Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Tue 30 Sep 2025· 11 advisory changes
2025-09-30published 2022-05-24Package added to advisoryGHSA-3hw2-h67c-wq66CVE-2021-42697highnot named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core_2.13not dated
2025-09-30published 2022-05-24Package added to advisoryGHSA-3hw2-h67c-wq66CVE-2021-42697highnot named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core_2.13.0-m5not dated
2025-09-30published 2022-05-24Package added to advisoryGHSA-3hw2-h67c-wq66CVE-2021-42697highnot named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core_2.13.0-rc2not dated
2025-09-30published 2022-05-24Package added to advisoryGHSA-3hw2-h67c-wq66CVE-2021-42697highnot named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core_2.13.0-rc3not dated
2025-09-30published 2022-07-29Package added to advisoryGHSA-2cpx-6pqp-wf35CVE-2022-31183criticalnot named as affected when the advisory was published, now names co.fs2:fs2-io_2.12not dated
2025-09-30published 2022-07-29Package added to advisoryGHSA-2cpx-6pqp-wf35CVE-2022-31183criticalnot named as affected when the advisory was published, now names co.fs2:fs2-io_2.13not dated
2025-09-30published 2022-07-29Package added to advisoryGHSA-2cpx-6pqp-wf35CVE-2022-31183criticalnot named as affected when the advisory was published, now names co.fs2:fs2-io_3not dated
2025-09-30published 2022-07-29Package added to advisoryGHSA-2cpx-6pqp-wf35CVE-2022-31183criticalnot named as affected when the advisory was published, now names co.fs2:fs2-io_sjs1_2.13not dated
2025-09-30published 2022-07-29Package added to advisoryGHSA-2cpx-6pqp-wf35CVE-2022-31183criticalnot named as affected when the advisory was published, now names co.fs2:fs2-io_sjs1_3not dated
2025-09-30published 2023-11-22Package added to advisoryGHSA-5xqm-hc45-f2g2CVE-2021-37942highnot named as affected when the advisory was published, now names co.elastic.apm:elastic-apm-agentDays to revision 679
2025-09-30published 2020-09-03Package added to advisoryGHSA-g64q-3vg8-8f93highnot named as affected when the advisory was published, now names peznot dated
Mon 29 Sep 2025· 2 advisory changes
2025-09-29published 2020-09-03Package added to advisoryGHSA-5854-jvxx-2cg9highnot named as affected when the advisory was published, now names contentnot dated
2025-09-29published 2025-08-13Package added to advisoryGHSA-prj3-ccx8-p6x4CVE-2025-55163highnot named as affected when the advisory was published, now names io.grpc:grpc-netty-shadedDays to revision 47
Sat 27 Sep 2025· 1 advisory change
2025-09-27published 2025-09-24Advisory severity changedGHSA-776q-jw43-fhjxCVE-2025-48459whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 3
Fri 26 Sep 2025· 15 advisory changes
2025-09-26published 2025-09-24Advisory fix version movedGHSA-vj76-c3g6-qr5vCVE-2025-59343
npmtar-fs
high
stated at publication 1.16.5, now states 1.16.6Days to revision 2
2025-09-26published 2025-09-24Advisory fix version movedGHSA-vj76-c3g6-qr5vCVE-2025-59343
npmtar-fs
high
stated at publication 2.1.3, now states 2.1.4Days to revision 2
2025-09-26published 2020-09-03Package added to advisoryGHSA-g9cg-h3jm-cwrchighnot named as affected when the advisory was published, now names @hapi/peznot dated
2025-09-26published 2025-09-17Package added to advisoryGHSA-mcvp-rpgg-9273CVE-2025-59410moderatenot named as affected when the advisory was published, now names d7y.io/dragonfly/v2Days to revision 9
2025-09-26published 2025-09-17Package added to advisoryGHSA-hx2h-vjw2-8r54CVE-2025-59354moderatenot named as affected when the advisory was published, now names d7y.io/dragonfly/v2Days to revision 9
2025-09-26published 2025-09-17Package added to advisoryGHSA-255v-qv84-29p5CVE-2025-59353highnot named as affected when the advisory was published, now names d7y.io/dragonfly/v2Days to revision 9
2025-09-26published 2025-09-17Package added to advisoryGHSA-79hx-3fp8-hj66CVE-2025-59352moderatenot named as affected when the advisory was published, now names d7y.io/dragonfly/v2Days to revision 9
2025-09-26published 2025-09-17Package added to advisoryGHSA-4mhv-8rh3-4ghwCVE-2025-59351moderatenot named as affected when the advisory was published, now names d7y.io/dragonfly/v2Days to revision 9
2025-09-26published 2025-09-17Package added to advisoryGHSA-c2fc-9q9c-5486CVE-2025-59350moderatenot named as affected when the advisory was published, now names d7y.io/dragonfly/v2Days to revision 9
2025-09-26published 2025-09-17Package added to advisoryGHSA-8425-8r2f-mrv6CVE-2025-59349lownot named as affected when the advisory was published, now names d7y.io/dragonfly/v2Days to revision 9
2025-09-26published 2025-09-17Package added to advisoryGHSA-2qgr-gfvj-qpcrCVE-2025-59348moderatenot named as affected when the advisory was published, now names d7y.io/dragonfly/v2Days to revision 9
2025-09-26published 2025-09-17Package added to advisoryGHSA-98x5-jw98-6c97CVE-2025-59347moderatenot named as affected when the advisory was published, now names d7y.io/dragonfly/v2Days to revision 9
2025-09-26published 2025-09-17Package added to advisoryGHSA-g2rq-jv54-wcprCVE-2025-59346highnot named as affected when the advisory was published, now names d7y.io/dragonfly/v2Days to revision 9
2025-09-26published 2025-09-17Package added to advisoryGHSA-89vc-vf32-ch59CVE-2025-59345highnot named as affected when the advisory was published, now names d7y.io/dragonfly/v2Days to revision 9
2025-09-26published 2025-09-15Advisory withdrawnGHSA-qhwp-454g-2gv4whole advisorymoderatewithdrawn 2025-09-26Days to revision 12
Thu 25 Sep 2025· 4 advisory changes
2025-09-25published 2020-09-03Package added to advisoryGHSA-3wqh-h42r-x8fqhighnot named as affected when the advisory was published, now names @hapi/contentnot dated
2025-09-25published 2025-09-17Advisory severity changedGHSA-9pw5-wx67-q964CVE-2025-10619whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2025-09-25published 2025-09-15Advisory severity changedGHSA-4hqq-7q79-932pCVE-2025-59377whole advisorycriticalstated at publication LOW, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 10
2025-09-25published 2025-09-15Advisory severity changedGHSA-hjm5-xgj8-vwj6CVE-2025-59376whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 10
Wed 24 Sep 2025· 4 advisory changes
2025-09-24published 2022-10-25Package added to advisoryGHSA-rwqr-m72q-v6cmCVE-2022-42890highnot named as affected when the advisory was published, now names org.apache.xmlgraphics:batik-bridgenot dated
2025-09-24published 2022-09-23Package added to advisoryGHSA-53jm-3hc9-fqqcCVE-2022-38648moderatenot named as affected when the advisory was published, now names org.apache.xmlgraphics:batik-bridgenot dated
2025-09-24published 2022-09-23Package added to advisoryGHSA-c5xv-qc8p-mh2vCVE-2022-38398moderatenot named as affected when the advisory was published, now names org.apache.xmlgraphics:batik-bridgenot dated
2025-09-24published 2025-08-11Advisory severity changedGHSA-qpjq-c5hr-7925CVE-2025-54478whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 44
Tue 23 Sep 2025· 6 advisory changes
2025-09-23published 2023-03-28Package added to advisoryGHSA-7phw-cxx7-q9vqCVE-2023-20860criticalnot named as affected when the advisory was published, now names org.springframework:spring-webmvcDays to revision 911
2025-09-23published 2025-09-18Advisory severity changedGHSA-vv9c-xxg7-wmv7CVE-2025-6237whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 6
2025-09-23published 2025-09-22Advisory severity changedGHSA-j2xj-h7w5-r7vpCVE-2025-59526whole advisorymoderatestated at publication LOW, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 1
2025-09-23published 2025-08-18Advisory severity changedGHSA-xfp8-x3j6-h67vCVE-2025-9096whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 37
2025-09-23published 2025-08-18Advisory severity changedGHSA-q4rg-7cjj-5r86CVE-2025-9095whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 37
2025-09-23published 2025-09-10Advisory severity changedGHSA-xp8g-32qh-mv28CVE-2025-57520whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 13
Mon 22 Sep 2025· 2 advisory changes
2025-09-22published 2025-09-16Advisory severity changedGHSA-mp7c-m3rh-r56vCVE-2025-59160whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 6
2025-09-22published 2025-09-11Advisory severity changedGHSA-33vc-wfww-vjfvCVE-2025-9910whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 12
Thu 18 Sep 2025· 3 advisory changes
2025-09-18published 2025-09-10Advisory severity changedGHSA-jgw4-cr84-mqxgCVE-2025-10155whole advisorycriticalstated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.Days to revision 8
2025-09-18published 2025-09-10Advisory severity changedGHSA-mjqp-26hc-grxgCVE-2025-10156whole advisorycriticalstated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.Days to revision 8
2025-09-18published 2025-09-10Advisory severity changedGHSA-f7qq-56ww-84crCVE-2025-10157whole advisorycriticalstated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.Days to revision 8
Wed 17 Sep 2025· 1 advisory change
2025-09-17published 2025-08-06Advisory withdrawnGHSA-qj5r-2r5p-phc7whole advisorymoderatewithdrawn 2025-09-17Days to revision 42
Tue 16 Sep 2025· 1 advisory change
2025-09-16published 2021-07-27Package added to advisoryGHSA-2363-cqg2-863cCVE-2021-33813highnot named as affected when the advisory was published, now names org.jdom:jdom2not dated
Mon 15 Sep 2025· 1 advisory change
2025-09-15published 2025-09-12Advisory fix version movedGHSA-wgpv-6j63-x5phCVE-2025-58434
npmflowise
critical
stated at publication 3.0.5, now states 3.0.6Days to revision 3
Fri 12 Sep 2025· 15 advisory changes
2025-09-12published 2025-06-03Package added to advisoryGHSA-7v6m-28jr-rg84CVE-2025-35036moderatenot named as affected when the advisory was published, now names org.hibernate:hibernate-validatorDays to revision 101
2025-09-12published 2021-06-04Package added to advisoryGHSA-rmrm-75hp-phr2CVE-2020-10693moderatenot named as affected when the advisory was published, now names org.hibernate:hibernate-validatornot dated
2025-09-12published 2020-01-08Package added to advisoryGHSA-m8p2-495h-ccmhCVE-2019-10219moderatenot named as affected when the advisory was published, now names org.hibernate:hibernate-validatornot dated
2025-09-12published 2018-10-17Package added to advisoryGHSA-4mv7-cq75-3qjmCVE-2015-7940moderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onnot dated
2025-09-12published 2018-10-17Package added to advisoryGHSA-r97x-3g8f-gx3mCVE-2016-1000340highnot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onnot dated
2025-09-12published 2018-10-17Package added to advisoryGHSA-4vhj-98r6-424hCVE-2016-1000338highnot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onnot dated
2025-09-12published 2018-10-16Package added to advisoryGHSA-xqj7-j8j5-f2xrCVE-2018-1000180highnot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onnot dated
2025-09-12published 2018-10-17Package added to advisoryGHSA-w285-wf9q-5w69CVE-2016-1000352highnot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onnot dated
2025-09-12published 2018-10-18Package added to advisoryGHSA-9gp4-qrff-c648CVE-2016-1000345moderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onnot dated
2025-09-12published 2018-10-17Package added to advisoryGHSA-fjqm-246c-mwqgCVE-2016-1000346lownot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onnot dated
2025-09-12published 2018-10-18Package added to advisoryGHSA-2j2x-hx4g-2gf4CVE-2016-1000344highnot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onnot dated
2025-09-12published 2018-10-17Package added to advisoryGHSA-rrvx-pwf8-p59pCVE-2016-1000343highnot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onnot dated
2025-09-12published 2018-10-17Package added to advisoryGHSA-r9ch-m4fh-fc7qCVE-2016-1000341moderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onnot dated
2025-09-12published 2018-10-17Package added to advisoryGHSA-c8xf-m4ff-jcxjCVE-2016-1000339moderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onnot dated
2025-09-12published 2024-11-07Package added to advisoryGHSA-x83m-pf6f-pf9gCVE-2023-1932moderatenot named as affected when the advisory was published, now names org.hibernate:hibernate-validatorDays to revision 309
Thu 11 Sep 2025· 1 advisory change
2025-09-11published 2024-07-11Advisory withdrawnGHSA-9mvj-f7w8-pvh2CVE-2024-6484whole advisorymoderatewithdrawn 2025-09-11Days to revision 427
Tue 9 Sep 2025· 1 advisory change
2025-09-09published 2025-09-09Advisory fix version movedGHSA-w62p-hx95-gf2cCVE-2025-59037
npm@duckdb/duckdb-wasm
high
stated at publication 1.29.3, now states 1.30.0Days to revision 0
Mon 8 Sep 2025· 1 advisory change
2025-09-08published 2025-07-09Package added to advisoryGHSA-q92v-3f4w-5xg8CVE-2025-53742moderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins:applitools-eyesDays to revision 61
Fri 5 Sep 2025· 1 advisory change
2025-09-05published 2025-09-04Advisory severity changedGHSA-fghv-69vj-qj49CVE-2025-58056whole advisorylowstated at publication HIGH, now states LOWCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 1
Tue 2 Sep 2025· 7 advisory changes
2025-09-02published 2022-05-14Package added to advisoryGHSA-xjgh-84hx-56c5CVE-2017-12617highnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-corenot dated
2025-09-02published 2022-05-14Package added to advisoryGHSA-xjgh-84hx-56c5CVE-2017-12617highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinanot dated
2025-09-02published 2022-05-14Package added to advisoryGHSA-w3j5-q8f2-3cqqCVE-2016-8745highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-utilnot dated
2025-09-02published 2023-03-10Package added to advisoryGHSA-vp98-w2p3-mv35CVE-2023-26464highnot named as affected when the advisory was published, now names log4j:log4jDays to revision 907
2025-09-02published 2022-05-17Package added to advisoryGHSA-rpjm-422r-95mhCVE-2022-30126moderatenot named as affected when the advisory was published, now names org.apache.tika:tika-corenot dated
2025-09-02published 2022-03-12Package added to advisoryGHSA-cr3q-pqgq-m8c2CVE-2018-25031moderatenot named as affected when the advisory was published, now names org.webjars:swagger-uinot dated
2025-09-02published 2018-10-17Package added to advisoryGHSA-qcj7-g2j5-g7r3CVE-2016-1000342highnot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onnot dated
Fri 29 Aug 2025· 5 advisory changes
2025-08-29published 2025-08-28Advisory fix version movedGHSA-jc7w-c686-c4v9CVE-2025-58058
gogithub.com/ulikunitz/xz
moderate
stated at publication 0.5.14, now states 0.5.15Days to revision 1
2025-08-29published 2025-08-20Package added to advisoryGHSA-mpww-r37c-vxjwCVE-2025-43746moderatenot named as affected when the advisory was published, now names ccom.liferay:com.liferay.dynamic.data.mapping.webDays to revision 9
2025-08-29published 2022-05-14Advisory withdrawnGHSA-7mj4-2984-955fCVE-2018-18307whole advisorymoderatewithdrawn 2025-08-29Days to revision 1,204
2025-08-29published 2025-08-20Advisory withdrawnGHSA-xh9h-692f-mmg4CVE-2025-54364whole advisorylowwithdrawn 2025-08-29Days to revision 10
2025-08-29published 2025-08-20Advisory withdrawnGHSA-6fxp-p9mg-q64wCVE-2025-54363whole advisorylowwithdrawn 2025-08-29Days to revision 10
Wed 27 Aug 2025· 1 advisory change
2025-08-27published 2022-05-20Advisory fix version movedGHSA-hp87-p4gw-j4gqCVE-2022-28948
gogopkg.in/yaml.v3
high
stated at publication 3.0.0, now states 3.0.1Days to revision 13
Tue 26 Aug 2025· 1 advisory change
2025-08-26published 2025-08-21Advisory severity changedGHSA-xr97-25v7-hc2qCVE-2025-55742whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 5
Mon 25 Aug 2025· 1 advisory change
2025-08-25published 2022-01-27Advisory withdrawnGHSA-77rm-9x9h-xj3gCVE-2021-22570whole advisoryhighwithdrawn 2025-08-25Days to revision 1,307
Fri 22 Aug 2025· 2 advisory changes
2025-08-22published 2025-08-13Package added to advisoryGHSA-gqp3-2cvr-x8m3CVE-2025-48989highnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDays to revision 9
2025-08-22published 2025-08-22Advisory severity changedGHSA-74rg-6f92-g6wxCVE-2025-55745whole advisorylowstated at publication HIGH, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 0
Thu 21 Aug 2025· 2 advisory changes
2025-08-21published 2025-08-14Advisory severity changedGHSA-r4mg-4433-c7g3CVE-2025-24293whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2025-08-21published 2025-08-21Advisory severity changedGHSA-8hmm-4crw-vm2cCVE-2025-57755whole advisoryhighstated at publication LOW, now states HIGHA CVSS version was added; the existing vectors stayed the same.Days to revision 0
Wed 20 Aug 2025· 1 advisory change
2025-08-20published 2025-07-14Advisory severity changedGHSA-6qjf-g333-pv38CVE-2025-53623whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 37
Thu 14 Aug 2025· 5 advisory changes
2025-08-14published 2021-03-18Advisory fix version movedGHSA-95q3-8gr9-gm8wCVE-2021-27923
pypipillow
high
stated at publication 8.1.1, now states 8.1.2not dated
2025-08-14published 2021-03-18Advisory fix version movedGHSA-3wvg-mj6g-m9cvCVE-2021-27922
pypipillow
high
stated at publication 8.1.1, now states 8.1.2not dated
2025-08-14published 2021-03-18Advisory fix version movedGHSA-f4w8-cv6p-x6r5CVE-2021-27921
pypipillow
high
stated at publication 8.1.1, now states 8.1.2not dated
2025-08-14published 2022-05-24Package added to advisoryGHSA-j2h2-cvwh-cr64CVE-2020-14457moderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v5Days to revision 1,178
2025-08-14published 2025-08-12Package added to advisoryGHSA-m5c7-5gv3-hcpfCVE-2025-43734moderatenot named as affected when the advisory was published, now names com.liferay:com.liferay.frontend.taglib.clayDays to revision 2
Wed 13 Aug 2025· 1 advisory change
2025-08-13published 2025-07-20Advisory withdrawnGHSA-mqcp-p2hv-vw6xCVE-2025-54314whole advisoryhighwithdrawn 2025-08-13Days to revision 25
Tue 12 Aug 2025· 2 advisory changes
2025-08-12published 2025-07-25Advisory severity changedGHSA-75jv-vfxf-3865CVE-2025-55013whole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 18
2025-08-12published 2025-08-11Advisory withdrawnGHSA-pwq7-2gvj-vg9vwhole advisoryhighwithdrawn 2025-08-12Days to revision 1
Mon 11 Aug 2025· 2 advisory changes
2025-08-11published 2019-07-19Package added to advisoryGHSA-x5rq-j2xg-h7qmCVE-2019-1010266moderatenot named as affected when the advisory was published, now names lodash-railsnot dated
2025-08-11published 2019-07-10Package added to advisoryGHSA-jf85-cpcp-j695CVE-2019-10744criticalnot named as affected when the advisory was published, now names lodash-railsnot dated

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →