Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

11,999 record changes · 5,026 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
Counted changes, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Sat 3 Jun 2023· 1 advisory change
2023-06-03published 2023-05-26Advisory severity changedGHSA-x487-866m-p8hrCVE-2023-30145whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
Fri 2 Jun 2023· 1 record change · 4 advisory changes
2023-06-02Record state changedCVE-2023-26931
whole record
mitre
stated at publication PUBLISHED, now states REJECTEDnot dated
2023-06-02published 2023-05-22Advisory severity changedGHSA-2h44-x2wx-49f4CVE-2023-30851whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 11
2023-06-02published 2023-05-22 to 2023-05-24Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 9 to 11
2023-06-02published 2023-05-24same kind of change as the line aboveGHSA-863x-868h-968xCVE-2021-25748same package and registry as the line abovemoderatesame change as the line aboveDays to revision 9
2023-06-02published 2023-05-22same kind of change as the line aboveGHSA-x7c2-7wvg-jpx7CVE-2023-32686same package and registry as the line abovemoderatesame change as the line aboveDays to revision 11
2023-06-02published 2023-05-24Advisory severity changedGHSA-g7vw-43xg-8m4hCVE-2023-33945whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 9
Thu 1 Jun 2023· 1 record change · 3 advisory changes
2023-06-01CVSS base score changedCVE-2023-33942
whole record
Liferay
stated at publication 6.4, now states 5.4CVSS v3.1 · base scoreMediumMediumDays to revision 8
2023-06-01published 2022-05-24Advisory severity changedGHSA-4wrc-f8pq-fpqpCVE-2016-1000027whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-06-01published 2022-01-06Advisory severity changedGHSA-9w7f-m4j4-j3xwCVE-2021-43857whole advisorycriticalstated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.not dated
2023-06-01published 2023-05-26Advisory severity changedGHSA-jv3f-7m33-qp65CVE-2023-33955whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 6
Wed 31 May 2023· 4 advisory changes
2023-05-31published 2018-01-22 to 2022-05-14Package added to advisorymoderatenot named as affected when the advisory was published, now names jquerynot dated
2023-05-31published 2020-04-29same kind of change as the line aboveGHSA-jpcq-cgw6-v4j6CVE-2020-11023same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-31published 2022-05-14same kind of change as the line aboveGHSA-579v-mp3v-rrw5CVE-2011-4969same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-31published 2020-09-01same kind of change as the line aboveGHSA-2pqj-h3vj-pqgwCVE-2012-6708same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-31published 2018-01-22same kind of change as the line aboveGHSA-rmxg-73gg-4p98CVE-2015-9251same package registry as the line abovemoderatesame change as the line abovenot dated
Tue 30 May 2023· 9 advisory changes
2023-05-30published 2019-10-24Advisory fix version movedGHSA-c9cg-q8r2-xvjqCVE-2019-16929
nugetauth0.authenticationapi
high
stated at publication 6.5.3, now states 6.5.4not dated
2023-05-30published 2018-07-26Package added to advisoryGHSA-rch9-xh7r-mqgwCVE-2018-3717moderatenot named as affected when the advisory was published, now names connectnot dated
2023-05-30published 2021-08-13Package added to advisoryGHSA-6xx3-rg99-gc3pCVE-2020-15522moderatenot named as affected when the advisory was published, now names bouncycastlenot dated
2023-05-30published 2019-04-26 to 2020-05-20Package added to advisorymoderatenot named as affected when the advisory was published, now names jquerynot dated
2023-05-30published 2020-05-20same kind of change as the line aboveGHSA-q4m3-2j7h-f7xwCVE-2020-7656same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-30published 2019-04-26same kind of change as the line aboveGHSA-6c3j-c64m-qhgqCVE-2019-11358same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-30published 2019-04-26Package added to advisoryGHSA-6c3j-c64m-qhgqCVE-2019-11358moderatenot named as affected when the advisory was published, now names jquery-railsnot dated
2023-05-30published 2023-05-22Advisory severity changedGHSA-xp5g-jhg3-3rg2CVE-2023-33252whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2023-05-30published 2023-05-26Advisory severity changedGHSA-qpgm-gjgf-8c2xCVE-2023-33195whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 4
2023-05-30published 2023-01-03Advisory severity changedGHSA-rq2w-37h9-vg94CVE-2022-45143whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 146
Fri 26 May 2023· 1 record change · 13 advisory changes
2023-05-26Record state changedCVE-2023-2004
whole record
redhat
stated at publication PUBLISHED, now states REJECTEDDays to revision 42
2023-05-26published 2017-10-24 to 2022-04-22Package added to advisorymoderatenot named as affected when the advisory was published, now names actionpacknot dated
2023-05-26published 2022-04-22same kind of change as the line aboveGHSA-q58j-fmvf-9rq6CVE-2011-1497same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24same kind of change as the line aboveGHSA-xxr8-833v-c7wcCVE-2011-4319same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24same kind of change as the line aboveGHSA-24fg-p96v-hxh8CVE-2011-0447same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24same kind of change as the line aboveGHSA-fg9w-g6m4-557jCVE-2009-3086same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24same kind of change as the line aboveGHSA-8fqx-7pv4-3jwmCVE-2008-7248same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24same kind of change as the line aboveGHSA-75w6-p6mg-vh8jCVE-2011-0446same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24Package added to advisoryGHSA-fg9w-g6m4-557jCVE-2009-3086moderatenot named as affected when the advisory was published, now names activesupportnot dated
2023-05-26published 2017-10-24Package added to advisory2 bandsnot named as affected when the advisory was published, now names activerecordnot dated
2023-05-26published 2017-10-24same kind of change as the line aboveGHSA-gjxw-5w2q-7grfCVE-2010-3933same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24same kind of change as the line aboveGHSA-xf96-32q2-9rw2CVE-2008-4094same package registry as the line abovehighsame change as the line abovenot dated
2023-05-26published 2023-05-26Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 0
2023-05-26published 2023-05-26same kind of change as the line aboveGHSA-6qjx-787v-6pxrCVE-2023-33197same package and registry as the line abovemoderatesame change as the line aboveDays to revision 0
2023-05-26published 2023-05-26same kind of change as the line aboveGHSA-cjmm-x9x9-m2w5CVE-2023-33196same package and registry as the line abovemoderatesame change as the line aboveDays to revision 0
2023-05-26published 2023-05-15Advisory severity changedGHSA-4xqq-73wg-5mjpCVE-2023-32758whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 12
2023-05-26published 2023-05-25Advisory severity changedGHSA-hj3f-6gcp-jg8jCVE-2023-28370whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 1
Thu 25 May 2023· 3 advisory changes
2023-05-25published 2023-05-17Advisory severity changedGHSA-25fx-3c2q-cq46CVE-2023-2756whole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 8
2023-05-25published 2023-05-17Advisory severity changedGHSA-92wq-q9pq-gw47CVE-2023-31135whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 8
2023-05-25published 2023-05-16Advisory severity changedGHSA-p6m6-9j36-vfjxCVE-2023-31890whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9
Wed 24 May 2023· 5 advisory changes
2023-05-24published 2022-01-13Package added to advisoryGHSA-vqwg-4v6f-h6x5CVE-2022-20615moderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins:matrix-projectnot dated
2023-05-24published 2023-05-17Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 7
2023-05-24published 2023-05-17same kind of change as the line aboveGHSA-j657-pjgc-c4h6CVE-2023-2752same package and registry as the line abovemoderatesame change as the line aboveDays to revision 7
2023-05-24published 2023-05-17same kind of change as the line aboveGHSA-vppq-6ff8-2m8wCVE-2023-2753same package and registry as the line abovemoderatesame change as the line aboveDays to revision 7
2023-05-24published 2022-01-21Advisory severity changedGHSA-fpj7-9xm6-8hgrCVE-2022-23106whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2023-05-24published 2022-04-23Advisory withdrawnGHSA-xm99-6pv5-q363CVE-2022-29583whole advisoryhighwithdrawn 2023-05-24Days to revision 397
Tue 23 May 2023· 2 advisory changes
2023-05-23published 2023-05-12Advisory severity changedGHSA-7g2v-2frm-rg94CVE-2023-2515whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 12
2023-05-23published 2023-03-10Advisory severity changedGHSA-frgr-c5f2-8qhhCVE-2023-27900whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 74
Mon 22 May 2023· 10 record changes · 7 advisory changes
2023-05-22Product addedCVE-2023-28649icscertnot named as affected at publication, now names ovrc cloudDays to revision 0
2023-05-222 commitsProduct added9 rows, one per record and product
vendor not named
snyk
not named as affected at publication, now names org.webjars.bower:angular and 2 moreBranches and original-value intervals are stated on each row.Days to revision 53
2023-05-22same kind of change as the line aboveCVE-2023-26117same vendor as the line abovenot named as affected at publication, now names org.webjars.bower:angularDays to revision 53
2023-05-22same kind of change as the line aboveCVE-2023-26117same vendor as the line abovenot named as affected at publication, now names org.webjars.bowergithub.angular:angularDays to revision 53
2023-05-22same kind of change as the line aboveCVE-2023-26117same vendor as the line abovenot named as affected at publication, now names org.webjars.npm:angularDays to revision 53
2023-05-22same kind of change as the line aboveCVE-2023-26118same vendor as the line abovenot named as affected at publication, now names org.webjars.bower:angularDays to revision 53
2023-05-22same kind of change as the line aboveCVE-2023-26118same vendor as the line abovenot named as affected at publication, now names org.webjars.bowergithub.angular:angularDays to revision 53
2023-05-22same kind of change as the line aboveCVE-2023-26118same vendor as the line abovenot named as affected at publication, now names org.webjars.npm:angularDays to revision 53
2023-05-22same kind of change as the line aboveCVE-2023-26116same vendor as the line abovenot named as affected at publication, now names org.webjars.bower:angularDays to revision 53
2023-05-22same kind of change as the line aboveCVE-2023-26116same vendor as the line abovenot named as affected at publication, now names org.webjars.bowergithub.angular:angularDays to revision 53
1 more row in this change is not listed here. Open all 9 rows
2023-05-22published 2022-05-13Package added to advisoryGHSA-3wqf-4x89-9g79CVE-2018-14040moderatenot named as affected when the advisory was published, now names bootstrapnot dated
2023-05-22published 2023-05-11 to 2023-05-12Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10 to 12
2023-05-22published 2023-05-11same kind of change as the line aboveGHSA-wc6j-5g83-xfm6CVE-2023-30172same package and registry as the line abovehighsame change as the line aboveDays to revision 12
2023-05-22published 2023-05-12same kind of change as the line aboveGHSA-fjx5-xm7q-whvjCVE-2023-30130same package and registry as the line abovehighsame change as the line aboveDays to revision 10
2023-05-22published 2023-05-12same kind of change as the line aboveGHSA-v9rm-7rv9-r3fwCVE-2023-29032same package and registry as the line abovehighsame change as the line aboveDays to revision 11
2023-05-22published 2023-05-12same kind of change as the line aboveGHSA-mg5h-f3q8-c96gCVE-2023-29246same package and registry as the line abovehighsame change as the line aboveDays to revision 11
2023-05-22published 2023-05-12Advisory severity changedGHSA-6vcf-cfjp-qxcwCVE-2023-27238whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 10
2023-05-22published 2022-12-14Advisory severity changedGHSA-2c7v-qcjp-4mg2CVE-2022-41089whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 159
Fri 19 May 2023· 1 record change · 1 advisory change
2023-05-19Product addedCVE-2023-27945not named as affected at publication, now names macosDays to revision 12
2023-05-19published 2023-03-10Advisory severity changedGHSA-j664-qhh4-hpf8CVE-2023-27898whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 70
Wed 17 May 2023· 1 record change · 3 advisory changes
2023-05-17Product addedCVE-2023-27482GitHub_Mnot named as affected at publication, now names supervisorDays to revision 71
2023-05-17published 2023-05-10Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-05-17published 2023-05-10same kind of change as the line aboveGHSA-97cp-mr4m-9mcfCVE-2023-27563same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-05-17published 2023-05-10same kind of change as the line aboveGHSA-r9xw-p7wj-w792CVE-2023-27564same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-05-17published 2023-05-11Advisory severity changedGHSA-mq3x-qgwx-3rfwCVE-2023-2629whole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 6
Tue 16 May 2023· 1 advisory change
2023-05-16published 2021-02-08Advisory severity changedGHSA-fwcm-636p-68r5CVE-2021-21288whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.not dated
Mon 15 May 2023· 2 advisory changes
2023-05-15published 2023-05-15Advisory severity changedGHSA-jh85-wwv9-24hvCVE-2023-32309whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 0
2023-05-15published 2023-05-07Advisory severity changedGHSA-r3xc-prgr-mg9pCVE-2023-31047whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9
Fri 12 May 2023· 1 advisory change
2023-05-12published 2023-05-09Advisory severity changedGHSA-qmqw-r4x6-3w2qCVE-2023-2590whole advisorylowstated at publication HIGH, now states LOWCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 3
Thu 11 May 2023· 3 advisory changes
2023-05-11published 2023-05-05Advisory severity changedGHSA-4m7v-wr6v-2mw5CVE-2023-2531whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-05-11published 2023-05-05Advisory severity changedGHSA-wf7x-fh6w-34r6CVE-2023-32235whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-05-11published 2023-05-04Advisory severity changedGHSA-jj45-24rw-v6jwCVE-2023-30094whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7
Wed 10 May 2023· 1 record change · 3 advisory changes
2023-05-10Product addedCVE-2023-25568GitHub_Mnot named as affected at publication, now names boxoDays to revision 1
2023-05-10published 2023-05-04Advisory severity changedGHSA-m69h-4frq-vwq7CVE-2023-30331whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-05-10published 2023-04-26Advisory severity changedGHSA-g36h-4jr6-qmm9CVE-2022-25273whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 13
2023-05-10published 2023-05-02Advisory severity changedGHSA-f8hp-grmr-pp7jCVE-2023-29918whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7
Tue 9 May 2023· 2 record changes · 8 advisory changes
2023-05-09CVSS base score changedCVE-2023-24892
whole record
microsoft
stated at publication 7.1, now states 8.2CVSS v3.1 · base scoreHighHighDays to revision 56
2023-05-09CVSS base score changedCVE-2023-28828
whole record
siemens
stated at publication 5.3, now states 5.9CVSS v3.1 · base scoreMediumMediumDays to revision 28
2023-05-09published 2023-04-26 to 2023-05-05Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 4 to 14
2023-05-09published 2023-04-26same kind of change as the line aboveGHSA-939c-3g97-vpvvCVE-2023-26735same package and registry as the line abovehighsame change as the line aboveDays to revision 14
2023-05-09published 2023-05-05same kind of change as the line aboveGHSA-mgv8-gggw-mrg6CVE-2023-30837same package and registry as the line abovehighsame change as the line aboveDays to revision 4
2023-05-09published 2023-05-03same kind of change as the line aboveGHSA-2h5h-59f5-c5x9CVE-2023-30551same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-05-09published 2023-05-01 to 2023-05-03Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 6 to 8
2023-05-09published 2023-05-01same kind of change as the line aboveGHSA-pjfj-qvqw-3f6vCVE-2022-45801same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-05-09published 2023-05-02same kind of change as the line aboveGHSA-g2mc-fqqc-hxg3CVE-2023-30855same package and registry as the line abovemoderatesame change as the line aboveDays to revision 7
2023-05-09published 2023-05-03same kind of change as the line aboveGHSA-q9mw-68c2-j6m5CVE-2023-31125same package and registry as the line abovemoderatesame change as the line aboveDays to revision 6
2023-05-09published 2023-04-27Advisory severity changedGHSA-8qhm-ch8h-xgjrCVE-2023-30349whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 12
2023-05-09published 2022-08-06Advisory severity changedGHSA-xh3v-6f9j-wxw3CVE-2022-25275whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
Mon 8 May 2023· 1 record change
2023-05-08Record state changedCVE-2023-2248
whole record
Google
stated at publication PUBLISHED, now states REJECTEDDays to revision 7
Fri 5 May 2023· 3 record changes · 6 advisory changes
2023-05-053 commitsRecord state changed
whole record
KNIME
stated at publication PUBLISHED, now states REJECTEDBranches and original-value intervals are stated on each row.Days to revision 0
2023-05-05same kind of change as the line aboveCVE-2023-2537same vendor as the line abovesame change as the line aboveDays to revision 0
2023-05-05same kind of change as the line aboveCVE-2023-2536same vendor as the line abovesame change as the line aboveDays to revision 0
2023-05-05same kind of change as the line aboveCVE-2023-2535same vendor as the line abovesame change as the line aboveDays to revision 0
2023-05-05published 2023-04-28Advisory severity changedGHSA-vcpr-hm2m-gjjjCVE-2023-28475whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7
2023-05-05published 2023-04-27Advisory severity changedGHSA-2hp9-3xfr-r9w2CVE-2023-31287whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2023-05-05published 2023-04-25Advisory severity changedGHSA-xgh5-gwq5-rpx8CVE-2023-22665whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
2023-05-05published 2023-04-26 to 2023-04-28Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7 to 9
2023-05-05published 2023-04-28same kind of change as the line aboveGHSA-pj76-75cm-3552CVE-2023-28473same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-05-05published 2023-04-26same kind of change as the line aboveGHSA-2x3r-7jgm-gh8xCVE-2020-36070same package and registry as the line abovecriticalsame change as the line aboveDays to revision 9
2023-05-05published 2023-04-26same kind of change as the line aboveGHSA-f737-3fh6-jf6wCVE-2023-30363same package and registry as the line abovecriticalsame change as the line aboveDays to revision 9
Thu 4 May 2023· 1 record change · 6 advisory changes
2023-05-04CVSS base score changedCVE-2023-22921
whole record
Zyxel
stated at publication 7.2, now states 7.5CVSS v3.1 · base scoreHighHighDays to revision 3
2023-05-04published 2020-02-20Package added to advisoryGHSA-cmcx-xhr8-3w9pCVE-2020-5243moderatenot named as affected when the advisory was published, now names user_agent_parsernot dated
2023-05-04published 2020-04-29Package added to advisoryGHSA-jpcq-cgw6-v4j6CVE-2020-11023moderatenot named as affected when the advisory was published, now names jquery-railsnot dated
2023-05-04published 2023-04-27Advisory severity changedGHSA-fq95-rx4q-qgg2CVE-2023-2341whole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 7
2023-05-04published 2020-02-20Advisory severity changedGHSA-cmcx-xhr8-3w9pCVE-2020-5243whole advisorymoderatestated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-05-04published 2020-11-13 to 2020-12-08Advisory severity changedwhole advisoryhighstated at publication LOW, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-05-04published 2020-12-08same kind of change as the line aboveGHSA-49r3-2549-3633CVE-2020-26254same package and registry as the line abovehighsame change as the line abovenot dated
2023-05-04published 2020-11-13same kind of change as the line aboveGHSA-23f7-99jx-m54rCVE-2020-26222same package and registry as the line abovehighsame change as the line abovenot dated
Wed 3 May 2023· 3 advisory changes
2023-05-03published 2023-04-24Advisory severity changedGHSA-f9xv-q969-pqx4CVE-2023-2251whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2023-05-03published 2023-04-21Advisory severity changedGHSA-67mg-gm8m-ph5rCVE-2023-2227whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 12
2023-05-03published 2023-04-28Advisory withdrawnGHSA-gh24-c683-79r2CVE-2023-26812whole advisorycriticalwithdrawn 2023-05-03Days to revision 5
Tue 2 May 2023· 2 record changes · 4 advisory changes
2023-05-022 commitsRecord state changed
whole record
mitre
stated at publication PUBLISHED, now states REJECTEDBranches and original-value intervals are stated on each row.not dated
2023-05-02same kind of change as the line aboveCVE-2023-26812same vendor as the line abovesame change as the line abovenot dated
2023-05-02same kind of change as the line aboveCVE-2023-30183same vendor as the line abovesame change as the line abovenot dated
2023-05-02published 2022-07-19Package added to advisoryGHSA-4x9r-j582-cgr8CVE-2022-33891highnot named as affected when the advisory was published, now names org.apache.spark:spark-parent_2.12not dated
2023-05-02published 2023-04-24Advisory severity changedGHSA-3862-c622-v4fpCVE-2023-31045whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 9
2023-05-02published 2023-04-24Advisory severity changedGHSA-4r6h-8v6p-xvw6CVE-2023-30533whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2023-05-02published 2023-04-20Advisory severity changedGHSA-g5h3-w546-pj7fCVE-2023-20873whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 12
Mon 1 May 2023· 3 advisory changes
2023-05-01published 2022-01-06Package added to advisoryGHSA-29mw-wpgm-hmr9moderatenot named as affected when the advisory was published, now names lodash.trim and 1 morenot dated
2023-05-01published 2022-01-06same kind of change as the line aboveGHSA-29mw-wpgm-hmr9CVE-2020-28500same package registry as the line abovemoderatenot named as affected when the advisory was published, now names lodash.trimnot dated
2023-05-01published 2022-01-06same kind of change as the line aboveGHSA-29mw-wpgm-hmr9CVE-2020-28500same package registry as the line abovemoderatenot named as affected when the advisory was published, now names lodash.trimendnot dated
2023-05-01published 2023-04-21Advisory severity changedGHSA-h3r8-h5qw-4r35CVE-2023-1892whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 11
Fri 28 Apr 2023· 1 record change · 10 advisory changes
2023-04-28Product addedCVE-2023-24934not named as affected at publication, now names microsoft malware protection platformDays to revision 14
2023-04-28published 2023-04-20Advisory severity changedwhole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2023-04-28published 2023-04-20same kind of change as the line aboveGHSA-mjw9-3f9f-jq2wCVE-2023-29522same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-04-28published 2023-04-20same kind of change as the line aboveGHSA-px54-3w5j-qjg9CVE-2023-29518same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-04-28published 2023-04-20same kind of change as the line aboveGHSA-3hjg-cghv-22wwCVE-2023-29519same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-04-28published 2023-04-20same kind of change as the line aboveGHSA-p67q-h88v-5jgrCVE-2023-29521same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-04-28published 2023-02-16Advisory severity changedGHSA-r3vq-92c6-3mqfwhole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 71
2023-04-28published 2023-04-20Advisory severity changedGHSA-9mh9-44q3-v79xCVE-2023-29926whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-04-28published 2023-04-22Advisory severity changedGHSA-h83h-77x2-6w6gCVE-2023-2239whole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 6
2023-04-28published 2023-04-17 to 2023-04-21Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7 to 11
2023-04-28published 2023-04-21same kind of change as the line aboveGHSA-c6mx-3fj9-9j7qCVE-2023-29924same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-04-28published 2023-04-17same kind of change as the line aboveGHSA-pvjv-386f-c8whCVE-2023-24831same package and registry as the line abovecriticalsame change as the line aboveDays to revision 11
2023-04-28published 2023-04-20Advisory severity changedGHSA-44h9-xxvx-pg6xCVE-2023-29515whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
Thu 27 Apr 2023· 4 record changes · 5 advisory changes
2023-04-27CVSS base score changedCVE-2023-21807
whole record
microsoft
stated at publication 5.8, now states 6.5CVSS v3.1 · base scoreMediumMediumOriginal value first replaced 2023-04-11; this value first seen 2023-04-27.Days to revision 56
2023-04-27CVSS base score changedCVE-2023-24858
whole record
microsoft
stated at publication 6.5, now states 7.5CVSS v3.1 · base scoreMediumHighDays to revision 44
2023-04-27CVSS base score changedCVE-2023-24911
whole record
microsoft
stated at publication 6.5, now states 4.3CVSS v3.1 · base scoreMediumMediumDays to revision 44
2023-04-27Record state changedCVE-2023-30842
whole record
GitHub_M
stated at publication PUBLISHED, now states REJECTEDnot dated
2023-04-27published 2023-04-17Advisory severity changedGHSA-7jhg-8m74-6f6gCVE-2023-27525whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 10
2023-04-27published 2023-04-17Advisory severity changedGHSA-329j-jfvr-rhr6CVE-2023-22946whole advisorycriticalstated at publication MODERATE, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 10
2023-04-27published 2023-04-20Advisory severity changedGHSA-93hq-5wgc-jc82CVE-2023-30542whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 7
2023-04-27published 2023-04-05Advisory severity changedGHSA-776f-qx25-q3ccCVE-2023-0842whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 22
2023-04-27published 2023-04-25Advisory withdrawnGHSA-wj6r-53f5-q789whole advisorycriticalwithdrawn 2023-04-27Days to revision 2

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →