Every change, newest first
What a record said when it was published, what it says now, and the commit that changed it.
5,026 advisory changes · newest first · grouped by day
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Kind | Advisory, Which advisory was edited, by its GHSA id. | Package, The package the advisory names, and the registry it comes from. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|---|
| Tue 30 Sep 2025· 11 advisory changes | |||||
| 2025-09-30published 2022-05-24 | Package added to advisory | GHSA-3hw2-h67c-wq66CVE-2021-42697 | high | not named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core_2.13 | not dated |
| 2025-09-30published 2022-05-24 | Package added to advisory | GHSA-3hw2-h67c-wq66CVE-2021-42697 | high | not named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core_2.13.0-m5 | not dated |
| 2025-09-30published 2022-05-24 | Package added to advisory | GHSA-3hw2-h67c-wq66CVE-2021-42697 | high | not named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core_2.13.0-rc2 | not dated |
| 2025-09-30published 2022-05-24 | Package added to advisory | GHSA-3hw2-h67c-wq66CVE-2021-42697 | high | not named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core_2.13.0-rc3 | not dated |
| 2025-09-30published 2022-07-29 | Package added to advisory | GHSA-2cpx-6pqp-wf35CVE-2022-31183 | critical | not named as affected when the advisory was published, now names co.fs2:fs2-io_2.12 | not dated |
| 2025-09-30published 2022-07-29 | Package added to advisory | GHSA-2cpx-6pqp-wf35CVE-2022-31183 | critical | not named as affected when the advisory was published, now names co.fs2:fs2-io_2.13 | not dated |
| 2025-09-30published 2022-07-29 | Package added to advisory | GHSA-2cpx-6pqp-wf35CVE-2022-31183 | critical | not named as affected when the advisory was published, now names co.fs2:fs2-io_3 | not dated |
| 2025-09-30published 2022-07-29 | Package added to advisory | GHSA-2cpx-6pqp-wf35CVE-2022-31183 | critical | not named as affected when the advisory was published, now names co.fs2:fs2-io_sjs1_2.13 | not dated |
| 2025-09-30published 2022-07-29 | Package added to advisory | GHSA-2cpx-6pqp-wf35CVE-2022-31183 | critical | not named as affected when the advisory was published, now names co.fs2:fs2-io_sjs1_3 | not dated |
| 2025-09-30published 2023-11-22 | Package added to advisory | GHSA-5xqm-hc45-f2g2CVE-2021-37942 | high | not named as affected when the advisory was published, now names co.elastic.apm:elastic-apm-agent | Days to revision 679 |
| 2025-09-30published 2020-09-03 | Package added to advisory | GHSA-g64q-3vg8-8f93 | high | not named as affected when the advisory was published, now names pez | not dated |
| Mon 29 Sep 2025· 2 advisory changes | |||||
| 2025-09-29published 2020-09-03 | Package added to advisory | GHSA-5854-jvxx-2cg9 | high | not named as affected when the advisory was published, now names content | not dated |
| 2025-09-29published 2025-08-13 | Package added to advisory | GHSA-prj3-ccx8-p6x4CVE-2025-55163 | high | not named as affected when the advisory was published, now names io.grpc:grpc-netty-shaded | Days to revision 47 |
| Sat 27 Sep 2025· 1 advisory change | |||||
| 2025-09-27published 2025-09-24 | Advisory severity changed | GHSA-776q-jw43-fhjxCVE-2025-48459 | whole advisorycritical | stated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 3 |
| Fri 26 Sep 2025· 15 advisory changes | |||||
| 2025-09-26published 2025-09-24 | Advisory fix version moved | GHSA-vj76-c3g6-qr5vCVE-2025-59343 | npmtar-fs high | stated at publication 1.16.5, now states 1.16.6 | Days to revision 2 |
| 2025-09-26published 2025-09-24 | Advisory fix version moved | GHSA-vj76-c3g6-qr5vCVE-2025-59343 | npmtar-fs high | stated at publication 2.1.3, now states 2.1.4 | Days to revision 2 |
| 2025-09-26published 2020-09-03 | Package added to advisory | GHSA-g9cg-h3jm-cwrc | high | not named as affected when the advisory was published, now names @hapi/pez | not dated |
| 2025-09-26published 2025-09-17 | Package added to advisory | GHSA-mcvp-rpgg-9273CVE-2025-59410 | moderate | not named as affected when the advisory was published, now names d7y.io/dragonfly/v2 | Days to revision 9 |
| 2025-09-26published 2025-09-17 | Package added to advisory | GHSA-hx2h-vjw2-8r54CVE-2025-59354 | moderate | not named as affected when the advisory was published, now names d7y.io/dragonfly/v2 | Days to revision 9 |
| 2025-09-26published 2025-09-17 | Package added to advisory | GHSA-255v-qv84-29p5CVE-2025-59353 | high | not named as affected when the advisory was published, now names d7y.io/dragonfly/v2 | Days to revision 9 |
| 2025-09-26published 2025-09-17 | Package added to advisory | GHSA-79hx-3fp8-hj66CVE-2025-59352 | moderate | not named as affected when the advisory was published, now names d7y.io/dragonfly/v2 | Days to revision 9 |
| 2025-09-26published 2025-09-17 | Package added to advisory | GHSA-4mhv-8rh3-4ghwCVE-2025-59351 | moderate | not named as affected when the advisory was published, now names d7y.io/dragonfly/v2 | Days to revision 9 |
| 2025-09-26published 2025-09-17 | Package added to advisory | GHSA-c2fc-9q9c-5486CVE-2025-59350 | moderate | not named as affected when the advisory was published, now names d7y.io/dragonfly/v2 | Days to revision 9 |
| 2025-09-26published 2025-09-17 | Package added to advisory | GHSA-8425-8r2f-mrv6CVE-2025-59349 | low | not named as affected when the advisory was published, now names d7y.io/dragonfly/v2 | Days to revision 9 |
| 2025-09-26published 2025-09-17 | Package added to advisory | GHSA-2qgr-gfvj-qpcrCVE-2025-59348 | moderate | not named as affected when the advisory was published, now names d7y.io/dragonfly/v2 | Days to revision 9 |
| 2025-09-26published 2025-09-17 | Package added to advisory | GHSA-98x5-jw98-6c97CVE-2025-59347 | moderate | not named as affected when the advisory was published, now names d7y.io/dragonfly/v2 | Days to revision 9 |
| 2025-09-26published 2025-09-17 | Package added to advisory | GHSA-g2rq-jv54-wcprCVE-2025-59346 | high | not named as affected when the advisory was published, now names d7y.io/dragonfly/v2 | Days to revision 9 |
| 2025-09-26published 2025-09-17 | Package added to advisory | GHSA-89vc-vf32-ch59CVE-2025-59345 | high | not named as affected when the advisory was published, now names d7y.io/dragonfly/v2 | Days to revision 9 |
| 2025-09-26published 2025-09-15 | Advisory withdrawn | GHSA-qhwp-454g-2gv4 | whole advisorymoderate | withdrawn 2025-09-26 | Days to revision 12 |
| Thu 25 Sep 2025· 4 advisory changes | |||||
| 2025-09-25published 2020-09-03 | Package added to advisory | GHSA-3wqh-h42r-x8fq | high | not named as affected when the advisory was published, now names @hapi/content | not dated |
| 2025-09-25published 2025-09-17 | Advisory severity changed | GHSA-9pw5-wx67-q964CVE-2025-10619 | whole advisorymoderate | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 8 |
| 2025-09-25published 2025-09-15 | Advisory severity changed | GHSA-4hqq-7q79-932pCVE-2025-59377 | whole advisorycritical | stated at publication LOW, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 10 |
| 2025-09-25published 2025-09-15 | Advisory severity changed | GHSA-hjm5-xgj8-vwj6CVE-2025-59376 | whole advisorymoderate | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 10 |
| Wed 24 Sep 2025· 4 advisory changes | |||||
| 2025-09-24published 2022-10-25 | Package added to advisory | GHSA-rwqr-m72q-v6cmCVE-2022-42890 | high | not named as affected when the advisory was published, now names org.apache.xmlgraphics:batik-bridge | not dated |
| 2025-09-24published 2022-09-23 | Package added to advisory | GHSA-53jm-3hc9-fqqcCVE-2022-38648 | moderate | not named as affected when the advisory was published, now names org.apache.xmlgraphics:batik-bridge | not dated |
| 2025-09-24published 2022-09-23 | Package added to advisory | GHSA-c5xv-qc8p-mh2vCVE-2022-38398 | moderate | not named as affected when the advisory was published, now names org.apache.xmlgraphics:batik-bridge | not dated |
| 2025-09-24published 2025-08-11 | Advisory severity changed | GHSA-qpjq-c5hr-7925CVE-2025-54478 | whole advisorymoderate | stated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 44 |
| Tue 23 Sep 2025· 6 advisory changes | |||||
| 2025-09-23published 2023-03-28 | Package added to advisory | GHSA-7phw-cxx7-q9vqCVE-2023-20860 | critical | not named as affected when the advisory was published, now names org.springframework:spring-webmvc | Days to revision 911 |
| 2025-09-23published 2025-09-18 | Advisory severity changed | GHSA-vv9c-xxg7-wmv7CVE-2025-6237 | whole advisorycritical | stated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 6 |
| 2025-09-23published 2025-09-22 | Advisory severity changed | GHSA-j2xj-h7w5-r7vpCVE-2025-59526 | whole advisorymoderate | stated at publication LOW, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored. | Days to revision 1 |
| 2025-09-23published 2025-08-18 | Advisory severity changed | GHSA-xfp8-x3j6-h67vCVE-2025-9096 | whole advisorymoderate | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 37 |
| 2025-09-23published 2025-08-18 | Advisory severity changed | GHSA-q4rg-7cjj-5r86CVE-2025-9095 | whole advisorymoderate | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 37 |
| 2025-09-23published 2025-09-10 | Advisory severity changed | GHSA-xp8g-32qh-mv28CVE-2025-57520 | whole advisorymoderate | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 13 |
| Mon 22 Sep 2025· 2 advisory changes | |||||
| 2025-09-22published 2025-09-16 | Advisory severity changed | GHSA-mp7c-m3rh-r56vCVE-2025-59160 | whole advisorymoderate | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 6 |
| 2025-09-22published 2025-09-11 | Advisory severity changed | GHSA-33vc-wfww-vjfvCVE-2025-9910 | whole advisorymoderate | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 12 |
| Thu 18 Sep 2025· 3 advisory changes | |||||
| 2025-09-18published 2025-09-10 | Advisory severity changed | GHSA-jgw4-cr84-mqxgCVE-2025-10155 | whole advisorycritical | stated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same. | Days to revision 8 |
| 2025-09-18published 2025-09-10 | Advisory severity changed | GHSA-mjqp-26hc-grxgCVE-2025-10156 | whole advisorycritical | stated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same. | Days to revision 8 |
| 2025-09-18published 2025-09-10 | Advisory severity changed | GHSA-f7qq-56ww-84crCVE-2025-10157 | whole advisorycritical | stated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same. | Days to revision 8 |
| Wed 17 Sep 2025· 1 advisory change | |||||
| 2025-09-17published 2025-08-06 | Advisory withdrawn | GHSA-qj5r-2r5p-phc7 | whole advisorymoderate | withdrawn 2025-09-17 | Days to revision 42 |
| Tue 16 Sep 2025· 1 advisory change | |||||
| 2025-09-16published 2021-07-27 | Package added to advisory | GHSA-2363-cqg2-863cCVE-2021-33813 | high | not named as affected when the advisory was published, now names org.jdom:jdom2 | not dated |
| Mon 15 Sep 2025· 1 advisory change | |||||
| 2025-09-15published 2025-09-12 | Advisory fix version moved | GHSA-wgpv-6j63-x5phCVE-2025-58434 | npmflowise critical | stated at publication 3.0.5, now states 3.0.6 | Days to revision 3 |
| Fri 12 Sep 2025· 15 advisory changes | |||||
| 2025-09-12published 2025-06-03 | Package added to advisory | GHSA-7v6m-28jr-rg84CVE-2025-35036 | moderate | not named as affected when the advisory was published, now names org.hibernate:hibernate-validator | Days to revision 101 |
| 2025-09-12published 2021-06-04 | Package added to advisory | GHSA-rmrm-75hp-phr2CVE-2020-10693 | moderate | not named as affected when the advisory was published, now names org.hibernate:hibernate-validator | not dated |
| 2025-09-12published 2020-01-08 | Package added to advisory | GHSA-m8p2-495h-ccmhCVE-2019-10219 | moderate | not named as affected when the advisory was published, now names org.hibernate:hibernate-validator | not dated |
| 2025-09-12published 2018-10-17 | Package added to advisory | GHSA-4mv7-cq75-3qjmCVE-2015-7940 | moderate | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | not dated |
| 2025-09-12published 2018-10-17 | Package added to advisory | GHSA-r97x-3g8f-gx3mCVE-2016-1000340 | high | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | not dated |
| 2025-09-12published 2018-10-17 | Package added to advisory | GHSA-4vhj-98r6-424hCVE-2016-1000338 | high | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | not dated |
| 2025-09-12published 2018-10-16 | Package added to advisory | GHSA-xqj7-j8j5-f2xrCVE-2018-1000180 | high | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | not dated |
| 2025-09-12published 2018-10-17 | Package added to advisory | GHSA-w285-wf9q-5w69CVE-2016-1000352 | high | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | not dated |
| 2025-09-12published 2018-10-18 | Package added to advisory | GHSA-9gp4-qrff-c648CVE-2016-1000345 | moderate | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | not dated |
| 2025-09-12published 2018-10-17 | Package added to advisory | GHSA-fjqm-246c-mwqgCVE-2016-1000346 | low | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | not dated |
| 2025-09-12published 2018-10-18 | Package added to advisory | GHSA-2j2x-hx4g-2gf4CVE-2016-1000344 | high | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | not dated |
| 2025-09-12published 2018-10-17 | Package added to advisory | GHSA-rrvx-pwf8-p59pCVE-2016-1000343 | high | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | not dated |
| 2025-09-12published 2018-10-17 | Package added to advisory | GHSA-r9ch-m4fh-fc7qCVE-2016-1000341 | moderate | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | not dated |
| 2025-09-12published 2018-10-17 | Package added to advisory | GHSA-c8xf-m4ff-jcxjCVE-2016-1000339 | moderate | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | not dated |
| 2025-09-12published 2024-11-07 | Package added to advisory | GHSA-x83m-pf6f-pf9gCVE-2023-1932 | moderate | not named as affected when the advisory was published, now names org.hibernate:hibernate-validator | Days to revision 309 |
| Thu 11 Sep 2025· 1 advisory change | |||||
| 2025-09-11published 2024-07-11 | Advisory withdrawn | GHSA-9mvj-f7w8-pvh2CVE-2024-6484 | whole advisorymoderate | withdrawn 2025-09-11 | Days to revision 427 |
| Tue 9 Sep 2025· 1 advisory change | |||||
| 2025-09-09published 2025-09-09 | Advisory fix version moved | GHSA-w62p-hx95-gf2cCVE-2025-59037 | npm@duckdb/duckdb-wasm high | stated at publication 1.29.3, now states 1.30.0 | Days to revision 0 |
| Mon 8 Sep 2025· 1 advisory change | |||||
| 2025-09-08published 2025-07-09 | Package added to advisory | GHSA-q92v-3f4w-5xg8CVE-2025-53742 | moderate | not named as affected when the advisory was published, now names org.jenkins-ci.plugins:applitools-eyes | Days to revision 61 |
| Fri 5 Sep 2025· 1 advisory change | |||||
| 2025-09-05published 2025-09-04 | Advisory severity changed | GHSA-fghv-69vj-qj49CVE-2025-58056 | whole advisorylow | stated at publication HIGH, now states LOWCVSS versions were removed or replaced; no shared version's vector was rescored. | Days to revision 1 |
| Tue 2 Sep 2025· 7 advisory changes | |||||
| 2025-09-02published 2022-05-14 | Package added to advisory | GHSA-xjgh-84hx-56c5CVE-2017-12617 | high | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | not dated |
| 2025-09-02published 2022-05-14 | Package added to advisory | GHSA-xjgh-84hx-56c5CVE-2017-12617 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina | not dated |
| 2025-09-02published 2022-05-14 | Package added to advisory | GHSA-w3j5-q8f2-3cqqCVE-2016-8745 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-util | not dated |
| 2025-09-02published 2023-03-10 | Package added to advisory | GHSA-vp98-w2p3-mv35CVE-2023-26464 | high | not named as affected when the advisory was published, now names log4j:log4j | Days to revision 907 |
| 2025-09-02published 2022-05-17 | Package added to advisory | GHSA-rpjm-422r-95mhCVE-2022-30126 | moderate | not named as affected when the advisory was published, now names org.apache.tika:tika-core | not dated |
| 2025-09-02published 2022-03-12 | Package added to advisory | GHSA-cr3q-pqgq-m8c2CVE-2018-25031 | moderate | not named as affected when the advisory was published, now names org.webjars:swagger-ui | not dated |
| 2025-09-02published 2018-10-17 | Package added to advisory | GHSA-qcj7-g2j5-g7r3CVE-2016-1000342 | high | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | not dated |
| Fri 29 Aug 2025· 5 advisory changes | |||||
| 2025-08-29published 2025-08-28 | Advisory fix version moved | GHSA-jc7w-c686-c4v9CVE-2025-58058 | gogithub.com/ulikunitz/xz moderate | stated at publication 0.5.14, now states 0.5.15 | Days to revision 1 |
| 2025-08-29published 2025-08-20 | Package added to advisory | GHSA-mpww-r37c-vxjwCVE-2025-43746 | moderate | not named as affected when the advisory was published, now names ccom.liferay:com.liferay.dynamic.data.mapping.web | Days to revision 9 |
| 2025-08-29published 2022-05-14 | Advisory withdrawn | GHSA-7mj4-2984-955fCVE-2018-18307 | whole advisorymoderate | withdrawn 2025-08-29 | Days to revision 1,204 |
| 2025-08-29published 2025-08-20 | Advisory withdrawn | GHSA-xh9h-692f-mmg4CVE-2025-54364 | whole advisorylow | withdrawn 2025-08-29 | Days to revision 10 |
| 2025-08-29published 2025-08-20 | Advisory withdrawn | GHSA-6fxp-p9mg-q64wCVE-2025-54363 | whole advisorylow | withdrawn 2025-08-29 | Days to revision 10 |
| Wed 27 Aug 2025· 1 advisory change | |||||
| 2025-08-27published 2022-05-20 | Advisory fix version moved | GHSA-hp87-p4gw-j4gqCVE-2022-28948 | gogopkg.in/yaml.v3 high | stated at publication 3.0.0, now states 3.0.1 | Days to revision 13 |
| Tue 26 Aug 2025· 1 advisory change | |||||
| 2025-08-26published 2025-08-21 | Advisory severity changed | GHSA-xr97-25v7-hc2qCVE-2025-55742 | whole advisorymoderate | stated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 5 |
| Mon 25 Aug 2025· 1 advisory change | |||||
| 2025-08-25published 2022-01-27 | Advisory withdrawn | GHSA-77rm-9x9h-xj3gCVE-2021-22570 | whole advisoryhigh | withdrawn 2025-08-25 | Days to revision 1,307 |
| Fri 22 Aug 2025· 2 advisory changes | |||||
| 2025-08-22published 2025-08-13 | Package added to advisory | GHSA-gqp3-2cvr-x8m3CVE-2025-48989 | high | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | Days to revision 9 |
| 2025-08-22published 2025-08-22 | Advisory severity changed | GHSA-74rg-6f92-g6wxCVE-2025-55745 | whole advisorylow | stated at publication HIGH, now states LOWNo CVSS vector was stated in the first observed version. | Days to revision 0 |
| Thu 21 Aug 2025· 2 advisory changes | |||||
| 2025-08-21published 2025-08-14 | Advisory severity changed | GHSA-r4mg-4433-c7g3CVE-2025-24293 | whole advisorycritical | stated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 8 |
| 2025-08-21published 2025-08-21 | Advisory severity changed | GHSA-8hmm-4crw-vm2cCVE-2025-57755 | whole advisoryhigh | stated at publication LOW, now states HIGHA CVSS version was added; the existing vectors stayed the same. | Days to revision 0 |
| Wed 20 Aug 2025· 1 advisory change | |||||
| 2025-08-20published 2025-07-14 | Advisory severity changed | GHSA-6qjf-g333-pv38CVE-2025-53623 | whole advisorycritical | stated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 37 |
| Thu 14 Aug 2025· 5 advisory changes | |||||
| 2025-08-14published 2021-03-18 | Advisory fix version moved | GHSA-95q3-8gr9-gm8wCVE-2021-27923 | pypipillow high | stated at publication 8.1.1, now states 8.1.2 | not dated |
| 2025-08-14published 2021-03-18 | Advisory fix version moved | GHSA-3wvg-mj6g-m9cvCVE-2021-27922 | pypipillow high | stated at publication 8.1.1, now states 8.1.2 | not dated |
| 2025-08-14published 2021-03-18 | Advisory fix version moved | GHSA-f4w8-cv6p-x6r5CVE-2021-27921 | pypipillow high | stated at publication 8.1.1, now states 8.1.2 | not dated |
| 2025-08-14published 2022-05-24 | Package added to advisory | GHSA-j2h2-cvwh-cr64CVE-2020-14457 | moderate | not named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v5 | Days to revision 1,178 |
| 2025-08-14published 2025-08-12 | Package added to advisory | GHSA-m5c7-5gv3-hcpfCVE-2025-43734 | moderate | not named as affected when the advisory was published, now names com.liferay:com.liferay.frontend.taglib.clay | Days to revision 2 |
| Wed 13 Aug 2025· 1 advisory change | |||||
| 2025-08-13published 2025-07-20 | Advisory withdrawn | GHSA-mqcp-p2hv-vw6xCVE-2025-54314 | whole advisoryhigh | withdrawn 2025-08-13 | Days to revision 25 |
| Tue 12 Aug 2025· 2 advisory changes | |||||
| 2025-08-12published 2025-07-25 | Advisory severity changed | GHSA-75jv-vfxf-3865CVE-2025-55013 | whole advisorymoderate | stated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Days to revision 18 |
| 2025-08-12published 2025-08-11 | Advisory withdrawn | GHSA-pwq7-2gvj-vg9v | whole advisoryhigh | withdrawn 2025-08-12 | Days to revision 1 |
| Mon 11 Aug 2025· 2 advisory changes | |||||
| 2025-08-11published 2019-07-19 | Package added to advisory | GHSA-x5rq-j2xg-h7qmCVE-2019-1010266 | moderate | not named as affected when the advisory was published, now names lodash-rails | not dated |
| 2025-08-11published 2019-07-10 | Package added to advisory | GHSA-jf85-cpcp-j695CVE-2019-10744 | critical | not named as affected when the advisory was published, now names lodash-rails | not dated |
Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none.
Data sources and quality
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →