Skip to content

Package added to advisory

What a record said when it was published, what it says now, and the commit that changed it.

1,695 advisory changes · newest first · grouped by day

SinceClear all
ChangedSourceRows
Counted changes of "Package added to advisory", newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.Advisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Tue 23 Jan 2024· 3 advisory changes
2024-01-23published 2021-05-18GHSA-2v6x-frw8-7r7fCVE-2019-17110moderatenot named as affected when the advisory was published, now names k8s.io/kube-state-metricsnot dated
2024-01-23published 2018-09-13GHSA-7mvr-5x2g-wfc8CVE-2018-14042moderatenot named as affected when the advisory was published, now names bootstrapnot dated
2024-01-23published 2024-01-15GHSA-rxgg-273w-rfw7CVE-2023-46226highnot named as affected when the advisory was published, now names apache-iotdbDays to revision 8
Fri 19 Jan 2024· 1 advisory change
2024-01-19published 2024-01-09GHSA-g777-crp9-m27gCVE-2023-50974moderatenot named as affected when the advisory was published, now names appwriteDays to revision 10
Tue 16 Jan 2024· 3 advisory changes
2024-01-16published 2023-09-19GHSA-6qjf-7g3j-qx25CVE-2023-37611moderatenot named as affected when the advisory was published, now names neos/media-browserDays to revision 120
2024-01-16published 2023-06-26GHSA-257q-pv89-v3xvCVE-2020-23064moderatenot named as affected when the advisory was published, now names org.webjars.npm:jqueryDays to revision 204
2024-01-16published 2024-01-03GHSA-vfxf-76hv-v4w4highnot named as affected when the advisory was published, now names github.com/gravitational/teleportDays to revision 13
Thu 11 Jan 2024· 1 advisory change
2024-01-11published 2022-05-24GHSA-j49x-jjmj-9fqjCVE-2019-8227moderatenot named as affected when the advisory was published, now names magento/coreDays to revision 597
Tue 9 Jan 2024· 2 advisory changes
2024-01-09published 2023-12-09GHSA-mvc8-6ffp-jrx5CVE-2023-6394highnot named as affected when the advisory was published, now names io.quarkus:quarkus-smallrye-graphql-clientDays to revision 32
2024-01-09published 2023-11-23GHSA-wjxj-5m7g-mg7qCVE-2023-33202moderatenot named as affected when the advisory was published, now names org.bouncycastle:bcpkix-jdk18onDays to revision 47
Thu 4 Jan 2024· 2 advisory changes
2024-01-04published 2022-05-14GHSA-44hv-jjx7-qfjgCVE-2016-6795criticalnot named as affected when the advisory was published, now names org.apache.struts:struts2-convention-pluginnot dated
2024-01-04published 2022-05-17GHSA-wm8w-qp2f-728qCVE-2016-4433highnot named as affected when the advisory was published, now names org.apache.struts.xwork:xwork-coreDays to revision 598
Thu 28 Dec 2023· 5 advisory changes
2023-12-28published 2022-05-14 to 2022-05-172 bandsnot named as affected when the advisory was published, now names org.apache.struts:struts2-rest-pluginnot dated
2023-12-28published 2022-05-14GHSA-4prj-vw9j-v6prCVE-2016-4438same package registry as the line abovecriticalsame change as the line abovenot dated
2023-12-28published 2022-05-17GHSA-j7h6-xr7g-m2c5CVE-2013-4316same package registry as the line abovehighsame change as the line abovenot dated
2023-12-28published 2022-05-14 to 2022-05-172 bandsnot named as affected when the advisory was published, now names org.apache.struts.xwork:xwork-corenot dated
2023-12-28published 2022-05-17GHSA-q2cg-xf9p-h457CVE-2015-1831same package registry as the line abovehighsame change as the line abovenot dated
2023-12-28published 2022-05-14GHSA-vrwc-qjmw-5rjmCVE-2014-0094same package registry as the line abovemoderatesame change as the line abovenot dated
2023-12-28published 2022-05-14GHSA-pw8r-x2qm-3h5mCVE-2013-2135same package registry as the line abovehighsame change as the line abovenot dated
Wed 27 Dec 2023· 7 advisory changes
2023-12-27published 2022-05-04 to 2022-05-173 bandsnot named as affected when the advisory was published, now names org.apache.struts.xwork:xwork-coreDays to revision 603
2023-12-27published 2022-05-14GHSA-gqqm-564f-vvxqCVE-2013-2134same package registry as the line abovehighsame change as the line abovenot dated
2023-12-27published 2022-05-13GHSA-7ghm-rpc7-p7g5CVE-2013-2115same package registry as the line abovehighsame change as the line abovenot dated
2023-12-27published 2022-05-14GHSA-737w-mh58-cxjpCVE-2013-1966same package registry as the line abovehighsame change as the line abovenot dated
2023-12-27published 2022-05-17GHSA-hrgc-54mv-58gvCVE-2012-4387same package registry as the line abovemoderatesame change as the line abovenot dated
2023-12-27published 2022-05-14GHSA-mwrx-hx6x-3hhvCVE-2012-0838same package registry as the line abovehighsame change as the line abovenot dated
2023-12-27published 2022-05-04GHSA-4wrr-9h5r-m92wCVE-2012-0391same package registry as the line abovecriticalsame change as the line aboveDays to revision 603
2023-12-27published 2022-05-04GHSA-4wrr-9h5r-m92wCVE-2012-0391criticalnot named as affected when the advisory was published, now names org.apache.struts:struts2-coreDays to revision 603
Fri 22 Dec 2023· 2 advisory changes
2023-12-22published 2022-05-13GHSA-f5ch-36rg-vfccCVE-2017-7662highnot named as affected when the advisory was published, now names org.apache.cxf.fediz:fediz-oidcnot dated
2023-12-22published 2022-05-24GHSA-6jfc-mc97-c7wgCVE-2019-10354moderatenot named as affected when the advisory was published, now names org.kohsuke.stapler:stapler-parentnot dated
Thu 21 Dec 2023· 5 advisory changes
2023-12-21published 2023-10-10 to 2023-11-282 bandsnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDays to revision 23 to 72
2023-12-21published 2023-10-10GHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatesame change as the line aboveDays to revision 72
2023-12-21published 2023-10-10GHSA-g8pj-r55q-5c2vCVE-2023-42795same package registry as the line abovemoderatesame change as the line aboveDays to revision 72
2023-12-21published 2023-11-28GHSA-fccv-jmmp-qg76CVE-2023-46589same package registry as the line abovehighsame change as the line aboveDays to revision 23
2023-12-21published 2023-10-10GHSA-r6j3-px5g-cq3xCVE-2023-45648same package registry as the line abovemoderatesame change as the line aboveDays to revision 72
2023-12-21published 2022-05-14GHSA-5hfp-964w-5vgmCVE-2018-1000997moderatenot named as affected when the advisory was published, now names org.kohsuke.stapler:stapler-parentnot dated
Wed 20 Dec 2023· 6 advisory changes
2023-12-20published 2022-05-14 to 2022-05-173 bandsnot named as affected when the advisory was published, now names org.apache.activemq:activemq-brokernot dated
2023-12-20published 2022-05-14GHSA-72m6-23ff-7q26CVE-2014-3612same package registry as the line abovehighsame change as the line abovenot dated
2023-12-20published 2022-05-17GHSA-23cr-5hr4-rgwvCVE-2015-6524same package registry as the line abovemoderatesame change as the line abovenot dated
2023-12-20published 2022-05-14GHSA-4vhf-2hv7-8mrxCVE-2014-3600same package registry as the line abovecriticalsame change as the line abovenot dated
2023-12-20published 2022-05-14 to 2022-05-172 bandsnot named as affected when the advisory was published, now names org.apache.activemq:activemq-jaasnot dated
2023-12-20published 2022-05-14GHSA-72m6-23ff-7q26CVE-2014-3612same package registry as the line abovehighsame change as the line abovenot dated
2023-12-20published 2022-05-17GHSA-23cr-5hr4-rgwvCVE-2015-6524same package registry as the line abovemoderatesame change as the line abovenot dated
2023-12-20published 2022-05-13GHSA-6456-xjm5-g3pgCVE-2018-1999007moderatenot named as affected when the advisory was published, now names org.kohsuke.stapler:stapler-parentnot dated
Tue 19 Dec 2023· 6 advisory changes
2023-12-19published 2018-10-16GHSA-26v6-w6fw-rh94highnot named as affected when the advisory was published, now names org.apache.camel:camel-ahc and 3 morenot dated
2023-12-19published 2018-10-16GHSA-26v6-w6fw-rh94CVE-2015-5348same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.camel:camel-ahcnot dated
2023-12-19published 2018-10-16GHSA-26v6-w6fw-rh94CVE-2015-5348same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.camel:camel-httpnot dated
2023-12-19published 2018-10-16GHSA-26v6-w6fw-rh94CVE-2015-5348same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.camel:camel-http-commonnot dated
2023-12-19published 2018-10-16GHSA-26v6-w6fw-rh94CVE-2015-5348same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.camel:camel-http4not dated
2023-12-19published 2021-11-17GHSA-7h26-63m7-qhf2CVE-2021-41165highnot named as affected when the advisory was published, now names ckeditor/ckeditornot dated
2023-12-19published 2023-12-18GHSA-45x7-px36-x8w8CVE-2023-48795moderatenot named as affected when the advisory was published, now names paramikoDays to revision 1
Mon 18 Dec 2023· 2 advisory changes
2023-12-18published 2023-12-18GHSA-45x7-px36-x8w8CVE-2023-48795moderatenot named as affected when the advisory was published, now names golang.org/x/cryptoDays to revision 0
2023-12-18published 2022-05-13GHSA-x6jx-cxg3-mgghCVE-2019-1003002highnot named as affected when the advisory was published, now names org.jenkinsci.plugins:pipeline-model-definitionDays to revision 584
Fri 15 Dec 2023· 4 advisory changes
2023-12-15published 2022-05-13GHSA-6q78-6xvr-26fghighnot named as affected when the advisory was published, now names org.jenkins-ci.plugins:pipeline-model-definition and 1 moreDays to revision 582
2023-12-15published 2022-05-13GHSA-6q78-6xvr-26fgCVE-2019-1003001same package registry as the line abovehighnot named as affected when the advisory was published, now names org.jenkins-ci.plugins:pipeline-model-definitionDays to revision 582
2023-12-15published 2022-05-13GHSA-6q78-6xvr-26fgCVE-2019-1003001same package registry as the line abovehighnot named as affected when the advisory was published, now names org.jenkins-ci.plugins:script-securityDays to revision 582
2023-12-15published 2022-05-18GHSA-8vfc-fcr2-47pjlownot named as affected when the advisory was published, now names org.jenkins-ci.plugins:git and 1 morenot dated
2023-12-15published 2022-05-18GHSA-8vfc-fcr2-47pjCVE-2022-30949same package registry as the line abovelownot named as affected when the advisory was published, now names org.jenkins-ci.plugins:gitnot dated
2023-12-15published 2022-05-18GHSA-8vfc-fcr2-47pjCVE-2022-30949same package registry as the line abovelownot named as affected when the advisory was published, now names org.jenkins-ci.plugins:mercurialnot dated
Fri 8 Dec 2023· 1 advisory change
2023-12-08published 2022-05-13GHSA-q6x7-f33r-3wxxCVE-2016-6797highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcatnot dated
Thu 7 Dec 2023· 2 advisory changes
2023-12-07published 2022-05-13GHSA-p9qj-4rjp-j3w9CVE-2015-5349highnot named as affected when the advisory was published, now names org.apache.directory.studio:org.apache.directory.studio.ldapbrowser.coreDays to revision 574
2023-12-07published 2022-05-13GHSA-4c5w-qqfg-grf3CVE-2015-8766moderatenot named as affected when the advisory was published, now names symphonycms/symphony-2Days to revision 574
Wed 6 Dec 2023· 4 advisory changes
2023-12-06published 2022-05-18GHSA-84cm-vjwm-m979highnot named as affected when the advisory was published, now names org.jenkins-ci.plugins:mercurial and 1 morenot dated
2023-12-06published 2022-05-18GHSA-84cm-vjwm-m979CVE-2022-30947same package registry as the line abovehighnot named as affected when the advisory was published, now names org.jenkins-ci.plugins:mercurialnot dated
2023-12-06published 2022-05-18GHSA-84cm-vjwm-m979CVE-2022-30947same package registry as the line abovehighnot named as affected when the advisory was published, now names org.jenkins-ci.plugins:reponot dated
2023-12-06published 2022-05-14GHSA-cwcf-5m5w-mq2wCVE-2018-1000601moderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins:credentialsnot dated
2023-12-06published 2022-05-24GHSA-682g-c99v-9r2gCVE-2019-10371highnot named as affected when the advisory was published, now names org.jenkins-ci.plugins:gitlab-oauthDays to revision 561
Tue 28 Nov 2023· 1 advisory change
2023-11-28published 2021-02-11GHSA-m56g-3g8v-2rxwmoderatenot named as affected when the advisory was published, now names vrana/adminernot dated
Mon 27 Nov 2023· 6 advisory changes
2023-11-27published 2023-06-27GHSA-ff3m-68vj-h86pCVE-2023-3432highnot named as affected when the advisory was published, now names net.sourceforge.plantuml:plantumlDays to revision 153
2023-11-27published 2023-11-18GHSA-3f2q-6294-fmq5CVE-2023-46402highnot named as affected when the advisory was published, now names github.com/whilp/git-urlsDays to revision 10
2023-11-27published 2023-07-12GHSA-w33c-445m-f8w7CVE-2023-3635moderatenot named as affected when the advisory was published, now names com.squareup.okio:okio-jvmDays to revision 138
2023-11-27published 2019-12-26GHSA-w457-6q6x-cgp9CVE-2019-19919criticalnot named as affected when the advisory was published, now names bootstrap-wysihtml5-railsnot dated
2023-11-27published 2019-02-22GHSA-9v3m-8fp8-mj99CVE-2019-8331moderatenot named as affected when the advisory was published, now names twitter-bootstrap-railsnot dated
2023-11-27published 2021-12-10GHSA-23fp-fmrv-f5pxCVE-2020-8123moderatenot named as affected when the advisory was published, now names strapi-adminnot dated
Tue 21 Nov 2023· 11 advisory changes
2023-11-21published 2022-02-09GHSA-grc3-8q8m-4j7cCVE-2020-17533highnot named as affected when the advisory was published, now names org.apache.accumulo:accumulo-masternot dated
2023-11-21published 2022-05-13GHSA-3336-h95j-hvvfCVE-2015-5253moderatenot named as affected when the advisory was published, now names org.apache.cxf:cxf-rt-rs-security-sso-samlnot dated
2023-11-21published 2018-10-17GHSA-xv7x-x6wr-xx7gCVE-2016-8746moderatenot named as affected when the advisory was published, now names org.apache.ranger:ranger-plugins-commonnot dated
2023-11-21published 2022-04-13GHSA-fcr6-6cph-vmcmCVE-2022-29040moderatenot named as affected when the advisory was published, now names org.jenkins-ci.tools:git-parameternot dated
2023-11-21published 2022-02-09GHSA-rcwj-2hj2-vmjjCVE-2020-9482moderatenot named as affected when the advisory was published, now names org.apache.nifi.registry:nifi-registry-web-apinot dated
2023-11-21published 2022-02-10GHSA-9jg9-6wm2-x7p5CVE-2020-11980moderatenot named as affected when the advisory was published, now names org.apache.karaf.management:org.apache.karaf.management.servernot dated
2023-11-21published 2022-02-09GHSA-7q5g-gph2-4rc6CVE-2020-17518highnot named as affected when the advisory was published, now names org.apache.flink:flink-runtimenot dated
2023-11-21published 2022-05-17GHSA-g4jg-gpwv-p7wvCVE-2011-5245moderatenot named as affected when the advisory was published, now names org.jboss.resteasy:resteasy-jaxb-providernot dated
2023-11-21published 2022-02-10GHSA-jrg3-qq99-35g7CVE-2018-21234criticalnot named as affected when the advisory was published, now names org.jodd:jodd-jsonnot dated
2023-11-21published 2021-12-09GHSA-5r5r-6hpj-8gg9CVE-2020-35728highnot named as affected when the advisory was published, now names com.fasterxml.jackson.core:jackson-databindnot dated
2023-11-21published 2021-05-07GHSA-fw5f-7c6c-3vmvCVE-2020-10544moderatenot named as affected when the advisory was published, now names org.primefaces:primefacesnot dated
Thu 16 Nov 2023· 1 advisory change
2023-11-16published 2023-02-24GHSA-j75r-vf64-6rrhCVE-2023-0481lownot named as affected when the advisory was published, now names io.quarkus.resteasy.reactive:resteasy-reactive-commonDays to revision 265
Wed 15 Nov 2023· 1 advisory change
2023-11-15published 2023-01-06GHSA-q84x-3476-8ff2CVE-2022-45787moderatenot named as affected when the advisory was published, now names org.apache.james:apache-mime4j-storageDays to revision 314
Tue 14 Nov 2023· 1 advisory change
2023-11-14published 2023-10-16GHSA-rp6x-ggw6-8g56CVE-2023-43668criticalnot named as affected when the advisory was published, now names org.apache.inlong:manager-pojoDays to revision 30
Wed 8 Nov 2023· 1 advisory change
2023-11-08published 2023-10-05GHSA-pffg-92cg-xf5clownot named as affected when the advisory was published, now names github.com/consensys/gnark-cryptoDays to revision 34
Tue 7 Nov 2023· 2 advisory changes
2023-11-07published 2022-05-17GHSA-9fc7-rhq3-wm7xCVE-2016-6801highnot named as affected when the advisory was published, now names org.apache.jackrabbit:jackrabbit-webdavDays to revision 540
2023-11-07published 2022-05-17GHSA-2j4q-9fff-236jCVE-2016-2162moderatenot named as affected when the advisory was published, now names org.apache.struts:struts2-coreDays to revision 540
Mon 6 Nov 2023· 2 advisory changes
2023-11-06published 2023-05-10GHSA-9cfh-vx93-84vvCVE-2023-31136lownot named as affected when the advisory was published, now names github.com/vapor/postgres-nioDays to revision 179
2023-11-06published 2023-05-18GHSA-ccw9-q5h2-8c2wCVE-2022-24666highnot named as affected when the advisory was published, now names github.com/apple/swift-nio-http2Days to revision 172
Thu 2 Nov 2023· 6 advisory changes
2023-11-02published 2022-05-13GHSA-fjq5-5j5f-mvxhcriticalnot named as affected when the advisory was published, now names org.apache.servicemix.bundles:org.apache.servicemix.bundles.collections-generic and 1 morenot dated
2023-11-02published 2022-05-13GHSA-fjq5-5j5f-mvxhCVE-2015-7501same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.servicemix.bundles:org.apache.servicemix.bundles.collections-genericnot dated
2023-11-02published 2022-05-13GHSA-fjq5-5j5f-mvxhCVE-2015-7501same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.servicemix.bundles:org.apache.servicemix.bundles.commons-collectionsnot dated
2023-11-02published 2022-05-17GHSA-vq79-mgpx-2wx4CVE-2016-4431highnot named as affected when the advisory was published, now names org.apache.struts:struts-parentDays to revision 535
2023-11-02published 2022-05-14GHSA-ggmp-fxfg-277rCVE-2016-3090highnot named as affected when the advisory was published, now names org.apache.struts:struts2-parentDays to revision 538
2023-11-02published 2022-05-17GHSA-38qw-j787-v8c2CVE-2016-4430highnot named as affected when the advisory was published, now names org.apache.struts.xwork:xwork-coreDays to revision 535
2023-11-02published 2022-05-13GHSA-p4xg-cpr9-vwvjCVE-2016-9589highnot named as affected when the advisory was published, now names org.wildfly:wildfly-undertowDays to revision 539
Tue 31 Oct 2023· 5 advisory changes
2023-10-31published 2022-01-19 to 2022-01-212 bandsnot named as affected when the advisory was published, now names org.zenframework.z8.dependencies.commons:log4j-1.2.17not dated
2023-10-31published 2022-01-21GHSA-65fg-84f6-3jq3CVE-2022-23305same package registry as the line abovecriticalsame change as the line abovenot dated
2023-10-31published 2022-01-19GHSA-f7vh-qwp3-x37mCVE-2022-23307same package registry as the line abovecriticalsame change as the line abovenot dated
2023-10-31published 2022-01-21GHSA-w9p3-5cr8-m3jjCVE-2022-23302same package registry as the line abovehighsame change as the line abovenot dated
2023-10-31published 2019-03-14GHSA-h436-432x-8fvxmoderatenot named as affected when the advisory was published, now names com.liferay:com.liferay.portal.tools.bundle.support and 1 morenot dated
2023-10-31published 2019-03-14GHSA-h436-432x-8fvxCVE-2018-1324same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.liferay:com.liferay.portal.tools.bundle.supportnot dated
2023-10-31published 2019-03-14GHSA-h436-432x-8fvxCVE-2018-1324same package registry as the line abovemoderatenot named as affected when the advisory was published, now names io.takari:commons-compressnot dated
Mon 30 Oct 2023· 1 advisory change
2023-10-30published 2022-05-13GHSA-rv63-gqm8-9w8qCVE-2016-4970highnot named as affected when the advisory was published, now names io.netty:netty-handlernot dated
Tue 24 Oct 2023· 3 advisory changes
2023-10-24published 2022-05-14moderatenot named as affected when the advisory was published, now names products.cmfploneDays to revision 529
2023-10-24published 2022-05-14GHSA-859j-668v-mrr6CVE-2017-1000482same package registry as the line abovemoderatesame change as the line aboveDays to revision 529
2023-10-24published 2022-05-14GHSA-8g72-gq68-6gqhCVE-2017-1000481same package registry as the line abovemoderatesame change as the line aboveDays to revision 529
2023-10-24published 2022-05-17GHSA-xj94-rgf9-cq37CVE-2017-15279moderatenot named as affected when the advisory was published, now names umbracocms.webDays to revision 526
Mon 23 Oct 2023· 1 advisory change
2023-10-23published 2022-05-17GHSA-h2vq-7gf2-qw9vCVE-2017-15280moderatenot named as affected when the advisory was published, now names umbracocms.webDays to revision 525
Thu 19 Oct 2023· 1 advisory change
2023-10-19published 2022-05-13GHSA-458h-wv48-fq75CVE-2018-14655moderatenot named as affected when the advisory was published, now names org.keycloak:keycloak-parentDays to revision 525
Wed 18 Oct 2023· 6 advisory changes
2023-10-18published 2023-09-12GHSA-j7hp-h8jx-5pprhighnot named as affected when the advisory was published, now names magick.net-q16-anycpu and 5 moreDays to revision 36
2023-10-18published 2023-09-12GHSA-j7hp-h8jx-5pprCVE-2023-4863same package registry as the line abovehighnot named as affected when the advisory was published, now names magick.net-q16-anycpuDays to revision 36
2023-10-18published 2023-09-12GHSA-j7hp-h8jx-5pprCVE-2023-4863same package registry as the line abovehighnot named as affected when the advisory was published, now names magick.net-q16-hdri-anycpuDays to revision 36
2023-10-18published 2023-09-12GHSA-j7hp-h8jx-5pprCVE-2023-4863same package registry as the line abovehighnot named as affected when the advisory was published, now names magick.net-q16-x64Days to revision 36
2023-10-18published 2023-09-12GHSA-j7hp-h8jx-5pprCVE-2023-4863same package registry as the line abovehighnot named as affected when the advisory was published, now names magick.net-q8-anycpuDays to revision 36
2023-10-18published 2023-09-12GHSA-j7hp-h8jx-5pprCVE-2023-4863same package registry as the line abovehighnot named as affected when the advisory was published, now names magick.net-q8-openmp-x64Days to revision 36
2023-10-18published 2023-09-12GHSA-j7hp-h8jx-5pprCVE-2023-4863same package registry as the line abovehighnot named as affected when the advisory was published, now names magick.net-q8-x64Days to revision 36
Mon 16 Oct 2023· 6 advisory changes
2023-10-16published 2023-10-16GHSA-rcjv-mgp8-qvmrhighnot named as affected when the advisory was published, now names go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful and 5 moreDays to revision 0
2023-10-16published 2023-10-16GHSA-rcjv-mgp8-qvmrCVE-2023-45142same package registry as the line abovehighnot named as affected when the advisory was published, now names go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestfulDays to revision 0
2023-10-16published 2023-10-16GHSA-rcjv-mgp8-qvmrCVE-2023-45142same package registry as the line abovehighnot named as affected when the advisory was published, now names go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelginDays to revision 0
2023-10-16published 2023-10-16GHSA-rcjv-mgp8-qvmrCVE-2023-45142same package registry as the line abovehighnot named as affected when the advisory was published, now names go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmuxDays to revision 0
2023-10-16published 2023-10-16GHSA-rcjv-mgp8-qvmrCVE-2023-45142same package registry as the line abovehighnot named as affected when the advisory was published, now names go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelechoDays to revision 0
2023-10-16published 2023-10-16GHSA-rcjv-mgp8-qvmrCVE-2023-45142same package registry as the line abovehighnot named as affected when the advisory was published, now names go.opentelemetry.io/contrib/instrumentation/gopkg.in/macaron.v1/otelmacaronDays to revision 0
2023-10-16published 2023-10-16GHSA-rcjv-mgp8-qvmrCVE-2023-45142same package registry as the line abovehighnot named as affected when the advisory was published, now names go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptraceDays to revision 0
Fri 13 Oct 2023· 3 advisory changes
2023-10-13published 2023-10-10GHSA-qppj-fm5r-hxr3CVE-2023-44487moderatenot named as affected when the advisory was published, now names golang.org/x/netDays to revision 3
2023-10-13published 2021-12-14GHSA-fp5r-v3w9-4333CVE-2021-4104highnot named as affected when the advisory was published, now names org.zenframework.z8.dependencies.commons:log4j-1.2.17not dated
2023-10-13published 2022-05-13GHSA-fjq5-5j5f-mvxhCVE-2015-7501criticalnot named as affected when the advisory was published, now names net.sourceforge.collections:collections-genericnot dated
Thu 12 Oct 2023· 1 advisory change
2023-10-12published 2020-01-06GHSA-2qrg-x229-3v8qCVE-2019-17571criticalnot named as affected when the advisory was published, now names org.zenframework.z8.dependencies.commons:log4j-1.2.17not dated
Wed 11 Oct 2023· 2 advisory changes
2023-10-11published 2022-05-13 to 2022-05-172 bandsnot named as affected when the advisory was published, now names org.apache.sling:org.apache.sling.xss.compatnot dated
2023-10-11published 2022-05-17GHSA-7g54-vgp6-jj5wCVE-2016-6798same package registry as the line abovecriticalsame change as the line abovenot dated
2023-10-11published 2022-05-13GHSA-xwf4-88xr-hx2jCVE-2016-5394same package registry as the line abovemoderatesame change as the line abovenot dated
Tue 10 Oct 2023· 1 advisory change
2023-10-10published 2022-05-13GHSA-vx9j-rvmj-jc32CVE-2017-3200highnot named as affected when the advisory was published, now names org.graniteds:granite-server-coreDays to revision 516
Mon 9 Oct 2023· 1 advisory change
2023-10-09published 2019-10-11GHSA-53x6-4x5p-rrvvCVE-2019-12402highnot named as affected when the advisory was published, now names io.github.1tchy.java9modular.org.apache.commons:commons-compressnot dated
Fri 6 Oct 2023· 9 advisory changes
2023-10-06published 2022-05-13 to 2022-05-148 rows, one per advisory and package2 bandsnot named as affected when the advisory was published, now names org.apache.flex.blazeds:flex-messaging-core and 7 moreDays to revision 511 to 512
2023-10-06published 2022-05-13GHSA-w8v7-prhw-xjpwCVE-2017-5641same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.flex.blazeds:flex-messaging-coreDays to revision 512
2023-10-06published 2022-05-13GHSA-w8v7-prhw-xjpwCVE-2017-5641same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.flex.blazeds:flex-messaging-remotingDays to revision 512
2023-10-06published 2022-05-14GHSA-6mvr-cq72-f66vCVE-2018-16277same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.xwiki.platform:xwiki-platformDays to revision 511
2023-10-06published 2022-05-13GHSA-xvv8-8wh9-9fh2CVE-2018-10894same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.keycloak:keycloak-saml-adapter-coreDays to revision 512
2023-10-06published 2022-05-13GHSA-xvv8-8wh9-9fh2CVE-2018-10894same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.keycloak:keycloak-servicesDays to revision 512
2023-10-06published 2022-05-14GHSA-f6fv-fjg8-4m6wCVE-2018-19859same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.openrefine:mainDays to revision 511
2023-10-06published 2022-05-13GHSA-h892-x453-86wcCVE-2018-18240same package registry as the line abovecriticalnot named as affected when the advisory was published, now names ro.pippo:pippo-coreDays to revision 511
2023-10-06published 2022-05-13GHSA-h892-x453-86wcCVE-2018-18240same package registry as the line abovecriticalnot named as affected when the advisory was published, now names ro.pippo:pippo-sessionDays to revision 511
2023-10-06published 2022-05-14GHSA-mv4h-qm24-x4ghCVE-2018-6591moderatenot named as affected when the advisory was published, now names converse.jsDays to revision 511
Tue 3 Oct 2023· 3 advisory changes
2023-10-03published 2022-05-13GHSA-96mh-7xpr-qcgwCVE-2018-7198moderatenot named as affected when the advisory was published, now names rainlab/blog-pluginDays to revision 509
2023-10-03published 2023-09-12GHSA-j7hp-h8jx-5pprCVE-2023-4863highnot named as affected when the advisory was published, now names webpDays to revision 21
2023-10-03published 2023-09-12GHSA-j7hp-h8jx-5pprCVE-2023-4863highnot named as affected when the advisory was published, now names pillowDays to revision 21
Mon 2 Oct 2023· 2 advisory changes
2023-10-02published 2023-09-26GHSA-r5hm-mp3j-285gCVE-2023-43644criticalnot named as affected when the advisory was published, now names github.com/sagernet/singDays to revision 6
2023-10-02published 2021-06-23GHSA-cjjc-xp8v-855wCVE-2020-7919highnot named as affected when the advisory was published, now names helm.sh/helm/v3not dated
Fri 29 Sep 2023· 1 advisory change
2023-09-29published 2018-12-21GHSA-xx68-jfcg-xmmfCVE-2014-0050highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcatnot dated
Thu 28 Sep 2023· 2 advisory changes
2023-09-28published 2022-05-13GHSA-5m3w-rvvh-8fx6CVE-2019-7743criticalnot named as affected when the advisory was published, now names joomla/joomla-cmsDays to revision 504
2023-09-28published 2023-08-25GHSA-q3mw-pvr8-9ggcCVE-2023-41080moderatenot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDays to revision 34
Wed 27 Sep 2023· 9 advisory changes
2023-09-27published 2019-12-02GHSA-fmqw-vqh5-cwq9highnot named as affected when the advisory was published, now names org.apache.nifi:nifi-web-api and 1 morenot dated
2023-09-27published 2019-12-02GHSA-fmqw-vqh5-cwq9CVE-2019-12421same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.nifi:nifi-web-apinot dated
2023-09-27published 2019-12-02GHSA-fmqw-vqh5-cwq9CVE-2019-12421same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.nifi:nifi-web-securitynot dated
2023-09-27published 2018-10-22GHSA-mm57-9j6q-rxm2CVE-2017-1000034highnot named as affected when the advisory was published, now names com.typesafe.akka:akka-actornot dated
2023-09-27published 2022-05-17GHSA-9xrj-439h-62hgCVE-2012-5886moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinanot dated
2023-09-27published 2022-02-10GHSA-wc4x-4gm2-74j8CVE-2019-10091highnot named as affected when the advisory was published, now names org.apache.geode:geode-corenot dated
2023-09-27published 2018-12-26GHSA-3448-vfvv-xp9gCVE-2018-17197moderatenot named as affected when the advisory was published, now names org.apache.tika:tika-parsersnot dated
2023-09-27published 2018-10-16GHSA-9gcm-f4x3-8jpwCVE-2018-11039moderatenot named as affected when the advisory was published, now names org.springframework:spring-webnot dated
2023-09-27published 2018-10-18GHSA-3357-829x-m9prhighnot named as affected when the advisory was published, now names org.apache.cxf.fediz:fediz-core and 1 morenot dated
2023-09-27published 2018-10-18GHSA-3357-829x-m9prCVE-2015-5175same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.cxf.fediz:fediz-corenot dated
2023-09-27published 2018-10-18GHSA-3357-829x-m9prCVE-2015-5175same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.cxf.fediz:fediz-idpnot dated

Counted in advisories, never added to the CVE and KEV figures. This kind is counted once per advisory and per package, so one advisory that named four further packages counts four times. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →