Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

11,999 record changes · 5,026 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
Counted changes, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Fri 25 Aug 2023· 1 record change · 4 advisory changes
2023-08-25CVSS base score changedCVE-2023-3264
whole record
trellix
stated at publication 8.4, now states 6.7CVSS v3.1 · base scoreHighMediumDays to revision 11
2023-08-25published 2023-08-23Advisory severity changedGHSA-8rj5-2857-877jCVE-2022-25024whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 2
2023-08-25published 2023-08-25Advisory severity changedGHSA-jcf2-mxr2-gmqpCVE-2023-40579whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 0
2023-08-25published 2023-08-25Advisory severity changedGHSA-j8g2-6fc7-q8f8CVE-2023-40587whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 0
2023-08-25published 2023-08-22Advisory severity changedGHSA-7ch3-7pp7-7cpqCVE-2023-40570whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 3
Thu 24 Aug 2023· 6 advisory changes
2023-08-24published 2022-06-01Package added to advisoryGHSA-qw3f-w4pf-jh5fCVE-2022-30973moderatenot named as affected when the advisory was published, now names org.apache.tika:tika-corenot dated
2023-08-24published 2023-08-15 to 2023-08-18Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 3 to 9
2023-08-24published 2023-08-18same kind of change as the line aboveGHSA-68xg-gqqm-vgj8CVE-2023-40175same package and registry as the line abovecriticalsame change as the line aboveDays to revision 3
2023-08-24published 2023-08-17same kind of change as the line aboveGHSA-5p42-m6f3-hpmjCVE-2023-38894same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
2023-08-24published 2023-08-15same kind of change as the line aboveGHSA-xrrh-h86w-pwfjCVE-2023-38889same package and registry as the line abovecriticalsame change as the line aboveDays to revision 9
2023-08-24published 2023-08-22Advisory severity changedGHSA-8697-479h-5mfpCVE-2023-38976whole advisoryhighstated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 2
2023-08-24published 2023-08-17Advisory severity changedGHSA-r2f6-6928-fh8fCVE-2023-40272whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
Wed 23 Aug 2023· 1 record change · 5 advisory changes
2023-08-23Record state changedCVE-2023-39583
whole record
mitre
stated at publication PUBLISHED, now states REJECTEDnot dated
2023-08-23published 2022-05-24Package added to advisoryGHSA-w6g9-xccc-347hCVE-2020-7941criticalnot named as affected when the advisory was published, now names plone.app.contenttypesDays to revision 456
2023-08-23published 2023-04-19Advisory severity changedGHSA-x873-6rgc-94jcCVE-2023-20862whole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 126
2023-08-23published 2023-08-17Advisory severity changedGHSA-443m-3fr6-w8wjCVE-2023-36106whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
2023-08-23published 2020-02-04Advisory severity changedGHSA-73m2-3pwg-5fgcCVE-2020-5236whole advisorymoderatestated at publication CRITICAL, now states MODERATEA CVSS version was added; the existing vectors stayed the same.not dated
2023-08-23published 2022-05-24Advisory withdrawnGHSA-jw82-xjgr-g6f8CVE-2020-1742whole advisoryhighwithdrawn 2023-08-23Days to revision 456
Tue 22 Aug 2023· 1 record change · 6 advisory changes
2023-08-22CVSS base score changedCVE-2023-0871
whole record
OpenNMS
stated at publication 8.8, now states 5.4CVSS v3.1 · base scoreHighMediumOriginal value first replaced 2023-08-17; this value first seen 2023-08-22.Days to revision 6
2023-08-22published 2022-05-24Package added to advisoryGHSA-qcch-9268-59jwCVE-2020-14297moderatenot named as affected when the advisory was published, now names org.jboss:jboss-ejb-clientDays to revision 455
2023-08-22published 2023-08-14Advisory severity changedGHSA-xvv9-5j67-3rpqCVE-2023-40274whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2023-08-22published 2023-08-15Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-08-22published 2023-08-15same kind of change as the line aboveGHSA-prgp-w7vf-ch62CVE-2023-39659same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-08-22published 2023-08-15same kind of change as the line aboveGHSA-fj32-q626-pjjcCVE-2023-38860same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-08-22published 2023-08-15same kind of change as the line aboveGHSA-92j5-3459-qgp4CVE-2023-38896same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-08-22published 2023-08-21Advisory withdrawnGHSA-ch6w-mc6c-g65gwhole advisorymoderatewithdrawn 2023-08-22Days to revision 1
Mon 21 Aug 2023· 4 record changes · 6 advisory changes
2023-08-21Product addedCVE-2023-32663
vendor not named
intel
not named as affected at publication, now names intel(r) realsense(tm) sdks in version 2.53.1Days to revision 10
2023-08-21CVSS base score changedCVE-2023-29360
whole record
microsoft
stated at publication 7.8, now states 8.4CVSS v3.1 · base scoreHighHighDays to revision 69
2023-08-21CVSS base score changedCVE-2023-40252
whole record
krcert
stated at publication 7.7, now states 6.0CVSS v3.1 · base scoreHighMediumDays to revision 4
2023-08-21CVSS base score changedCVE-2023-40253
whole record
krcert
stated at publication 4.4, now states 6.0CVSS v3.1 · base scoreMediumMediumOriginal value first replaced 2023-08-17; this value first seen 2023-08-21.Days to revision 6
2023-08-21published 2022-05-24Package added to advisoryGHSA-853f-x27w-8r74CVE-2020-12760highnot named as affected when the advisory was published, now names org.opennms.core:org.opennms.core.daemonDays to revision 454
2023-08-21published 2023-07-10Package added to advisoryGHSA-mjmq-gwgm-5qhmCVE-2023-35887moderatenot named as affected when the advisory was published, now names org.apache.sshd:sshd-coreDays to revision 42
2023-08-21published 2023-08-15Advisory severity changedGHSA-xvhg-w6qc-m3qqCVE-2023-40023whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 6
2023-08-21published 2023-08-11Advisory severity changedGHSA-mq4v-6vg4-796cCVE-2023-39553whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2023-08-21published 2023-08-11Advisory severity changedGHSA-cx3j-qqxj-9597CVE-2023-3481whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 10
2023-08-21published 2022-05-24Advisory withdrawnGHSA-f478-xwv9-p93qwhole advisoryhighwithdrawn 2023-08-21Days to revision 454
Fri 18 Aug 2023· 19 record changes · 6 advisory changes
2023-08-18Product added17 rows, one per record and productjpcertnot named as affected at publication, now names wrc-1467ghbk-a and 6 moreDays to revision 36
2023-08-18same kind of change as the line aboveCVE-2023-37563same vendor as the line abovenot named as affected at publication, now names wrc-1467ghbk-aDays to revision 36
2023-08-18same kind of change as the line aboveCVE-2023-37563same vendor as the line abovenot named as affected at publication, now names wrc-1467ghbk-sDays to revision 36
2023-08-18same kind of change as the line aboveCVE-2023-37563same vendor as the line abovenot named as affected at publication, now names wrc-1900ghbk-aDays to revision 36
2023-08-18same kind of change as the line aboveCVE-2023-37563same vendor as the line abovenot named as affected at publication, now names wrc-1900ghbk-sDays to revision 36
2023-08-18same kind of change as the line aboveCVE-2023-37563same vendor as the line abovenot named as affected at publication, now names wrc-600ghbk-aDays to revision 36
2023-08-18same kind of change as the line aboveCVE-2023-37563same vendor as the line abovenot named as affected at publication, now names wrc-733febk2-aDays to revision 36
2023-08-18same kind of change as the line aboveCVE-2023-37563same vendor as the line abovenot named as affected at publication, now names wrc-f1167acf2Days to revision 36
2023-08-18same kind of change as the line aboveCVE-2023-37566same vendor as the line abovenot named as affected at publication, now names wrc-1467ghbk-aDays to revision 36
9 more rows in this change are not listed here. Open all 17 rows
2023-08-18Product addedjpcertnot named as affected at publication, now names lan-w301nrDays to revision 36
2023-08-18same kind of change as the line aboveCVE-2023-37566same vendor as the line abovesame change as the line aboveDays to revision 36
2023-08-18same kind of change as the line aboveCVE-2023-37567same vendor as the line abovesame change as the line aboveDays to revision 36
2023-08-18published 2022-11-16Package added to advisoryGHSA-fhw8-8j55-vwgqCVE-2022-45047criticalnot named as affected when the advisory was published, now names org.apache.sshd:sshd-coreDays to revision 275
2023-08-18published 2018-10-17Package added to advisoryGHSA-4446-656p-f54gCVE-2018-1000613criticalnot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onnot dated
2023-08-18published 2023-08-11Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-08-18published 2023-08-11same kind of change as the line aboveGHSA-5x64-925v-h4gvCVE-2020-35141same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-08-18published 2023-08-11same kind of change as the line aboveGHSA-4987-5p3p-9r27CVE-2020-35139same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-08-18published 2023-08-11Advisory severity changedGHSA-pr76-5cm5-w9cjCVE-2023-40267whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-08-18published 2022-05-13Advisory withdrawnGHSA-m833-87vf-576cCVE-2017-15113whole advisorymoderatewithdrawn 2023-08-18Days to revision 463
Thu 17 Aug 2023· 2 record changes · 1 advisory change
2023-08-17Record state changed
whole record
mitre
stated at publication PUBLISHED, now states REJECTEDnot dated
2023-08-17same kind of change as the line aboveCVE-2023-39848same vendor as the line abovesame change as the line abovenot dated
2023-08-17same kind of change as the line aboveCVE-2023-39849same vendor as the line abovesame change as the line abovenot dated
2023-08-17published 2023-08-11Advisory severity changedGHSA-jp5r-4x9q-4vcfCVE-2020-24922whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
Wed 16 Aug 2023· 4 record changes · 2 advisory changes
2023-08-16CVSS base score changedCVE-2023-2959
whole record
TR-CERT
stated at publication 8.2, now states 7.5CVSS v3.1 · base scoreHighHighDays to revision 30
2023-08-16CVSS base score changedCVE-2023-35067
whole record
TR-CERT
stated at publication 9.1, now states 7.5CVSS v3.1 · base scoreCriticalHighDays to revision 22
2023-08-16CVSS base score changedCVE-2023-3632
whole record
TR-CERT
stated at publication 9.0, now states 9.8CVSS v3.1 · base scoreCriticalCriticalDays to revision 7
2023-08-16CVSS base score changedCVE-2023-3653
whole record
TR-CERT
stated at publication 6.1, now states 5.4CVSS v3.1 · base scoreMediumMediumDays to revision 8
2023-08-16published 2023-08-11Advisory severity changedGHSA-g3vf-47fv-8f3cCVE-2021-26505whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5
2023-08-16published 2023-08-11Advisory severity changedGHSA-7rvp-xqj7-rxf2CVE-2020-24950whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 5
Tue 15 Aug 2023· 1 record change · 6 advisory changes
2023-08-15Affected range extendedCVE-2023-2495
unknowngreeklish-permalink
WPScan
stated at publication 3.3, now states 3.5Release branch starts at 0.Days to revision 36
2023-08-15published 2023-08-09Package added to advisoryGHSA-vmch-3w2x-vhgqhighnot named as affected when the advisory was published, now names microsoft.aspnetcore.server.kestrel.transport.libuv and 1 moreDays to revision 6
2023-08-15published 2023-08-09same kind of change as the line aboveGHSA-vmch-3w2x-vhgqCVE-2023-38180same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.server.kestrel.transport.libuvDays to revision 6
2023-08-15published 2023-08-09same kind of change as the line aboveGHSA-vmch-3w2x-vhgqCVE-2023-38180same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.server.kestrel.transport.socketsDays to revision 6
2023-08-15published 2021-06-16Package added to advisoryGHSA-2f88-5hg8-9x2xcriticalnot named as affected when the advisory was published, now names org.apache.maven:maven-compat and 1 morenot dated
2023-08-15published 2021-06-16same kind of change as the line aboveGHSA-2f88-5hg8-9x2xCVE-2021-26291same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.maven:maven-compatnot dated
2023-08-15published 2021-06-16same kind of change as the line aboveGHSA-2f88-5hg8-9x2xCVE-2021-26291same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.maven:maven-corenot dated
2023-08-15published 2023-07-05Advisory severity changedGHSA-h755-8qp9-cq85CVE-2023-36665whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 41
2023-08-15published 2023-07-14Advisory severity changedGHSA-cf7p-gm2m-833mCVE-2023-38325whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 32
Mon 14 Aug 2023· 2 advisory changes
2023-08-14published 2023-07-18Package added to advisoryGHSA-p9xf-74xh-mhw5CVE-2023-37477highnot named as affected when the advisory was published, now names github.com/1panel-dev/1panelDays to revision 27
2023-08-14published 2023-04-04Advisory withdrawnGHSA-gq63-p39p-jrjfCVE-2023-26750whole advisorycriticalwithdrawn 2023-08-14Days to revision 132
Fri 11 Aug 2023· 1 record change
2023-08-11Product addedCVE-2023-26309not named as affected at publication, now names oneplus storeDays to revision 1
Thu 10 Aug 2023· 1 record change
2023-08-10Record state changedCVE-2023-4205
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 3
Wed 9 Aug 2023· 1 record change · 3 advisory changes
2023-08-09CVSS base score changedCVE-2023-26310
whole record
OPPO
stated at publication 9.1, now states 7.4CVSS v3.1 · base scoreCriticalHighDays to revision 0
2023-08-09published 2023-08-05Advisory severity changedGHSA-269x-pg5c-5xgmCVE-2023-39508whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 5
2023-08-09published 2023-08-05Advisory severity changedGHSA-gwqq-6vq7-5j86CVE-2023-36095whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5
2023-08-09published 2023-08-04Advisory severity changedGHSA-w7vm-4v3j-vgpwCVE-2023-29689whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5
Tue 8 Aug 2023· 12 record changes · 7 advisory changes
2023-08-08Affected range extendedCVE-2023-2329
unknownwoocommerce google sheet connector
WPScan
stated at publication 1.3.4, now states 1.3.6Release branch starts at 0.Days to revision 22
2023-08-08Product addedCVE-2023-25957not named as affected at publication, now names mendix saml (mendix 9 latest compatible, new track) and 3 moreDays to revision 147
2023-08-08same kind of change as the line aboveCVE-2023-25957same vendor as the line abovenot named as affected at publication, now names mendix saml (mendix 9 latest compatible, new track)Days to revision 147
2023-08-08same kind of change as the line aboveCVE-2023-25957same vendor as the line abovenot named as affected at publication, now names mendix saml (mendix 9 latest compatible, upgrade track)Days to revision 147
2023-08-08same kind of change as the line aboveCVE-2023-25957same vendor as the line abovenot named as affected at publication, now names mendix saml (mendix 9.6 compatible, new track)Days to revision 147
2023-08-08same kind of change as the line aboveCVE-2023-25957same vendor as the line abovenot named as affected at publication, now names mendix saml (mendix 9.6 compatible, upgrade track)Days to revision 147
2023-08-08Product addedCVE-2023-29129not named as affected at publication, now names mendix saml (mendix 9.12/9.18 compatible, new track) and 3 moreDays to revision 56
2023-08-08same kind of change as the line aboveCVE-2023-29129same vendor as the line abovenot named as affected at publication, now names mendix saml (mendix 9.12/9.18 compatible, new track)Days to revision 56
2023-08-08same kind of change as the line aboveCVE-2023-29129same vendor as the line abovenot named as affected at publication, now names mendix saml (mendix 9.12/9.18 compatible, upgrade track)Days to revision 56
2023-08-08same kind of change as the line aboveCVE-2023-29129same vendor as the line abovenot named as affected at publication, now names mendix saml (mendix 9.6 compatible, new track)Days to revision 56
2023-08-08same kind of change as the line aboveCVE-2023-29129same vendor as the line abovenot named as affected at publication, now names mendix saml (mendix 9.6 compatible, upgrade track)Days to revision 56
2023-08-08CVSS base score changedCVE-2023-36884
whole record
microsoft
stated at publication 0.0, now states 7.5CVSS v3.1 · base scoreNoneHighOriginal value first replaced 2023-07-31; this value first seen 2023-08-08.Days to revision 20
2023-08-08CVSS base score changedCVE-2023-3618
whole record
redhat
stated at publication 7.5, now states 6.5CVSS v3.1 · base scoreHighMediumDays to revision 27
2023-08-08Record state changedCVE-2023-39977
whole record
mitre
stated at publication PUBLISHED, now states REJECTEDnot dated
2023-08-08published 2022-12-14Advisory severity changedGHSA-995x-33wq-8gc9CVE-2022-24377whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 238
2023-08-08published 2022-09-21Advisory severity changedGHSA-crf8-h2wq-2h9xCVE-2022-39974whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-08-08published 2022-02-08Advisory severity changedGHSA-g6w6-r76c-28j7CVE-2022-24450whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-08-08published 2021-11-19Advisory severity changedGHSA-vhrp-8qx4-vr6cCVE-2021-43996whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-08-08published 2021-10-05Advisory severity changedGHSA-cr3f-r24j-3chwCVE-2021-40325whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-08-08published 2021-02-05Advisory severity changedGHSA-f5c9-x9j6-87qpCVE-2021-25912whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-08-08published 2022-10-16Advisory severity changedGHSA-w596-4wvx-j9j6CVE-2022-42969whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
Mon 7 Aug 2023· 3 record changes · 14 advisory changes
2023-08-07Product addednot named as affected at publication, now names thunderbirdDays to revision 6
2023-08-07same kind of change as the line aboveCVE-2023-4052same vendor as the line abovesame change as the line aboveDays to revision 6
2023-08-07same kind of change as the line aboveCVE-2023-4054same vendor as the line abovesame change as the line aboveDays to revision 6
2023-08-07same kind of change as the line aboveCVE-2023-4057same vendor as the line abovesame change as the line aboveDays to revision 6
2023-08-07published 2020-02-21 to 2021-12-09Package added to advisory3 bandsnot named as affected when the advisory was published, now names io.netty:nettynot dated
2023-08-07published 2021-09-09same kind of change as the line aboveGHSA-9vjp-v76f-g363CVE-2021-37137same package registry as the line abovehighsame change as the line abovenot dated
2023-08-07published 2021-03-09same kind of change as the line aboveGHSA-wm47-8v5p-wjpjCVE-2021-21295same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-07published 2021-12-09same kind of change as the line aboveGHSA-wx5j-54mm-rqqqCVE-2021-43797same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-07published 2021-09-09same kind of change as the line aboveGHSA-grg4-wf29-r9vvCVE-2021-37136same package registry as the line abovehighsame change as the line abovenot dated
2023-08-07published 2021-03-30same kind of change as the line aboveGHSA-f256-j965-7f32CVE-2021-21409same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-07published 2021-02-08same kind of change as the line aboveGHSA-5mcr-gq6c-3hq2CVE-2021-21290same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-07published 2020-02-21same kind of change as the line aboveGHSA-cqqj-4p63-rrmmCVE-2019-20444same package registry as the line abovecriticalsame change as the line abovenot dated
2023-08-07published 2020-02-21same kind of change as the line aboveGHSA-p2v9-g2qv-p635CVE-2019-20445same package registry as the line abovemoderatesame change as the line abovenot dated
1 more row in this change is not listed here. Open all 9 rows
2023-08-07published 2022-01-27Package added to advisoryGHSA-77rm-9x9h-xj3gCVE-2021-22570highnot named as affected when the advisory was published, now names com.google.protobuf:protobuf-javanot dated
2023-08-07published 2023-07-31Advisory severity changedGHSA-36xx-7vf6-7mv3CVE-2023-32302whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 7
2023-08-07published 2019-03-25Advisory severity changedGHSA-gcm4-q2pg-xw89CVE-2019-7539whole advisorycriticalstated at publication HIGH, now states CRITICALCVSS versions were removed or replaced; no shared version's vector was rescored.not dated
2023-08-07published 2022-05-24Advisory withdrawnwhole advisory2 bandswithdrawn 2023-08-07Days to revision 440
2023-08-07published 2022-05-24same kind of change as the line aboveGHSA-6q5m-22mq-q2xvCVE-2021-31920same package and registry as the line abovemoderatewithdrawn 2023-08-07Days to revision 440
2023-08-07published 2022-05-24same kind of change as the line aboveGHSA-39mj-fpg2-3jrgCVE-2021-28667same package and registry as the line abovehighwithdrawn 2023-08-07Days to revision 440
Fri 4 Aug 2023· 16 advisory changes
2023-08-04published 2022-05-24Package added to advisoryGHSA-hr65-qq6p-87r4CVE-2021-22137moderatenot named as affected when the advisory was published, now names org.elasticsearch:elasticsearchnot dated
2023-08-04published 2019-10-11 to 2021-12-09Package added to advisory3 bandsnot named as affected when the advisory was published, now names org.jboss.netty:nettynot dated
2023-08-04published 2021-12-09same kind of change as the line aboveGHSA-wx5j-54mm-rqqqCVE-2021-43797same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-04published 2021-09-09same kind of change as the line aboveGHSA-9vjp-v76f-g363CVE-2021-37137same package registry as the line abovehighsame change as the line abovenot dated
2023-08-04published 2021-09-09same kind of change as the line aboveGHSA-grg4-wf29-r9vvCVE-2021-37136same package registry as the line abovehighsame change as the line abovenot dated
2023-08-04published 2021-03-30same kind of change as the line aboveGHSA-f256-j965-7f32CVE-2021-21409same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-04published 2021-03-09same kind of change as the line aboveGHSA-wm47-8v5p-wjpjCVE-2021-21295same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-04published 2021-02-08same kind of change as the line aboveGHSA-5mcr-gq6c-3hq2CVE-2021-21290same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-04published 2020-02-21same kind of change as the line aboveGHSA-cqqj-4p63-rrmmCVE-2019-20444same package registry as the line abovecriticalsame change as the line abovenot dated
2023-08-04published 2020-02-21same kind of change as the line aboveGHSA-p2v9-g2qv-p635CVE-2019-20445same package registry as the line abovemoderatesame change as the line abovenot dated
2 more rows in this change are not listed here. Open all 10 rows
2023-08-04published 2020-06-30Package added to advisoryGHSA-xfv3-rrfm-f2rvCVE-2015-2156highnot named as affected when the advisory was published, now names io.netty:netty-parentnot dated
2023-08-04published 2023-07-31Advisory severity changedGHSA-p6hw-wm59-3g5gCVE-2023-38686whole advisorycriticalstated at publication LOW, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 4
2023-08-04published 2023-08-01 to 2023-08-03Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 1 to 3
2023-08-04published 2023-08-03same kind of change as the line aboveGHSA-jj95-55cr-9597CVE-2023-36480same package and registry as the line abovecriticalsame change as the line aboveDays to revision 1
2023-08-04published 2023-08-01same kind of change as the line aboveGHSA-7c28-wg7r-pg6fCVE-2022-39986same package and registry as the line abovecriticalsame change as the line aboveDays to revision 3
2023-08-04published 2023-08-01Advisory severity changedGHSA-7r88-wjhj-jr8mCVE-2022-39987whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 3
Thu 3 Aug 2023· 4 record changes · 15 advisory changes
2023-08-03CVSS base score changed
whole record
SolarWinds
stated at publication 6.8, now states 7.2CVSS v3.1 · base scoreMediumHighDays to revision 8
2023-08-03same kind of change as the line aboveCVE-2023-23843same vendor as the line abovesame change as the line aboveDays to revision 8
2023-08-03same kind of change as the line aboveCVE-2023-23844same vendor as the line abovesame change as the line aboveDays to revision 8
2023-08-03same kind of change as the line aboveCVE-2023-33224same vendor as the line abovesame change as the line aboveDays to revision 8
2023-08-03CVSS base score changedCVE-2023-33231
whole record
SolarWinds
stated at publication 5.4, now states 6.1CVSS v3.1 · base scoreMediumMediumDays to revision 16
2023-08-03published 2022-05-24Package added to advisoryGHSA-c3mp-9vx3-2rvvhighnot named as affected when the advisory was published, now names org.opennms.features:org.opennms.features.measurements and 2 moreDays to revision 436
2023-08-03published 2022-05-24same kind of change as the line aboveGHSA-c3mp-9vx3-2rvvCVE-2021-3396same package registry as the line abovehighnot named as affected when the advisory was published, now names org.opennms.features:org.opennms.features.measurementsDays to revision 436
2023-08-03published 2022-05-24same kind of change as the line aboveGHSA-c3mp-9vx3-2rvvCVE-2021-3396same package registry as the line abovehighnot named as affected when the advisory was published, now names org.opennms:opennms-provisionDays to revision 436
2023-08-03published 2022-05-24same kind of change as the line aboveGHSA-c3mp-9vx3-2rvvCVE-2021-3396same package registry as the line abovehighnot named as affected when the advisory was published, now names org.opennms:opennms-utilDays to revision 436
2023-08-03published 2022-05-13Package added to advisoryGHSA-hmx6-gc2p-5p82CVE-2019-5919criticalnot named as affected when the advisory was published, now names com.nablarch.framework:nablarch-fw-webDays to revision 448
2023-08-03published 2023-07-29Advisory severity changedGHSA-r969-8v3h-23v9CVE-2023-36542whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
2023-08-03published 2023-07-25 to 2023-07-28Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6 to 9
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-859m-2pfx-fwhfCVE-2023-39022same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-fx3v-4w3w-wpwrCVE-2023-39021same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-2h26-qfxm-r3pqCVE-2023-37754same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-353m-jh2m-72v4CVE-2023-39020same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-99p5-qpqx-mhwcCVE-2023-39010same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-grvq-vjqr-x8vmCVE-2023-39015same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-p83q-99rc-vfmvCVE-2023-39013same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-wp6c-29r3-jqw9CVE-2023-38992same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
1 more row in this change is not listed here. Open all 9 rows
2023-08-03published 2023-07-25Advisory severity changedGHSA-xqr8-7jwr-rhp7CVE-2023-37920whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
Wed 2 Aug 2023· 2 record changes
2023-08-02Product addedCVE-2023-3568@huntrdevnot named as affected at publication, now names alextselegidis/easyappointmentsDays to revision 23
2023-08-02CVSS base score changedCVE-2023-25841
whole record
Esri
stated at publication 4.8, now states 6.1CVSS v3.1 · base scoreMediumMediumDays to revision 11
Tue 1 Aug 2023· 9 record changes
2023-08-01Product addedCVE-2023-28260not named as affected at publication, now names powershell 7.2 and 1 moreDays to revision 112
2023-08-01same kind of change as the line aboveCVE-2023-28260same vendor as the line abovenot named as affected at publication, now names powershell 7.2Days to revision 112
2023-08-01same kind of change as the line aboveCVE-2023-28260same vendor as the line abovenot named as affected at publication, now names powershell 7.3Days to revision 112
2023-08-01CVSS base score changedCVE-2023-31427
whole record
brocade
stated at publication 5.3, now states 7.8CVSS v3.1 · base scoreMediumHighDays to revision 0
2023-08-01CVSS base score changedCVE-2023-28261
whole record
microsoft
stated at publication 6.1, now states 5.7CVSS v3.1 · base scoreMediumMediumOriginal value first replaced 2023-06-17; this value first seen 2023-08-01.Days to revision 50
2023-08-01CVSS base score changedCVE-2023-24936
whole record
microsoft
stated at publication 8.1, now states 7.5CVSS v3.1 · base scoreHighHighDays to revision 48
2023-08-01CVSS base score changedCVE-2023-32012
whole record
microsoft
stated at publication 6.3, now states 7.8CVSS v3.1 · base scoreMediumHighDays to revision 49
2023-08-01CVSS base score changedCVE-2023-32013
whole record
microsoft
stated at publication 6.5, now states 5.3CVSS v3.1 · base scoreMediumMediumDays to revision 49
2023-08-01CVSS base score changedCVE-2023-32020
whole record
microsoft
stated at publication 3.7, now states 5.6CVSS v3.1 · base scoreLowMediumDays to revision 49
2023-08-01CVSS base score changedCVE-2023-33144
whole record
microsoft
stated at publication 5.0, now states 6.6CVSS v3.1 · base scoreMediumMediumDays to revision 49

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →