Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

11,999 record changes · 5,026 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
Counted changes, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Tue 1 Aug 2023· 1 record change · 2 advisory changes
2023-08-01Record state changedCVE-2023-3117
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 33
2023-08-01published 2023-07-24Advisory severity changedGHSA-pmhc-2g4f-85cgCVE-2023-34478whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-08-01published 2022-05-13Advisory withdrawnGHSA-6hvf-xvwm-vrw4CVE-2019-9628whole advisoryhighwithdrawn 2023-08-01Days to revision 446
Mon 31 Jul 2023· 6 record changes · 4 advisory changes
2023-07-31Fix version movedCVE-2023-32712
splunksplunk enterprise
stated at publication 8.2.11, now states 8.2.11.2Release branch starts at 8.2.Days to revision 60
2023-07-31Fix version movedCVE-2023-32712
splunksplunk enterprise
stated at publication 9.0.5, now states 9.0.5.1Release branch starts at 9.0.Days to revision 60
2023-07-31Product addedCVE-2023-28013HCLnot named as affected at publication, now names hcl verseDays to revision 5
2023-07-31CVSS base score changedCVE-2023-0009
whole record
palo_alto
stated at publication 6.7, now states 7.8CVSS v3.1 · base scoreMediumHighDays to revision 47
2023-07-31CVSS base score changedCVE-2023-28013
whole record
HCL
stated at publication 6.6, now states 6.5CVSS v3.1 · base scoreMediumMediumDays to revision 5
2023-07-31CVSS base score changedCVE-2023-32712
whole record
Splunk
stated at publication 3.4, now states 8.6CVSS v3.1 · base scoreLowHighDays to revision 60
2023-07-31published 2022-01-06Package added to advisoryGHSA-7q8g-gpfp-v8gxhighnot named as affected when the advisory was published, now names org.apache.nifi:nifi-framework-core and 1 morenot dated
2023-07-31published 2022-01-06same kind of change as the line aboveGHSA-7q8g-gpfp-v8gxCVE-2020-1942same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.nifi:nifi-framework-corenot dated
2023-07-31published 2022-01-06same kind of change as the line aboveGHSA-7q8g-gpfp-v8gxCVE-2020-1942same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.nifi:nifi-security-utilsnot dated
2023-07-31published 2023-03-16Package added to advisoryGHSA-p8p7-x288-28g6CVE-2023-28155moderatenot named as affected when the advisory was published, now names @cypress/requestDays to revision 137
2023-07-31published 2022-03-11Advisory withdrawnGHSA-29vr-79w7-p649CVE-2021-44597whole advisorycriticalwithdrawn 2023-07-31Days to revision 508
Fri 28 Jul 2023· 4 advisory changes
2023-07-28published 2022-06-15 to 2022-10-26Package added to advisory2 bandsnot named as affected when the advisory was published, now names org.apache.flume.flume-ng-sources:flume-jms-sourcenot dated
2023-07-28published 2022-10-26same kind of change as the line aboveGHSA-9w4g-fp9h-3q2vCVE-2022-42468same package registry as the line abovecriticalsame change as the line abovenot dated
2023-07-28published 2022-06-15same kind of change as the line aboveGHSA-x5m7-rwfx-w7qmCVE-2022-25167same package registry as the line abovehighsame change as the line abovenot dated
2023-07-28published 2023-07-19Advisory severity changedGHSA-3cxh-xp3g-jxjmCVE-2023-28754whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2023-07-28published 2021-10-22Advisory severity changedGHSA-pjwm-rvh2-c87wCVE-2021-4229whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.not dated
Thu 27 Jul 2023· 131 record changes · 3 advisory changes
2023-07-272 commitsProduct added130 rows, one per record and productnot named as affected at publication, now names macos and 5 moreBranches and original-value intervals are stated on each row.Days to revision 34 to 150
2023-07-27same kind of change as the line aboveCVE-2023-23496same vendor as the line abovenot named as affected at publication, now names macosDays to revision 150
2023-07-27same kind of change as the line aboveCVE-2023-23496same vendor as the line abovenot named as affected at publication, now names safariDays to revision 150
2023-07-27same kind of change as the line aboveCVE-2023-23500same vendor as the line abovenot named as affected at publication, now names macosDays to revision 150
2023-07-27same kind of change as the line aboveCVE-2023-23503same vendor as the line abovenot named as affected at publication, now names macosDays to revision 150
2023-07-27same kind of change as the line aboveCVE-2023-23511same vendor as the line abovenot named as affected at publication, now names macosDays to revision 150
2023-07-27same kind of change as the line aboveCVE-2023-23517same vendor as the line abovenot named as affected at publication, now names macosDays to revision 150
2023-07-27same kind of change as the line aboveCVE-2023-23517same vendor as the line abovenot named as affected at publication, now names safariDays to revision 150
2023-07-27same kind of change as the line aboveCVE-2023-23519same vendor as the line abovenot named as affected at publication, now names macosDays to revision 150
122 more rows in this change are not listed here. Open all 130 rows
2023-07-27CVSS base score changedCVE-2023-28012
whole record
HCL
stated at publication 6.6, now states 5.4CVSS v3.1 · base scoreMediumMediumDays to revision 0
2023-07-27published 2023-07-14 to 2023-07-18Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9 to 13
2023-07-27published 2023-07-14same kind of change as the line aboveGHSA-7gj7-224w-vpr3CVE-2023-38286same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-07-27published 2023-07-18same kind of change as the line aboveGHSA-4r8x-2p26-976pCVE-2023-37788same package and registry as the line abovehighsame change as the line aboveDays to revision 9
2023-07-27published 2023-07-15same kind of change as the line aboveGHSA-vc79-65pr-q82vCVE-2023-38337same package and registry as the line abovehighsame change as the line aboveDays to revision 13
Wed 26 Jul 2023· 35 record changes · 3 advisory changes
2023-07-263 commitsProduct added18 rows, one per record and productnot named as affected at publication, now names macos and 3 moreBranches and original-value intervals are stated on each row.Days to revision 34 to 150
2023-07-26same kind of change as the line aboveCVE-2023-23499same vendor as the line abovenot named as affected at publication, now names macosDays to revision 150
2023-07-26same kind of change as the line aboveCVE-2023-23504same vendor as the line abovenot named as affected at publication, now names macosDays to revision 150
2023-07-26same kind of change as the line aboveCVE-2023-23512same vendor as the line abovenot named as affected at publication, now names macosDays to revision 150
2023-07-26same kind of change as the line aboveCVE-2023-23524same vendor as the line abovenot named as affected at publication, now names macosDays to revision 150
2023-07-26same kind of change as the line aboveCVE-2023-23524same vendor as the line abovenot named as affected at publication, now names tvosDays to revision 150
2023-07-26same kind of change as the line aboveCVE-2023-23525same vendor as the line abovenot named as affected at publication, now names ios and ipadosDays to revision 80
2023-07-26same kind of change as the line aboveCVE-2023-23532same vendor as the line abovenot named as affected at publication, now names ios and ipadosDays to revision 80
2023-07-26same kind of change as the line aboveCVE-2023-27930same vendor as the line abovenot named as affected at publication, now names ios and ipadosDays to revision 34
10 more rows in this change are not listed here. Open all 18 rows
2023-07-26CVSS base score changedCVE-2023-2884
whole record
TR-CERT
stated at publication 6.4, now states 9.8CVSS v3.1 · base scoreMediumCriticalDays to revision 62
2023-07-26CVSS base score changedCVE-2023-2885
whole record
TR-CERT
stated at publication 9.9, now states 8.1CVSS v3.1 · base scoreCriticalHighDays to revision 62
2023-07-26CVSS base score changedCVE-2023-2887
whole record
TR-CERT
stated at publication 9.1, now states 9.8CVSS v3.1 · base scoreCriticalCriticalDays to revision 62
2023-07-262 commitsCVSS base score changed
whole record
TR-CERT
stated at publication 8.8, now states 9.8CVSS v3.1 · base scoreHighCriticalBranches and original-value intervals are stated on each row.Days to revision 9 to 67
2023-07-26same kind of change as the line aboveCVE-2023-2958same vendor as the line abovesame change as the line aboveDays to revision 9
2023-07-26same kind of change as the line aboveCVE-2023-3048same vendor as the line abovesame change as the line aboveDays to revision 43
2023-07-26same kind of change as the line aboveCVE-2023-2713same vendor as the line abovesame change as the line aboveDays to revision 67
2023-07-26CVSS base score changedCVE-2023-35069
whole record
TR-CERT
stated at publication 8.6, now states 7.5CVSS v3.1 · base scoreHighHighDays to revision 13
2023-07-262 commitsCVSS base score changed
whole record
TR-CERT
stated at publication 10.0, now states 9.8CVSS v3.1 · base scoreCriticalCriticalBranches and original-value intervals are stated on each row.Days to revision 13 to 103
2023-07-26same kind of change as the line aboveCVE-2023-3049same vendor as the line abovesame change as the line aboveDays to revision 43
2023-07-26same kind of change as the line aboveCVE-2023-1547same vendor as the line abovesame change as the line aboveDays to revision 13
2023-07-26same kind of change as the line aboveCVE-2023-1803same vendor as the line abovesame change as the line aboveDays to revision 103
2023-07-26same kind of change as the line aboveCVE-2023-1833same vendor as the line abovesame change as the line aboveDays to revision 103
2023-07-26same kind of change as the line aboveCVE-2023-2712same vendor as the line abovesame change as the line aboveDays to revision 67
2023-07-26same kind of change as the line aboveCVE-2023-2851same vendor as the line abovesame change as the line aboveDays to revision 62
2023-07-26CVSS base score changedCVE-2023-3319
whole record
TR-CERT
stated at publication 6.1, now states 5.4CVSS v3.1 · base scoreMediumMediumDays to revision 13
2023-07-26CVSS base score changedCVE-2023-2703
whole record
TR-CERT
stated at publication 7.6, now states 7.5CVSS v3.1 · base scoreHighHighDays to revision 64
2023-07-26CVSS base score changedCVE-2023-2882
whole record
TR-CERT
stated at publication 9.9, now states 9.8CVSS v3.1 · base scoreCriticalCriticalDays to revision 62
2023-07-26Record state changedCVE-2023-21261
whole record
google_android
stated at publication PUBLISHED, now states REJECTEDDays to revision 14
2023-07-26published 2023-07-20Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
2023-07-26published 2023-07-20same kind of change as the line aboveGHSA-45g2-r339-pjwfCVE-2023-37650same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-07-26published 2023-07-20same kind of change as the line aboveGHSA-9r25-4j77-9wc7CVE-2023-37649same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-07-26published 2023-07-16Advisory severity changedGHSA-hx4h-676r-j3qpCVE-2023-3691whole advisorymoderatestated at publication LOW, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 10
Tue 25 Jul 2023· 7 record changes · 2 advisory changes
2023-07-25Product addedCVE-2023-21405Axisnot named as affected at publication, now names axis a1001 network door controller and 5 moreDays to revision 0
2023-07-25same kind of change as the line aboveCVE-2023-21405same vendor as the line abovenot named as affected at publication, now names axis a1001 network door controllerDays to revision 0
2023-07-25same kind of change as the line aboveCVE-2023-21405same vendor as the line abovenot named as affected at publication, now names axis a1210-b network door controllerDays to revision 0
2023-07-25same kind of change as the line aboveCVE-2023-21405same vendor as the line abovenot named as affected at publication, now names axis a1601 network door controllerDays to revision 0
2023-07-25same kind of change as the line aboveCVE-2023-21405same vendor as the line abovenot named as affected at publication, now names axis a1610 (-b) network door controllerDays to revision 0
2023-07-25same kind of change as the line aboveCVE-2023-21405same vendor as the line abovenot named as affected at publication, now names axis a8207-ve mk ii network video door stationDays to revision 0
2023-07-25same kind of change as the line aboveCVE-2023-21405same vendor as the line abovenot named as affected at publication, now names axis a8207-ve network video door stationDays to revision 0
2023-07-25CVSS base score changedCVE-2023-3897
whole record
42Gears
stated at publication 3.7, now states 4.8CVSS v3.1 · base scoreLowMediumDays to revision 0
2023-07-25published 2023-03-31Package added to advisoryGHSA-5c9c-6x87-f9vmCVE-2022-4899highnot named as affected when the advisory was published, now names zstdDays to revision 116
2023-07-25published 2023-07-13Advisory severity changedGHSA-4q2q-q5pw-2342CVE-2023-37415whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 12
Mon 24 Jul 2023· 5 record changes · 2 advisory changes
2023-07-24Product addedredhatnot named as affected at publication, now names fedoraDays to revision 25 to 27
2023-07-24same kind of change as the line aboveCVE-2023-2908same vendor as the line abovesame change as the line aboveDays to revision 25
2023-07-24same kind of change as the line aboveCVE-2023-3338same vendor as the line abovesame change as the line aboveDays to revision 25
2023-07-24same kind of change as the line aboveCVE-2023-3355same vendor as the line abovesame change as the line aboveDays to revision 27
2023-07-24Product addedCVE-2023-3600not named as affected at publication, now names thunderbirdDays to revision 12
2023-07-24Record state changedCVE-2023-3870
whole record
Arm
stated at publication PUBLISHED, now states REJECTEDDays to revision 0
2023-07-24published 2022-05-14Package added to advisoryGHSA-43q7-q5vp-3g68CVE-2018-14371highnot named as affected when the advisory was published, now names org.glassfish:mojarra-parentnot dated
2023-07-24published 2022-01-12Advisory severity changedGHSA-7w54-gp8x-f33mCVE-2022-21671whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
Fri 21 Jul 2023· 9 record changes · 3 advisory changes
2023-07-21Product addedCVE-2023-21538not named as affected at publication, now names powershell 7.2Days to revision 193
2023-07-21Record state changed
whole record
GandC
stated at publication PUBLISHED, now states REJECTEDDays to revision 73 to 121
2023-07-21same kind of change as the line aboveCVE-2023-26934same vendor as the line abovesame change as the line aboveDays to revision 87
2023-07-21same kind of change as the line aboveCVE-2023-26935same vendor as the line abovesame change as the line aboveDays to revision 87
2023-07-21same kind of change as the line aboveCVE-2023-26936same vendor as the line abovesame change as the line aboveDays to revision 87
2023-07-21same kind of change as the line aboveCVE-2023-26937same vendor as the line abovesame change as the line aboveDays to revision 87
2023-07-21same kind of change as the line aboveCVE-2023-26938same vendor as the line abovesame change as the line aboveDays to revision 87
2023-07-21same kind of change as the line aboveCVE-2023-27655same vendor as the line abovesame change as the line aboveDays to revision 121
2023-07-21same kind of change as the line aboveCVE-2023-31554same vendor as the line abovesame change as the line aboveDays to revision 73
2023-07-21same kind of change as the line aboveCVE-2023-31557same vendor as the line abovesame change as the line aboveDays to revision 73
2023-07-21published 2022-08-16Package added to advisoryGHSA-8wj3-cpmr-8whpCVE-2022-2818highnot named as affected when the advisory was published, now names cockpit-hq/cockpitnot dated
2023-07-21published 2023-07-19Package added to advisoryGHSA-9436-3gmp-4f53CVE-2023-37897highnot named as affected when the advisory was published, now names getgrav/gravDays to revision 2
2023-07-21published 2022-01-08Advisory severity changedGHSA-9fj5-jg6f-qg5rCVE-2021-45458whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
Thu 20 Jul 2023· 1 record change · 12 advisory changes
2023-07-20CVSS base score changedCVE-2023-24568
whole record
dell
stated at publication 7.4, now states 5.0CVSS v3.1 · base scoreHighMediumDays to revision 51
2023-07-20published 2023-07-11 to 2023-07-12Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8 to 9
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-74mc-g2xv-pch2CVE-2023-37579same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-07-20published 2023-07-11same kind of change as the line aboveGHSA-469h-mqg8-535rCVE-2023-32693same package and registry as the line abovemoderatesame change as the line aboveDays to revision 9
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-wvgr-5wgr-c6fjCVE-2023-37952same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-g4c3-4f3v-84x8CVE-2023-37942same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-m9jj-p947-m8xvCVE-2023-37953same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-07-20published 2023-07-12Advisory severity changedGHSA-j927-w6g7-7c7wCVE-2023-32200whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8
2023-07-20published 2023-07-12Advisory severity changedGHSA-gpq8-963w-8qc9CVE-2023-37582whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-07-20published 2023-07-12Advisory severity changedGHSA-g8c3-6fj2-87w7CVE-2023-37943whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2023-07-20published 2023-07-12Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-7jrr-fwhw-762vCVE-2023-37958same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-wgvx-9rh5-4g4mCVE-2023-37962same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-p756-66w2-35g7CVE-2023-37961same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-5v46-54vj-4mjqCVE-2023-37964same package and registry as the line abovehighsame change as the line aboveDays to revision 8
Wed 19 Jul 2023· 7 advisory changes
2023-07-19published 2023-07-11Advisory fix version moved4 rows, one per advisory and package
rubygems2 packages
2 bands
stated at publication 0.26.6, now states 0.26.7Days to revision 8
2023-07-19published 2023-07-11Advisory fix version movedGHSA-5652-92r9-3fx9CVE-2023-34089
rubygemsdecidim
high
same change as the line aboveDays to revision 8
2023-07-19published 2023-07-11Advisory fix version movedGHSA-5652-92r9-3fx9CVE-2023-34089
rubygemsdecidim-core
high
same change as the line aboveDays to revision 8
2023-07-19published 2023-07-11Advisory fix version movedGHSA-469h-mqg8-535rCVE-2023-32693
rubygemsdecidim
moderate
same change as the line aboveDays to revision 8
2023-07-19published 2023-07-11Advisory fix version movedGHSA-469h-mqg8-535rCVE-2023-32693
rubygemsdecidim-core
moderate
same change as the line aboveDays to revision 8
2023-07-19published 2022-05-24Package added to advisoryGHSA-gfwj-fwqj-fp3vCVE-2021-22118highnot named as affected when the advisory was published, now names org.springframework:spring-webnot dated
2023-07-19published 2023-07-10Advisory severity changedGHSA-6qq7-3hqc-p5w4CVE-2023-3566whole advisorymoderatestated at publication LOW, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 9
2023-07-19published 2023-07-10Advisory severity changedGHSA-6g2w-257v-3c9fCVE-2023-34442whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 9
Tue 18 Jul 2023· 4 advisory changes
2023-07-18published 2023-07-14Package added to advisoryGHSA-7gj7-224w-vpr3CVE-2023-38286highnot named as affected when the advisory was published, now names de.codecentric:spring-boot-admin-serverDays to revision 5
2023-07-18published 2023-07-05Advisory severity changedGHSA-mvj3-qrqh-cjvrCVE-2023-34450whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 13
2023-07-18published 2023-07-11Advisory severity changedGHSA-jx3q-5rgf-vrrrCVE-2023-37659whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-07-18published 2023-01-13Advisory withdrawnGHSA-vhvq-jh34-3fc8whole advisorymoderatewithdrawn 2023-07-18Days to revision 187
Mon 17 Jul 2023· 6 record changes
2023-07-17CVSS base score changedCVE-2023-31194
whole record
talos
stated at publication 4.0, now states 5.3CVSS v3.1 · base scoreMediumMediumDays to revision 12
2023-07-17CVSS base score changedCVE-2023-27390
whole record
talos
stated at publication 8.4, now states 7.8CVSS v3.1 · base scoreHighHighDays to revision 12
2023-07-17CVSS base score changedCVE-2023-24019
whole record
talos
stated at publication 7.5, now states 8.1CVSS v3.1 · base scoreHighHighDays to revision 11
2023-07-17CVSS base score changed
whole record
talos
stated at publication 8.3, now states 4.7CVSS v3.1 · base scoreHighMediumDays to revision 11
2023-07-17same kind of change as the line aboveCVE-2023-24496same vendor as the line abovesame change as the line aboveDays to revision 11
2023-07-17same kind of change as the line aboveCVE-2023-24497same vendor as the line abovesame change as the line aboveDays to revision 11
2023-07-17CVSS base score changedCVE-2023-23571
whole record
talos
stated at publication 8.2, now states 7.5CVSS v3.1 · base scoreHighHighDays to revision 11
Sat 15 Jul 2023· 2 record changes · 2 advisory changes
2023-07-152 commitsRecord state changed
whole record
mitre
stated at publication PUBLISHED, now states REJECTEDBranches and original-value intervals are stated on each row.not dated
2023-07-15same kind of change as the line aboveCVE-2023-36164same vendor as the line abovesame change as the line abovenot dated
2023-07-15same kind of change as the line aboveCVE-2023-36167same vendor as the line abovesame change as the line abovenot dated
2023-07-15published 2023-07-06Package added to advisorymoderatenot named as affected when the advisory was published, now names github.com/zinclabs/zincDays to revision 8
2023-07-15published 2023-07-06same kind of change as the line aboveGHSA-4fgv-8448-gf82CVE-2022-32171same package registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-07-15published 2023-07-06same kind of change as the line aboveGHSA-7j6x-42mm-p7jmCVE-2022-32172same package registry as the line abovemoderatesame change as the line aboveDays to revision 8
Fri 14 Jul 2023· 5 record changes · 1 advisory change
2023-07-14Product addedCVE-2023-32052not named as affected at publication, now names microsoft power appsDays to revision 3
2023-07-14Product addedCVE-2023-33127not named as affected at publication, now names powershell 7.2 and 1 moreDays to revision 3
2023-07-14same kind of change as the line aboveCVE-2023-33127same vendor as the line abovenot named as affected at publication, now names powershell 7.2Days to revision 3
2023-07-14same kind of change as the line aboveCVE-2023-33127same vendor as the line abovenot named as affected at publication, now names powershell 7.3Days to revision 3
2023-07-14CVSS base score changedCVE-2023-30990
whole record
ibm
stated at publication 5.6, now states 8.6CVSS v3.1 · base scoreMediumHighDays to revision 11
2023-07-14CVSS base score changedCVE-2023-35348
whole record
microsoft
stated at publication 7.5, now states 6.5CVSS v3.1 · base scoreHighMediumDays to revision 3
2023-07-14published 2023-07-08Advisory severity changedGHSA-2rhg-hqq9-8xjhCVE-2023-3553whole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 6
Thu 13 Jul 2023· 1 advisory change
2023-07-13published 2023-07-07Advisory withdrawnGHSA-f7xj-rg7h-mc87whole advisorylowwithdrawn 2023-07-13Days to revision 6
Wed 12 Jul 2023· 3 record changes · 2 advisory changes
2023-07-12Product addedCVE-2023-20006not named as affected at publication, now names cisco firepower threat defense softwareDays to revision 15
2023-07-12Product addedCVE-2023-20116not named as affected at publication, now names cisco unified communications manager / cisco unity connectionDays to revision 15
2023-07-12CVSS base score changedCVE-2023-0090
whole record
Proofpoint
stated at publication 8.1, now states 9.8CVSS v3.1 · base scoreHighCriticalDays to revision 127
2023-07-12published 2023-07-06Advisory severity changedGHSA-57fc-8q82-gfp3CVE-2023-36188whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6
2023-07-12published 2023-07-05Advisory severity changedGHSA-9jx5-6pgf-crrpCVE-2023-25399whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7
Tue 11 Jul 2023· 1 record change · 3 advisory changes
2023-07-11CVSS base score changedCVE-2023-25910
whole record
siemens
stated at publication 9.9, now states 10.0CVSS v3.1 · base scoreCriticalCriticalDays to revision 28
2023-07-11published 2023-07-10Advisory fix version movedGHSA-q9w4-w667-qqj4CVE-2023-37905
npmckeditor-wordcount-plugin
moderate
stated at publication 1.17.11, now states 1.17.12Days to revision 1
2023-07-11published 2023-07-03Advisory severity changedGHSA-jh3w-4vvf-mjgrCVE-2023-36053whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8
2023-07-11published 2023-07-03Advisory severity changedGHSA-hg6c-qqcm-r79rCVE-2023-35797whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
Mon 10 Jul 2023· 1 record change · 2 advisory changes
2023-07-10CVSS base score changedCVE-2023-3389
whole record
Google
stated at publication 5.5, now states 7.8CVSS v3.1 · base scoreMediumHighDays to revision 12
2023-07-10published 2023-07-03Advisory severity changedGHSA-2qmj-7962-cjq8CVE-2023-36258whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-07-10published 2023-06-30Advisory severity changedGHSA-v4f4-23wc-99mhCVE-2023-31543whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 10
Sun 9 Jul 2023· 1 record change
2023-07-09Record state changedCVE-2023-33715
whole record
mitre
stated at publication PUBLISHED, now states REJECTEDnot dated
Fri 7 Jul 2023· 22 record changes · 3 advisory changes
2023-07-07Product addedCVE-2023-1424Mitsubishinot named as affected at publication, now names melsec iq-r series r00cpu and 20 moreDays to revision 44
2023-07-07same kind of change as the line aboveCVE-2023-1424same vendor as the line abovenot named as affected at publication, now names melsec iq-r series r00cpuDays to revision 44
2023-07-07same kind of change as the line aboveCVE-2023-1424same vendor as the line abovenot named as affected at publication, now names melsec iq-r series r01cpuDays to revision 44
2023-07-07same kind of change as the line aboveCVE-2023-1424same vendor as the line abovenot named as affected at publication, now names melsec iq-r series r02cpuDays to revision 44
2023-07-07same kind of change as the line aboveCVE-2023-1424same vendor as the line abovenot named as affected at publication, now names melsec iq-r series r04cpuDays to revision 44
2023-07-07same kind of change as the line aboveCVE-2023-1424same vendor as the line abovenot named as affected at publication, now names melsec iq-r series r04encpuDays to revision 44
2023-07-07same kind of change as the line aboveCVE-2023-1424same vendor as the line abovenot named as affected at publication, now names melsec iq-r series r08cpuDays to revision 44
2023-07-07same kind of change as the line aboveCVE-2023-1424same vendor as the line abovenot named as affected at publication, now names melsec iq-r series r08encpuDays to revision 44
2023-07-07same kind of change as the line aboveCVE-2023-1424same vendor as the line abovenot named as affected at publication, now names melsec iq-r series r08pcpuDays to revision 44
13 more rows in this change are not listed here. Open all 21 rows
2023-07-07CVSS base score changedCVE-2023-35987
whole record
icscert
stated at publication 7.5, now states 9.8CVSS v3.1 · base scoreHighCriticalDays to revision 1
2023-07-07published 2023-06-30Advisory severity changedGHSA-3p62-6fjh-3p5hCVE-2022-4361whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-07-07published 2023-06-29Advisory severity changedGHSA-vv6q-6hwp-vrgpCVE-2020-26710whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8
2023-07-07published 2022-01-27Advisory severity changedGHSA-m36x-mgfh-8g78CVE-2023-36474whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
Thu 6 Jul 2023· 2 record changes · 5 advisory changes
2023-07-06CVSS base score changedCVE-2023-3529
whole record
VulDB
stated at publication 4.3, now states 5.3CVSS v3.1 · base scoreMediumMediumDays to revision 0
2023-07-06Record state changedCVE-2023-35935
whole record
GitHub_M
stated at publication PUBLISHED, now states REJECTEDDays to revision 3
2023-07-06published 2023-06-30Package added to advisoryGHSA-fmrf-p77g-vv5cCVE-2023-37302moderatenot named as affected when the advisory was published, now names wikibase/wikibaseDays to revision 6
2023-07-06published 2023-06-27 to 2023-06-29Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7 to 9
2023-07-06published 2023-06-29same kind of change as the line aboveGHSA-ccrc-9x59-3vc4CVE-2020-26708same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-07-06published 2023-06-29same kind of change as the line aboveGHSA-j6v2-mwxm-f952CVE-2020-26709same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-07-06published 2023-06-29same kind of change as the line aboveGHSA-mm87-c3x2-6f89CVE-2023-22886same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-07-06published 2023-06-27same kind of change as the line aboveGHSA-9766-v29c-4vm7CVE-2023-34395same package and registry as the line abovehighsame change as the line aboveDays to revision 9
Wed 5 Jul 2023· 1 record change · 7 advisory changes
2023-07-05Record state changedCVE-2023-36262
whole record
mitre
stated at publication PUBLISHED, now states REJECTEDnot dated
2023-07-05published 2022-12-28Advisory fix version movedGHSA-6jvc-q2x7-pchvCVE-2022-2582
gogithub.com/aws/aws-sdk-go
moderate
stated at publication 1.33.0, now states 1.34.0Days to revision 44
2023-07-05published 2018-01-22 to 2020-09-01Package added to advisorymoderatenot named as affected when the advisory was published, now names jquery-railsnot dated
2023-07-05published 2020-09-01same kind of change as the line aboveGHSA-2pqj-h3vj-pqgwCVE-2012-6708same package registry as the line abovemoderatesame change as the line abovenot dated
2023-07-05published 2018-01-22same kind of change as the line aboveGHSA-rmxg-73gg-4p98CVE-2015-9251same package registry as the line abovemoderatesame change as the line abovenot dated
2023-07-05published 2020-05-20same kind of change as the line aboveGHSA-q4m3-2j7h-f7xwCVE-2020-7656same package registry as the line abovemoderatesame change as the line abovenot dated
2023-07-05published 2022-09-17Advisory severity changedGHSA-3f7h-mf4q-vrm4CVE-2022-40152whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-07-05published 2023-06-26Advisory severity changedGHSA-cgmm-c2m9-ff7rCVE-2021-31635whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9
2023-07-05published 2023-06-23Advisory severity changedGHSA-pm73-x2h5-cmj3CVE-2023-31469whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 12

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →