Advisory fix version moved
What a record said when it was published, what it says now, and the commit that changed it.
151 advisory changes · newest first · grouped by day
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Advisory, Which advisory was edited, by its GHSA id. | Package, The package the advisory names, and the registry it comes from. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|
| Wed 22 Mar 2023· 1 change | ||||
| 2023-03-22published 2021-05-10 | GHSA-x5r6-x823-9848CVE-2020-7766 | npmjson-ptr high | stated at publication 2.0.0, now states 2.1.0 | Duration unknown |
| Fri 17 Mar 2023· 1 change | ||||
| 2023-03-17published 2023-03-08 | GHSA-933g-v89r-x8pfCVE-2023-23638 | mavenorg.apache.dubbo:dubbo critical | stated at publication 2.7.21, now states 2.7.22 | Time to revision 9 days |
| Wed 15 Feb 2023· 1 change | ||||
| 2023-02-15published 2021-07-26 | GHSA-xcf7-q56x-78ghCVE-2021-23409 | gogithub.com/pires/go-proxyproto high | stated at publication 0.6.0, now states 0.6.1 | Duration unknown |
| Thu 9 Feb 2023· 4 changes | ||||
| 2023-02-09published 2022-07-15 | GHSA-qwrj-9hmp-gpxhCVE-2022-31145 | gogithub.com/flyteorg/flyteadmin moderate | stated at publication 1.1.30, now states 1.1.31 | Duration unknown |
| 2023-02-09published 2021-06-23 | GHSA-h395-qcrw-5vmqCVE-2020-28483 | gogithub.com/gin-gonic/gin high | stated at publication 1.7.0, now states 1.7.7 | Duration unknown |
| 2023-02-09published 2022-05-22 | GHSA-qx32-f6g6-fcfrCVE-2022-31259 | gogithub.com/beego/beego critical | stated at publication 1.12.4, now states 1.12.9 | Duration unknown |
| 2023-02-09published 2022-04-06 | GHSA-28r6-jm5h-mrggCVE-2021-30080 | gogithub.com/beego/beego/v2 high | stated at publication 2.0.2, now states 2.0.3 | Duration unknown |
| Mon 6 Feb 2023· 1 change | ||||
| 2023-02-06published 2022-09-16 | GHSA-3pgj-pg6c-r5p7CVE-2022-36087 | pypioauthlib moderate | stated at publication 3.2.1, now states 3.2.2 | Duration unknown |
| Fri 6 Jan 2023· 1 change | ||||
| 2023-01-06published 2022-04-08 | GHSA-h6xw-mghq-7523CVE-2022-27819 | crates.iosimple-wayland-hotkey-daemon moderate | stated at publication 1.1.7, now states 1.2.0 | Duration unknown |
| Thu 5 Jan 2023· 1 change | ||||
| 2023-01-05published 2022-04-08 | GHSA-r3r5-jhw6-4634CVE-2022-27818 | crates.iosimple-wayland-hotkey-daemon critical | stated at publication 1.1.7, now states 1.2.0 | Duration unknown |
| Thu 1 Dec 2022· 1 change | ||||
| 2022-12-01published 2021-03-29 | GHSA-mvg9-xffr-p774CVE-2021-25291 | pypipillow high | stated at publication 8.1.1, now states 8.2.0 | Duration unknown |
| Tue 15 Nov 2022· 1 change | ||||
| 2022-11-15published 2018-12-20 | GHSA-jxm5-5xcw-h57qCVE-2018-1000823 | mavenorg.exist-db:exist-core critical | stated at publication 5.0.0, now states 5.1.0 | Time to revision 1,426 days |
| Mon 19 Sep 2022· 1 change | ||||
| 2022-09-19published 2020-09-23 | GHSA-q3vw-4jx3-rrr2 | mavendev.personnummer:personnummer low | stated at publication 1.0.1, now states 3.3.0 | Time to revision 726 days |
| Fri 9 Sep 2022· 2 changes | ||||
| 2022-09-09published 2021-05-07 | GHSA-cgc7-mwp4-3ccxCVE-2020-15930 | npmjoplin moderate | stated at publication 1.0.246, now states 1.1.7 | Time to revision 490 days |
| 2022-09-09published 2020-09-11 | GHSA-p82g-2xpp-m5r3CVE-2015-5654 | npmdojo moderate | stated at publication 1.2.0, now states 1.9.1 | Time to revision 728 days |
| Fri 2 Sep 2022· 2 changes | ||||
| 2022-09-02published 2022-05-24 | GHSA-xr8f-59pp-rxxhCVE-2019-1302 | nugetmicrosoft.aspnetcore.spaservices moderate | stated at publication 2.1.2, now states 2.1.13 | Time to revision 101 days |
| 2022-09-02published 2022-05-24 | GHSA-xr8f-59pp-rxxhCVE-2019-1302 | nugetmicrosoft.aspnetcore.spaservices moderate | stated at publication 2.2.1, now states 2.2.7 | Time to revision 101 days |
| Tue 23 Aug 2022· 1 change | ||||
| 2022-08-23published 2022-08-10 | GHSA-9jmq-rx5f-8jwqCVE-2021-32862 | pypinbconvert moderate | stated at publication 6.3, now states 6.5.1 | Time to revision 13 days |
| Wed 3 Aug 2022· 1 change | ||||
| 2022-08-03published 2020-08-31 | GHSA-4mv4-gmmf-q382CVE-2015-6584 | npmdatatables high | stated at publication 1.10.8, now states 1.10.10 | Time to revision 702 days |
| Wed 29 Jun 2022· 1 change | ||||
| 2022-06-29published 2021-05-21 | GHSA-xg2h-wx96-xgxrCVE-2021-4238 | gogithub.com/masterminds/goutils low | stated at publication 1.0.2, now states 1.1.1 | Time to revision 404 days |
| Fri 27 May 2022· 2 changes | ||||
| 2022-05-27published 2022-04-20 | GHSA-x2w5-725j-gf2gCVE-2022-22143 | npmconvict high | stated at publication 6.2.2, now states 6.2.3 | Time to revision 37 days |
| 2022-05-27published 2022-04-05 | GHSA-jj47-x69x-mxrmCVE-2022-24795 | rubygemsyajl-ruby moderate | stated at publication 1.4.2, now states 1.4.3 | Time to revision 52 days |
| Wed 25 May 2022· 1 change | ||||
| 2022-05-25published 2022-02-10 | GHSA-h236-g5gh-vq6cCVE-2019-19935 | npmfroala-editor moderate | stated at publication 3.0.6, now states 3.2.3 | Time to revision 104 days |
| Wed 27 Apr 2022· 1 change | ||||
| 2022-04-27published 2021-04-13 | GHSA-w8h4-vw8f-rvvjCVE-2021-26276 | npmconfig-shield moderate | stated at publication 0.2.2, now states 0.2.3 | Time to revision 379 days |
| Fri 8 Apr 2022· 1 change | ||||
| 2022-04-08published 2022-02-25 | GHSA-q62h-jw38-24vhCVE-2022-24615 | mavennet.lingala.zip4j:zip4j moderate | stated at publication 2.9.0, now states 2.10.0 | Time to revision 1 days |
| Mon 4 Apr 2022· 3 changes | ||||
| 2022-04-04published 2021-08-13 | GHSA-4vww-mc66-62m6CVE-2021-33037 | mavenorg.apache.tomcat:tomcat moderate | stated at publication 10.0.6, now states 10.0.7 | Time to revision 234 days |
| 2022-04-04published 2021-08-13 | GHSA-4vww-mc66-62m6CVE-2021-33037 | mavenorg.apache.tomcat:tomcat moderate | stated at publication 8.5.66, now states 8.5.68 | Time to revision 234 days |
| 2022-04-04published 2021-08-13 | GHSA-4vww-mc66-62m6CVE-2021-33037 | mavenorg.apache.tomcat:tomcat moderate | stated at publication 9.0.46, now states 9.0.48 | Time to revision 234 days |
| Tue 29 Mar 2022· 2 changes | ||||
| 2022-03-29published 2022-03-15 | packagisttribalsystems/zenario 2 bands | stated at publication 9.0.55141, now states 9.0.55143 | Time to revision 15 days | |
| 2022-03-29published 2022-03-15 | GHSA-rgg3-3wh7-w935CVE-2021-42171 | same package and registry as the line abovecritical | same change as the line above | Time to revision 15 days |
| 2022-03-29published 2022-03-15 | GHSA-x8wj-cqmp-3wmmCVE-2021-41952 | same package and registry as the line abovemoderate | same change as the line above | Time to revision 15 days |
| Sat 26 Mar 2022· 1 change | ||||
| 2022-03-26published 2022-02-18 | GHSA-4cpg-3vgw-4877CVE-2022-22912 | npmplist critical | stated at publication 3.0.4, now states 3.0.5 | Time to revision 34 days |
| Tue 22 Mar 2022· 2 changes | ||||
| 2022-03-22published 2022-03-12 to 2022-03-13 | packagistmicroweber/microweber moderate | stated at publication 1.2.11, now states 1.2.12 | Time to revision 10 to 11 days | |
| 2022-03-22published 2022-03-12 | GHSA-6vx5-cg2p-7g5vCVE-2022-0912 | same package and registry as the line abovemoderate | same change as the line above | Time to revision 11 days |
| 2022-03-22published 2022-03-13 | GHSA-5fxf-x22x-5q38CVE-2022-0929 | same package and registry as the line abovemoderate | same change as the line above | Time to revision 10 days |
| Thu 17 Mar 2022· 1 change | ||||
| 2022-03-17published 2022-03-11 | GHSA-vx8q-j7h9-vf6qCVE-2022-0813 | packagistphpmyadmin/phpmyadmin high | stated at publication 5.1.2, now states 5.1.3 | Time to revision 7 days |
| Fri 11 Mar 2022· 1 change | ||||
| 2022-03-11published 2022-01-12 | GHSA-8vj2-vxx3-667wCVE-2022-22817 | pypipillow critical | stated at publication 9.0.0, now states 9.0.1 | Time to revision 58 days |
| Wed 16 Feb 2022· 1 change | ||||
| 2022-02-16published 2022-02-09 | GHSA-hcw3-j74m-qc58CVE-2022-23628 | gogithub.com/open-policy-agent/opa moderate | stated at publication 0.37.0, now states 0.37.2 | Time to revision 7 days |
Counted in advisories, never added to the CVE and KEV figures. This kind is counted once per advisory and per package, so one advisory that named four further packages counts four times. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.
What this page cannot see
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →
Paste your closed CVE tickets and see which of these changes hit them →