Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

11,999 record changes · 5,026 advisory changes · newest first · grouped by dayCSVJSONRSS

Since
Counted changes, newest first, one line per change to a CVE record or a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together.Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Wed 15 Feb 2023· 1 advisory change
2023-02-15published 2023-02-13Advisory withdrawnGHSA-6p89-3p7c-qrhvCVE-2022-48110whole advisorymoderatewithdrawn 2023-02-15Days to revision 2
Tue 14 Feb 2023· 5 advisory changes
2023-02-14published 2022-08-18Package added to advisoryGHSA-8449-7gc2-pwrpCVE-2022-38149highnot named as affected when the advisory was published, now names github.com/hashicorp/consul-templatenot dated
2023-02-14published 2022-09-29Package added to advisoryGHSA-c9qr-f6c8-rgxfCVE-2022-40082highnot named as affected when the advisory was published, now names github.com/cloudwego/hertznot dated
2023-02-14published 2023-02-06Advisory severity changedGHSA-84mm-prjg-49xmCVE-2015-10073whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-02-14published 2023-02-04Advisory severity changedGHSA-p9w8-2mpq-49h9CVE-2018-25079whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2023-02-14published 2023-02-11Advisory withdrawnGHSA-8x6c-cv3v-vp6gwhole advisoryhighwithdrawn 2023-02-14Days to revision 3
Mon 13 Feb 2023· 2 advisory changes
2023-02-13published 2022-02-22Package added to advisoryGHSA-fgv8-vj5c-2ppqCVE-2019-16884highnot named as affected when the advisory was published, now names github.com/opencontainers/selinuxnot dated
2023-02-13published 2023-02-02Advisory severity changedGHSA-8xv4-jj4h-qww6CVE-2023-23937whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
Fri 10 Feb 2023· 4 advisory changes
2023-02-10published 2023-02-04Advisory severity changedGHSA-9fqc-9cpr-w73qCVE-2023-0671whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-02-10published 2023-02-03Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
2023-02-10published 2023-02-03same kind of change as the line aboveGHSA-fqp6-fw9g-xpxpCVE-2021-37306same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-02-10published 2023-02-03same kind of change as the line aboveGHSA-rwhw-6c6r-2823CVE-2021-37304same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-02-10published 2023-02-03same kind of change as the line aboveGHSA-4f48-qpch-4ppxCVE-2021-37305same package and registry as the line abovehighsame change as the line aboveDays to revision 6
Thu 9 Feb 2023· 20 advisory changes
2023-02-09published 2022-07-15Advisory fix version movedGHSA-qwrj-9hmp-gpxhCVE-2022-31145
gogithub.com/flyteorg/flyteadmin
moderate
stated at publication 1.1.30, now states 1.1.31not dated
2023-02-09published 2021-06-23Advisory fix version movedGHSA-h395-qcrw-5vmqCVE-2020-28483
gogithub.com/gin-gonic/gin
high
stated at publication 1.7.0, now states 1.7.7not dated
2023-02-09published 2022-05-22Advisory fix version movedGHSA-qx32-f6g6-fcfrCVE-2022-31259
gogithub.com/beego/beego
critical
stated at publication 1.12.4, now states 1.12.9not dated
2023-02-09published 2022-04-06Advisory fix version movedGHSA-28r6-jm5h-mrggCVE-2021-30080
gogithub.com/beego/beego/v2
high
stated at publication 2.0.2, now states 2.0.3not dated
2023-02-09published 2021-12-20 to 2022-12-28Package added to advisorymoderatenot named as affected when the advisory was published, now names github.com/go-yaml/yamlDays to revision 44
2023-02-09published 2022-12-28same kind of change as the line aboveGHSA-r88r-gmrh-7j83CVE-2021-4235same package registry as the line abovemoderatesame change as the line aboveDays to revision 44
2023-02-09published 2021-12-20same kind of change as the line aboveGHSA-wxc4-f4m6-wwqvCVE-2019-11254same package registry as the line abovemoderatesame change as the line abovenot dated
2023-02-09published 2022-08-30Package added to advisoryGHSA-grvv-h2f9-7v9cCVE-2022-36009moderatenot named as affected when the advisory was published, now names github.com/matrix-org/gomatrixserverlibnot dated
2023-02-09published 2021-06-29Package added to advisoryGHSA-mr6h-chqp-p9g2CVE-2014-8681moderatenot named as affected when the advisory was published, now names github.com/gogits/gogsnot dated
2023-02-09published 2021-06-29Package added to advisoryGHSA-jm5c-rv3w-w83mCVE-2020-26242moderatenot named as affected when the advisory was published, now names github.com/holiman/uint256not dated
2023-02-09published 2019-07-05Package added to advisoryGHSA-x64g-wjmw-w328CVE-2015-5306criticalnot named as affected when the advisory was published, now names python-ironic-inspector-clientnot dated
2023-02-09published 2021-08-25Package added to advisory2 bandsnot named as affected when the advisory was published, now names tensorflownot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-cfpj-3q4c-jhvrCVE-2021-37680same package registry as the line abovemoderatesame change as the line abovenot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-7xwj-5r4v-429pCVE-2021-37681same package registry as the line abovehighsame change as the line abovenot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-rhrq-64mq-hf9hCVE-2021-37683same package registry as the line abovemoderatesame change as the line abovenot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-c545-c4f9-rf6vCVE-2021-37685same package registry as the line abovemoderatesame change as the line abovenot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-jwf9-w5xm-f437CVE-2021-37687same package registry as the line abovemoderatesame change as the line abovenot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-vcjj-9vg7-vf68CVE-2021-37688same package registry as the line abovehighsame change as the line abovenot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-wf5p-c75w-w3whCVE-2021-37689same package registry as the line abovehighsame change as the line abovenot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-4c4g-crqm-xrxwCVE-2021-37682same package registry as the line abovemoderatesame change as the line abovenot dated
2023-02-09published 2022-04-30Package added to advisoryGHSA-66vw-v2x9-hw75CVE-2022-1227highnot named as affected when the advisory was published, now names github.com/containers/psgonot dated
2023-02-09published 2023-02-06Advisory withdrawnGHSA-6pm2-j2v8-h3cjCVE-2023-0669whole advisoryhighwithdrawn 2023-02-09Days to revision 3
Wed 8 Feb 2023· 4 advisory changes
2023-02-08published 2023-02-01Advisory severity changedGHSA-22j4-qc48-j8f8CVE-2023-24997whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-02-08published 2023-02-01Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-02-08published 2023-02-01same kind of change as the line aboveGHSA-q2jf-h9jm-m7p4CVE-2023-23969same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-02-08published 2023-02-01same kind of change as the line aboveGHSA-q9p5-w2v9-6wxfCVE-2023-24977same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-02-08published 2022-03-24Advisory severity changedGHSA-vvff-6wrr-4g7qCVE-2021-3589whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 13
Tue 7 Feb 2023· 13 advisory changes
2023-02-07published 2022-12-14Package added to advisoryGHSA-53mm-hx32-6475CVE-2022-47406criticalnot named as affected when the advisory was published, now names derhansen/fe_change_pwdDays to revision 55
2023-02-07published 2022-12-28Package added to advisoryGHSA-vp56-r7qv-783vCVE-2020-36559highnot named as affected when the advisory was published, now names aahframe.workDays to revision 42
2023-02-07published 2022-12-22 to 2022-12-25Package added to advisory2 bandsnot named as affected when the advisory was published, now names code.sajari.com/docconvDays to revision 44 to 48
2023-02-07published 2022-12-25same kind of change as the line aboveGHSA-qvx2-59g8-8hphCVE-2022-4741same package registry as the line abovemoderatesame change as the line aboveDays to revision 44
2023-02-07published 2022-12-22same kind of change as the line aboveGHSA-6m4h-hfpp-x8cxCVE-2022-4643same package registry as the line abovecriticalsame change as the line aboveDays to revision 48
2023-02-07published 2023-01-30Advisory severity changedGHSA-rw83-v3pw-m362whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 9
2023-02-07published 2023-01-29 to 2023-01-31Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7 to 10
2023-02-07published 2023-01-29same kind of change as the line aboveGHSA-9mq4-9556-6qxqCVE-2021-4315same package and registry as the line abovehighsame change as the line aboveDays to revision 10
2023-02-07published 2023-01-31same kind of change as the line aboveGHSA-rc47-6667-2j5jCVE-2022-25881same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-02-07published 2023-01-30same kind of change as the line aboveGHSA-pp4w-9x82-6r47CVE-2023-24830same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-02-07published 2021-05-10Advisory severity changedGHSA-7qw8-847f-pggmCVE-2021-20291whole advisorymoderatestated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-02-07published 2021-06-23Advisory severity changedGHSA-4hq8-gmxx-h6w9CVE-2020-27846whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-02-07published 2023-01-31Advisory severity changedGHSA-c6rx-gxqv-vr5jCVE-2022-21129whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-02-07published 2021-05-18Advisory severity changedGHSA-rmh2-65xw-9m6qCVE-2020-10675whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-02-07published 2023-01-29Advisory severity changedGHSA-g7gf-2rqw-5rwxCVE-2023-0569whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 9
Mon 6 Feb 2023· 7 advisory changes
2023-02-06published 2022-09-16Advisory fix version movedGHSA-3pgj-pg6c-r5p7CVE-2022-36087
pypioauthlib
moderate
stated at publication 3.2.1, now states 3.2.2not dated
2023-02-06published 2023-01-29Advisory severity changedGHSA-pm72-27mg-fc28CVE-2023-0564whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2023-02-06published 2023-01-26Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 11
2023-02-06published 2023-01-26same kind of change as the line aboveGHSA-x9q4-qwfh-9gjqCVE-2023-24427same package and registry as the line abovecriticalsame change as the line aboveDays to revision 11
2023-02-06published 2023-01-26same kind of change as the line aboveGHSA-h8p8-6378-649pCVE-2023-24430same package and registry as the line abovecriticalsame change as the line aboveDays to revision 11
2023-02-06published 2023-01-26Advisory severity changedGHSA-3g2g-rcm6-rrq2CVE-2023-24440whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
2023-02-06published 2023-01-26Advisory severity changedGHSA-pcc2-w6m8-x5w4CVE-2023-24429whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 11
2023-02-06published 2023-01-26Advisory severity changedGHSA-g29v-5pwh-wxx4CVE-2023-24439whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
Fri 3 Feb 2023· 16 advisory changes
2023-02-03published 2019-07-16Advisory severity changedGHSA-2mp5-m968-gwr2CVE-2019-5447whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-02-03published 2018-09-17Advisory severity changedGHSA-c9j3-wqph-5xx9CVE-2018-3786whole advisorycriticalstated at publication LOW, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-02-03published 2018-08-21Advisory severity changedGHSA-h3c2-x77c-7pvrCVE-2018-3785whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-02-03published 2022-02-15Advisory severity changedGHSA-xx8c-m748-xr4jCVE-2016-1905whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-02-03published 2022-02-09Advisory severity changedGHSA-h39q-95q5-9jfpCVE-2020-1734whole advisoryhighstated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.not dated
2023-02-03published 2023-01-26Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-4x65-4fjx-r7m6CVE-2023-24442same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-98qc-v8vg-mcx4CVE-2023-24454same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-96jv-c7m6-q43gCVE-2023-24446same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-wj79-9fxj-j86pCVE-2023-24447same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-px2f-cqrf-f2qgCVE-2023-24452same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-5xhh-6xfv-7q42CVE-2023-24458same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-g5mj-c26g-vmpmCVE-2023-24443same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-9963-gmh8-vvm6CVE-2023-24456same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-54jw-jqr9-6cj9CVE-2022-25962same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-9w5j-4mwv-2wj8CVE-2022-25860same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-j8wr-fwf2-vvr9CVE-2022-25908same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
Thu 2 Feb 2023· 4 advisory changes
2023-02-02published 2021-01-06Package added to advisoryGHSA-w7jx-j77m-wp65CVE-2024-21911moderatenot named as affected when the advisory was published, now names tinymcenot dated
2023-02-02published 2021-01-06Package added to advisoryGHSA-w7jx-j77m-wp65CVE-2024-21911moderatenot named as affected when the advisory was published, now names tinymce/tinymcenot dated
2023-02-02published 2023-01-26Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-02-02published 2023-01-26same kind of change as the line aboveGHSA-69f2-4375-qv9hCVE-2022-21810same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-02-02published 2023-01-26same kind of change as the line aboveGHSA-g5qr-xgg7-8q2wCVE-2022-25350same package and registry as the line abovehighsame change as the line aboveDays to revision 7
Wed 1 Feb 2023· 4 advisory changes
2023-02-01published 2023-01-27Advisory severity changedGHSA-jgh8-vchw-q3g7CVE-2023-24622whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 6
2023-02-01published 2023-01-23Advisory severity changedGHSA-6jmx-pv77-wm5wCVE-2023-0435whole advisorycriticalstated at publication MODERATE, now states CRITICALCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 9
2023-02-01published 2019-07-31Advisory severity changedGHSA-7j93-2h6r-hm49CVE-2019-5458whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-02-01published 2023-01-21Advisory severity changedGHSA-c732-xvv8-g94cCVE-2023-22884whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 11
Tue 31 Jan 2023· 7 advisory changes
2023-01-31published 2018-07-18Advisory severity changedGHSA-h24f-9mm4-w336CVE-2018-3726whole advisorymoderatestated at publication CRITICAL, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-01-31published 2018-07-26 to 2018-08-08Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-01-31published 2018-08-08same kind of change as the line aboveGHSA-8f64-q7jc-ccgpCVE-2018-3773same package and registry as the line abovemoderatesame change as the line abovenot dated
2023-01-31published 2018-07-26same kind of change as the line aboveGHSA-jrhj-2j3q-xf3vCVE-2018-3716same package and registry as the line abovemoderatesame change as the line abovenot dated
2023-01-31published 2018-07-26same kind of change as the line aboveGHSA-2x4q-6jfv-8h9hCVE-2018-3715same package and registry as the line abovemoderatesame change as the line abovenot dated
2023-01-31published 2018-07-18Advisory severity changedGHSA-qmm9-x5gr-4gfmCVE-2018-3743whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-01-31published 2018-06-07 to 2018-09-18Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-01-31published 2018-09-18same kind of change as the line aboveGHSA-fm87-46vv-jqrrCVE-2018-3744same package and registry as the line abovecriticalsame change as the line abovenot dated
2023-01-31published 2018-06-07same kind of change as the line aboveGHSA-3pxp-6963-46r9CVE-2018-3746same package and registry as the line abovecriticalsame change as the line abovenot dated
Mon 30 Jan 2023· 1 advisory change
2023-01-30published 2020-02-19Package added to advisoryGHSA-mxhp-79qh-mcx6CVE-2019-10790highnot named as affected when the advisory was published, now names taffydbnot dated
Fri 27 Jan 2023· 5 advisory changes
2023-01-27published 2023-01-14 to 2023-01-20Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7 to 13
2023-01-27published 2023-01-20same kind of change as the line aboveGHSA-hj4g-4w36-x8hpCVE-2022-47747same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-01-27published 2023-01-14same kind of change as the line aboveGHSA-7cxr-h8wm-fg4cCVE-2023-22602same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-01-27published 2022-02-15Advisory severity changedGHSA-qhm4-jxv7-j9pqCVE-2020-8551whole advisorymoderatestated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-01-27published 2021-04-20Advisory severity changedGHSA-2xpj-f5g2-8p7mCVE-2020-17446whole advisorycriticalstated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.not dated
2023-01-27published 2022-12-22Advisory withdrawnGHSA-27h2-hvpr-p74qCVE-2022-23529whole advisoryhighwithdrawn 2023-01-27Days to revision 37
Thu 26 Jan 2023· 3 advisory changes
2023-01-26published 2021-05-06Package added to advisoryGHSA-3c6g-pvg8-gqw2CVE-2020-7712highnot named as affected when the advisory was published, now names org.webjars.npm:jsonnot dated
2023-01-26published 2017-10-24Package added to advisoryGHSA-hpcf-8vf9-q4gjCVE-2016-7103moderatenot named as affected when the advisory was published, now names jquery-ui-railsnot dated
2023-01-26published 2023-01-19Advisory severity changedGHSA-6w89-c65w-jx2cCVE-2022-47105whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 7
Wed 25 Jan 2023· 4 advisory changes
2023-01-25published 2023-01-20Package added to advisoryGHSA-6g8q-qfpv-57wpCVE-2023-22727criticalnot named as affected when the advisory was published, now names cakephp/databaseDays to revision 5
2023-01-25published 2021-05-24Advisory severity changedGHSA-3892-2r52-p65mCVE-2020-7671whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-01-25published 2023-01-13Advisory severity changedGHSA-jmj6-p2j9-68cpCVE-2022-3143whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 13
2023-01-25published 2022-12-13Advisory severity changedGHSA-g8q8-fggx-9r3qCVE-2022-3782whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 43
Tue 24 Jan 2023· 7 advisory changes
2023-01-24published 2023-01-09 to 2023-01-14Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 11 to 15
2023-01-24published 2023-01-09same kind of change as the line aboveGHSA-pfpr-3463-c6jhCVE-2022-46648same package and registry as the line abovehighsame change as the line aboveDays to revision 15
2023-01-24published 2023-01-14same kind of change as the line aboveGHSA-fxg5-wq6x-vr4wCVE-2022-41721same package and registry as the line abovehighsame change as the line aboveDays to revision 11
2023-01-24published 2023-01-16Advisory severity changedGHSA-85gf-wr67-f83wCVE-2015-10053whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-01-24published 2023-01-16Advisory severity changedGHSA-7222-r37x-8q3mCVE-2022-43719whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2023-01-24published 2023-01-16Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 8
2023-01-24published 2023-01-16same kind of change as the line aboveGHSA-cxvp-3frm-3876CVE-2022-41703same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-01-24published 2023-01-16same kind of change as the line aboveGHSA-fpmr-qmgh-42x2CVE-2022-43720same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-01-24published 2023-01-23Advisory severity changedGHSA-q764-g6fm-555vCVE-2023-23608whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 1
Mon 23 Jan 2023· 10 advisory changes
2023-01-23published 2017-10-24Advisory severity changedGHSA-5vx5-9q73-wgp4CVE-2017-7540whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-01-23published 2018-01-22Advisory severity changedGHSA-5jcf-c5rg-rmm8CVE-2017-0889whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-01-23published 2021-05-24Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-01-23published 2021-05-24same kind of change as the line aboveGHSA-x3v4-pxvm-63j8CVE-2020-7659same package and registry as the line abovehighsame change as the line abovenot dated
2023-01-23published 2021-05-24same kind of change as the line aboveGHSA-4f68-49qq-h392CVE-2020-13163same package and registry as the line abovehighsame change as the line abovenot dated
2023-01-23published 2019-09-11Advisory severity changedGHSA-fcjw-8rhj-gwwcCVE-2019-16109whole advisorymoderatestated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-01-23published 2023-01-14Advisory severity changedGHSA-q3rm-f527-ghxjCVE-2023-0299whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9
2023-01-23published 2023-01-13 to 2023-01-16Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8 to 10
2023-01-23published 2023-01-16same kind of change as the line aboveGHSA-g92r-9rxw-cmgxCVE-2023-0311same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
2023-01-23published 2023-01-13same kind of change as the line aboveGHSA-m589-mv4q-p7rjCVE-2022-45299same package and registry as the line abovecriticalsame change as the line aboveDays to revision 10
2023-01-23published 2023-01-12Advisory severity changedGHSA-v436-q368-hvggCVE-2023-0091whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
2023-01-23published 2022-10-27Advisory withdrawnGHSA-9chr-4fjh-5rgwCVE-2022-3704whole advisorylowwithdrawn 2023-01-23Days to revision 88
Fri 20 Jan 2023· 3 advisory changes
2023-01-20published 2019-11-05Advisory severity changedGHSA-c3gv-9cxf-6f57CVE-2019-15587whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-01-20published 2023-01-13Advisory severity changedGHSA-vvj3-85vf-fgmwCVE-2022-21191whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-01-20published 2023-01-12Advisory severity changedGHSA-rv9x-wmw4-44qjCVE-2023-0227whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 9
Thu 19 Jan 2023· 2 advisory changes
2023-01-19published 2023-01-11Advisory severity changedwhole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8
2023-01-19published 2023-01-11same kind of change as the line aboveGHSA-798h-g4j5-5537same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-01-19published 2023-01-11same kind of change as the line aboveGHSA-qv66-f876-vjvrCVE-2018-25074same package and registry as the line abovehighsame change as the line aboveDays to revision 8
Tue 17 Jan 2023· 1 advisory change
2023-01-17published 2022-12-12Advisory severity changedGHSA-j8x2-2m5w-j939CVE-2022-23511whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 36
Fri 13 Jan 2023· 4 advisory changes
2023-01-13published 2023-01-10Advisory severity changedGHSA-4r2f-6fm9-2qghwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 4
2023-01-13published 2023-01-10Advisory severity changedGHSA-96jv-r488-c2rjCVE-2023-22895whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 4
2023-01-13published 2023-01-09Advisory severity changedGHSA-9vvw-cc9w-f27hCVE-2017-20165whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-01-13published 2023-01-09Advisory severity changedGHSA-xj9v-6q2f-vqhxCVE-2022-25890whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 4
Thu 12 Jan 2023· 2 advisory changes
2023-01-12published 2023-01-07Advisory severity changedGHSA-wvr2-q86m-6whpCVE-2021-4307whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5
2023-01-12published 2023-01-06Advisory severity changedGHSA-f259-h6m8-hm8mCVE-2022-25923whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6
Wed 11 Jan 2023· 5 advisory changes
2023-01-11published 2023-01-05Advisory severity changedGHSA-wg99-5vrx-j2ggCVE-2020-36640whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6
2023-01-11published 2023-01-05Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6 to 7
2023-01-11published 2023-01-05same kind of change as the line aboveGHSA-6g33-8w2q-4hxvCVE-2021-4305same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-01-11published 2023-01-05same kind of change as the line aboveGHSA-vf99-xw26-86g5CVE-2023-22626same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-01-11published 2023-01-05Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7
2023-01-11published 2023-01-05same kind of change as the line aboveGHSA-h8r9-467r-vjjfCVE-2023-0057same package and registry as the line abovemoderatesame change as the line aboveDays to revision 7
2023-01-11published 2023-01-05same kind of change as the line aboveGHSA-m3g7-wrrq-v5c8CVE-2023-0055same package and registry as the line abovemoderatesame change as the line aboveDays to revision 7

Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →