Skip to content

Package added to advisory

What a record said when it was published, what it says now, and the commit that changed it.

1,695 advisory changes · newest first · grouped by day

SinceClear all
ChangedSourceRows
Counted changes of "Package added to advisory", newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.Advisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Mon 13 Oct 2025· 6 changes
2025-10-13published 2025-10-13GHSA-3cm9-jrf5-h2cxCVE-2025-62242moderatenot named as affected when the advisory was published, now names com.liferay:com.liferay.change.tracking.webTime to revision 0 days
2025-10-13published 2023-06-14GHSA-4g42-gqrg-4633CVE-2023-34396highnot named as affected when the advisory was published, now names org.apache.struts:struts-coreTime to revision 852 days
2025-10-13published 2022-05-13 to 2023-06-14highnot named as affected when the advisory was published, now names struts:strutsTime to revision 852 days
2025-10-13published 2023-06-14GHSA-4g42-gqrg-4633CVE-2023-34396same package registry as the line abovehighsame change as the line aboveTime to revision 852 days
2025-10-13published 2022-05-13GHSA-7jw3-5q4w-89qgCVE-2016-1181same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-10-13published 2022-05-13GHSA-5ggr-mpgw-3mgxCVE-2016-1182same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-10-13published 2022-05-14GHSA-cvvx-r33m-v7pqCVE-2015-0899same package registry as the line abovehighsame change as the line aboveDuration unknown
Fri 10 Oct 2025· 1 change
2025-10-10published 2023-08-08GHSA-rg2c-cfxv-qp6fCVE-2023-3894highnot named as affected when the advisory was published, now names com.fasterxml.jackson.dataformat:jackson-dataformat-tomlTime to revision 794 days
Mon 6 Oct 2025· 6 changes
2025-10-06published 2025-07-11 to 2025-08-082 bandsnot named as affected when the advisory was published, now names org.pytorch:executorch-androidTime to revision 60 to 87 days
2025-10-06published 2025-07-11GHSA-h952-963h-rv99CVE-2025-30402same package registry as the line abovehighsame change as the line aboveTime to revision 87 days
2025-10-06published 2025-08-08GHSA-84m3-f99p-cqx5CVE-2025-30405same package registry as the line abovecriticalsame change as the line aboveTime to revision 60 days
2025-10-06published 2025-08-08GHSA-hj95-mhgf-jxc4CVE-2025-30404same package registry as the line abovecriticalsame change as the line aboveTime to revision 60 days
2025-10-06published 2025-08-08GHSA-xc7w-r669-48pfCVE-2025-54951same package registry as the line abovecriticalsame change as the line aboveTime to revision 60 days
2025-10-06published 2025-08-08GHSA-9m39-3mf3-xwchCVE-2025-54949same package registry as the line abovecriticalsame change as the line aboveTime to revision 60 days
2025-10-06published 2025-08-08GHSA-f9hx-c6jf-3qxmCVE-2025-54950same package registry as the line abovecriticalsame change as the line aboveTime to revision 60 days
Fri 3 Oct 2025· 1 change
2025-10-03published 2025-09-30GHSA-27w5-gj5q-82fvCVE-2025-11149highnot named as affected when the advisory was published, now names @nubosoftware/node-staticTime to revision 3 days
Tue 30 Sep 2025· 37 changes
2025-09-30published 2022-05-17 to 2023-11-2236 rows, one per advisory and package3 bandsnot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.7.7 and 35 moreTime to revision 679 to 1,233 days
2025-09-30published 2022-05-17GHSA-jf9v-fxfq-wm76CVE-2013-3300same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.7.7Time to revision 1,233 days
2025-09-30published 2022-05-17GHSA-jf9v-fxfq-wm76CVE-2013-3300same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.8.0Time to revision 1,233 days
2025-09-30published 2022-05-17GHSA-jf9v-fxfq-wm76CVE-2013-3300same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.8.1Time to revision 1,233 days
2025-09-30published 2022-05-17GHSA-jf9v-fxfq-wm76CVE-2013-3300same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.8.2Time to revision 1,233 days
2025-09-30published 2022-05-17GHSA-jf9v-fxfq-wm76CVE-2013-3300same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.9.0Time to revision 1,233 days
2025-09-30published 2022-05-17GHSA-jf9v-fxfq-wm76CVE-2013-3300same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.9.0-1Time to revision 1,233 days
2025-09-30published 2022-05-17GHSA-jf9v-fxfq-wm76CVE-2013-3300same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.9.1Time to revision 1,233 days
2025-09-30published 2022-06-28GHSA-ww3v-6xjf-jv28CVE-2018-18855same package registry as the line abovemoderatenot named as affected when the advisory was published, now names io.spray:spray-json_2.10Duration unknown
28 more rows in this change are not listed here. Open all 36 rows
2025-09-30published 2020-09-03GHSA-g64q-3vg8-8f93highnot named as affected when the advisory was published, now names pezDuration unknown
Mon 29 Sep 2025· 2 changes
2025-09-29published 2020-09-03GHSA-5854-jvxx-2cg9highnot named as affected when the advisory was published, now names contentDuration unknown
2025-09-29published 2025-08-13GHSA-prj3-ccx8-p6x4CVE-2025-55163highnot named as affected when the advisory was published, now names io.grpc:grpc-netty-shadedTime to revision 47 days
Fri 26 Sep 2025· 12 changes
2025-09-26published 2020-09-03GHSA-g9cg-h3jm-cwrchighnot named as affected when the advisory was published, now names @hapi/pezDuration unknown
2025-09-26published 2025-09-173 bandsnot named as affected when the advisory was published, now names d7y.io/dragonfly/v2Time to revision 9 to 9 days
2025-09-26published 2025-09-17GHSA-mcvp-rpgg-9273CVE-2025-59410same package registry as the line abovemoderatesame change as the line aboveTime to revision 9 days
2025-09-26published 2025-09-17GHSA-hx2h-vjw2-8r54CVE-2025-59354same package registry as the line abovemoderatesame change as the line aboveTime to revision 9 days
2025-09-26published 2025-09-17GHSA-255v-qv84-29p5CVE-2025-59353same package registry as the line abovehighsame change as the line aboveTime to revision 9 days
2025-09-26published 2025-09-17GHSA-79hx-3fp8-hj66CVE-2025-59352same package registry as the line abovemoderatesame change as the line aboveTime to revision 9 days
2025-09-26published 2025-09-17GHSA-4mhv-8rh3-4ghwCVE-2025-59351same package registry as the line abovemoderatesame change as the line aboveTime to revision 9 days
2025-09-26published 2025-09-17GHSA-c2fc-9q9c-5486CVE-2025-59350same package registry as the line abovemoderatesame change as the line aboveTime to revision 9 days
2025-09-26published 2025-09-17GHSA-8425-8r2f-mrv6CVE-2025-59349same package registry as the line abovelowsame change as the line aboveTime to revision 9 days
2025-09-26published 2025-09-17GHSA-2qgr-gfvj-qpcrCVE-2025-59348same package registry as the line abovemoderatesame change as the line aboveTime to revision 9 days
3 more rows in this change are not listed here. Open all 11 rows
Thu 25 Sep 2025· 1 change
2025-09-25published 2020-09-03GHSA-3wqh-h42r-x8fqhighnot named as affected when the advisory was published, now names @hapi/contentDuration unknown
Wed 24 Sep 2025· 3 changes
2025-09-24published 2022-09-23 to 2022-10-252 bandsnot named as affected when the advisory was published, now names org.apache.xmlgraphics:batik-bridgeDuration unknown
2025-09-24published 2022-10-25GHSA-rwqr-m72q-v6cmCVE-2022-42890same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-09-24published 2022-09-23GHSA-53jm-3hc9-fqqcCVE-2022-38648same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-09-24published 2022-09-23GHSA-c5xv-qc8p-mh2vCVE-2022-38398same package registry as the line abovemoderatesame change as the line aboveDuration unknown
Tue 23 Sep 2025· 1 change
2025-09-23published 2023-03-28GHSA-7phw-cxx7-q9vqCVE-2023-20860criticalnot named as affected when the advisory was published, now names org.springframework:spring-webmvcTime to revision 911 days
Tue 16 Sep 2025· 1 change
2025-09-16published 2021-07-27GHSA-2363-cqg2-863cCVE-2021-33813highnot named as affected when the advisory was published, now names org.jdom:jdom2Duration unknown
Fri 12 Sep 2025· 15 changes
2025-09-12published 2020-01-08 to 2025-06-03moderatenot named as affected when the advisory was published, now names org.hibernate:hibernate-validatorTime to revision 101 to 309 days
2025-09-12published 2025-06-03GHSA-7v6m-28jr-rg84CVE-2025-35036same package registry as the line abovemoderatesame change as the line aboveTime to revision 101 days
2025-09-12published 2021-06-04GHSA-rmrm-75hp-phr2CVE-2020-10693same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-09-12published 2020-01-08GHSA-m8p2-495h-ccmhCVE-2019-10219same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-09-12published 2024-11-07GHSA-x83m-pf6f-pf9gCVE-2023-1932same package registry as the line abovemoderatesame change as the line aboveTime to revision 309 days
2025-09-12published 2018-10-16 to 2018-10-183 bandsnot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onDuration unknown
2025-09-12published 2018-10-17GHSA-4mv7-cq75-3qjmCVE-2015-7940same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-09-12published 2018-10-17GHSA-r97x-3g8f-gx3mCVE-2016-1000340same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-09-12published 2018-10-17GHSA-4vhj-98r6-424hCVE-2016-1000338same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-09-12published 2018-10-16GHSA-xqj7-j8j5-f2xrCVE-2018-1000180same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-09-12published 2018-10-17GHSA-w285-wf9q-5w69CVE-2016-1000352same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-09-12published 2018-10-18GHSA-9gp4-qrff-c648CVE-2016-1000345same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-09-12published 2018-10-17GHSA-fjqm-246c-mwqgCVE-2016-1000346same package registry as the line abovelowsame change as the line aboveDuration unknown
2025-09-12published 2018-10-18GHSA-2j2x-hx4g-2gf4CVE-2016-1000344same package registry as the line abovehighsame change as the line aboveDuration unknown
3 more rows in this change are not listed here. Open all 11 rows
Mon 8 Sep 2025· 1 change
2025-09-08published 2025-07-09GHSA-q92v-3f4w-5xg8CVE-2025-53742moderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins:applitools-eyesTime to revision 61 days
Tue 2 Sep 2025· 7 changes
2025-09-02published 2022-05-14GHSA-xjgh-84hx-56c5highnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core and 1 moreDuration unknown
2025-09-02published 2022-05-14GHSA-xjgh-84hx-56c5CVE-2017-12617same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDuration unknown
2025-09-02published 2022-05-14GHSA-xjgh-84hx-56c5CVE-2017-12617same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaDuration unknown
2025-09-02published 2022-05-14GHSA-w3j5-q8f2-3cqqCVE-2016-8745highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-utilDuration unknown
2025-09-02published 2023-03-10GHSA-vp98-w2p3-mv35CVE-2023-26464highnot named as affected when the advisory was published, now names log4j:log4jTime to revision 907 days
2025-09-02published 2022-05-17GHSA-rpjm-422r-95mhCVE-2022-30126moderatenot named as affected when the advisory was published, now names org.apache.tika:tika-coreDuration unknown
2025-09-02published 2022-03-12GHSA-cr3q-pqgq-m8c2CVE-2018-25031moderatenot named as affected when the advisory was published, now names org.webjars:swagger-uiDuration unknown
2025-09-02published 2018-10-17GHSA-qcj7-g2j5-g7r3CVE-2016-1000342highnot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onDuration unknown
Fri 29 Aug 2025· 1 change
2025-08-29published 2025-08-20GHSA-mpww-r37c-vxjwCVE-2025-43746moderatenot named as affected when the advisory was published, now names ccom.liferay:com.liferay.dynamic.data.mapping.webTime to revision 9 days
Fri 22 Aug 2025· 1 change
2025-08-22published 2025-08-13GHSA-gqp3-2cvr-x8m3CVE-2025-48989highnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreTime to revision 9 days
Thu 14 Aug 2025· 2 changes
2025-08-14published 2022-05-24GHSA-j2h2-cvwh-cr64CVE-2020-14457moderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v5Time to revision 1,178 days
2025-08-14published 2025-08-12GHSA-m5c7-5gv3-hcpfCVE-2025-43734moderatenot named as affected when the advisory was published, now names com.liferay:com.liferay.frontend.taglib.clayTime to revision 2 days
Mon 11 Aug 2025· 7 changes
2025-08-11published 2018-07-26 to 2022-01-063 bandsnot named as affected when the advisory was published, now names lodash-railsDuration unknown
2025-08-11published 2019-07-19GHSA-x5rq-j2xg-h7qmCVE-2019-1010266same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-08-11published 2019-07-10GHSA-jf85-cpcp-j695CVE-2019-10744same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2025-08-11published 2019-02-07GHSA-4xc9-xhrj-v574CVE-2018-16487same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-08-11published 2018-07-26GHSA-fvqr-27wr-82fmCVE-2018-3721same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-08-11published 2020-07-15GHSA-p6mc-m468-83gwCVE-2020-8203same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-08-11published 2021-05-06GHSA-35jh-r3h4-6jhmCVE-2021-23337same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-08-11published 2022-01-06GHSA-29mw-wpgm-hmr9CVE-2020-28500same package registry as the line abovemoderatesame change as the line aboveDuration unknown
Fri 8 Aug 2025· 2 changes
2025-08-08published 2025-07-28GHSA-4mxg-3p6v-xgq3criticalnot named as affected when the advisory was published, now names @node-saml/passport-saml and 1 moreTime to revision 11 days
2025-08-08published 2025-07-28GHSA-4mxg-3p6v-xgq3CVE-2025-54419same package registry as the line abovecriticalnot named as affected when the advisory was published, now names @node-saml/passport-samlTime to revision 11 days
2025-08-08published 2025-07-28GHSA-4mxg-3p6v-xgq3CVE-2025-54419same package registry as the line abovecriticalnot named as affected when the advisory was published, now names passport-samlTime to revision 11 days
Mon 4 Aug 2025· 3 changes
2025-08-04published 2024-09-26 to 2024-10-31highnot named as affected when the advisory was published, now names github.com/openbao/openbaoTime to revision 277 to 312 days
2025-08-04published 2024-10-10GHSA-rr8j-7w34-xp5jCVE-2024-9180same package registry as the line abovehighsame change as the line aboveTime to revision 298 days
2025-08-04published 2024-10-31GHSA-g233-2p4r-3q7vCVE-2024-8185same package registry as the line abovehighsame change as the line aboveTime to revision 277 days
2025-08-04published 2024-09-26GHSA-jg74-mwgw-v6x3CVE-2024-7594same package registry as the line abovehighsame change as the line aboveTime to revision 312 days
Tue 29 Jul 2025· 1 change
2025-07-29published 2025-06-26GHSA-xh32-cx6c-cp4vCVE-2025-47943moderatenot named as affected when the advisory was published, now names gogs.io/gogsTime to revision 33 days
Mon 28 Jul 2025· 1 change
2025-07-28published 2025-05-30GHSA-6j2q-c73v-97c5CVE-2025-41235highnot named as affected when the advisory was published, now names org.springframework.cloud:spring-cloud-gateway-server-mvcTime to revision 60 days
Fri 25 Jul 2025· 3 changes
2025-07-25published 2024-08-01GHSA-vvpg-55p7-5h8wlownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server and 2 moreTime to revision 358 days
2025-07-25published 2024-08-01GHSA-vvpg-55p7-5h8wCVE-2024-39837same package registry as the line abovelownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-serverTime to revision 358 days
2025-07-25published 2024-08-01GHSA-vvpg-55p7-5h8wCVE-2024-39837same package registry as the line abovelownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v5Time to revision 358 days
2025-07-25published 2024-08-01GHSA-vvpg-55p7-5h8wCVE-2024-39837same package registry as the line abovelownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v6Time to revision 358 days
Tue 22 Jul 2025· 3 changes
2025-07-22published 2023-11-06GHSA-r67m-mf7v-qp7jCVE-2023-5968moderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v5Time to revision 624 days
2025-07-22published 2025-07-19GHSA-f29h-pxvx-f335CVE-2025-54313highnot named as affected when the advisory was published, now names got-fetchTime to revision 3 days
2025-07-22published 2025-07-21GHSA-96c2-h667-9fxpCVE-2025-54082criticalnot named as affected when the advisory was published, now names manogi/nova-tiptapTime to revision 1 days
Mon 21 Jul 2025· 1 change
2025-07-21published 2025-07-18GHSA-fm79-3f68-h2fcCVE-2025-53901lownot named as affected when the advisory was published, now names wasmtimeTime to revision 3 days
Fri 18 Jul 2025· 6 changes
2025-07-18published 2022-11-252 bandsnot named as affected when the advisory was published, now names org.jeecgframework.boot:jeecg-module-systemTime to revision 966 days
2025-07-18published 2022-11-25GHSA-g5cj-5h58-j93wCVE-2022-45206same package registry as the line abovecriticalsame change as the line aboveTime to revision 966 days
2025-07-18published 2022-11-25GHSA-v87q-rpwp-qr7qCVE-2022-45210same package registry as the line abovemoderatesame change as the line aboveTime to revision 966 days
2025-07-18published 2022-11-25GHSA-4j2x-v3mr-467mCVE-2022-45207same package registry as the line abovecriticalsame change as the line aboveTime to revision 966 days
2025-07-18published 2022-11-25GHSA-25gv-mvm7-5h3hCVE-2022-45208same package registry as the line abovemoderatesame change as the line aboveTime to revision 966 days
2025-07-18published 2022-02-01GHSA-2m53-83f3-562jCVE-2021-23460highnot named as affected when the advisory was published, now names org.webjars.npm:min-dashDuration unknown
2025-07-18published 2022-05-17GHSA-cm99-x97g-9qx8CVE-2017-12648moderatenot named as affected when the advisory was published, now names com.liferay:com.liferay.frontend.taglibTime to revision 1,159 days
Fri 11 Jul 2025· 1 change
2025-07-11published 2025-07-10GHSA-275g-g844-73jhCVE-2025-53549moderatenot named as affected when the advisory was published, now names matrix-sdk-sqliteTime to revision 1 days
Thu 10 Jul 2025· 1 change
2025-07-10published 2020-09-02GHSA-7p6w-x2gr-rrf8highnot named as affected when the advisory was published, now names ag-gridDuration unknown
Wed 9 Jul 2025· 2 changes
2025-07-09published 2025-06-16GHSA-vv7r-c36w-3prjCVE-2025-48976highnot named as affected when the advisory was published, now names commons-fileupload:commons-fileuploadTime to revision 23 days
2025-07-09published 2025-03-03GHSA-vm7w-2724-5m23CVE-2024-24778moderatenot named as affected when the advisory was published, now names streampipesTime to revision 128 days
Wed 2 Jul 2025· 6 changes
2025-07-02published 2024-12-18GHSA-p7c9-8xx8-h74flownot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.10 and 3 moreTime to revision 196 to 196 days
2025-07-02published 2024-12-18GHSA-p7c9-8xx8-h74fCVE-2024-56128same package registry as the line abovelownot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.10Time to revision 196 days
2025-07-02published 2024-12-18GHSA-p7c9-8xx8-h74fCVE-2024-56128same package registry as the line abovelownot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.11Time to revision 196 days
2025-07-02published 2024-12-18GHSA-p7c9-8xx8-h74fCVE-2024-56128same package registry as the line abovelownot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.12Time to revision 196 days
2025-07-02published 2024-12-18GHSA-p7c9-8xx8-h74fCVE-2024-56128same package registry as the line abovelownot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.13Time to revision 196 days
2025-07-02published 2025-05-142 bandsnot named as affected when the advisory was published, now names apache-iotdbTime to revision 49 days
2025-07-02published 2025-05-14GHSA-5fc3-pqf2-57cxCVE-2025-26864same package registry as the line abovemoderatesame change as the line aboveTime to revision 49 days
2025-07-02published 2025-05-14GHSA-f4rq-f4j9-f6rmCVE-2024-24780same package registry as the line abovecriticalsame change as the line aboveTime to revision 49 days
Tue 1 Jul 2025· 2 changes
2025-07-01published 2021-10-06GHSA-v6w3-2prq-h95fmoderatenot named as affected when the advisory was published, now names org.glassfish:jakarta.el and 1 moreDuration unknown
2025-07-01published 2021-10-06GHSA-v6w3-2prq-h95fCVE-2021-28170same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.glassfish:jakarta.elDuration unknown
2025-07-01published 2021-10-06GHSA-v6w3-2prq-h95fCVE-2021-28170same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.glassfish:javax.elDuration unknown
Mon 30 Jun 2025· 1 change
2025-06-30published 2025-06-17GHSA-rvqx-wpfh-mfx7CVE-2025-3248criticalnot named as affected when the advisory was published, now names langflow-baseTime to revision 13 days
Tue 24 Jun 2025· 2 changes
2025-06-24published 2024-05-03GHSA-4h8f-2wvx-gg5wmoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-lts8on and 1 moreTime to revision 417 days
2025-06-24published 2024-05-03GHSA-4h8f-2wvx-gg5wCVE-2024-34447same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-lts8onTime to revision 417 days
2025-06-24published 2024-05-03GHSA-4h8f-2wvx-gg5wCVE-2024-34447same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bctls-fipsTime to revision 417 days
Fri 20 Jun 2025· 1 change
2025-06-20published 2024-09-13GHSA-v6x6-4v4x-2fx9CVE-2024-6862moderatenot named as affected when the advisory was published, now names @lunary/backendTime to revision 280 days
Mon 9 Jun 2025· 2 changes
2025-06-09published 2025-03-26GHSA-56p6-qw3c-fq2glownot named as affected when the advisory was published, now names @directus/api and 1 moreTime to revision 75 days
2025-06-09published 2025-03-26GHSA-56p6-qw3c-fq2gCVE-2025-30351same package registry as the line abovelownot named as affected when the advisory was published, now names @directus/apiTime to revision 75 days
2025-06-09published 2025-03-26GHSA-56p6-qw3c-fq2gCVE-2025-30351same package registry as the line abovelownot named as affected when the advisory was published, now names @directus/typesTime to revision 75 days
Mon 2 Jun 2025· 1 change
2025-06-02published 2022-05-17GHSA-2pcj-76hj-xqhmCVE-2016-10131criticalnot named as affected when the advisory was published, now names bcit-ci/codeigniterTime to revision 1,113 days
Fri 30 May 2025· 1 change
2025-05-30published 2024-02-27GHSA-xh6m-7cr7-xx66CVE-2023-45859highnot named as affected when the advisory was published, now names com.hazelcast:hazelcast-allTime to revision 458 days
Thu 29 May 2025· 1 change
2025-05-29published 2018-10-19GHSA-jc7r-v6fg-2gpfCVE-2018-8039highnot named as affected when the advisory was published, now names org.apache.cxf:cxf-rt-transports-httpDuration unknown
Tue 27 May 2025· 4 changes
2025-05-27published 2024-10-18GHSA-4gc7-5j7h-4qphCVE-2024-38820moderatenot named as affected when the advisory was published, now names org.springframework:spring-webTime to revision 222 days
2025-05-27published 2025-04-01GHSA-6jwp-4wvj-6597criticalnot named as affected when the advisory was published, now names org.apache.pinot:pinot-broker and 2 moreTime to revision 56 days
2025-05-27published 2025-04-01GHSA-6jwp-4wvj-6597CVE-2024-56325same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.pinot:pinot-brokerTime to revision 56 days
2025-05-27published 2025-04-01GHSA-6jwp-4wvj-6597CVE-2024-56325same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.pinot:pinot-commonTime to revision 56 days
2025-05-27published 2025-04-01GHSA-6jwp-4wvj-6597CVE-2024-56325same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.pinot:pinot-controllerTime to revision 56 days
Wed 14 May 2025· 2 changes
2025-05-14published 2025-04-282 bandsnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreTime to revision 16 days
2025-05-14published 2025-04-28GHSA-ff77-26x5-69crCVE-2025-31651same package registry as the line abovelowsame change as the line aboveTime to revision 16 days
2025-05-14published 2025-04-28GHSA-3p2h-wqq4-wf4hCVE-2025-31650same package registry as the line abovemoderatesame change as the line aboveTime to revision 16 days
Wed 7 May 2025· 4 changes
2025-05-07published 2021-12-10 to 2022-01-043 bandsnot named as affected when the advisory was published, now names org.ops4j.pax.logging:pax-logging-log4j2Duration unknown
2025-05-07published 2022-01-04GHSA-8489-44mv-ggj8CVE-2021-44832same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-05-07published 2021-12-18GHSA-p6xc-xr62-6r2gCVE-2021-45105same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-05-07published 2021-12-14GHSA-7rjr-3q55-vv33CVE-2021-45046same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2025-05-07published 2021-12-10GHSA-jfh8-c2jp-5v3qCVE-2021-44228same package registry as the line abovecriticalsame change as the line aboveDuration unknown
Mon 14 Apr 2025· 5 changes
2025-04-14published 2022-05-14moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaDuration unknown
2025-04-14published 2022-05-14GHSA-prc3-7f44-w48jCVE-2014-0119same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-04-14published 2022-05-14GHSA-qprx-q2r7-3rx6CVE-2014-0096same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-04-14published 2022-05-14GHSA-prc3-7f44-w48jCVE-2014-0119moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-jasperDuration unknown
2025-04-14published 2022-05-14GHSA-xh5x-j8jf-pcpxCVE-2014-0099moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-utilDuration unknown
2025-04-14published 2022-05-14GHSA-475f-74wp-pqv5CVE-2014-0075moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDuration unknown
Thu 3 Apr 2025· 1 change
2025-04-03published 2025-03-20GHSA-x48g-hm9c-ww42CVE-2024-12909criticalnot named as affected when the advisory was published, now names llama-index-packs-finchatTime to revision 14 days
Thu 20 Mar 2025· 2 changes
2025-03-20published 2025-03-20GHSA-h7xg-cmpp-48hfCVE-2024-10553criticalnot named as affected when the advisory was published, now names ai.h2o:h2o-coreTime to revision 0 days
2025-03-20published 2025-03-20GHSA-2r4x-667f-mpfhCVE-2024-47552lownot named as affected when the advisory was published, now names org.apache.seata:seata-config-coreTime to revision 0 days
Mon 17 Mar 2025· 3 changes
2025-03-17published 2022-02-10GHSA-3c7p-vv5r-cmr5criticalnot named as affected when the advisory was published, now names org.apache.solr:solr-core and 1 moreDuration unknown
2025-03-17published 2022-02-10GHSA-3c7p-vv5r-cmr5CVE-2020-13957same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.solr:solr-coreDuration unknown
2025-03-17published 2022-02-10GHSA-3c7p-vv5r-cmr5CVE-2020-13957same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.solr:solr-solrjDuration unknown
2025-03-17published 2025-03-10GHSA-83qj-6fr2-vhqgCVE-2025-24813criticalnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreTime to revision 7 days
Fri 14 Mar 2025· 2 changes
2025-03-14published 2025-03-11GHSA-44f7-5fj5-h4pxCVE-2025-27403highnot named as affected when the advisory was published, now names github.com/deislabs/ratifyTime to revision 3 days
2025-03-14published 2023-09-15GHSA-hvpq-7vcc-5hj5CVE-2023-41592moderatenot named as affected when the advisory was published, now names froala-editorTime to revision 547 days
Tue 11 Mar 2025· 3 changes
2025-03-11published 2025-02-12GHSA-6fgm-x6ff-w78fmoderatenot named as affected when the advisory was published, now names github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v4 and 2 moreTime to revision 27 days
2025-03-11published 2025-02-12GHSA-6fgm-x6ff-w78fsame package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v4Time to revision 27 days
2025-03-11published 2025-02-12GHSA-6fgm-x6ff-w78fsame package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v5Time to revision 27 days
2025-03-11published 2025-02-12GHSA-6fgm-x6ff-w78fsame package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v6Time to revision 27 days
Thu 6 Mar 2025· 21 changes
2025-03-06published 2019-11-20 to 2025-02-032 bandsnot named as affected when the advisory was published, now names phpoffice/phpexcelTime to revision 31 to 189 days
2025-03-06published 2025-02-03GHSA-r57h-547h-w24fCVE-2025-23210same package registry as the line abovemoderatesame change as the line aboveTime to revision 31 days
2025-03-06published 2025-01-03GHSA-jmpx-686v-c3wxCVE-2024-56365same package registry as the line abovehighsame change as the line aboveTime to revision 62 days
2025-03-06published 2024-11-18GHSA-7cc9-j4mv-vcjpCVE-2024-48917same package registry as the line abovehighsame change as the line aboveTime to revision 108 days
2025-03-06published 2025-01-03GHSA-q9jv-mm3r-j47rCVE-2024-56412same package registry as the line abovemoderatesame change as the line aboveTime to revision 62 days
2025-03-06published 2025-01-03GHSA-hwcp-2h35-p66wCVE-2024-56411same package registry as the line abovemoderatesame change as the line aboveTime to revision 62 days
2025-03-06published 2025-01-03GHSA-wv23-996v-q229CVE-2024-56410same package registry as the line abovemoderatesame change as the line aboveTime to revision 62 days
2025-03-06published 2025-01-03GHSA-j2xg-cjcx-4677CVE-2024-56409same package registry as the line abovehighsame change as the line aboveTime to revision 62 days
2025-03-06published 2025-01-03GHSA-c6fv-7vh8-2rhrCVE-2024-56366same package registry as the line abovehighsame change as the line aboveTime to revision 62 days
13 more rows in this change are not listed here. Open all 21 rows
Wed 5 Mar 2025· 2 changes
2025-03-05published 2021-11-08GHSA-282f-qqgm-c34qCVE-2021-23807moderatenot named as affected when the advisory was published, now names org.webjars.npm:json-pointerDuration unknown
2025-03-05published 2021-05-10GHSA-7mg4-w3w5-x5pcCVE-2020-7709moderatenot named as affected when the advisory was published, now names org.webjars.npm:json-pointerDuration unknown
Wed 26 Feb 2025· 1 change
2025-02-26published 2025-02-24GHSA-c6gw-w398-hv78CVE-2025-27144moderatenot named as affected when the advisory was published, now names github.com/go-jose/go-jose/v3Time to revision 2 days
Wed 19 Feb 2025· 1 change
2025-02-19published 2025-01-21GHSA-69cg-w8vm-h229CVE-2024-10761moderatenot named as affected when the advisory was published, now names umbraco.cms.web.commonTime to revision 29 days
Tue 18 Feb 2025· 1 change
2025-02-18published 2024-08-21GHSA-7r32-vfj5-c2jvCVE-2024-43407moderatenot named as affected when the advisory was published, now names ckeditor/ckeditorTime to revision 181 days
Thu 13 Feb 2025· 2 changes
2025-02-13published 2023-10-10GHSA-jm7m-8jh6-29hpCVE-2023-42794moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 492 days
2025-02-13published 2025-01-28GHSA-58fx-7v9q-3g56CVE-2024-13484highnot named as affected when the advisory was published, now names github.com/redhat-developer/gitops-operatorTime to revision 16 days
Tue 11 Feb 2025· 1 change
2025-02-11published 2025-01-23GHSA-pmf4-v838-29hgCVE-2025-24353moderatenot named as affected when the advisory was published, now names @directus/appTime to revision 19 days
Mon 10 Feb 2025· 38 changes
2025-02-10published 2019-11-20 to 2022-05-244 bandsnot named as affected when the advisory was published, now names magento/project-community-editionTime to revision 993 days
2025-02-10published 2022-05-24GHSA-cc3w-r3w8-hfh7CVE-2021-28567same package registry as the line abovemoderatesame change as the line aboveTime to revision 993 days
2025-02-10published 2022-05-24GHSA-39ch-rg26-gmq5CVE-2021-28556same package registry as the line abovemoderatesame change as the line aboveTime to revision 993 days
2025-02-10published 2022-05-24GHSA-7gh6-f4jh-3crqCVE-2021-28583same package registry as the line abovehighsame change as the line aboveTime to revision 993 days
2025-02-10published 2022-05-24GHSA-7gpv-xrjr-f5h4CVE-2021-28584same package registry as the line abovemoderatesame change as the line aboveTime to revision 993 days
2025-02-10published 2022-05-24GHSA-c38m-9668-6j2wCVE-2021-28585same package registry as the line abovemoderatesame change as the line aboveTime to revision 993 days
2025-02-10published 2022-05-24GHSA-4h3p-63x6-vwg2CVE-2021-21031same package registry as the line abovemoderatesame change as the line aboveTime to revision 993 days
2025-02-10published 2022-05-24GHSA-4jfq-f8hc-775qCVE-2021-21032same package registry as the line abovemoderatesame change as the line aboveTime to revision 993 days
2025-02-10published 2022-05-24GHSA-6988-g89m-27vfCVE-2021-21030same package registry as the line abovehighsame change as the line aboveTime to revision 993 days
30 more rows in this change are not listed here. Open all 38 rows
Fri 31 Jan 2025· 5 changes
2025-01-31published 2020-04-29moderatenot named as affected when the advisory was published, now names components/jqueryDuration unknown
2025-01-31published 2020-04-29GHSA-jpcq-cgw6-v4j6CVE-2020-11023same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-01-31published 2020-04-29GHSA-gxr4-xjj5-5px2CVE-2020-11022same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-01-31published 2018-10-17criticalnot named as affected when the advisory was published, now names org.springframework:spring-messagingDuration unknown
2025-01-31published 2018-10-17GHSA-3rmv-2pg5-xvqjCVE-2018-1275same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2025-01-31published 2018-10-17GHSA-p5hg-3xm3-gcjgCVE-2018-1270same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2025-01-31published 2024-07-11GHSA-9mvj-f7w8-pvh2CVE-2024-6484moderatenot named as affected when the advisory was published, now names bootstrap-sassTime to revision 204 days
Thu 30 Jan 2025· 1 change
2025-01-30published 2020-04-29GHSA-gxr4-xjj5-5px2CVE-2020-11022moderatenot named as affected when the advisory was published, now names athlon1600/youtube-downloaderDuration unknown
Tue 21 Jan 2025· 3 changes
2025-01-21published 2024-07-172 bandsnot named as affected when the advisory was published, now names streampipesTime to revision 188 to 188 days
2025-01-21published 2024-07-17GHSA-6523-jf4r-c962CVE-2024-31411same package registry as the line abovehighsame change as the line aboveTime to revision 188 days
2025-01-21published 2024-07-17GHSA-2qph-v9p2-q2gvCVE-2024-30471same package registry as the line abovemoderatesame change as the line aboveTime to revision 188 days
2025-01-21published 2024-07-17GHSA-9gr7-gh74-qg9xCVE-2024-31979same package registry as the line abovemoderatesame change as the line aboveTime to revision 188 days
Mon 20 Jan 2025· 1 change
2025-01-20published 2021-11-10GHSA-r28h-x6hv-2fq3CVE-2021-43570criticalnot named as affected when the advisory was published, now names com.starkbank.ellipticcurve:starkbank-ecdsaDuration unknown
Fri 17 Jan 2025· 5 changes
2025-01-17published 2024-05-20GHSA-qxqf-2mfx-x8jwhighnot named as affected when the advisory was published, now names org.verapdf:verapdf-library and 2 moreTime to revision 242 days
2025-01-17published 2024-05-20GHSA-qxqf-2mfx-x8jwCVE-2024-28109same package registry as the line abovehighnot named as affected when the advisory was published, now names org.verapdf:verapdf-libraryTime to revision 242 days
2025-01-17published 2024-05-20GHSA-qxqf-2mfx-x8jwCVE-2024-28109same package registry as the line abovehighnot named as affected when the advisory was published, now names org.verapdf:verapdf-library-arlingtonTime to revision 242 days
2025-01-17published 2024-05-20GHSA-qxqf-2mfx-x8jwCVE-2024-28109same package registry as the line abovehighnot named as affected when the advisory was published, now names org.verapdf:verapdf-library-jakartaTime to revision 242 days
2025-01-17published 2022-02-10GHSA-6566-9526-52v6CVE-2020-10591highnot named as affected when the advisory was published, now names com.walmartlabs.concord:concord-commonDuration unknown
2025-01-17published 2022-05-24GHSA-jffq-528j-mp6cCVE-2020-10991criticalnot named as affected when the advisory was published, now names org.mule.modules:mule-apikit-moduleDuration unknown
Thu 16 Jan 2025· 2 changes
2025-01-16published 2023-01-24moderatenot named as affected when the advisory was published, now names org.opensearch.plugin:opensearch-securityTime to revision 723 days
2025-01-16published 2023-01-24GHSA-v3cg-7r9h-r2g6CVE-2023-23613same package registry as the line abovemoderatesame change as the line aboveTime to revision 723 days
2025-01-16published 2023-01-24GHSA-864v-6qj7-62qjCVE-2023-23612same package registry as the line abovemoderatesame change as the line aboveTime to revision 723 days
Wed 15 Jan 2025· 5 changes
2025-01-15published 2023-02-18GHSA-jrmh-v64j-mjm9moderatenot named as affected when the advisory was published, now names org.jboss.resteasy:resteasy-core and 1 moreTime to revision 698 days
2025-01-15published 2023-02-18GHSA-jrmh-v64j-mjm9same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.jboss.resteasy:resteasy-coreTime to revision 698 days
2025-01-15published 2023-02-18GHSA-jrmh-v64j-mjm9same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.jboss.resteasy:resteasy-multipart-providerTime to revision 698 days
2025-01-15published 2024-07-09GHSA-vfwh-gvf6-mff8CVE-2024-39031moderatenot named as affected when the advisory was published, now names org.silverpeas.core:silverpeas-core-webTime to revision 190 days
2025-01-15published 2024-05-22GHSA-9rrw-82r2-623pCVE-2024-29392moderatenot named as affected when the advisory was published, now names org.silverpeas.core:silverpeas-coreTime to revision 238 days
2025-01-15published 2022-05-13GHSA-57q5-x8jf-g7h8CVE-2017-7561highnot named as affected when the advisory was published, now names org.jboss.resteasy:resteasy-jaxrsDuration unknown
Fri 10 Jan 2025· 1 change
2025-01-10published 2024-12-02GHSA-q3v6-hm2v-pw99CVE-2024-38827moderatenot named as affected when the advisory was published, now names org.springframework.security:spring-security-coreTime to revision 39 days
Wed 8 Jan 2025· 2 changes
2025-01-08published 2024-12-20GHSA-27hp-xhwr-wr2mhighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core and 1 moreTime to revision 19 days
2025-01-08published 2024-12-20GHSA-27hp-xhwr-wr2mCVE-2024-56337same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreTime to revision 19 days
2025-01-08published 2024-12-20GHSA-27hp-xhwr-wr2mCVE-2024-56337same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-embed-coreTime to revision 19 days
Thu 26 Dec 2024· 1 change
2024-12-26published 2024-12-17GHSA-5j33-cvvr-w245CVE-2024-50379highnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreTime to revision 9 days
Mon 23 Dec 2024· 1 change
2024-12-23published 2024-12-16GHSA-8wcc-m6j2-qxvmhighnot named as affected when the advisory was published, now names cosmossdk.io/x/txTime to revision 7 days

Counted in advisories, never added to the CVE and KEV figures. This kind is counted once per advisory and per package, so one advisory that named four further packages counts four times. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

What this page cannot see

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Paste your closed CVE tickets and see which of these changes hit them →