Skip to content

Package added to advisory

What a record said when it was published, what it says now, and the commit that changed it.

1,695 advisory changes · newest first · grouped by day

SinceClear all
ChangedSourceRows
Counted changes of "Package added to advisory", newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.Advisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Fri 5 Jul 2024· 3 advisory changes
2024-07-05published 2024-06-29GHSA-869c-j7wc-8jqvCVE-2019-25211criticalnot named as affected when the advisory was published, now names github.com/gin-contrib/corsDays to revision 7
2024-07-05published 2024-06-10GHSA-xmmx-7jpf-fx42moderatenot named as affected when the advisory was published, now names github.com/moby/mobyDays to revision 25
2024-07-05published 2024-07-01GHSA-gc7m-596h-x57rCVE-2024-38992highnot named as affected when the advisory was published, now names @airvertco/frappejsDays to revision 4
Wed 3 Jul 2024· 1 advisory change
2024-07-03published 2022-01-13GHSA-gqm2-2gcx-p88wCVE-2022-20616moderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins:credentials-bindingnot dated
Tue 2 Jul 2024· 2 advisory changes
2024-07-02published 2024-06-19moderatenot named as affected when the advisory was published, now names django-tinymceDays to revision 13
2024-07-02published 2024-06-19GHSA-w9jx-4g6g-rp7xCVE-2024-38357same package registry as the line abovemoderatesame change as the line aboveDays to revision 13
2024-07-02published 2024-06-19GHSA-9hcv-j9pv-qmphCVE-2024-38356same package registry as the line abovemoderatesame change as the line aboveDays to revision 13
Fri 28 Jun 2024· 1 advisory change
2024-06-28published 2023-11-28GHSA-q24v-hpg3-v3jpCVE-2023-34054highnot named as affected when the advisory was published, now names io.projectreactor.netty:reactor-netty-coreDays to revision 213
Thu 27 Jun 2024· 2 advisory changes
2024-06-27published 2022-02-10GHSA-8grg-q944-cch5CVE-2019-14900moderatenot named as affected when the advisory was published, now names org.hibernate:hibernate-corenot dated
2024-06-27published 2023-11-28GHSA-jjfh-589g-3hjxCVE-2023-34055moderatenot named as affected when the advisory was published, now names org.springframework.boot:spring-boot-actuatorDays to revision 212
Fri 14 Jun 2024· 1 advisory change
2024-06-14published 2024-06-06GHSA-3hjh-jh2h-vrg6CVE-2024-2965moderatenot named as affected when the advisory was published, now names langchain-communityDays to revision 8
Mon 10 Jun 2024· 1 advisory change
2024-06-10published 2024-03-05GHSA-m4pq-fv2w-6hrwCVE-2024-27936highnot named as affected when the advisory was published, now names denoDays to revision 97
Tue 4 Jun 2024· 1 advisory change
2024-06-04published 2024-06-03GHSA-4w54-wwc9-x62cCVE-2024-36042criticalnot named as affected when the advisory was published, now names org.silverpeas.core:silverpeas-coreDays to revision 2
Mon 3 Jun 2024· 2 advisory changes
2024-06-03published 2024-05-07GHSA-qjqp-xr96-cj99CVE-2024-34341moderatenot named as affected when the advisory was published, now names actiontextDays to revision 27
2024-06-03published 2024-05-31GHSA-8hqg-whrw-pv92CVE-2024-37032moderatenot named as affected when the advisory was published, now names github.com/ollama/ollamaDays to revision 3
Fri 31 May 2024· 3 advisory changes
2024-05-31published 2022-05-13moderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins:kmap-jenkinsDays to revision 750
2024-05-31published 2022-05-13GHSA-fvcf-wgxj-h7chCVE-2019-10292same package registry as the line abovemoderatesame change as the line aboveDays to revision 750
2024-05-31published 2022-05-13GHSA-q5wm-qgxj-h9phCVE-2019-10293same package registry as the line abovemoderatesame change as the line aboveDays to revision 750
2024-05-31published 2024-03-07GHSA-c5q2-7r4c-mv6gCVE-2024-28180moderatenot named as affected when the advisory was published, now names gopkg.in/square/go-jose.v2Days to revision 85
Thu 30 May 2024· 5 advisory changes
2024-05-30published 2022-05-24GHSA-922h-x9qv-2274CVE-2019-10374moderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins:pegdown-formatterDays to revision 737
2024-05-30published 2022-05-24GHSA-g6h2-4x64-c59xCVE-2019-10337highnot named as affected when the advisory was published, now names org.jenkins-ci.plugins:token-macronot dated
2024-05-30published 2023-11-29moderatenot named as affected when the advisory was published, now names io.jenkins.plugins:neuvector-vulnerability-scannerDays to revision 183
2024-05-30published 2023-11-29GHSA-ph87-4x2g-6hp4CVE-2023-49674same package registry as the line abovemoderatesame change as the line aboveDays to revision 183
2024-05-30published 2023-11-29GHSA-wpfc-r5qq-7r7pCVE-2023-49673same package registry as the line abovemoderatesame change as the line aboveDays to revision 183
2024-05-30published 2024-05-30GHSA-vfm6-r2gc-pwwwmoderatenot named as affected when the advisory was published, now names symfony/symfonyDays to revision 0
Thu 23 May 2024· 3 advisory changes
2024-05-23published 2022-07-13GHSA-64x4-9hc6-r2h6CVE-2022-30187moderatenot named as affected when the advisory was published, now names com.azure:azure-storage-blobnot dated
2024-05-23published 2022-07-13GHSA-64x4-9hc6-r2h6moderatenot named as affected when the advisory was published, now names azure-storage-blob and 1 morenot dated
2024-05-23published 2022-07-13GHSA-64x4-9hc6-r2h6CVE-2022-30187same package registry as the line abovemoderatenot named as affected when the advisory was published, now names azure-storage-blobnot dated
2024-05-23published 2022-07-13GHSA-64x4-9hc6-r2h6CVE-2022-30187same package registry as the line abovemoderatenot named as affected when the advisory was published, now names azure-storage-queuenot dated
Tue 21 May 2024· 1 advisory change
2024-05-21published 2024-05-14GHSA-jj54-5q2m-q7pjCVE-2021-32026lownot named as affected when the advisory was published, now names github.com/nats-io/nats-server/v2Days to revision 7
Mon 20 May 2024· 3 advisory changes
2024-05-20published 2022-05-14GHSA-927h-x4qj-r242CVE-2018-20744moderatenot named as affected when the advisory was published, now names github.com/rs/corsDays to revision 738
2024-05-20published 2024-02-23GHSA-rc6h-qwj9-2c53CVE-2024-23320highnot named as affected when the advisory was published, now names org.apache.dolphinscheduler:dolphinscheduler-masterDays to revision 87
2024-05-20published 2024-05-18GHSA-9328-gcfq-p269CVE-2024-35312highnot named as affected when the advisory was published, now names tor-circmgrDays to revision 3
Tue 14 May 2024· 2 advisory changes
2024-05-14published 2024-02-03GHSA-mf74-qq7w-6j7vmoderatenot named as affected when the advisory was published, now names remark-images-downloadDays to revision 102
2024-05-14published 2024-01-31GHSA-3fwx-pjgw-3558CVE-2021-41091moderatenot named as affected when the advisory was published, now names github.com/docker/dockerDays to revision 104
Fri 10 May 2024· 2 advisory changes
2024-05-10published 2024-05-08GHSA-649x-hxfx-57j2CVE-2024-32886moderatenot named as affected when the advisory was published, now names vitess.io/vitessDays to revision 2
2024-05-10published 2022-05-13GHSA-cw54-59pw-4g8cCVE-2016-8735criticalnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina-jmx-remoteDays to revision 729
Tue 30 Apr 2024· 1 advisory change
2024-04-30published 2022-05-14GHSA-9848-v244-962pCVE-2012-1007moderatenot named as affected when the advisory was published, now names org.apache.struts:struts-corenot dated
Thu 25 Apr 2024· 1 advisory change
2024-04-25published 2024-04-24GHSA-33c5-9fx5-fvjmCVE-2020-8559moderatenot named as affected when the advisory was published, now names k8s.io/kubernetesDays to revision 1
Wed 24 Apr 2024· 4 advisory changes
2024-04-24published 2023-06-21 to 2023-07-064 rows, one per advisory and packagehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core and 1 moreDays to revision 293 to 308
2024-04-24published 2023-06-21GHSA-mppv-79ch-vw6qCVE-2023-34981same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDays to revision 308
2024-04-24published 2023-06-21GHSA-mppv-79ch-vw6qCVE-2023-34981same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 308
2024-04-24published 2023-07-06GHSA-cx6h-86xw-9x34CVE-2023-28709same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDays to revision 293
2024-04-24published 2023-07-06GHSA-cx6h-86xw-9x34CVE-2023-28709same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 293
Tue 23 Apr 2024· 7 advisory changes
2024-04-23published 2022-11-01 to 2024-01-197 rows, one per advisory and package2 bandsnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core and 3 moreDays to revision 95 to 476
2024-04-23published 2024-01-19GHSA-f4qf-m5gf-8jm8CVE-2024-21733same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDays to revision 95
2024-04-23published 2024-01-19GHSA-f4qf-m5gf-8jm8CVE-2024-21733same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 95
2024-04-23published 2023-01-03GHSA-rq2w-37h9-vg94CVE-2022-45143same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDays to revision 476
2024-04-23published 2023-01-03GHSA-rq2w-37h9-vg94CVE-2022-45143same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaDays to revision 476
2024-04-23published 2023-01-03GHSA-rq2w-37h9-vg94CVE-2022-45143same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-utilDays to revision 476
2024-04-23published 2022-11-01GHSA-p22x-g9px-3945CVE-2022-42252same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-corenot dated
2024-04-23published 2022-11-01GHSA-p22x-g9px-3945CVE-2022-42252same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyotenot dated
Mon 22 Apr 2024· 4 advisory changes
2024-04-22published 2022-02-09GHSA-484q-784p-8m5hmoderatenot named as affected when the advisory was published, now names org.keycloak:keycloak-server-spi-private and 1 morenot dated
2024-04-22published 2022-02-09GHSA-484q-784p-8m5hCVE-2020-10776same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.keycloak:keycloak-server-spi-privatenot dated
2024-04-22published 2022-02-09GHSA-484q-784p-8m5hCVE-2020-10776same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.keycloak:keycloak-servicesnot dated
2024-04-22published 2024-01-31GHSA-6hwg-w5jg-9c6xCVE-2020-27534moderatenot named as affected when the advisory was published, now names github.com/docker/dockerDays to revision 82
2024-04-22published 2022-05-24GHSA-hf4p-4j9r-3cvxCVE-2019-16355moderatenot named as affected when the advisory was published, now names github.com/astaxie/beegoDays to revision 699
Thu 18 Apr 2024· 9 advisory changes
2024-04-18published 2022-05-13 to 2023-02-209 rows, one per advisory and package2 bandsnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core and 5 moreDays to revision 423
2024-04-18published 2023-02-20GHSA-hfrx-6qgj-fp6cCVE-2023-24998same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDays to revision 423
2024-04-18published 2023-02-20GHSA-hfrx-6qgj-fp6cCVE-2023-24998same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 423
2024-04-18published 2022-05-13GHSA-9hg2-395j-83rmCVE-2017-5651same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-corenot dated
2024-04-18published 2022-05-13GHSA-9hg2-395j-83rmCVE-2017-5651same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyotenot dated
2024-04-18published 2022-05-13GHSA-3vx3-xf6q-r5xpCVE-2017-5648same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-corenot dated
2024-04-18published 2022-05-13GHSA-3vx3-xf6q-r5xpCVE-2017-5648same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinanot dated
2024-04-18published 2022-05-13GHSA-4v3g-g84w-hv7rCVE-2016-5018same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-jaspernot dated
2024-04-18published 2022-05-13GHSA-4v3g-g84w-hv7rCVE-2016-5018same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.tomcat:jaspernot dated
1 more row in this change is not listed here. Open all 9 rows
Wed 17 Apr 2024· 6 advisory changes
2024-04-17published 2022-05-13GHSA-cw54-59pw-4g8cCVE-2016-8735criticalnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaDays to revision 706
2024-04-17published 2021-05-06GHSA-35jh-r3h4-6jhmhighnot named as affected when the advisory was published, now names lodash-template and 1 morenot dated
2024-04-17published 2021-05-06GHSA-35jh-r3h4-6jhmCVE-2021-23337same package registry as the line abovehighnot named as affected when the advisory was published, now names lodash-templatenot dated
2024-04-17published 2021-05-06GHSA-35jh-r3h4-6jhmCVE-2021-23337same package registry as the line abovehighnot named as affected when the advisory was published, now names lodash.templatenot dated
2024-04-17published 2024-03-18GHSA-wjv8-pxr6-5f4rmoderatenot named as affected when the advisory was published, now names friendsofsymfony1/swiftmailer and 1 moreDays to revision 30
2024-04-17published 2024-03-18GHSA-wjv8-pxr6-5f4rCVE-2024-28859same package registry as the line abovemoderatenot named as affected when the advisory was published, now names friendsofsymfony1/swiftmailerDays to revision 30
2024-04-17published 2024-03-18GHSA-wjv8-pxr6-5f4rCVE-2024-28859same package registry as the line abovemoderatenot named as affected when the advisory was published, now names swiftmailer/swiftmailerDays to revision 30
2024-04-17published 2024-04-03GHSA-qjfw-cvjf-f4fmCVE-2024-2653highnot named as affected when the advisory was published, now names amphp/http-clientDays to revision 14
Tue 16 Apr 2024· 1 advisory change
2024-04-16published 2022-05-13GHSA-7vpq-g998-qpv7CVE-2014-0193moderatenot named as affected when the advisory was published, now names io.netty:netty-allDays to revision 705
Fri 12 Apr 2024· 2 advisory changes
2024-04-12published 2024-01-03GHSA-264p-99wq-f4j6CVE-2024-21634highnot named as affected when the advisory was published, now names software.amazon.ion:ion-javaDays to revision 100
2024-04-12published 2023-06-12GHSA-xm2m-2q6h-22jwCVE-2023-34468highnot named as affected when the advisory was published, now names org.apache.nifi:nifi-dbcp-service-narDays to revision 305
Thu 11 Apr 2024· 3 advisory changes
2024-04-11published 2024-03-13GHSA-7w75-32cg-r6g2CVE-2024-24549moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 29
2024-04-11published 2024-03-13GHSA-v682-8vv8-vpwrmoderatenot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocket and 1 moreDays to revision 29
2024-04-11published 2024-03-13GHSA-v682-8vv8-vpwrCVE-2024-23672same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocketDays to revision 29
2024-04-11published 2024-03-13GHSA-v682-8vv8-vpwrCVE-2024-23672same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-websocketDays to revision 29
Wed 10 Apr 2024· 4 advisory changes
2024-04-10published 2024-03-19GHSA-9mg4-v392-8j68CVE-2023-50966moderatenot named as affected when the advisory was published, now names joseDays to revision 22
2024-04-10published 2024-03-22GHSA-f5x3-32g6-xq36CVE-2024-28863moderatenot named as affected when the advisory was published, now names tarDays to revision 19
2024-04-10published 2022-05-13GHSA-pjqh-2jcc-5j84CVE-2017-8028highnot named as affected when the advisory was published, now names org.springframework.ldap:spring-ldap-corenot dated
2024-04-10published 2023-10-16GHSA-67hx-6x53-jw92CVE-2023-45133criticalnot named as affected when the advisory was published, now names babel-traverseDays to revision 177
Mon 1 Apr 2024· 5 advisory changes
2024-04-01published 2024-04-01GHSA-r65j-6h5f-4f92CVE-2024-31033moderatenot named as affected when the advisory was published, now names io.jsonwebtoken:jjwt-implDays to revision 1
2024-04-01published 2023-10-10GHSA-qppj-fm5r-hxr3moderatenot named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core and 3 moreDays to revision 174
2024-04-01published 2023-10-10GHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.typesafe.akka:akka-http-coreDays to revision 174
2024-04-01published 2023-10-10GHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core_2.11Days to revision 174
2024-04-01published 2023-10-10GHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core_2.12Days to revision 174
2024-04-01published 2023-10-10GHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core_2.13Days to revision 174
Wed 20 Mar 2024· 1 advisory change
2024-03-20published 2024-02-01GHSA-xw73-rw38-6vjcCVE-2024-24557moderatenot named as affected when the advisory was published, now names github.com/docker/dockerDays to revision 48
Thu 14 Mar 2024· 32 advisory changes
2024-03-14published 2024-03-04GHSA-h59x-p739-982cCVE-2024-28088lownot named as affected when the advisory was published, now names langchain-coreDays to revision 11
2024-03-14published 2019-05-14 to 2024-01-0619 rows, one per advisory and package3 bandsnot named as affected when the advisory was published, now names org.apache.activemq:activemq-web-demo and 12 moreDays to revision 68 to 668
2024-03-14published 2022-05-17GHSA-34fp-xvxp-rg22CVE-2012-6551same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.activemq:activemq-web-demoDays to revision 668
2024-03-14published 2022-05-17GHSA-34fp-xvxp-rg22CVE-2012-6551same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.activemq:apache-activemqDays to revision 668
2024-03-14published 2022-04-22GHSA-c2cp-3xj9-97w9CVE-2022-22969same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.springframework.security.oauth:spring-security-oauth2not dated
2024-03-14published 2023-11-23GHSA-wjxj-5m7g-mg7qCVE-2023-33202same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-ext-jdk15onDays to revision 112
2024-03-14published 2023-11-23GHSA-wjxj-5m7g-mg7qCVE-2023-33202same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-ext-jdk16Days to revision 112
2024-03-14published 2023-11-23GHSA-wjxj-5m7g-mg7qCVE-2023-33202same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk14Days to revision 112
2024-03-14published 2023-11-23GHSA-wjxj-5m7g-mg7qCVE-2023-33202same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15Days to revision 112
2024-03-14published 2023-11-23GHSA-wjxj-5m7g-mg7qCVE-2023-33202same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onDays to revision 112
11 more rows in this change are not listed here. Open all 19 rows
2024-03-14published 2024-03-12GHSA-5fxj-whcv-crrchighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.linux-arm and 11 moreDays to revision 2
2024-03-14published 2024-03-12GHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.linux-armDays to revision 2
2024-03-14published 2024-03-12GHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.linux-arm64Days to revision 2
2024-03-14published 2024-03-12GHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.linux-musl-armDays to revision 2
2024-03-14published 2024-03-12GHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.linux-musl-arm64Days to revision 2
2024-03-14published 2024-03-12GHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.linux-musl-x64Days to revision 2
2024-03-14published 2024-03-12GHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.linux-x64Days to revision 2
2024-03-14published 2024-03-12GHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.osx-arm64Days to revision 2
2024-03-14published 2024-03-12GHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.osx-x64Days to revision 2
4 more rows in this change are not listed here. Open all 12 rows
Tue 12 Mar 2024· 1 advisory change
2024-03-12published 2024-02-09GHSA-xrj7-x7gp-wwqrCVE-2023-50298moderatenot named as affected when the advisory was published, now names org.apache.solr:solr-solrjDays to revision 32
Wed 6 Mar 2024· 5 advisory changes
2024-03-06published 2023-10-24GHSA-cqpc-x2c6-2gmfCVE-2023-41339moderatenot named as affected when the advisory was published, now names org.geoserver.web:gs-web-appDays to revision 134
2024-03-06published 2022-05-13GHSA-86p9-x5pw-94qxCVE-2017-9096highnot named as affected when the advisory was published, now names com.lowagie:itextnot dated
2024-03-06published 2024-03-06GHSA-m757-p8rv-4q93CVE-2023-50740moderatenot named as affected when the advisory was published, now names org.apache.linkis:linkisDays to revision 0
2024-03-06published 2024-02-10GHSA-4w4v-5hc9-xrr2highnot named as affected when the advisory was published, now names org.webjars.bower:angular and 1 moreDays to revision 25
2024-03-06published 2024-02-10GHSA-4w4v-5hc9-xrr2CVE-2024-21490same package registry as the line abovehighnot named as affected when the advisory was published, now names org.webjars.bower:angularDays to revision 25
2024-03-06published 2024-02-10GHSA-4w4v-5hc9-xrr2CVE-2024-21490same package registry as the line abovehighnot named as affected when the advisory was published, now names org.webjars.npm:angularDays to revision 25
Tue 5 Mar 2024· 12 advisory changes
2024-03-05published 2023-10-10GHSA-qppj-fm5r-hxr3moderatenot named as affected when the advisory was published, now names org.eclipse.jetty.http2:http2-common and 3 moreDays to revision 147
2024-03-05published 2023-10-10GHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.jetty.http2:http2-commonDays to revision 147
2024-03-05published 2023-10-10GHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.jetty.http2:http2-serverDays to revision 147
2024-03-05published 2023-10-10GHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.jetty.http2:jetty-http2-commonDays to revision 147
2024-03-05published 2023-10-10GHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.jetty.http2:jetty-http2-serverDays to revision 147
2024-03-05published 2023-11-30GHSA-j24h-xcpc-9jw8moderatenot named as affected when the advisory was published, now names org.eclipse.jdt:org.eclipse.jdt.ui and 7 moreDays to revision 96
2024-03-05published 2023-11-30GHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.jdt:org.eclipse.jdt.uiDays to revision 96
2024-03-05published 2023-11-30GHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.core.runtimeDays to revision 96
2024-03-05published 2023-11-30GHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.jfaceDays to revision 96
2024-03-05published 2023-11-30GHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.platformDays to revision 96
2024-03-05published 2023-11-30GHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.ui.formsDays to revision 96
2024-03-05published 2023-11-30GHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.ui.ideDays to revision 96
2024-03-05published 2023-11-30GHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.ui.workbenchDays to revision 96
2024-03-05published 2023-11-30GHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.urischemeDays to revision 96
Mon 4 Mar 2024· 1 advisory change
2024-03-04published 2024-02-27GHSA-p5q9-86w4-2xr5CVE-2023-51747highnot named as affected when the advisory was published, now names org.apache.james:james-serverDays to revision 6
Fri 1 Mar 2024· 4 advisory changes
2024-03-01published 2024-02-272 bandsnot named as affected when the advisory was published, now names actionpackDays to revision 3
2024-03-01published 2024-02-27GHSA-9822-6m93-xqf4CVE-2024-26143same package registry as the line abovemoderatesame change as the line aboveDays to revision 3
2024-03-01published 2024-02-27GHSA-jjhx-jhvp-74wqCVE-2024-26142same package registry as the line abovelowsame change as the line aboveDays to revision 3
2024-03-01published 2024-02-27GHSA-8h22-8cf7-hq6gCVE-2024-26144moderatenot named as affected when the advisory was published, now names activestorageDays to revision 3
2024-03-01published 2018-10-16GHSA-r53v-vm87-f72cCVE-2014-3596moderatenot named as affected when the advisory was published, now names axis:axisnot dated
Mon 26 Feb 2024· 3 advisory changes
2024-02-26published 2021-05-13GHSA-5pv8-ppvj-4h68moderatenot named as affected when the advisory was published, now names lexik/jwt-authentication-bundle and 2 morenot dated
2024-02-26published 2021-05-13GHSA-5pv8-ppvj-4h68CVE-2021-21424same package registry as the line abovemoderatenot named as affected when the advisory was published, now names lexik/jwt-authentication-bundlenot dated
2024-02-26published 2021-05-13GHSA-5pv8-ppvj-4h68CVE-2021-21424same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/maker-bundlenot dated
2024-02-26published 2021-05-13GHSA-5pv8-ppvj-4h68CVE-2021-21424same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/symfonynot dated
Thu 22 Feb 2024· 2 advisory changes
2024-02-22published 2024-02-22GHSA-97m3-52wr-xvv2criticalnot named as affected when the advisory was published, now names phenx/php-svg-libDays to revision 0
2024-02-22published 2021-08-03GHSA-5fg8-2547-mr8qCVE-2021-32796moderatenot named as affected when the advisory was published, now names @xmldom/xmldomnot dated
Tue 20 Feb 2024· 1 advisory change
2024-02-20published 2024-02-07GHSA-fq6h-4g8v-qqvmCVE-2024-24815moderatenot named as affected when the advisory was published, now names ckeditor/ckeditorDays to revision 13
Wed 14 Feb 2024· 10 advisory changes
2024-02-14published 2021-04-26GHSA-gwrp-pvrq-jmwvmoderatenot named as affected when the advisory was published, now names com.cosium.vet:vet and 8 morenot dated
2024-02-14published 2021-04-26GHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.cosium.vet:vetnot dated
2024-02-14published 2021-04-26GHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.diamondq.common:common-thirdparty.jcasbinnot dated
2024-02-14published 2021-04-26GHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.liferay:com.liferay.sass.compiler.jsassnot dated
2024-02-14published 2021-04-26GHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.virjar:ratel-apinot dated
2024-02-14published 2021-04-26GHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.hasor:cobble-langnot dated
2024-02-14published 2021-04-26GHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.commons:commons-ionot dated
2024-02-14published 2021-04-26GHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.servicemix.bundles:org.apache.servicemix.bundles.commons-ionot dated
2024-02-14published 2021-04-26GHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.checkerframework.annotatedlib:commons-ionot dated
1 more row in this change is not listed here. Open all 9 rows
2024-02-14published 2019-11-12GHSA-g996-q5r8-w7g2CVE-2019-10909moderatenot named as affected when the advisory was published, now names drupal/drupalnot dated
Mon 12 Feb 2024· 5 advisory changes
2024-02-12published 2022-05-242 bandsnot named as affected when the advisory was published, now names magento/product-community-editionDays to revision 629
2024-02-12published 2022-05-24GHSA-wmrg-w9vg-7jqxCVE-2019-7865same package registry as the line abovehighsame change as the line aboveDays to revision 629
2024-02-12published 2022-05-24GHSA-6qh6-v99h-vh4cCVE-2019-7876same package registry as the line abovehighsame change as the line aboveDays to revision 629
2024-02-12published 2022-05-24GHSA-mgfr-44wv-hqv6CVE-2019-7938same package registry as the line abovemoderatesame change as the line aboveDays to revision 629
2024-02-12published 2022-05-24GHSA-mgfr-44wv-hqv6moderatenot named as affected when the advisory was published, now names magento/magento1ce and 1 moreDays to revision 629
2024-02-12published 2022-05-24GHSA-mgfr-44wv-hqv6CVE-2019-7938same package registry as the line abovemoderatenot named as affected when the advisory was published, now names magento/magento1ceDays to revision 629
2024-02-12published 2022-05-24GHSA-mgfr-44wv-hqv6CVE-2019-7938same package registry as the line abovemoderatenot named as affected when the advisory was published, now names magento/magento1eeDays to revision 629
Fri 9 Feb 2024· 10 advisory changes
2024-02-09published 2023-06-09 to 2023-10-102 bandsnot named as affected when the advisory was published, now names github.com/apple/swift-nio-http2Days to revision 121 to 244
2024-02-09published 2023-10-10GHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatesame change as the line aboveDays to revision 121
2024-02-09published 2023-06-09GHSA-q36x-r5x4-h4q6CVE-2022-0618same package registry as the line abovehighsame change as the line aboveDays to revision 244
2024-02-09published 2023-10-05 to 2024-01-03moderatenot named as affected when the advisory was published, now names github.com/vapor/vaporDays to revision 36 to 126
2024-02-09published 2023-10-05GHSA-3mwq-h3g6-ffhmCVE-2023-44386same package registry as the line abovemoderatesame change as the line aboveDays to revision 126
2024-02-09published 2024-01-03GHSA-r6r4-5pr8-gjcpCVE-2024-21631same package registry as the line abovemoderatesame change as the line aboveDays to revision 36
2024-02-09published 2023-08-31GHSA-c2cc-3569-6jh2CVE-2023-39138highnot named as affected when the advisory was published, now names github.com/weichsel/zipfoundationDays to revision 162
2024-02-09published 2023-08-31GHSA-g454-wj9r-jpg4CVE-2023-39135highnot named as affected when the advisory was published, now names github.com/marmelroy/zipDays to revision 162
2024-02-09published 2023-08-29GHSA-vxvm-qww3-2fh7CVE-2021-32050moderatenot named as affected when the advisory was published, now names github.com/mongodb/mongo-swift-driverDays to revision 163
2024-02-09published 2023-07-14GHSA-jq43-q8mx-r7mqCVE-2022-23465highnot named as affected when the advisory was published, now names github.com/migueldeicaza/swifttermDays to revision 209
2024-02-09published 2023-06-09GHSA-r6ww-5963-7r95CVE-2022-24777highnot named as affected when the advisory was published, now names github.com/grpc/grpc-swiftDays to revision 244
2024-02-09published 2023-12-06GHSA-5844-q3fc-56rhCVE-2023-26154moderatenot named as affected when the advisory was published, now names github.com/pubnub/swiftDays to revision 65
Thu 8 Feb 2024· 18 advisory changes
2024-02-08published 2021-06-21 to 2022-05-2418 rows, one per advisory and package4 bandsnot named as affected when the advisory was published, now names symfony/security and 8 moreDays to revision 625 to 645
2024-02-08published 2022-05-24GHSA-q87v-q8fw-gmj5CVE-2017-11365same package registry as the line abovecriticalnot named as affected when the advisory was published, now names symfony/securityDays to revision 625
2024-02-08published 2022-05-24GHSA-q87v-q8fw-gmj5CVE-2017-11365same package registry as the line abovecriticalnot named as affected when the advisory was published, now names symfony/security-coreDays to revision 625
2024-02-08published 2022-05-05GHSA-22pv-7v9j-hqxpCVE-2013-4752same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/http-foundationDays to revision 645
2024-02-08published 2022-05-17GHSA-jjx5-fq5g-8xpcCVE-2016-1902same package registry as the line abovehighnot named as affected when the advisory was published, now names symfony/securityDays to revision 633
2024-02-08published 2022-05-17GHSA-jjx5-fq5g-8xpcCVE-2016-1902same package registry as the line abovehighnot named as affected when the advisory was published, now names symfony/security-coreDays to revision 633
2024-02-08published 2022-05-13GHSA-8wgj-6wx8-h5hqCVE-2018-14773same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/symfonyDays to revision 637
2024-02-08published 2022-05-14GHSA-g4g7-q726-v5hgCVE-2018-11406same package registry as the line abovehighnot named as affected when the advisory was published, now names symfony/securityDays to revision 636
2024-02-08published 2022-05-14GHSA-g4g7-q726-v5hgCVE-2018-11406same package registry as the line abovehighnot named as affected when the advisory was published, now names symfony/security-bundleDays to revision 636
10 more rows in this change are not listed here. Open all 18 rows
Wed 7 Feb 2024· 22 advisory changes
2024-02-07published 2019-11-12 to 2022-05-2421 rows, one per advisory and package3 bandsnot named as affected when the advisory was published, now names symfony/yaml and 11 moreDays to revision 624 to 644
2024-02-07published 2022-05-17GHSA-7w53-hfpw-rg3gCVE-2013-1397same package registry as the line abovehighnot named as affected when the advisory was published, now names symfony/yamlDays to revision 632
2024-02-07published 2022-05-24GHSA-v59p-p692-v382CVE-2015-0270same package registry as the line abovecriticalnot named as affected when the advisory was published, now names zendframework/zend-dbDays to revision 624
2024-02-07published 2022-05-17GHSA-xp8p-9rq5-4wgvCVE-2015-5161same package registry as the line abovemoderatenot named as affected when the advisory was published, now names zendframework/zendframework1Days to revision 632
2024-02-07published 2022-05-05GHSA-q8j7-fjh7-25v5CVE-2013-4751same package registry as the line abovehighnot named as affected when the advisory was published, now names symfony/symfonyDays to revision 644
2024-02-07published 2022-05-14GHSA-p9hp-3gpv-52w3CVE-2016-6233same package registry as the line abovecriticalnot named as affected when the advisory was published, now names zendframework/zendframework1Days to revision 635
2024-02-07published 2022-05-13GHSA-j6c3-3c4w-qv8pCVE-2013-7341same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsDays to revision 636
2024-02-07published 2021-08-19GHSA-c5c9-8c6m-727vCVE-2021-32768same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-07published 2022-05-24GHSA-r6fv-56gp-j3r4CVE-2019-12748same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsDays to revision 624
13 more rows in this change are not listed here. Open all 21 rows
2024-02-07published 2022-09-25GHSA-c429-5p7v-vgjpCVE-2020-36604highnot named as affected when the advisory was published, now names hoeknot dated
Tue 6 Feb 2024· 20 advisory changes
2024-02-06published 2024-02-02GHSA-9gh8-877r-g477CVE-2024-22533criticalnot named as affected when the advisory was published, now names com.ibeetl:beetl-coreDays to revision 5
2024-02-06published 2019-10-10 to 2022-05-2419 rows, one per advisory and package3 bandsnot named as affected when the advisory was published, now names symfony/form and 11 moreDays to revision 623 to 634
2024-02-06published 2022-05-14GHSA-x3cf-w64x-4cp2CVE-2018-19789same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/formDays to revision 634
2024-02-06published 2022-05-17GHSA-83c3-qx27-2rwrCVE-2012-6431same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/http-foundationDays to revision 630
2024-02-06published 2022-05-17GHSA-83c3-qx27-2rwrCVE-2012-6431same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/routingDays to revision 630
2024-02-06published 2022-05-17GHSA-83c3-qx27-2rwrCVE-2012-6431same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/securityDays to revision 630
2024-02-06published 2020-03-30GHSA-m884-279h-32v2CVE-2020-5274same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/error-handlernot dated
2024-02-06published 2020-03-30GHSA-m884-279h-32v2CVE-2020-5274same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/symfonynot dated
2024-02-06published 2022-05-17GHSA-5qp6-78pr-gv8cCVE-2013-4701same package registry as the line abovehighnot named as affected when the advisory was published, now names typo3/cmsDays to revision 630
2024-02-06published 2022-05-17GHSA-vc74-c4m6-9979CVE-2013-7082same package registry as the line abovemoderatenot named as affected when the advisory was published, now names neos/flowDays to revision 631
11 more rows in this change are not listed here. Open all 19 rows
Mon 5 Feb 2024· 46 advisory changes
2024-02-05published 2018-09-13 to 2022-10-0646 rows, one per advisory and package4 bandsnot named as affected when the advisory was published, now names yiisoft/yii2-elasticsearch and 15 moreDays to revision 622 to 632
2024-02-05published 2022-05-24GHSA-m2p5-fwp2-qcw2CVE-2018-8074same package registry as the line abovehighnot named as affected when the advisory was published, now names yiisoft/yii2-elasticsearchDays to revision 622
2024-02-05published 2018-11-21GHSA-g68x-vvqq-pvw3CVE-2018-17960same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-05published 2018-11-21GHSA-g68x-vvqq-pvw3CVE-2018-17960same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cms-corenot dated
2024-02-05published 2018-09-13GHSA-pj7m-g53m-7638CVE-2018-14041same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-05published 2018-09-13GHSA-pj7m-g53m-7638CVE-2018-14041same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cms-corenot dated
2024-02-05published 2021-10-05GHSA-657m-v5vm-f6rwCVE-2021-41113same package registry as the line abovehighnot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-05published 2021-10-05GHSA-m2jh-fxw4-gphmCVE-2021-41114same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-05published 2021-07-22GHSA-rgcg-28xm-8mmwCVE-2021-32669same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
38 more rows in this change are not listed here. Open all 46 rows
Fri 2 Feb 2024· 14 advisory changes
2024-02-02published 2023-03-23 to 2023-04-132 bandsnot named as affected when the advisory was published, now names org.springframework:spring-expressionDays to revision 295 to 316
2024-02-02published 2023-04-13GHSA-wxqc-pxw9-g2p8CVE-2023-20863same package registry as the line abovehighsame change as the line aboveDays to revision 295
2024-02-02published 2023-03-23GHSA-564r-hj7v-mcr5CVE-2023-20861same package registry as the line abovemoderatesame change as the line aboveDays to revision 316
2024-02-02published 2022-04-15GHSA-g5mm-vmx4-3rg7CVE-2022-22968highnot named as affected when the advisory was published, now names org.springframework:spring-contextnot dated
2024-02-02published 2022-05-13GHSA-hh26-6xwr-ggv7CVE-2022-22970highnot named as affected when the advisory was published, now names org.springframework:spring-beansnot dated
2024-02-02published 2022-05-13GHSA-rqph-vqwm-22vcCVE-2022-22971moderatenot named as affected when the advisory was published, now names org.springframework:spring-messagingnot dated
2024-02-02published 2021-03-232 bandsnot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-02published 2021-03-23GHSA-x79j-wgqv-g8h2CVE-2021-21358same package registry as the line abovemoderatesame change as the line abovenot dated
2024-02-02published 2021-03-23GHSA-qx3w-4864-94chCVE-2021-21339same package registry as the line abovemoderatesame change as the line abovenot dated
2024-02-02published 2021-03-23GHSA-x7hc-x7fm-f7qhCVE-2021-21370same package registry as the line abovemoderatesame change as the line abovenot dated
2024-02-02published 2021-03-23GHSA-2r6j-862c-m2v2CVE-2021-21355same package registry as the line abovehighsame change as the line abovenot dated
2024-02-02published 2021-03-23GHSA-fjh3-g8gq-9q92CVE-2021-21340same package registry as the line abovemoderatesame change as the line abovenot dated
2024-02-02published 2021-03-232 bandsnot named as affected when the advisory was published, now names typo3/cms-corenot dated
2024-02-02published 2021-03-23GHSA-x79j-wgqv-g8h2CVE-2021-21358same package registry as the line abovemoderatesame change as the line abovenot dated
2024-02-02published 2021-03-23GHSA-x7hc-x7fm-f7qhCVE-2021-21370same package registry as the line abovemoderatesame change as the line abovenot dated
2024-02-02published 2021-03-23GHSA-2r6j-862c-m2v2CVE-2021-21355same package registry as the line abovehighsame change as the line abovenot dated
2024-02-02published 2021-03-23GHSA-fjh3-g8gq-9q92CVE-2021-21340same package registry as the line abovemoderatesame change as the line abovenot dated
Thu 1 Feb 2024· 8 advisory changes
2024-02-01published 2020-10-08 to 2022-05-248 rows, one per advisory and package2 bandsnot named as affected when the advisory was published, now names zendframework/zend-http and 3 moreDays to revision 618
2024-02-01published 2022-05-24GHSA-5957-5crx-79jxCVE-2015-3154same package registry as the line abovemoderatenot named as affected when the advisory was published, now names zendframework/zend-httpDays to revision 618
2024-02-01published 2022-05-24GHSA-5957-5crx-79jxCVE-2015-3154same package registry as the line abovemoderatenot named as affected when the advisory was published, now names zendframework/zendframework1Days to revision 618
2024-02-01published 2021-03-23GHSA-4jhw-2p6j-5wmpCVE-2021-21338same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-01published 2021-03-23GHSA-3vg7-jw9m-pc3fCVE-2021-21357same package registry as the line abovehighnot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-01published 2021-03-23GHSA-3vg7-jw9m-pc3fCVE-2021-21357same package registry as the line abovehighnot named as affected when the advisory was published, now names typo3/cms-corenot dated
2024-02-01published 2020-12-21GHSA-vqqx-jw6p-q3rfCVE-2020-26227same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-01published 2020-10-08GHSA-7733-hjv6-4h47CVE-2020-15241same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-01published 2020-10-08GHSA-7733-hjv6-4h47CVE-2020-15241same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cms-corenot dated
Thu 25 Jan 2024· 1 advisory change
2024-01-25published 2022-05-14GHSA-vjwc-5hfh-2vv5CVE-2015-0226highnot named as affected when the advisory was published, now names org.apache.wss4j:wss4j-ws-security-domnot dated
Wed 24 Jan 2024· 7 advisory changes
2024-01-24published 2020-07-15GHSA-p6mc-m468-83gwhighnot named as affected when the advisory was published, now names lodash.pick and 4 morenot dated
2024-01-24published 2020-07-15GHSA-p6mc-m468-83gwCVE-2020-8203same package registry as the line abovehighnot named as affected when the advisory was published, now names lodash.picknot dated
2024-01-24published 2020-07-15GHSA-p6mc-m468-83gwCVE-2020-8203same package registry as the line abovehighnot named as affected when the advisory was published, now names lodash.setnot dated
2024-01-24published 2020-07-15GHSA-p6mc-m468-83gwCVE-2020-8203same package registry as the line abovehighnot named as affected when the advisory was published, now names lodash.setwithnot dated
2024-01-24published 2020-07-15GHSA-p6mc-m468-83gwCVE-2020-8203same package registry as the line abovehighnot named as affected when the advisory was published, now names lodash.updatenot dated
2024-01-24published 2020-07-15GHSA-p6mc-m468-83gwCVE-2020-8203same package registry as the line abovehighnot named as affected when the advisory was published, now names lodash.updatewithnot dated
2024-01-24published 2019-12-17moderatenot named as affected when the advisory was published, now names contao/contaonot dated
2024-01-24published 2019-12-17GHSA-jc43-qrrp-98f5CVE-2019-19714same package registry as the line abovemoderatesame change as the line abovenot dated
2024-01-24published 2019-12-17GHSA-4mvc-qc5w-v5qrCVE-2019-19712same package registry as the line abovemoderatesame change as the line abovenot dated
Tue 23 Jan 2024· 2 advisory changes
2024-01-23published 2023-12-27 to 2024-01-102 bandsnot named as affected when the advisory was published, now names gopkg.in/src-d/go-git.v4Days to revision 13 to 27
2024-01-23published 2024-01-10GHSA-449p-3h89-pw88CVE-2023-49569same package registry as the line abovecriticalsame change as the line aboveDays to revision 13
2024-01-23published 2023-12-27GHSA-mw99-9chc-xw7rCVE-2023-49568same package registry as the line abovehighsame change as the line aboveDays to revision 27

Counted in advisories, never added to the CVE and KEV figures. This kind is counted once per advisory and per package, so one advisory that named four further packages counts four times. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →