2022-03-17published 2022-03-11Advisory fix version movedGHSA-vx8q-j7h9-vf6qCVE-2022-0813
packagistphpmyadmin/phpmyadmin
high
stated at publication 5.1.2, now states 5.1.3Days to revision 7
2022-03-17published 2022-03-12Advisory severity changedGHSA-6c9x-mj3g-h47xCVE-2021-46708whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 6
2022-03-17published 2022-03-12Advisory severity changedGHSA-cr3q-pqgq-m8c2CVE-2018-25031whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 6
Tue 15 Mar 2022· 4 advisory changes
2022-03-15published 2022-03-06Advisory severity changedGHSA-2rmm-87v7-34rjCVE-2022-25312whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 10
2022-03-15published 2022-03-11Advisory severity changedGHSA-9rr6-jpg7-9jg6CVE-2021-38296whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 5
2022-03-15published 2022-03-01Advisory severity changedGHSA-32x6-qvw6-mxj4CVE-2022-24719whole advisorylowstated at publication HIGH, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 14
2022-03-15published 2021-10-12Advisory severity changedGHSA-3r3g-g73x-g593CVE-2021-20319whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 153
Mon 14 Mar 2022· 3 advisory changes
2022-03-14published 2022-03-07Advisory severity changedGHSA-2877-693q-pj33CVE-2021-46704whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2022-03-14published 2022-03-07Advisory severity changedGHSA-8h2f-7jc4-7m3mCVE-2022-0868whole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 8
2022-03-14published 2022-03-09Advisory severity changedGHSA-5rcc-6cmj-7728CVE-2022-0877whole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 6
Fri 11 Mar 2022· 7 advisory changes
2022-03-11published 2022-01-12Advisory fix version movedGHSA-8vj2-vxx3-667wCVE-2022-22817
pypipillow
critical
stated at publication 9.0.0, now states 9.0.1Days to revision 58
2022-03-11published 2021-05-18Package added to advisoryGHSA-vj3f-3286-r4pfCVE-2014-9356moderatenot named as affected when the advisory was published, now names github.com/docker/dockerDays to revision 297
2022-03-11published 2020-07-15Package added to advisoryGHSA-p6mc-m468-83gwCVE-2020-8203highnot named as affected when the advisory was published, now names lodash-esDays to revision 604
2022-03-11published 2021-05-06Package added to advisoryGHSA-35jh-r3h4-6jhmCVE-2021-23337highnot named as affected when the advisory was published, now names lodash-esDays to revision 309
2022-03-11published 2022-01-06Package added to advisoryGHSA-29mw-wpgm-hmr9CVE-2020-28500moderatenot named as affected when the advisory was published, now names lodash-esDays to revision 64
2022-03-11published 2020-03-24Advisory severity changedGHSA-7q25-qrjw-6fg2CVE-2020-5252whole advisorymoderatestated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 717
2022-03-11published 2021-12-09Advisory severity changedGHSA-vrc7-6g8w-jh56CVE-2015-9544whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 92
Thu 10 Mar 2022· 3 advisory changes
2022-03-10published 2022-03-02Advisory severity changedGHSA-7r79-mrp6-8mhqCVE-2022-0777whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2022-03-10published 2022-03-01Advisory severity changedGHSA-7f63-h6g3-7cwmCVE-2022-24717whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 9
2022-03-10published 2022-03-01Advisory severity changedGHSA-w6cx-qg2q-rvq8CVE-2022-24718whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
Wed 9 Mar 2022· 6 advisory changes
2022-03-09published 2019-07-19Package added to advisoryGHSA-x5rq-j2xg-h7qmCVE-2019-1010266moderatenot named as affected when the advisory was published, now names lodash-amdDays to revision 964
2022-03-09published 2019-07-19Package added to advisoryGHSA-x5rq-j2xg-h7qmCVE-2019-1010266moderatenot named as affected when the advisory was published, now names lodash-esDays to revision 964
2022-03-09published 2022-03-04Advisory severity changedGHSA-cr6m-62pq-hmqhCVE-2022-0841whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6
2022-03-09published 2022-02-25Advisory severity changedGHSA-6w4v-qr4m-97ggCVE-2022-25838whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 13
2022-03-09published 2022-02-27Advisory severity changedGHSA-4p92-fv6v-fhfjCVE-2022-0723whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
2022-03-09published 2022-03-01Advisory severity changedGHSA-3382-r9q8-4hfgCVE-2022-24685whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
Tue 8 Mar 2022· 1 advisory change
2022-03-08published 2022-03-07Advisory severity changedGHSA-5jgq-x857-p8xwCVE-2022-24738whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 1
Fri 4 Mar 2022· 4 advisory changes
2022-03-04published 2022-03-02Advisory severity changedGHSA-crp2-qrr5-8pq7CVE-2022-23648whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 2
2022-03-04published 2022-02-25Advisory severity changedGHSA-82rr-mq4r-p4r3CVE-2021-44567whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2022-03-04published 2021-12-14Advisory severity changedGHSA-5cqm-crxm-6qpvCVE-2021-41816whole advisorycriticalstated at publication LOW, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 64
2022-03-04published 2022-03-03Advisory severity changedGHSA-rv6r-3f5q-9rgxCVE-2022-21716whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 1
Thu 3 Mar 2022· 2 advisory changes
2022-03-03published 2022-02-25Advisory severity changedGHSA-x2p8-rgfm-qw3vCVE-2021-44550whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 7
2022-03-03published 2022-02-21Advisory severity changedGHSA-hgjh-723h-mx2jCVE-2022-0686whole advisorycriticalstated at publication MODERATE, now states CRITICALCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 11

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →