Skip to content

Package added to advisory

What a record said when it was published, what it says now, and the commit that changed it.

1,695 advisory changes · newest first · grouped by day

SinceClear all
ChangedSourceRows
Counted changes of "Package added to advisory", newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.Advisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Wed 18 Dec 2024· 3 changes
2024-12-18published 2024-03-15GHSA-qqc8-rv37-79q5lownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server and 2 moreTime to revision 278 days
2024-12-18published 2024-03-15GHSA-qqc8-rv37-79q5CVE-2024-28053same package registry as the line abovelownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-serverTime to revision 278 days
2024-12-18published 2024-03-15GHSA-qqc8-rv37-79q5CVE-2024-28053same package registry as the line abovelownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v5Time to revision 278 days
2024-12-18published 2024-03-15GHSA-qqc8-rv37-79q5CVE-2024-28053same package registry as the line abovelownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v6Time to revision 278 days
Mon 9 Dec 2024· 1 change
2024-12-09published 2024-12-09GHSA-849r-qrwj-8rv4CVE-2024-54151highnot named as affected when the advisory was published, now names @directus/apiTime to revision 0 days
Thu 5 Dec 2024· 2 changes
2024-12-05published 2022-05-14GHSA-92rv-mvmj-47qhCVE-2018-1000186lownot named as affected when the advisory was published, now names org.jenkins-ci.plugins:ghprbTime to revision 937 days
2024-12-05published 2023-10-18GHSA-m6vm-37g8-gqvhCVE-2023-22102highnot named as affected when the advisory was published, now names mysql:mysql-connector-javaTime to revision 415 days
Mon 2 Dec 2024· 1 change
2024-12-02published 2024-11-21GHSA-49cc-xrjf-9qf7CVE-2024-52309moderatenot named as affected when the advisory was published, now names sftpgoTime to revision 11 days
Mon 25 Nov 2024· 1 change
2024-11-25published 2024-11-20GHSA-gjcc-jvgw-wvwjCVE-2024-52581highnot named as affected when the advisory was published, now names starliteTime to revision 5 days
Fri 22 Nov 2024· 2 changes
2024-11-22published 2023-11-14GHSA-vc3v-ppc7-v486CVE-2023-47631highnot named as affected when the advisory was published, now names vantage6-nodeTime to revision 374 days
2024-11-22published 2018-11-09GHSA-8rhc-48pp-52grCVE-2017-12612highnot named as affected when the advisory was published, now names pysparkDuration unknown
Thu 21 Nov 2024· 1 change
2024-11-21published 2023-11-24GHSA-4vvc-r4p4-qgrrCVE-2023-48796highnot named as affected when the advisory was published, now names apache-dolphinschedulerTime to revision 364 days
Tue 19 Nov 2024· 4 changes
2024-11-19published 2021-08-25 to 2021-09-202 bandsnot named as affected when the advisory was published, now names wasmtimeDuration unknown
2024-11-19published 2021-08-25GHSA-hpqh-2wqx-7qp5CVE-2021-32629same package registry as the line abovehighsame change as the line aboveDuration unknown
2024-11-19published 2021-09-20GHSA-q879-9g95-56mxCVE-2021-39219same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-11-19published 2021-09-20GHSA-4873-36h9-wv49CVE-2021-39218same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-11-19published 2021-09-20GHSA-v4cp-h94r-m7xfCVE-2021-39216same package registry as the line abovemoderatesame change as the line aboveDuration unknown
Mon 18 Nov 2024· 2 changes
2024-11-18published 2024-11-13GHSA-xhg6-9j5j-w4vfCVE-2024-48510highnot named as affected when the advisory was published, now names prodotnetzipTime to revision 5 days
2024-11-18published 2022-05-14GHSA-m9jj-5qvj-5fhxCVE-2014-6633highnot named as affected when the advisory was published, now names trytondTime to revision 920 days
Wed 13 Nov 2024· 3 changes
2024-11-13published 2024-10-02GHSA-4xqv-47rm-37mmCVE-2024-47529moderatenot named as affected when the advisory was published, now names openc3Time to revision 42 days
2024-11-13published 2021-11-10GHSA-7v94-64hj-m82hmoderatenot named as affected when the advisory was published, now names tensorflow-cpu and 1 moreDuration unknown
2024-11-13published 2021-11-10GHSA-7v94-64hj-m82hCVE-2021-41207same package registry as the line abovemoderatenot named as affected when the advisory was published, now names tensorflow-cpuDuration unknown
2024-11-13published 2021-11-10GHSA-7v94-64hj-m82hCVE-2021-41207same package registry as the line abovemoderatenot named as affected when the advisory was published, now names tensorflow-gpuDuration unknown
Tue 12 Nov 2024· 1 change
2024-11-12published 2024-10-11GHSA-pppg-cpfq-h7wrCVE-2024-21534criticalnot named as affected when the advisory was published, now names org.webjars.npm:jsonpath-plusTime to revision 32 days
Tue 5 Nov 2024· 3 changes
2024-11-05published 2019-04-26 to 2020-04-29moderatenot named as affected when the advisory was published, now names maximebf/debugbarDuration unknown
2024-11-05published 2020-04-29GHSA-gxr4-xjj5-5px2CVE-2020-11022same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-11-05published 2019-04-26GHSA-6c3j-c64m-qhgqCVE-2019-11358same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-11-05published 2024-09-13GHSA-cx7f-g6mp-7hqmCVE-2024-38816highnot named as affected when the advisory was published, now names org.springframework:spring-webfluxTime to revision 53 days
Wed 30 Oct 2024· 1 change
2024-10-30published 2024-10-29GHSA-45pg-36p6-83v9CVE-2024-8309lownot named as affected when the advisory was published, now names langchain-communityTime to revision 1 days
Mon 28 Oct 2024· 2 changes
2024-10-28published 2022-05-14GHSA-vpqp-hx68-p2wxCVE-2013-2217moderatenot named as affected when the advisory was published, now names suds-py3Duration unknown
2024-10-28published 2019-04-24GHSA-frxx-2m33-6wcrCVE-2018-8825highnot named as affected when the advisory was published, now names tensorflow-gpuDuration unknown
Thu 24 Oct 2024· 7 changes
2024-10-24published 2021-09-01 to 2022-09-23moderatenot named as affected when the advisory was published, now names pallet-ethereumDuration unknown
2024-10-24published 2022-09-23GHSA-v57h-6hmh-g2p4CVE-2022-39242same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-10-24published 2021-10-13GHSA-vj62-g63v-f8mfCVE-2021-41138same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-10-24published 2021-09-01GHSA-hw4v-5x4h-c3xmCVE-2021-39193same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-10-24published 2022-01-14 to 2023-03-212 bandsnot named as affected when the advisory was published, now names pallet-evm-precompile-modexpTime to revision 583 days
2024-10-24published 2022-01-14GHSA-cjg2-2fjg-fph4CVE-2022-21685same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-10-24published 2023-03-21GHSA-fcmm-54jp-7vf6CVE-2023-28431same package registry as the line abovehighsame change as the line aboveTime to revision 583 days
2024-10-24published 2022-08-18GHSA-mjvm-mhgc-q4gpCVE-2022-36008moderatenot named as affected when the advisory was published, now names fc-rpcDuration unknown
2024-10-24published 2019-08-08GHSA-fp5j-3fpf-mhj5CVE-2019-10099highnot named as affected when the advisory was published, now names pysparkDuration unknown
Mon 21 Oct 2024· 2 changes
2024-10-21published 2019-03-14GHSA-6mqq-8r44-vmjcCVE-2018-1334moderatenot named as affected when the advisory was published, now names pysparkDuration unknown
2024-10-21published 2021-04-06GHSA-gg2g-m5wc-vccqCVE-2021-21423highnot named as affected when the advisory was published, now names projenDuration unknown
Fri 18 Oct 2024· 2 changes
2024-10-18published 2022-05-17 to 2022-05-24highnot named as affected when the advisory was published, now names ploneTime to revision 878 to 886 days
2024-10-18published 2022-05-24GHSA-cjg3-q24h-9qwfCVE-2020-7938same package registry as the line abovehighsame change as the line aboveTime to revision 878 days
2024-10-18published 2022-05-17GHSA-984m-rj28-8c6xCVE-2015-7315same package registry as the line abovehighsame change as the line aboveTime to revision 886 days
Thu 17 Oct 2024· 3 changes
2024-10-17published 2020-12-09 to 2022-05-132 bandsnot named as affected when the advisory was published, now names org.codehaus.groovy:groovy-allDuration unknown
2024-10-17published 2022-05-13GHSA-xphj-m9cc-8fmqCVE-2016-6814same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2024-10-17published 2020-12-09GHSA-rcjj-h6gh-jf3rCVE-2020-17521same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-10-17published 2022-05-13GHSA-qg25-hgjv-cg9qCVE-2015-3253same package registry as the line abovecriticalsame change as the line aboveDuration unknown
Wed 16 Oct 2024· 1 change
2024-10-16published 2020-01-31GHSA-7q36-4xx7-xcxfCVE-2020-5234moderatenot named as affected when the advisory was published, now names messagepack.unityDuration unknown
Tue 15 Oct 2024· 4 changes
2024-10-15published 2022-02-10 to 2023-04-17criticalnot named as affected when the advisory was published, now names pysparkTime to revision 547 days
2024-10-15published 2023-04-17GHSA-329j-jfvr-rhr6CVE-2023-22946same package registry as the line abovecriticalsame change as the line aboveTime to revision 547 days
2024-10-15published 2022-02-10GHSA-wgx7-jwwm-cgjvCVE-2020-9480same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2024-10-15published 2022-05-17moderatenot named as affected when the advisory was published, now names products.cmfploneTime to revision 883 days
2024-10-15published 2022-05-17GHSA-rg52-j87w-pf83CVE-2013-7060same package registry as the line abovemoderatesame change as the line aboveTime to revision 883 days
2024-10-15published 2022-05-17GHSA-4vr8-r7qr-fpvqCVE-2013-7061same package registry as the line abovemoderatesame change as the line aboveTime to revision 883 days
Mon 14 Oct 2024· 4 changes
2024-10-14published 2018-07-23GHSA-p7h9-vf92-5fj5CVE-2011-1948moderatenot named as affected when the advisory was published, now names ploneDuration unknown
2024-10-14published 2024-10-08GHSA-qj66-m88j-hmgjCVE-2024-43483highnot named as affected when the advisory was published, now names microsoft.extensions.caching.memoryTime to revision 6 days
2024-10-14published 2023-02-10GHSA-hxjp-q6c3-38fxCVE-2023-22832highnot named as affected when the advisory was published, now names org.apache.nifi:nifi-ccda-processorsTime to revision 612 days
2024-10-14published 2023-06-12GHSA-65wh-g8x8-gm2hCVE-2023-34212moderatenot named as affected when the advisory was published, now names org.apache.nifi:nifi-jms-processorsTime to revision 490 days
Fri 11 Oct 2024· 1 change
2024-10-11published 2023-09-20GHSA-fv2h-753j-9g39CVE-2023-41890highnot named as affected when the advisory was published, now names kentor.authservicesTime to revision 387 days
Wed 9 Oct 2024· 6 changes
2024-10-09published 2024-10-01GHSA-fhqq-8f65-5xfcmoderatenot named as affected when the advisory was published, now names github.com/containers/podman/v2 and 2 moreTime to revision 8 days
2024-10-09published 2024-10-01GHSA-fhqq-8f65-5xfcCVE-2024-9407same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/containers/podman/v2Time to revision 8 days
2024-10-09published 2024-10-01GHSA-fhqq-8f65-5xfcCVE-2024-9407same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/containers/podman/v3Time to revision 8 days
2024-10-09published 2024-10-01GHSA-fhqq-8f65-5xfcCVE-2024-9407same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/containers/podman/v4Time to revision 8 days
2024-10-09published 2022-05-17GHSA-27px-qpmj-qg38CVE-2012-0878highnot named as affected when the advisory was published, now names pasteTime to revision 877 days
2024-10-09published 2024-10-022 bandsnot named as affected when the advisory was published, now names openc3Time to revision 7 days
2024-10-09published 2024-10-02GHSA-8jxr-mccc-mwg8CVE-2024-46977same package registry as the line abovehighsame change as the line aboveTime to revision 7 days
2024-10-09published 2024-10-02GHSA-vfj8-5pj7-2f9gCVE-2024-43795same package registry as the line abovemoderatesame change as the line aboveTime to revision 7 days
Tue 8 Oct 2024· 1 change
2024-10-08published 2024-10-03GHSA-r7pg-v2c8-mfg3CVE-2024-47561criticalnot named as affected when the advisory was published, now names org.apache.avro:avroTime to revision 5 days
Fri 4 Oct 2024· 1 change
2024-10-04published 2022-05-20GHSA-hh32-7344-cg2fCVE-2022-22978criticalnot named as affected when the advisory was published, now names org.springframework.security:spring-security-webDuration unknown
Mon 30 Sep 2024· 2 changes
2024-09-30published 2018-09-06GHSA-fpcv-j2q9-vqhwCVE-2018-16405moderatenot named as affected when the advisory was published, now names mayan-edms-ngDuration unknown
2024-09-30published 2023-09-01GHSA-f73w-4m7g-ch9xCVE-2023-39631criticalnot named as affected when the advisory was published, now names numexprTime to revision 395 days
Fri 27 Sep 2024· 3 changes
2024-09-27published 2024-09-25GHSA-rgg8-g5x8-wr9vCVE-2024-45613moderatenot named as affected when the advisory was published, now names @ckeditor/ckeditor5-clipboardTime to revision 2 days
2024-09-27published 2022-05-17GHSA-7f2c-vp52-gmfwCVE-2014-7144highnot named as affected when the advisory was published, now names python-keystoneclientTime to revision 865 days
2024-09-27published 2022-05-14GHSA-mffc-9gx5-99g3CVE-2015-3206criticalnot named as affected when the advisory was published, now names pykerberosTime to revision 868 days
Thu 26 Sep 2024· 3 changes
2024-09-26published 2024-06-122 bandsnot named as affected when the advisory was published, now names apache-submarineTime to revision 106 days
2024-09-26published 2024-06-12GHSA-6q97-8v3g-rpxwCVE-2024-36265same package registry as the line abovecriticalsame change as the line aboveTime to revision 106 days
2024-09-26published 2024-06-12GHSA-jwcg-wv5x-vg3gCVE-2024-36264same package registry as the line abovemoderatesame change as the line aboveTime to revision 106 days
2024-09-26published 2022-05-14GHSA-hhx8-cr55-qcxxCVE-2019-9644moderatenot named as affected when the advisory was published, now names notebookDuration unknown
Wed 25 Sep 2024· 1 change
2024-09-25published 2022-05-17GHSA-6vvc-c2m3-cjf3CVE-2014-9390criticalnot named as affected when the advisory was published, now names mercurialTime to revision 862 days
Tue 24 Sep 2024· 1 change
2024-09-24published 2019-07-05GHSA-x64g-wjmw-w328CVE-2015-5306criticalnot named as affected when the advisory was published, now names ironic-inspectorDuration unknown
Fri 20 Sep 2024· 3 changes
2024-09-20published 2021-12-06GHSA-7hpj-hfcr-5qwmCVE-2019-14867highnot named as affected when the advisory was published, now names freeipaDuration unknown
2024-09-20published 2022-05-24GHSA-w4q7-f34x-vpgcCVE-2019-10195moderatenot named as affected when the advisory was published, now names ipaTime to revision 850 days
2024-09-20published 2024-09-17GHSA-f2jm-rw3h-6phgCVE-2024-5998highnot named as affected when the advisory was published, now names langchain-communityTime to revision 3 days
Wed 18 Sep 2024· 1 change
2024-09-18published 2024-09-18GHSA-x3jx-5w6m-q2fcCVE-2022-25768highnot named as affected when the advisory was published, now names mautic/coreTime to revision 0 days
Mon 16 Sep 2024· 5 changes
2024-09-16published 2024-09-16GHSA-jpxc-vmjf-9fcjCVE-2024-8775highnot named as affected when the advisory was published, now names ansible-coreTime to revision 0 days
2024-09-16published 2024-08-26GHSA-cj55-gc7m-wvcqCVE-2024-45258moderatenot named as affected when the advisory was published, now names github.com/imroc/req/v2Time to revision 22 days
2024-09-16published 2023-06-062 bandsnot named as affected when the advisory was published, now names github.com/rancher/rancherTime to revision 469 days
2024-09-16published 2023-06-06GHSA-p976-h52c-26p6CVE-2023-22647same package registry as the line abovecriticalsame change as the line aboveTime to revision 469 days
2024-09-16published 2023-06-06GHSA-46v3-ggjg-qq3xCVE-2022-43760same package registry as the line abovemoderatesame change as the line aboveTime to revision 469 days
2024-09-16published 2022-05-24GHSA-5v8v-66v8-mwm7CVE-2020-8927moderatenot named as affected when the advisory was published, now names brotliDuration unknown
Thu 12 Sep 2024· 6 changes
2024-09-12published 2022-10-26GHSA-g6hg-4v3c-6jq7highnot named as affected when the advisory was published, now names org.apache.iotdb:flink-tsfile-connector and 2 moreDuration unknown
2024-09-12published 2022-10-26GHSA-g6hg-4v3c-6jq7CVE-2022-43766same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.iotdb:flink-tsfile-connectorDuration unknown
2024-09-12published 2022-10-26GHSA-g6hg-4v3c-6jq7CVE-2022-43766same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.iotdb:iotdb-serverDuration unknown
2024-09-12published 2022-10-26GHSA-g6hg-4v3c-6jq7CVE-2022-43766same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.iotdb:tsfileDuration unknown
2024-09-12published 2022-02-09GHSA-qhh5-9738-g9mxCVE-2020-13922highnot named as affected when the advisory was published, now names org.apache.dolphinscheduler:dolphinscheduler-apiDuration unknown
2024-09-12published 2023-04-17GHSA-pvjv-386f-c8whCVE-2023-24831criticalnot named as affected when the advisory was published, now names apache-iotdbTime to revision 514 days
2024-09-12published 2024-07-22GHSA-mmwx-rj87-vfgrhighnot named as affected when the advisory was published, now names org.jitsi:dnssecjavaTime to revision 52 days
Wed 11 Sep 2024· 2 changes
2024-09-11published 2024-07-22GHSA-crjg-w57m-rqqfhighnot named as affected when the advisory was published, now names org.jitsi:dnssecjavaTime to revision 51 days
2024-09-11published 2019-11-22GHSA-q3p4-gw7r-wqjcCVE-2019-12417moderatenot named as affected when the advisory was published, now names airflowDuration unknown
Mon 9 Sep 2024· 1 change
2024-09-09published 2022-05-24GHSA-pm48-cvv2-29q5CVE-2019-14846highnot named as affected when the advisory was published, now names ansibleTime to revision 839 days
Fri 6 Sep 2024· 3 changes
2024-09-06published 2024-09-05GHSA-7q74-g774-7x3ghighnot named as affected when the advisory was published, now names github.com/cosmos/interchain-security/v2 and 2 moreTime to revision 1 days
2024-09-06published 2024-09-05GHSA-7q74-g774-7x3gsame package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/cosmos/interchain-security/v2Time to revision 1 days
2024-09-06published 2024-09-05GHSA-7q74-g774-7x3gsame package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/cosmos/interchain-security/v3Time to revision 1 days
2024-09-06published 2024-09-05GHSA-7q74-g774-7x3gsame package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/cosmos/interchain-security/v4Time to revision 1 days
Tue 3 Sep 2024· 2 changes
2024-09-03published 2018-07-13GHSA-c2w9-48qc-qpj4CVE-2017-2809highnot named as affected when the advisory was published, now names ansible-vaultDuration unknown
2024-09-03published 2021-08-05GHSA-qcx9-j53g-ccgfCVE-2021-32807moderatenot named as affected when the advisory was published, now names zopeDuration unknown
Sat 31 Aug 2024· 1 change
2024-08-31published 2024-08-21GHSA-7r32-vfj5-c2jvCVE-2024-43407moderatenot named as affected when the advisory was published, now names ckeditor4Time to revision 9 days
Thu 29 Aug 2024· 50 changes
2024-08-29published 2021-05-21 to 2021-08-2550 rows, one per advisory and package3 bandsnot named as affected when the advisory was published, now names tensorflow-cpu and 1 moreDuration unknown
2024-08-29published 2021-08-25GHSA-wf5p-c75w-w3whCVE-2021-37689same package registry as the line abovehighnot named as affected when the advisory was published, now names tensorflow-cpuDuration unknown
2024-08-29published 2021-08-25GHSA-wf5p-c75w-w3whCVE-2021-37689same package registry as the line abovehighnot named as affected when the advisory was published, now names tensorflow-gpuDuration unknown
2024-08-29published 2021-08-25GHSA-vcjj-9vg7-vf68CVE-2021-37688same package registry as the line abovehighnot named as affected when the advisory was published, now names tensorflow-cpuDuration unknown
2024-08-29published 2021-08-25GHSA-vcjj-9vg7-vf68CVE-2021-37688same package registry as the line abovehighnot named as affected when the advisory was published, now names tensorflow-gpuDuration unknown
2024-08-29published 2021-08-25GHSA-jwf9-w5xm-f437CVE-2021-37687same package registry as the line abovemoderatenot named as affected when the advisory was published, now names tensorflow-cpuDuration unknown
2024-08-29published 2021-08-25GHSA-jwf9-w5xm-f437CVE-2021-37687same package registry as the line abovemoderatenot named as affected when the advisory was published, now names tensorflow-gpuDuration unknown
2024-08-29published 2021-08-25GHSA-c545-c4f9-rf6vCVE-2021-37685same package registry as the line abovemoderatenot named as affected when the advisory was published, now names tensorflow-cpuDuration unknown
2024-08-29published 2021-08-25GHSA-c545-c4f9-rf6vCVE-2021-37685same package registry as the line abovemoderatenot named as affected when the advisory was published, now names tensorflow-gpuDuration unknown
42 more rows in this change are not listed here. Open all 50 rows
Wed 28 Aug 2024· 15 changes
2024-08-28published 2020-09-25 to 2021-05-213 bandsnot named as affected when the advisory was published, now names tensorflow-cpuDuration unknown
2024-08-28published 2021-05-21GHSA-vfr4-x8j2-3rf9CVE-2021-29588same package registry as the line abovelowsame change as the line aboveDuration unknown
2024-08-28published 2021-05-21GHSA-j7rm-8ww4-xx2gCVE-2021-29587same package registry as the line abovelowsame change as the line aboveDuration unknown
2024-08-28published 2021-05-21GHSA-26j7-6w8w-7922CVE-2021-29586same package registry as the line abovelowsame change as the line aboveDuration unknown
2024-08-28published 2021-05-21GHSA-mv78-g7wq-mhp4CVE-2021-29585same package registry as the line abovelowsame change as the line aboveDuration unknown
2024-08-28published 2020-09-25GHSA-hjmq-236j-8m87CVE-2020-15213same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-28published 2020-09-25GHSA-hx2x-85gr-wrpqCVE-2020-15212same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2024-08-28published 2020-09-25GHSA-p2cq-cprg-frvmCVE-2020-15214same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2024-08-28published 2020-05-13 to 2021-05-214 bandsnot named as affected when the advisory was published, now names tensorflow-gpuDuration unknown
2024-08-28published 2021-05-21GHSA-vfr4-x8j2-3rf9CVE-2021-29588same package registry as the line abovelowsame change as the line aboveDuration unknown
2024-08-28published 2021-05-21GHSA-j7rm-8ww4-xx2gCVE-2021-29587same package registry as the line abovelowsame change as the line aboveDuration unknown
2024-08-28published 2021-05-21GHSA-26j7-6w8w-7922CVE-2021-29586same package registry as the line abovelowsame change as the line aboveDuration unknown
2024-08-28published 2021-05-21GHSA-mv78-g7wq-mhp4CVE-2021-29585same package registry as the line abovelowsame change as the line aboveDuration unknown
2024-08-28published 2020-05-13GHSA-h98h-8mxr-m8gxCVE-2018-21233same package registry as the line abovehighsame change as the line aboveDuration unknown
2024-08-28published 2020-09-25GHSA-hjmq-236j-8m87CVE-2020-15213same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-28published 2020-09-25GHSA-hx2x-85gr-wrpqCVE-2020-15212same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2024-08-28published 2020-09-25GHSA-p2cq-cprg-frvmCVE-2020-15214same package registry as the line abovecriticalsame change as the line aboveDuration unknown
Tue 27 Aug 2024· 5 changes
2024-08-27published 2020-09-252 bandsnot named as affected when the advisory was published, now names tensorflow-cpuDuration unknown
2024-08-27published 2020-09-25GHSA-cvpc-8phh-8f45CVE-2020-15211same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-27published 2020-09-25GHSA-x9j7-x98r-r4w2CVE-2020-15210same package registry as the line abovehighsame change as the line aboveDuration unknown
2024-08-27published 2020-09-252 bandsnot named as affected when the advisory was published, now names tensorflow-gpuDuration unknown
2024-08-27published 2020-09-25GHSA-cvpc-8phh-8f45CVE-2020-15211same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-27published 2020-09-25GHSA-x9j7-x98r-r4w2CVE-2020-15210same package registry as the line abovehighsame change as the line aboveDuration unknown
2024-08-27published 2024-08-20GHSA-r5ph-4jxm-6j9pCVE-2024-43406highnot named as affected when the advisory was published, now names ekuiperTime to revision 7 days
Mon 26 Aug 2024· 7 changes
2024-08-26published 2019-04-24 to 2019-04-302 bandsnot named as affected when the advisory was published, now names tensorflow-gpuDuration unknown
2024-08-26published 2019-04-30GHSA-mfg7-x5m7-6p8wCVE-2019-9635same package registry as the line abovehighsame change as the line aboveDuration unknown
2024-08-26published 2019-04-30GHSA-qx2v-j445-g354CVE-2018-7577same package registry as the line abovehighsame change as the line aboveDuration unknown
2024-08-26published 2019-04-24GHSA-jfq2-rj7f-9gvfCVE-2018-7576same package registry as the line abovehighsame change as the line aboveDuration unknown
2024-08-26published 2019-04-30GHSA-mw6v-crh8-8533CVE-2018-7575same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2024-08-26published 2019-10-15GHSA-c427-hjc3-wrfwcriticalnot named as affected when the advisory was published, now names io.springfox:springfox-swagger-ui and 2 moreDuration unknown
2024-08-26published 2019-10-15GHSA-c427-hjc3-wrfwCVE-2019-17495same package registry as the line abovecriticalnot named as affected when the advisory was published, now names io.springfox:springfox-swagger-uiDuration unknown
2024-08-26published 2019-10-15GHSA-c427-hjc3-wrfwCVE-2019-17495same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.webjars.npm:swagger-uiDuration unknown
2024-08-26published 2019-10-15GHSA-c427-hjc3-wrfwCVE-2019-17495same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.webjars:swagger-uiDuration unknown
Fri 23 Aug 2024· 1 change
2024-08-23published 2019-04-30GHSA-q492-f7gr-27rpCVE-2018-10055highnot named as affected when the advisory was published, now names tensorflow-gpuDuration unknown
Fri 16 Aug 2024· 2 changes
2024-08-16published 2024-07-11moderatenot named as affected when the advisory was published, now names org.webjars.npm:bootstrapTime to revision 36 days
2024-08-16published 2024-07-11GHSA-9mvj-f7w8-pvh2CVE-2024-6484same package registry as the line abovemoderatesame change as the line aboveTime to revision 36 days
2024-08-16published 2024-07-11GHSA-vc8w-jr9v-vj7fCVE-2024-6531same package registry as the line abovemoderatesame change as the line aboveTime to revision 36 days
Wed 7 Aug 2024· 5 changes
2024-08-07published 2024-08-02GHSA-rpcc-p8xm-rc6phighnot named as affected when the advisory was published, now names github.com/containers/podman/v2 and 2 moreTime to revision 5 days
2024-08-07published 2024-08-02GHSA-rpcc-p8xm-rc6pCVE-2024-3056same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/containers/podman/v2Time to revision 5 days
2024-08-07published 2024-08-02GHSA-rpcc-p8xm-rc6pCVE-2024-3056same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/containers/podman/v3Time to revision 5 days
2024-08-07published 2024-08-02GHSA-rpcc-p8xm-rc6pCVE-2024-3056same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/containers/podman/v4Time to revision 5 days
2024-08-07published 2023-10-10GHSA-qppj-fm5r-hxr3CVE-2023-44487moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 302 days
2024-08-07published 2024-07-24GHSA-5g3x-8g2v-r8x8CVE-2024-36533criticalnot named as affected when the advisory was published, now names volcano.sh/volcanoTime to revision 14 days
Fri 2 Aug 2024· 6 changes
2024-08-02published 2024-08-02GHSA-frvj-cfq4-3228CVE-2024-36116highnot named as affected when the advisory was published, now names com.reposilite:reposilite-backendTime to revision 0 days
2024-08-02published 2022-05-13GHSA-3wqf-4x89-9g79moderatenot named as affected when the advisory was published, now names bootstrap and 1 moreDuration unknown
2024-08-02published 2022-05-13GHSA-3wqf-4x89-9g79CVE-2018-14040same package registry as the line abovemoderatenot named as affected when the advisory was published, now names bootstrapDuration unknown
2024-08-02published 2022-05-13GHSA-3wqf-4x89-9g79CVE-2018-14040same package registry as the line abovemoderatenot named as affected when the advisory was published, now names bootstrap.sassDuration unknown
2024-08-02published 2022-05-13GHSA-3wqf-4x89-9g79CVE-2018-14040moderatenot named as affected when the advisory was published, now names twbs/bootstrapDuration unknown
2024-08-02published 2022-05-13GHSA-3wqf-4x89-9g79CVE-2018-14040moderatenot named as affected when the advisory was published, now names bootstrap-sassDuration unknown
2024-08-02published 2021-05-07GHSA-7c82-mp33-r854CVE-2019-20921moderatenot named as affected when the advisory was published, now names bootstrap-selectDuration unknown
Thu 1 Aug 2024· 32 changes
2024-08-01published 2018-09-13 to 2019-02-22moderatenot named as affected when the advisory was published, now names org.webjars:bootstrapDuration unknown
2024-08-01published 2019-02-22GHSA-9v3m-8fp8-mj99CVE-2019-8331same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2019-01-17GHSA-ph58-4vrj-w6hrCVE-2018-20677same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2019-01-17GHSA-3mgp-fx93-9xv5CVE-2018-20676same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2019-01-17GHSA-4p24-vmcr-4gqjCVE-2016-10735same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13GHSA-7mvr-5x2g-wfc8CVE-2018-14042same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13GHSA-pj7m-g53m-7638CVE-2018-14041same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13 to 2019-02-22moderatenot named as affected when the advisory was published, now names twbs/bootstrapDuration unknown
2024-08-01published 2019-02-22GHSA-9v3m-8fp8-mj99CVE-2019-8331same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2019-01-17GHSA-ph58-4vrj-w6hrCVE-2018-20677same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2019-01-17GHSA-3mgp-fx93-9xv5CVE-2018-20676same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2019-01-17GHSA-4p24-vmcr-4gqjCVE-2016-10735same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13GHSA-7mvr-5x2g-wfc8CVE-2018-14042same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13GHSA-pj7m-g53m-7638CVE-2018-14041same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13 to 2019-01-17moderatenot named as affected when the advisory was published, now names bootstrap-sassDuration unknown
2024-08-01published 2019-01-17GHSA-ph58-4vrj-w6hrCVE-2018-20677same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2019-01-17GHSA-3mgp-fx93-9xv5CVE-2018-20676same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2019-01-17GHSA-4p24-vmcr-4gqjCVE-2016-10735same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13GHSA-7mvr-5x2g-wfc8CVE-2018-14042same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13 to 2019-01-17moderatenot named as affected when the advisory was published, now names bootstrapDuration unknown
2024-08-01published 2019-01-17GHSA-ph58-4vrj-w6hrCVE-2018-20677same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2019-01-17GHSA-3mgp-fx93-9xv5CVE-2018-20676same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2019-01-17GHSA-4p24-vmcr-4gqjCVE-2016-10735same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13GHSA-7mvr-5x2g-wfc8CVE-2018-14042same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13GHSA-pj7m-g53m-7638CVE-2018-14041same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13 to 2019-01-17moderatenot named as affected when the advisory was published, now names bootstrapDuration unknown
2024-08-01published 2019-01-17GHSA-ph58-4vrj-w6hrCVE-2018-20677same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2019-01-17GHSA-3mgp-fx93-9xv5CVE-2018-20676same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2019-01-17GHSA-4p24-vmcr-4gqjCVE-2016-10735same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13GHSA-pj7m-g53m-7638CVE-2018-14041same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13 to 2019-01-17moderatenot named as affected when the advisory was published, now names bootstrap-sassDuration unknown
2024-08-01published 2019-01-17GHSA-ph58-4vrj-w6hrCVE-2018-20677same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2019-01-17GHSA-3mgp-fx93-9xv5CVE-2018-20676same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2019-01-17GHSA-4p24-vmcr-4gqjCVE-2016-10735same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13GHSA-7mvr-5x2g-wfc8CVE-2018-14042same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13 to 2019-01-17moderatenot named as affected when the advisory was published, now names bootstrap.sassDuration unknown
2024-08-01published 2019-01-17GHSA-4p24-vmcr-4gqjCVE-2016-10735same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13GHSA-7mvr-5x2g-wfc8CVE-2018-14042same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-08-01published 2018-09-13GHSA-pj7m-g53m-7638CVE-2018-14041same package registry as the line abovemoderatesame change as the line aboveDuration unknown
Tue 30 Jul 2024· 1 change
2024-07-30published 2022-05-13GHSA-3wqf-4x89-9g79CVE-2018-14040moderatenot named as affected when the advisory was published, now names org.webjars:bootstrapDuration unknown
Wed 24 Jul 2024· 1 change
2024-07-24published 2024-06-06GHSA-q25c-c977-4cmhCVE-2024-3095moderatenot named as affected when the advisory was published, now names langchain-communityTime to revision 48 days
Fri 19 Jul 2024· 1 change
2024-07-19published 2022-05-24GHSA-rfmp-97jj-h8m6CVE-2021-22096moderatenot named as affected when the advisory was published, now names org.springframework:springDuration unknown
Thu 18 Jul 2024· 1 change
2024-07-18published 2024-07-12GHSA-hhwc-gh8h-9rrpCVE-2024-36522highnot named as affected when the advisory was published, now names org.apache.wicket:wicket-utilTime to revision 6 days
Tue 9 Jul 2024· 1 change
2024-07-09published 2024-07-05GHSA-xr7q-jx4m-x55mlownot named as affected when the advisory was published, now names google.golang.org/grpcTime to revision 4 days
Mon 8 Jul 2024· 6 changes
2024-07-08published 2022-02-15 to 2024-01-314 bandsnot named as affected when the advisory was published, now names github.com/docker/dockerTime to revision 159 to 776 days
2024-07-08published 2022-05-24GHSA-v2cv-wwxq-qq97CVE-2019-14271same package registry as the line abovecriticalsame change as the line aboveTime to revision 776 days
2024-07-08published 2024-01-31GHSA-qrqr-3x5j-2xw9CVE-2018-12608same package registry as the line abovehighsame change as the line aboveTime to revision 159 days
2024-07-08published 2022-02-15GHSA-8fvr-5rqf-3wwhCVE-2015-3630same package registry as the line abovehighsame change as the line aboveDuration unknown
2024-07-08published 2022-02-15GHSA-v4h8-794j-g8mmCVE-2015-3631same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2024-07-08published 2022-11-11GHSA-vp35-85q5-9f25same package registry as the line abovelowsame change as the line aboveDuration unknown
2024-07-08published 2022-09-16GHSA-rc4r-wh2q-q6c4CVE-2022-36109same package registry as the line abovemoderatesame change as the line aboveDuration unknown

Counted in advisories, never added to the CVE and KEV figures. This kind is counted once per advisory and per package, so one advisory that named four further packages counts four times. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

What this page cannot see

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Paste your closed CVE tickets and see which of these changes hit them →