Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

11,999 record changes · 5,026 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
Counted changes, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Fri 22 Sep 2023· 1 advisory change
2023-09-22published 2023-09-19Advisory severity changedGHSA-95xr-cq6h-vwr3CVE-2023-42399whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 4
Thu 21 Sep 2023· 6 advisory changes
2023-09-21published 2020-04-15Package added to advisoryGHSA-rc5r-697f-28x6moderatenot named as affected when the advisory was published, now names sylius/grid-bundle and 1 morenot dated
2023-09-21published 2020-04-15same kind of change as the line aboveGHSA-rc5r-697f-28x6CVE-2019-12186same package registry as the line abovemoderatenot named as affected when the advisory was published, now names sylius/grid-bundlenot dated
2023-09-21published 2020-04-15same kind of change as the line aboveGHSA-rc5r-697f-28x6CVE-2019-12186same package registry as the line abovemoderatenot named as affected when the advisory was published, now names sylius/syliusnot dated
2023-09-21published 2023-09-12Package added to advisoryGHSA-j7hp-h8jx-5pprCVE-2023-4863highnot named as affected when the advisory was published, now names github.com/chai2010/webpDays to revision 9
2023-09-21published 2023-09-12Package added to advisoryGHSA-j7hp-h8jx-5pprCVE-2023-4863highnot named as affected when the advisory was published, now names skiasharpDays to revision 9
2023-09-21published 2021-09-08Package added to advisoryGHSA-7q44-gfvq-6g93CVE-2020-18155criticalnot named as affected when the advisory was published, now names intelliants/subrionnot dated
2023-09-21published 2021-10-25Advisory severity changedGHSA-4286-h47h-m5v6CVE-2021-41745whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
Wed 20 Sep 2023· 3 record changes · 14 advisory changes
2023-09-20Product addedCVE-2023-4456not named as affected at publication, now names rhol-5.5-rhel-8 and 1 moreDays to revision 30
2023-09-20same kind of change as the line aboveCVE-2023-4456same vendor as the line abovenot named as affected at publication, now names rhol-5.5-rhel-8Days to revision 30
2023-09-20same kind of change as the line aboveCVE-2023-4456same vendor as the line abovenot named as affected at publication, now names rhol-5.6-rhel-8Days to revision 30
2023-09-20Record state changedCVE-2023-4881
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 9
2023-09-20published 2023-06-12Package added to advisoryGHSA-59x6-g4jr-4hxcCVE-2023-35042criticalnot named as affected when the advisory was published, now names org.geoserver:gs-wpsDays to revision 100
2023-09-20published 2023-09-15Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 6
2023-09-20published 2023-09-15same kind of change as the line aboveGHSA-5jjm-qp48-qp86CVE-2023-4981same package and registry as the line abovemoderatesame change as the line aboveDays to revision 6
2023-09-20published 2023-09-15same kind of change as the line aboveGHSA-qxrq-376q-p39hCVE-2023-4980same package and registry as the line abovemoderatesame change as the line aboveDays to revision 6
2023-09-20published 2023-09-15same kind of change as the line aboveGHSA-57m2-mpc7-gwgxCVE-2023-4977same package and registry as the line abovemoderatesame change as the line aboveDays to revision 6
2023-09-20published 2023-09-15same kind of change as the line aboveGHSA-jp3c-g46v-jg2cCVE-2023-4979same package and registry as the line abovemoderatesame change as the line aboveDays to revision 6
2023-09-20published 2023-09-15Advisory severity changedwhole advisorymoderatestated at publication CRITICAL, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 6
2023-09-20published 2023-09-15same kind of change as the line aboveGHSA-m6jj-fgmh-3p8rCVE-2023-4982same package and registry as the line abovemoderatesame change as the line aboveDays to revision 6
2023-09-20published 2023-09-15same kind of change as the line aboveGHSA-qjpw-rg56-jh8vCVE-2023-4978same package and registry as the line abovemoderatesame change as the line aboveDays to revision 6
2023-09-20published 2023-09-18Advisory severity changedGHSA-r87q-fq37-pvr6CVE-2023-33831whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 2
2023-09-20published 2022-05-17Advisory severity changedGHSA-jjwj-w3gc-gcw4CVE-2014-5013whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 491
2023-09-20published 2023-09-12Advisory severity changedGHSA-p3r5-x3hr-gpg5CVE-2023-41887whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-09-20published 2023-09-12Advisory severity changedGHSA-qqh2-wvmv-h72mCVE-2023-41886whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8
2023-09-20published 2022-05-24Advisory severity changedGHSA-7v44-75jf-22gjCVE-2019-15481whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-20published 2023-09-12Advisory severity changedGHSA-h7cm-mrvq-wcfrCVE-2023-41885whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 8
2023-09-20published 2019-11-12Advisory severity changedGHSA-6r58-4xgr-gm6mCVE-2019-12617whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.not dated
Tue 19 Sep 2023· 2 record changes · 3 advisory changes
2023-09-19Product addedCVE-2023-0125VulDBnot named as affected at publication, now names gerencia webDays to revision 252
2023-09-19CVSS base score changedCVE-2023-3935
whole record
CERTVDE
stated at publication 10.0, now states 9.8CVSS v3.1 · base scoreCriticalCriticalDays to revision 6
2023-09-19published 2021-12-10Package added to advisoryGHSA-jfh8-c2jp-5v3qcriticalnot named as affected when the advisory was published, now names com.guicedee.services:log4j-core and 2 morenot dated
2023-09-19published 2021-12-10same kind of change as the line aboveGHSA-jfh8-c2jp-5v3qCVE-2021-44228same package registry as the line abovecriticalnot named as affected when the advisory was published, now names com.guicedee.services:log4j-corenot dated
2023-09-19published 2021-12-10same kind of change as the line aboveGHSA-jfh8-c2jp-5v3qCVE-2021-44228same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.xbib.elasticsearch:log4jnot dated
2023-09-19published 2021-12-10same kind of change as the line aboveGHSA-jfh8-c2jp-5v3qCVE-2021-44228same package registry as the line abovecriticalnot named as affected when the advisory was published, now names uk.co.nichesolutions.logging.log4j:log4j-corenot dated
Mon 18 Sep 2023· 1 record change · 10 advisory changes
2023-09-18CVSS base score changedCVE-2023-4387
whole record
redhat
stated at publication 6.6, now states 7.1CVSS v3.1 · base scoreMediumHighDays to revision 33
2023-09-18published 2021-05-18 to 2022-02-15Package added to advisorymoderatenot named as affected when the advisory was published, now names k8s.io/kubernetesnot dated
2023-09-18published 2022-02-15same kind of change as the line aboveGHSA-qhm4-jxv7-j9pqCVE-2020-8551same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-18published 2022-02-15same kind of change as the line aboveGHSA-x6mj-w4jf-jmgwCVE-2020-8555same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-18published 2021-05-18same kind of change as the line aboveGHSA-6qfg-8799-r575CVE-2019-11251same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-18published 2022-02-15same kind of change as the line aboveGHSA-34jx-wx69-9x8vCVE-2019-1002101same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-18published 2022-02-15Package added to advisoryGHSA-82hx-w2r5-c2wqCVE-2020-8552moderatenot named as affected when the advisory was published, now names k8s.io/apiservernot dated
2023-09-18published 2022-02-15Package added to advisoryGHSA-2575-pghm-6qqxCVE-2019-11244moderatenot named as affected when the advisory was published, now names k8s.io/client-gonot dated
2023-09-18published 2023-09-12Package added to advisoryGHSA-j7hp-h8jx-5pprCVE-2023-4863highnot named as affected when the advisory was published, now names libwebp-sysDays to revision 6
2023-09-18published 2023-09-12Package added to advisoryGHSA-j7hp-h8jx-5pprCVE-2023-4863highnot named as affected when the advisory was published, now names electronDays to revision 6
2023-09-18published 2022-02-15Advisory severity changedGHSA-x6mj-w4jf-jmgwCVE-2020-8555whole advisorymoderatestated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-09-18published 2023-09-12Advisory severity changedGHSA-j7hp-h8jx-5pprCVE-2023-4863whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
Sat 16 Sep 2023· 41 record changes
2023-09-163 commitsProduct addedcertccnot named as affected at publication, now names lsi storage authority (lsa)Branches and original-value intervals are stated on each row.Days to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4331same vendor as the line abovesame change as the line aboveDays to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4332same vendor as the line abovesame change as the line aboveDays to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4333same vendor as the line abovesame change as the line aboveDays to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4334same vendor as the line abovesame change as the line aboveDays to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4335same vendor as the line abovesame change as the line aboveDays to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4336same vendor as the line abovesame change as the line aboveDays to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4337same vendor as the line abovesame change as the line aboveDays to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4338same vendor as the line abovesame change as the line aboveDays to revision 31
14 more rows in this change are not listed here. Open all 22 rows
2023-09-163 commitsProduct addedcertccnot named as affected at publication, now names raid web console 3 (rwc3)Branches and original-value intervals are stated on each row.Days to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4331same vendor as the line abovesame change as the line aboveDays to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4332same vendor as the line abovesame change as the line aboveDays to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4334same vendor as the line abovesame change as the line aboveDays to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4335same vendor as the line abovesame change as the line aboveDays to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4336same vendor as the line abovesame change as the line aboveDays to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4337same vendor as the line abovesame change as the line aboveDays to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4338same vendor as the line abovesame change as the line aboveDays to revision 31
2023-09-16same kind of change as the line aboveCVE-2023-4339same vendor as the line abovesame change as the line aboveDays to revision 31
11 more rows in this change are not listed here. Open all 19 rows
Fri 15 Sep 2023· 4 record changes · 1 advisory change
2023-09-15Product addedCVE-2023-37905GitHub_Mnot named as affected at publication, now names cms-rte-ckeditorDays to revision 56
2023-09-15CVSS base score changedCVE-2023-4661
whole record
TR-CERT
stated at publication 10.0, now states 9.8CVSS v3.1 · base scoreCriticalCriticalDays to revision 0
2023-09-15Record state changedCVE-2023-4330
whole record
certcc
stated at publication PUBLISHED, now states REJECTEDDays to revision 31
2023-09-15Record state changedCVE-2023-1576
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 1
2023-09-15published 2021-05-18Advisory severity changedGHSA-gh32-pc56-4c96CVE-2020-10750whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
Thu 14 Sep 2023· 9 record changes · 4 advisory changes
2023-09-14Product addedCVE-2023-38207not named as affected at publication, now names adobe commerceDays to revision 36
2023-09-142 commitsCVSS base score changed
whole record
SolarWinds
stated at publication 6.8, now states 7.2CVSS v3.1 · base scoreMediumHighBranches and original-value intervals are stated on each row.Days to revision 50
2023-09-14same kind of change as the line aboveCVE-2023-33225same vendor as the line abovesame change as the line aboveDays to revision 50
2023-09-14same kind of change as the line aboveCVE-2023-23842same vendor as the line abovesame change as the line aboveDays to revision 50
2023-09-14CVSS base score changedCVE-2023-33229
whole record
SolarWinds
stated at publication 3.1, now states 3.5CVSS v3.1 · base scoreLowLowDays to revision 50
2023-09-14CVSS base score changed
whole record
SolarWinds
stated at publication 6.6, now states 7.2CVSS v3.1 · base scoreMediumHighDays to revision 7 to 35
2023-09-14same kind of change as the line aboveCVE-2023-35179same vendor as the line abovesame change as the line aboveDays to revision 35
2023-09-14same kind of change as the line aboveCVE-2023-40060same vendor as the line abovesame change as the line aboveDays to revision 7
2023-09-14CVSS base score changedCVE-2023-3622
whole record
SolarWinds
stated at publication 4.6, now states 4.3CVSS v3.1 · base scoreMediumMediumDays to revision 50
2023-09-14CVSS base score changedCVE-2023-38235
whole record
adobe
stated at publication 7.8, now states 5.5CVSS v3.1 · base scoreHighMediumDays to revision 35
2023-09-14CVSS base score changedCVE-2023-38207
whole record
adobe
stated at publication 5.3, now states 7.5CVSS v3.1 · base scoreMediumHighDays to revision 36
2023-09-14published 2020-08-31Package added to advisoryGHSA-4mv4-gmmf-q382CVE-2015-6584highnot named as affected when the advisory was published, now names datatables/datatablesnot dated
2023-09-14published 2018-11-09Advisory severity changedGHSA-9xgh-xgw5-p5cwCVE-2017-16057whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-09-14published 2023-09-12Advisory severity changedGHSA-q8hr-4w58-985pCVE-2023-4914whole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 2
2023-09-14published 2020-05-15Advisory severity changedGHSA-fqwf-pjwf-7vqvCVE-2020-10673whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
Wed 13 Sep 2023· 1 record change · 19 advisory changes
2023-09-13Product addedCVE-2023-4456not named as affected at publication, now names rhol-5.7-rhel-8Days to revision 23
2023-09-13published 2019-02-18Advisory severity changedGHSA-j6p2-cx3w-6jcpCVE-2016-10537whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-13published 2018-04-26 to 2018-11-09Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-09-13published 2018-07-23same kind of change as the line aboveGHSA-wwf2-5cj8-jx6wCVE-2017-16049same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-13published 2018-08-29same kind of change as the line aboveGHSA-c2m4-w5hm-vqjwCVE-2017-16074same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-13published 2018-07-23same kind of change as the line aboveGHSA-jp27-cwp2-5qqrCVE-2017-16045same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-13published 2018-04-26same kind of change as the line aboveGHSA-jp4x-w63m-7wgmCVE-2018-3728same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-13published 2018-11-09same kind of change as the line aboveGHSA-9xw9-pvgv-6p76CVE-2017-16014same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-13published 2020-10-29Advisory severity changedGHSA-qvp5-mm7v-4f36CVE-2020-27666whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-13published 2021-03-01Advisory severity changedGHSA-2mm9-c2fx-c7m4CVE-2021-23342whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-13published 2019-01-04Advisory severity changedGHSA-mvjj-gqq2-p4hwCVE-2018-6341whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-13published 2018-08-29Advisory severity changedGHSA-f523-2f5j-gfcgCVE-2017-16115whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-09-13published 2020-08-13 to 2020-10-29Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-09-13published 2020-10-29same kind of change as the line aboveGHSA-4p55-xj37-fx7gCVE-2020-27665same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-13published 2020-08-13same kind of change as the line aboveGHSA-9m4x-8w29-r78gCVE-2020-8205same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-13published 2018-07-24Advisory severity changedGHSA-4w88-rjj3-x7wpCVE-2017-16151whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-09-13published 2020-08-28Advisory severity changedGHSA-chqj-j4fh-rw7mCVE-2019-16728whole advisorymoderatestated at publication CRITICAL, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-13published 2023-09-08 to 2023-09-09Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5
2023-09-13published 2023-09-09same kind of change as the line aboveGHSA-7p8c-crfr-q93pCVE-2023-42277same package and registry as the line abovecriticalsame change as the line aboveDays to revision 5
2023-09-13published 2023-09-09same kind of change as the line aboveGHSA-rxgf-r843-g53hCVE-2023-42276same package and registry as the line abovecriticalsame change as the line aboveDays to revision 5
2023-09-13published 2023-09-08same kind of change as the line aboveGHSA-m7vh-pgfq-v4rqCVE-2023-42268same package and registry as the line abovecriticalsame change as the line aboveDays to revision 5
2023-09-13published 2023-09-08 to 2023-09-09Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 5
2023-09-13published 2023-09-09same kind of change as the line aboveGHSA-rr66-qh5m-w6mxCVE-2023-42278same package and registry as the line abovehighsame change as the line aboveDays to revision 5
2023-09-13published 2023-09-08same kind of change as the line aboveGHSA-pm8v-ppx7-8hr4CVE-2023-41578same package and registry as the line abovehighsame change as the line aboveDays to revision 5
Tue 12 Sep 2023· 3 record changes · 36 advisory changes
2023-09-12Fix version moved
microsoftmicrosoft dynamics 365 (on-premises) version 9.0
stated at publication 9.0.47.xx, now states 9.0.49.04Release branch starts at 9.0.0.same dayDays to revision 0
2023-09-12same kind of change as the line aboveCVE-2023-36886same vendor as the line abovesame change as the line aboveRelease branch starts at 9.0.0.same dayDays to revision 0
2023-09-12same kind of change as the line aboveCVE-2023-38164same vendor as the line abovesame change as the line aboveRelease branch starts at 9.0.0.same dayDays to revision 0
2023-09-12Record state changedCVE-2023-36191
whole record
mitre
stated at publication PUBLISHED, now states REJECTEDDays to revision 82
2023-09-12published 2022-05-14Package added to advisoryGHSA-42wx-65g4-5cxvCVE-2018-1309criticalnot named as affected when the advisory was published, now names org.apache.nifi:nifi-standard-processorsnot dated
2023-09-12published 2021-02-25Package added to advisoryGHSA-pr5m-4w22-8483CVE-2020-13697moderatenot named as affected when the advisory was published, now names org.nanohttpd:nanohttpd-nanoletsnot dated
2023-09-12published 2018-10-17Package added to advisoryGHSA-ccjp-w723-2jf2CVE-2015-3271moderatenot named as affected when the advisory was published, now names org.apache.tika:tika-servernot dated
2023-09-12published 2022-01-06Package added to advisoryGHSA-g644-pr5v-vppfCVE-2020-9486highnot named as affected when the advisory was published, now names org.apache.nifi:nifi-statelessnot dated
2023-09-12published 2018-10-18Package added to advisoryGHSA-v6wr-fch2-vm5wCVE-2015-2913moderatenot named as affected when the advisory was published, now names com.orientechnologies:orientdb-servernot dated
2023-09-12published 2022-05-17Package added to advisoryGHSA-r6fx-55x3-f9x6CVE-2021-23267highnot named as affected when the advisory was published, now names org.craftercms:crafter-studionot dated
2023-09-12published 2018-07-20 to 2018-11-09Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2018-11-09same kind of change as the line aboveGHSA-xqqr-p362-6rmcCVE-2017-16029same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-12published 2018-10-10same kind of change as the line aboveGHSA-894f-rw44-qrw5CVE-2017-16077same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-12published 2018-08-06same kind of change as the line aboveGHSA-mc9x-v9xg-25pmCVE-2017-16205same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-12published 2018-11-09same kind of change as the line aboveGHSA-3rh7-vm4x-q2hpCVE-2017-16055same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-12published 2018-10-03same kind of change as the line aboveGHSA-646x-m363-9rh4CVE-2017-16063same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-12published 2018-08-29same kind of change as the line aboveGHSA-vv6q-9cfw-4c83CVE-2017-16079same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-12published 2018-07-20same kind of change as the line aboveGHSA-wrvr-8mpx-r7ppCVE-2017-16138same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-12published 2018-07-31 to 2018-08-21Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2018-07-31same kind of change as the line aboveGHSA-wjr4-2jgw-hmv8CVE-2018-3772same package and registry as the line abovecriticalsame change as the line abovenot dated
2023-09-12published 2018-08-21same kind of change as the line aboveGHSA-38f5-ghc2-fcmvCVE-2018-3784same package and registry as the line abovecriticalsame change as the line abovenot dated
2023-09-12published 2020-09-01Advisory severity changedGHSA-5h5r-23r4-m87hCVE-2017-16019whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2019-02-07 to 2019-03-25Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2019-02-07same kind of change as the line aboveGHSA-pjxw-22xf-6pwcCVE-2018-16486same package and registry as the line abovecriticalsame change as the line abovenot dated
2023-09-12published 2019-03-25same kind of change as the line aboveGHSA-gwg9-rgvj-4h5jCVE-2019-5413same package and registry as the line abovecriticalsame change as the line abovenot dated
2023-09-12published 2019-02-07same kind of change as the line aboveGHSA-r96c-57pf-9jjmCVE-2018-16491same package and registry as the line abovecriticalsame change as the line abovenot dated
2023-09-12published 2018-07-24 to 2018-11-09Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2018-11-09same kind of change as the line aboveGHSA-hfj4-96f7-6r5gCVE-2017-0931same package and registry as the line abovemoderatesame change as the line abovenot dated
2023-09-12published 2018-07-24same kind of change as the line aboveGHSA-fx46-whrj-73v5CVE-2017-0928same package and registry as the line abovemoderatesame change as the line abovenot dated
2023-09-12published 2018-07-27same kind of change as the line aboveGHSA-3v6h-hqm4-2rg6CVE-2018-1002204same package and registry as the line abovemoderatesame change as the line abovenot dated
2023-09-12published 2022-01-21Advisory severity changedGHSA-c6rp-xvqv-mwmfCVE-2021-33040whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2019-02-07Advisory severity changedGHSA-cxmj-qjv6-vx9pCVE-2018-16482whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2018-07-26Advisory severity changedGHSA-cqp5-m4pq-gfgpCVE-2018-3723whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2019-02-18Advisory severity changedGHSA-899g-6q6w-7v94CVE-2018-16485whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2019-02-07Advisory severity changedGHSA-5p26-hw7f-3cprCVE-2018-16481whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2019-09-04Advisory severity changedGHSA-2j5x-56p6-hj6xCVE-2019-5480whole advisorymoderatestated at publication CRITICAL, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2021-04-13Advisory severity changedGHSA-hxmg-hm46-cf62CVE-2020-24391whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2020-09-01Advisory severity changedGHSA-8gv6-g7vp-hr34CVE-2017-16047whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2018-10-10Advisory severity changedGHSA-cx8m-8xmx-q8v3CVE-2018-3767whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2018-11-06Advisory severity changedGHSA-jhgp-hvj6-x2p2CVE-2018-16474whole advisorymoderatestated at publication CRITICAL, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2019-02-18Advisory severity changedGHSA-pp4v-55vr-9gxhCVE-2016-10527whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2019-12-30Advisory severity changedGHSA-h47j-hc6x-h3qqCVE-2019-10758whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2020-09-01Advisory severity changedGHSA-322m-p39j-r5m2CVE-2017-16128whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-09-12published 2023-09-06Advisory severity changedGHSA-fm4q-j8g4-c9j4CVE-2023-39265whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 6
Mon 11 Sep 2023· 4 record changes · 20 advisory changes
2023-09-11Product added4 rows, one per record and productnot named as affected at publication, now names firefox esr and 1 moreDays to revision 41
2023-09-11same kind of change as the line aboveCVE-2023-4051same vendor as the line abovenot named as affected at publication, now names firefox esrDays to revision 41
2023-09-11same kind of change as the line aboveCVE-2023-4051same vendor as the line abovenot named as affected at publication, now names thunderbirdDays to revision 41
2023-09-11same kind of change as the line aboveCVE-2023-4053same vendor as the line abovenot named as affected at publication, now names firefox esrDays to revision 41
2023-09-11same kind of change as the line aboveCVE-2023-4053same vendor as the line abovenot named as affected at publication, now names thunderbirdDays to revision 41
2023-09-11published 2019-01-07Package added to advisoryGHSA-92wj-x78c-m4fxCVE-2018-11788criticalnot named as affected when the advisory was published, now names org.apache.karaf.specs:org.apache.karaf.specs.java.xmlnot dated
2023-09-11published 2022-09-14Package added to advisoryGHSA-2jv3-v37p-65w3CVE-2022-40634highnot named as affected when the advisory was published, now names org.craftercms:crafter-studionot dated
2023-09-11published 2021-06-16Package added to advisoryGHSA-q7fr-vqhq-v5xrCVE-2021-26118highnot named as affected when the advisory was published, now names org.apache.activemq:artemis-openwire-protocolnot dated
2023-09-11published 2022-05-01Package added to advisoryGHSA-h7mf-qrm9-2848CVE-2007-4556moderatenot named as affected when the advisory was published, now names opensymphony:xworknot dated
2023-09-11published 2018-12-20Package added to advisoryGHSA-43fp-vwwg-qgv6CVE-2018-17194highnot named as affected when the advisory was published, now names org.apache.nifi:nifi-framework-clusternot dated
2023-09-11published 2022-05-24Package added to advisoryGHSA-9x5v-8352-244gCVE-2019-10357moderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins.workflow:workflow-cps-global-libnot dated
2023-09-11published 2018-12-19Package added to advisoryGHSA-8j39-fgfp-vxh8CVE-2018-20094highnot named as affected when the advisory was published, now names com.xuxueli:xxl-conf-adminnot dated
2023-09-11published 2019-08-27Package added to advisoryGHSA-f5f4-m7qp-w6gcCVE-2019-15477moderatenot named as affected when the advisory was published, now names org.jooby:joobynot dated
2023-09-11published 2018-07-27Advisory severity changedGHSA-884w-698f-927fCVE-2018-1002203whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-11published 2021-05-06Advisory severity changedGHSA-qcg2-h349-vwm3CVE-2021-31712whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-11published 2018-08-29Advisory severity changedGHSA-2wpq-vvw6-67wrCVE-2017-16070whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-09-11published 2018-07-24 to 2018-08-13Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-09-11published 2018-08-13same kind of change as the line aboveGHSA-pv4c-p2j5-38j4CVE-2018-3774same package and registry as the line abovecriticalsame change as the line abovenot dated
2023-09-11published 2018-07-24same kind of change as the line aboveGHSA-wc9v-mj63-m9g5CVE-2017-16082same package and registry as the line abovecriticalsame change as the line abovenot dated
2023-09-11published 2018-07-23 to 2018-11-09Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-09-11published 2018-11-09same kind of change as the line aboveGHSA-9fg5-f5pj-rwccCVE-2017-16058same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-11published 2018-08-29same kind of change as the line aboveGHSA-72hv-rp4q-q7f3CVE-2017-16060same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-11published 2018-08-29same kind of change as the line aboveGHSA-4g54-95xv-f353CVE-2017-16075same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-11published 2018-08-29same kind of change as the line aboveGHSA-wqh4-27cc-j8f2CVE-2017-16069same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-11published 2018-07-23same kind of change as the line aboveGHSA-qmjg-g86h-6rc9CVE-2017-16044same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-11published 2018-11-09same kind of change as the line aboveGHSA-5mhv-9qw8-j63gCVE-2017-16056same package and registry as the line abovehighsame change as the line abovenot dated
2023-09-11published 2018-08-29same kind of change as the line aboveGHSA-4x37-5rh2-hp8cCVE-2017-16067same package and registry as the line abovehighsame change as the line abovenot dated

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →