Package added to advisory
What a record said when it was published, what it says now, and the commit that changed it.
1,695 advisory changes · newest first · grouped by day
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Advisory, Which advisory was edited, by its GHSA id. | Package, The package the advisory names, and the registry it comes from. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|
| Wed 27 Sep 2023· 1 advisory change | ||||
| 2023-09-27published 2022-02-09 | GHSA-f268-65qc-98vgCVE-2020-13943 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | not dated |
| Tue 26 Sep 2023· 37 advisory changes | ||||
| 2023-09-26published 2017-10-24 to 2022-07-18 | 28 rows, one per advisory and package | 3 bands | not named as affected when the advisory was published, now names org.webjars.npm:jquery and 19 more | Days to revision 490 |
| 2023-09-26published 2019-04-26 | GHSA-6c3j-c64m-qhgqCVE-2019-11358 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.webjars.npm:jquery | not dated |
| 2023-09-26published 2018-07-27 | GHSA-g8q2-24jh-5hpc | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.webjars.npm:jquery-ui | not dated |
| 2023-09-26published 2020-05-20 | GHSA-q4m3-2j7h-f7xwCVE-2020-7656 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.webjars.npm:jquery | not dated |
| 2023-09-26published 2022-05-14 | GHSA-579v-mp3v-rrw5CVE-2011-4969 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.webjars.npm:jquery | not dated |
| 2023-09-26published 2022-07-18 | GHSA-h6gj-6jjq-h8g9CVE-2022-31160 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.webjars.npm:jquery-ui | not dated |
| 2023-09-26published 2017-10-24 | GHSA-qqxp-xp9v-vvx6CVE-2012-6662 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.webjars.npm:jquery-ui | not dated |
| 2023-09-26published 2017-10-24 | GHSA-wcm2-9c89-wmfmCVE-2010-5312 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.webjars.npm:jquery-ui | not dated |
| 2023-09-26published 2017-10-24 | GHSA-hpcf-8vf9-q4gjCVE-2016-7103 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.webjars.npm:jquery-ui | not dated |
| 20 more rows in this change are not listed here. Open all 28 rows → | ||||
| 2023-09-26published 2017-10-24 to 2022-07-18 | 2 bands | not named as affected when the advisory was published, now names jquery.ui.combined | not dated | |
| 2023-09-26published 2018-07-27 | GHSA-g8q2-24jh-5hpc | same package registry as the line abovehigh | same change as the line above | not dated |
| 2023-09-26published 2022-07-18 | GHSA-h6gj-6jjq-h8g9CVE-2022-31160 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-26published 2017-10-24 | GHSA-qqxp-xp9v-vvx6CVE-2012-6662 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-26published 2017-10-24 | GHSA-wcm2-9c89-wmfmCVE-2010-5312 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-26published 2017-10-24 | GHSA-hpcf-8vf9-q4gjCVE-2016-7103 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-26published 2017-10-24 to 2022-07-18 | 2 bands | not named as affected when the advisory was published, now names jquery-ui-rails | not dated | |
| 2023-09-26published 2018-07-27 | GHSA-g8q2-24jh-5hpc | same package registry as the line abovehigh | same change as the line above | not dated |
| 2023-09-26published 2022-07-18 | GHSA-h6gj-6jjq-h8g9CVE-2022-31160 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-26published 2017-10-24 | GHSA-qqxp-xp9v-vvx6CVE-2012-6662 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-26published 2017-10-24 | GHSA-wcm2-9c89-wmfmCVE-2010-5312 | same package registry as the line abovemoderate | same change as the line above | not dated |
| Mon 25 Sep 2023· 37 advisory changes | ||||
| 2023-09-25published 2018-01-22 to 2022-04-19 | 23 rows, one per advisory and package | 3 bands | not named as affected when the advisory was published, now names org.webjars.npm:jquery-ui and 16 more | not dated |
| 2023-09-25published 2021-10-26 | GHSA-gpqq-952q-5327CVE-2021-41184 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.webjars.npm:jquery-ui | not dated |
| 2023-09-25published 2021-10-26 | GHSA-j7qv-pgf6-hvh4CVE-2021-41183 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.webjars.npm:jquery-ui | not dated |
| 2023-09-25published 2021-10-26 | GHSA-9gj3-hwp5-pmwcCVE-2021-41182 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.webjars.npm:jquery-ui | not dated |
| 2023-09-25published 2018-01-22 | GHSA-mhpp-875w-9cpvCVE-2016-10707 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.webjars.npm:jquery | not dated |
| 2023-09-25published 2018-01-22 | GHSA-rmxg-73gg-4p98CVE-2015-9251 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.webjars.npm:jquery | not dated |
| 2023-09-25published 2020-04-29 | GHSA-gxr4-xjj5-5px2CVE-2020-11022 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.webjars.npm:jquery | not dated |
| 2023-09-25published 2020-04-29 | GHSA-jpcq-cgw6-v4j6CVE-2020-11023 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.webjars.npm:jquery | not dated |
| 2023-09-25published 2019-04-23 | GHSA-wv67-q8rr-grjpCVE-2019-5428 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.webjars.npm:jquery | not dated |
| 15 more rows in this change are not listed here. Open all 23 rows → | ||||
| 2023-09-25published 2021-10-26 | moderate | not named as affected when the advisory was published, now names jquery.ui.combined | not dated | |
| 2023-09-25published 2021-10-26 | GHSA-gpqq-952q-5327CVE-2021-41184 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-25published 2021-10-26 | GHSA-j7qv-pgf6-hvh4CVE-2021-41183 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-25published 2021-10-26 | GHSA-9gj3-hwp5-pmwcCVE-2021-41182 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-25published 2021-10-26 | moderate | not named as affected when the advisory was published, now names jquery-ui-rails | not dated | |
| 2023-09-25published 2021-10-26 | GHSA-gpqq-952q-5327CVE-2021-41184 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-25published 2021-10-26 | GHSA-j7qv-pgf6-hvh4CVE-2021-41183 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-25published 2021-10-26 | GHSA-9gj3-hwp5-pmwcCVE-2021-41182 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-25published 2018-01-22 to 2022-05-14 | 2 bands | not named as affected when the advisory was published, now names jquery-rails | not dated | |
| 2023-09-25published 2018-01-22 | GHSA-mhpp-875w-9cpvCVE-2016-10707 | same package registry as the line abovehigh | same change as the line above | not dated |
| 2023-09-25published 2020-04-29 | GHSA-gxr4-xjj5-5px2CVE-2020-11022 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-25published 2019-04-23 | GHSA-wv67-q8rr-grjpCVE-2019-5428 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-25published 2022-05-14 | GHSA-579v-mp3v-rrw5CVE-2011-4969 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-25published 2019-04-23 to 2020-04-29 | moderate | not named as affected when the advisory was published, now names jquery | not dated | |
| 2023-09-25published 2020-04-29 | GHSA-gxr4-xjj5-5px2CVE-2020-11022 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-25published 2019-04-23 | GHSA-wv67-q8rr-grjpCVE-2019-5428 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-25published 2022-05-24 | GHSA-fp37-c92q-4pwqCVE-2019-11247 | high | not named as affected when the advisory was published, now names k8s.io/apiextensions-apiserver | Days to revision 489 |
| 2023-09-25published 2021-07-26 | GHSA-h8jc-jmrf-9h8fCVE-2020-8828 | high | not named as affected when the advisory was published, now names github.com/argoproj/argo-cd | not dated |
| Thu 21 Sep 2023· 5 advisory changes | ||||
| 2023-09-21published 2020-04-15 | GHSA-rc5r-697f-28x6 | moderate | not named as affected when the advisory was published, now names sylius/grid-bundle and 1 more | not dated |
| 2023-09-21published 2020-04-15 | GHSA-rc5r-697f-28x6CVE-2019-12186 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names sylius/grid-bundle | not dated |
| 2023-09-21published 2020-04-15 | GHSA-rc5r-697f-28x6CVE-2019-12186 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names sylius/sylius | not dated |
| 2023-09-21published 2023-09-12 | GHSA-j7hp-h8jx-5pprCVE-2023-4863 | high | not named as affected when the advisory was published, now names github.com/chai2010/webp | Days to revision 9 |
| 2023-09-21published 2023-09-12 | GHSA-j7hp-h8jx-5pprCVE-2023-4863 | high | not named as affected when the advisory was published, now names skiasharp | Days to revision 9 |
| 2023-09-21published 2021-09-08 | GHSA-7q44-gfvq-6g93CVE-2020-18155 | critical | not named as affected when the advisory was published, now names intelliants/subrion | not dated |
| Wed 20 Sep 2023· 1 advisory change | ||||
| 2023-09-20published 2023-06-12 | GHSA-59x6-g4jr-4hxcCVE-2023-35042 | critical | not named as affected when the advisory was published, now names org.geoserver:gs-wps | Days to revision 100 |
| Tue 19 Sep 2023· 3 advisory changes | ||||
| 2023-09-19published 2021-12-10 | GHSA-jfh8-c2jp-5v3q | critical | not named as affected when the advisory was published, now names com.guicedee.services:log4j-core and 2 more | not dated |
| 2023-09-19published 2021-12-10 | GHSA-jfh8-c2jp-5v3qCVE-2021-44228 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names com.guicedee.services:log4j-core | not dated |
| 2023-09-19published 2021-12-10 | GHSA-jfh8-c2jp-5v3qCVE-2021-44228 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.xbib.elasticsearch:log4j | not dated |
| 2023-09-19published 2021-12-10 | GHSA-jfh8-c2jp-5v3qCVE-2021-44228 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names uk.co.nichesolutions.logging.log4j:log4j-core | not dated |
| Mon 18 Sep 2023· 8 advisory changes | ||||
| 2023-09-18published 2021-05-18 to 2022-02-15 | moderate | not named as affected when the advisory was published, now names k8s.io/kubernetes | not dated | |
| 2023-09-18published 2022-02-15 | GHSA-qhm4-jxv7-j9pqCVE-2020-8551 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-18published 2022-02-15 | GHSA-x6mj-w4jf-jmgwCVE-2020-8555 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-18published 2021-05-18 | GHSA-6qfg-8799-r575CVE-2019-11251 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-18published 2022-02-15 | GHSA-34jx-wx69-9x8vCVE-2019-1002101 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-09-18published 2022-02-15 | GHSA-82hx-w2r5-c2wqCVE-2020-8552 | moderate | not named as affected when the advisory was published, now names k8s.io/apiserver | not dated |
| 2023-09-18published 2022-02-15 | GHSA-2575-pghm-6qqxCVE-2019-11244 | moderate | not named as affected when the advisory was published, now names k8s.io/client-go | not dated |
| 2023-09-18published 2023-09-12 | GHSA-j7hp-h8jx-5pprCVE-2023-4863 | high | not named as affected when the advisory was published, now names libwebp-sys | Days to revision 6 |
| 2023-09-18published 2023-09-12 | GHSA-j7hp-h8jx-5pprCVE-2023-4863 | high | not named as affected when the advisory was published, now names electron | Days to revision 6 |
| Thu 14 Sep 2023· 1 advisory change | ||||
| 2023-09-14published 2020-08-31 | GHSA-4mv4-gmmf-q382CVE-2015-6584 | high | not named as affected when the advisory was published, now names datatables/datatables | not dated |
| Tue 12 Sep 2023· 6 advisory changes | ||||
| 2023-09-12published 2022-05-14 | GHSA-42wx-65g4-5cxvCVE-2018-1309 | critical | not named as affected when the advisory was published, now names org.apache.nifi:nifi-standard-processors | not dated |
| 2023-09-12published 2021-02-25 | GHSA-pr5m-4w22-8483CVE-2020-13697 | moderate | not named as affected when the advisory was published, now names org.nanohttpd:nanohttpd-nanolets | not dated |
| 2023-09-12published 2018-10-17 | GHSA-ccjp-w723-2jf2CVE-2015-3271 | moderate | not named as affected when the advisory was published, now names org.apache.tika:tika-server | not dated |
| 2023-09-12published 2022-01-06 | GHSA-g644-pr5v-vppfCVE-2020-9486 | high | not named as affected when the advisory was published, now names org.apache.nifi:nifi-stateless | not dated |
| 2023-09-12published 2018-10-18 | GHSA-v6wr-fch2-vm5wCVE-2015-2913 | moderate | not named as affected when the advisory was published, now names com.orientechnologies:orientdb-server | not dated |
| 2023-09-12published 2022-05-17 | GHSA-r6fx-55x3-f9x6CVE-2021-23267 | high | not named as affected when the advisory was published, now names org.craftercms:crafter-studio | not dated |
| Mon 11 Sep 2023· 8 advisory changes | ||||
| 2023-09-11published 2019-01-07 | GHSA-92wj-x78c-m4fxCVE-2018-11788 | critical | not named as affected when the advisory was published, now names org.apache.karaf.specs:org.apache.karaf.specs.java.xml | not dated |
| 2023-09-11published 2022-09-14 | GHSA-2jv3-v37p-65w3CVE-2022-40634 | high | not named as affected when the advisory was published, now names org.craftercms:crafter-studio | not dated |
| 2023-09-11published 2021-06-16 | GHSA-q7fr-vqhq-v5xrCVE-2021-26118 | high | not named as affected when the advisory was published, now names org.apache.activemq:artemis-openwire-protocol | not dated |
| 2023-09-11published 2022-05-01 | GHSA-h7mf-qrm9-2848CVE-2007-4556 | moderate | not named as affected when the advisory was published, now names opensymphony:xwork | not dated |
| 2023-09-11published 2018-12-20 | GHSA-43fp-vwwg-qgv6CVE-2018-17194 | high | not named as affected when the advisory was published, now names org.apache.nifi:nifi-framework-cluster | not dated |
| 2023-09-11published 2022-05-24 | GHSA-9x5v-8352-244gCVE-2019-10357 | moderate | not named as affected when the advisory was published, now names org.jenkins-ci.plugins.workflow:workflow-cps-global-lib | not dated |
| 2023-09-11published 2018-12-19 | GHSA-8j39-fgfp-vxh8CVE-2018-20094 | high | not named as affected when the advisory was published, now names com.xuxueli:xxl-conf-admin | not dated |
| 2023-09-11published 2019-08-27 | GHSA-f5f4-m7qp-w6gcCVE-2019-15477 | moderate | not named as affected when the advisory was published, now names org.jooby:jooby | not dated |
| Fri 8 Sep 2023· 1 advisory change | ||||
| 2023-09-08published 2019-11-12 | GHSA-g996-q5r8-w7g2CVE-2019-10909 | moderate | not named as affected when the advisory was published, now names drupal/core | not dated |
| Thu 7 Sep 2023· 5 advisory changes | ||||
| 2023-09-07published 2020-06-15 | GHSA-mvr2-9pj6-7w5j | moderate | not named as affected when the advisory was published, now names com.google.guava:guava-jdk5 and 4 more | not dated |
| 2023-09-07published 2020-06-15 | GHSA-mvr2-9pj6-7w5jCVE-2018-10237 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names com.google.guava:guava-jdk5 | not dated |
| 2023-09-07published 2020-06-15 | GHSA-mvr2-9pj6-7w5jCVE-2018-10237 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names com.googlecode.guava-osgi:guava-osgi | not dated |
| 2023-09-07published 2020-06-15 | GHSA-mvr2-9pj6-7w5jCVE-2018-10237 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names de.mhus.ports:vaadin-shared-deps | not dated |
| 2023-09-07published 2020-06-15 | GHSA-mvr2-9pj6-7w5jCVE-2018-10237 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.hudsonci.lib.guava:guava | not dated |
| 2023-09-07published 2020-06-15 | GHSA-mvr2-9pj6-7w5jCVE-2018-10237 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.sonatype.sisu:sisu-guava | not dated |
| Tue 5 Sep 2023· 10 advisory changes | ||||
| 2023-09-05published 2021-09-23 | GHSA-3j6g-hxx5-3q26 | moderate | not named as affected when the advisory was published, now names org.apache.kafka:kafka-clients and 3 more | not dated |
| 2023-09-05published 2021-09-23 | GHSA-3j6g-hxx5-3q26CVE-2021-38153 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.kafka:kafka-clients | not dated |
| 2023-09-05published 2021-09-23 | GHSA-3j6g-hxx5-3q26CVE-2021-38153 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.kafka:kafka_2.11 | not dated |
| 2023-09-05published 2021-09-23 | GHSA-3j6g-hxx5-3q26CVE-2021-38153 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.kafka:kafka_2.12 | not dated |
| 2023-09-05published 2021-09-23 | GHSA-3j6g-hxx5-3q26CVE-2021-38153 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.kafka:kafka_2.13 | not dated |
| 2023-09-05published 2022-01-06 | GHSA-2h63-qp69-fwvwCVE-2020-11987 | high | not named as affected when the advisory was published, now names org.apache.xmlgraphics:batik-svgbrowser | not dated |
| 2023-09-05published 2023-07-05 | GHSA-hr8g-6v94-x4m9 | moderate | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-debug-jdk15on and 2 more | Days to revision 63 |
| 2023-09-05published 2023-07-05 | GHSA-hr8g-6v94-x4m9CVE-2023-33201 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-debug-jdk15on | Days to revision 63 |
| 2023-09-05published 2023-07-05 | GHSA-hr8g-6v94-x4m9CVE-2023-33201 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-ext-jdk15on | Days to revision 63 |
| 2023-09-05published 2023-07-05 | GHSA-hr8g-6v94-x4m9CVE-2023-33201 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | Days to revision 63 |
| 2023-09-05published 2019-04-10 | GHSA-f6f2-pwrj-64h3CVE-2019-10868 | high | not named as affected when the advisory was published, now names trytond | not dated |
| 2023-09-05published 2019-04-26 | GHSA-6c3j-c64m-qhgqCVE-2019-11358 | moderate | not named as affected when the advisory was published, now names django | not dated |
| Wed 30 Aug 2023· 1 advisory change | ||||
| 2023-08-30published 2022-11-15 | GHSA-prjq-f4q3-fvfrCVE-2020-7731 | high | not named as affected when the advisory was published, now names github.com/russellhaering/goxmldsig | not dated |
| Mon 28 Aug 2023· 3 advisory changes | ||||
| 2023-08-28published 2019-04-09 | moderate | not named as affected when the advisory was published, now names @materializecss/materialize | not dated | |
| 2023-08-28published 2019-04-09 | GHSA-7752-f4gf-94gcCVE-2019-11003 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-08-28published 2019-04-09 | GHSA-98f7-p5rc-jx67CVE-2019-11002 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-08-28published 2019-04-09 | GHSA-rg3q-jxmp-pvjjCVE-2019-11004 | same package registry as the line abovemoderate | same change as the line above | not dated |
| Thu 24 Aug 2023· 1 advisory change | ||||
| 2023-08-24published 2022-06-01 | GHSA-qw3f-w4pf-jh5fCVE-2022-30973 | moderate | not named as affected when the advisory was published, now names org.apache.tika:tika-core | not dated |
| Wed 23 Aug 2023· 1 advisory change | ||||
| 2023-08-23published 2022-05-24 | GHSA-w6g9-xccc-347hCVE-2020-7941 | critical | not named as affected when the advisory was published, now names plone.app.contenttypes | Days to revision 456 |
| Tue 22 Aug 2023· 1 advisory change | ||||
| 2023-08-22published 2022-05-24 | GHSA-qcch-9268-59jwCVE-2020-14297 | moderate | not named as affected when the advisory was published, now names org.jboss:jboss-ejb-client | Days to revision 455 |
| Mon 21 Aug 2023· 2 advisory changes | ||||
| 2023-08-21published 2022-05-24 | GHSA-853f-x27w-8r74CVE-2020-12760 | high | not named as affected when the advisory was published, now names org.opennms.core:org.opennms.core.daemon | Days to revision 454 |
| 2023-08-21published 2023-07-10 | GHSA-mjmq-gwgm-5qhmCVE-2023-35887 | moderate | not named as affected when the advisory was published, now names org.apache.sshd:sshd-core | Days to revision 42 |
| Fri 18 Aug 2023· 2 advisory changes | ||||
| 2023-08-18published 2022-11-16 | GHSA-fhw8-8j55-vwgqCVE-2022-45047 | critical | not named as affected when the advisory was published, now names org.apache.sshd:sshd-core | Days to revision 275 |
| 2023-08-18published 2018-10-17 | GHSA-4446-656p-f54gCVE-2018-1000613 | critical | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | not dated |
| Tue 15 Aug 2023· 4 advisory changes | ||||
| 2023-08-15published 2023-08-09 | GHSA-vmch-3w2x-vhgq | high | not named as affected when the advisory was published, now names microsoft.aspnetcore.server.kestrel.transport.libuv and 1 more | Days to revision 6 |
| 2023-08-15published 2023-08-09 | GHSA-vmch-3w2x-vhgqCVE-2023-38180 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.aspnetcore.server.kestrel.transport.libuv | Days to revision 6 |
| 2023-08-15published 2023-08-09 | GHSA-vmch-3w2x-vhgqCVE-2023-38180 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.aspnetcore.server.kestrel.transport.sockets | Days to revision 6 |
| 2023-08-15published 2021-06-16 | GHSA-2f88-5hg8-9x2x | critical | not named as affected when the advisory was published, now names org.apache.maven:maven-compat and 1 more | not dated |
| 2023-08-15published 2021-06-16 | GHSA-2f88-5hg8-9x2xCVE-2021-26291 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.apache.maven:maven-compat | not dated |
| 2023-08-15published 2021-06-16 | GHSA-2f88-5hg8-9x2xCVE-2021-26291 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.apache.maven:maven-core | not dated |
| Mon 14 Aug 2023· 1 advisory change | ||||
| 2023-08-14published 2023-07-18 | GHSA-p9xf-74xh-mhw5CVE-2023-37477 | high | not named as affected when the advisory was published, now names github.com/1panel-dev/1panel | Days to revision 27 |
| Mon 7 Aug 2023· 10 advisory changes | ||||
| 2023-08-07published 2020-02-21 to 2021-12-09 | 3 bands | not named as affected when the advisory was published, now names io.netty:netty | not dated | |
| 2023-08-07published 2021-09-09 | GHSA-9vjp-v76f-g363CVE-2021-37137 | same package registry as the line abovehigh | same change as the line above | not dated |
| 2023-08-07published 2021-03-09 | GHSA-wm47-8v5p-wjpjCVE-2021-21295 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-08-07published 2021-12-09 | GHSA-wx5j-54mm-rqqqCVE-2021-43797 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-08-07published 2021-09-09 | GHSA-grg4-wf29-r9vvCVE-2021-37136 | same package registry as the line abovehigh | same change as the line above | not dated |
| 2023-08-07published 2021-03-30 | GHSA-f256-j965-7f32CVE-2021-21409 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-08-07published 2021-02-08 | GHSA-5mcr-gq6c-3hq2CVE-2021-21290 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-08-07published 2020-02-21 | GHSA-cqqj-4p63-rrmmCVE-2019-20444 | same package registry as the line abovecritical | same change as the line above | not dated |
| 2023-08-07published 2020-02-21 | GHSA-p2v9-g2qv-p635CVE-2019-20445 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 1 more row in this change is not listed here. Open all 9 rows → | ||||
| 2023-08-07published 2022-01-27 | GHSA-77rm-9x9h-xj3gCVE-2021-22570 | high | not named as affected when the advisory was published, now names com.google.protobuf:protobuf-java | not dated |
| Fri 4 Aug 2023· 12 advisory changes | ||||
| 2023-08-04published 2022-05-24 | GHSA-hr65-qq6p-87r4CVE-2021-22137 | moderate | not named as affected when the advisory was published, now names org.elasticsearch:elasticsearch | not dated |
| 2023-08-04published 2019-10-11 to 2021-12-09 | 3 bands | not named as affected when the advisory was published, now names org.jboss.netty:netty | not dated | |
| 2023-08-04published 2021-12-09 | GHSA-wx5j-54mm-rqqqCVE-2021-43797 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-08-04published 2021-09-09 | GHSA-9vjp-v76f-g363CVE-2021-37137 | same package registry as the line abovehigh | same change as the line above | not dated |
| 2023-08-04published 2021-09-09 | GHSA-grg4-wf29-r9vvCVE-2021-37136 | same package registry as the line abovehigh | same change as the line above | not dated |
| 2023-08-04published 2021-03-30 | GHSA-f256-j965-7f32CVE-2021-21409 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-08-04published 2021-03-09 | GHSA-wm47-8v5p-wjpjCVE-2021-21295 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-08-04published 2021-02-08 | GHSA-5mcr-gq6c-3hq2CVE-2021-21290 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-08-04published 2020-02-21 | GHSA-cqqj-4p63-rrmmCVE-2019-20444 | same package registry as the line abovecritical | same change as the line above | not dated |
| 2023-08-04published 2020-02-21 | GHSA-p2v9-g2qv-p635CVE-2019-20445 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2 more rows in this change are not listed here. Open all 10 rows → | ||||
| 2023-08-04published 2020-06-30 | GHSA-xfv3-rrfm-f2rvCVE-2015-2156 | high | not named as affected when the advisory was published, now names io.netty:netty-parent | not dated |
| Thu 3 Aug 2023· 4 advisory changes | ||||
| 2023-08-03published 2022-05-24 | GHSA-c3mp-9vx3-2rvv | high | not named as affected when the advisory was published, now names org.opennms.features:org.opennms.features.measurements and 2 more | Days to revision 436 |
| 2023-08-03published 2022-05-24 | GHSA-c3mp-9vx3-2rvvCVE-2021-3396 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.opennms.features:org.opennms.features.measurements | Days to revision 436 |
| 2023-08-03published 2022-05-24 | GHSA-c3mp-9vx3-2rvvCVE-2021-3396 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.opennms:opennms-provision | Days to revision 436 |
| 2023-08-03published 2022-05-24 | GHSA-c3mp-9vx3-2rvvCVE-2021-3396 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.opennms:opennms-util | Days to revision 436 |
| 2023-08-03published 2022-05-13 | GHSA-hmx6-gc2p-5p82CVE-2019-5919 | critical | not named as affected when the advisory was published, now names com.nablarch.framework:nablarch-fw-web | Days to revision 448 |
| Mon 31 Jul 2023· 3 advisory changes | ||||
| 2023-07-31published 2022-01-06 | GHSA-7q8g-gpfp-v8gx | high | not named as affected when the advisory was published, now names org.apache.nifi:nifi-framework-core and 1 more | not dated |
| 2023-07-31published 2022-01-06 | GHSA-7q8g-gpfp-v8gxCVE-2020-1942 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.apache.nifi:nifi-framework-core | not dated |
| 2023-07-31published 2022-01-06 | GHSA-7q8g-gpfp-v8gxCVE-2020-1942 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.apache.nifi:nifi-security-utils | not dated |
| 2023-07-31published 2023-03-16 | GHSA-p8p7-x288-28g6CVE-2023-28155 | moderate | not named as affected when the advisory was published, now names @cypress/request | Days to revision 137 |
| Fri 28 Jul 2023· 2 advisory changes | ||||
| 2023-07-28published 2022-06-15 to 2022-10-26 | 2 bands | not named as affected when the advisory was published, now names org.apache.flume.flume-ng-sources:flume-jms-source | not dated | |
| 2023-07-28published 2022-10-26 | GHSA-9w4g-fp9h-3q2vCVE-2022-42468 | same package registry as the line abovecritical | same change as the line above | not dated |
| 2023-07-28published 2022-06-15 | GHSA-x5m7-rwfx-w7qmCVE-2022-25167 | same package registry as the line abovehigh | same change as the line above | not dated |
| Tue 25 Jul 2023· 1 advisory change | ||||
| 2023-07-25published 2023-03-31 | GHSA-5c9c-6x87-f9vmCVE-2022-4899 | high | not named as affected when the advisory was published, now names zstd | Days to revision 116 |
| Mon 24 Jul 2023· 1 advisory change | ||||
| 2023-07-24published 2022-05-14 | GHSA-43q7-q5vp-3g68CVE-2018-14371 | high | not named as affected when the advisory was published, now names org.glassfish:mojarra-parent | not dated |
| Fri 21 Jul 2023· 2 advisory changes | ||||
| 2023-07-21published 2022-08-16 | GHSA-8wj3-cpmr-8whpCVE-2022-2818 | high | not named as affected when the advisory was published, now names cockpit-hq/cockpit | not dated |
| 2023-07-21published 2023-07-19 | GHSA-9436-3gmp-4f53CVE-2023-37897 | high | not named as affected when the advisory was published, now names getgrav/grav | Days to revision 2 |
| Wed 19 Jul 2023· 1 advisory change | ||||
| 2023-07-19published 2022-05-24 | GHSA-gfwj-fwqj-fp3vCVE-2021-22118 | high | not named as affected when the advisory was published, now names org.springframework:spring-web | not dated |
| Tue 18 Jul 2023· 1 advisory change | ||||
| 2023-07-18published 2023-07-14 | GHSA-7gj7-224w-vpr3CVE-2023-38286 | high | not named as affected when the advisory was published, now names de.codecentric:spring-boot-admin-server | Days to revision 5 |
| Sat 15 Jul 2023· 2 advisory changes | ||||
| 2023-07-15published 2023-07-06 | moderate | not named as affected when the advisory was published, now names github.com/zinclabs/zinc | Days to revision 8 | |
| 2023-07-15published 2023-07-06 | GHSA-4fgv-8448-gf82CVE-2022-32171 | same package registry as the line abovemoderate | same change as the line above | Days to revision 8 |
| 2023-07-15published 2023-07-06 | GHSA-7j6x-42mm-p7jmCVE-2022-32172 | same package registry as the line abovemoderate | same change as the line above | Days to revision 8 |
| Thu 6 Jul 2023· 1 advisory change | ||||
| 2023-07-06published 2023-06-30 | GHSA-fmrf-p77g-vv5cCVE-2023-37302 | moderate | not named as affected when the advisory was published, now names wikibase/wikibase | Days to revision 6 |
| Wed 5 Jul 2023· 3 advisory changes | ||||
| 2023-07-05published 2018-01-22 to 2020-09-01 | moderate | not named as affected when the advisory was published, now names jquery-rails | not dated | |
| 2023-07-05published 2020-09-01 | GHSA-2pqj-h3vj-pqgwCVE-2012-6708 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-07-05published 2018-01-22 | GHSA-rmxg-73gg-4p98CVE-2015-9251 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-07-05published 2020-05-20 | GHSA-q4m3-2j7h-f7xwCVE-2020-7656 | same package registry as the line abovemoderate | same change as the line above | not dated |
| Mon 3 Jul 2023· 1 advisory change | ||||
| 2023-07-03published 2022-02-15 | GHSA-x5m6-jh4r-34mvCVE-2014-0177 | moderate | not named as affected when the advisory was published, now names hub | not dated |
| Mon 19 Jun 2023· 4 advisory changes | ||||
| 2023-06-19published 2017-10-24 | 4 rows, one per advisory and package | moderate | not named as affected when the advisory was published, now names actionpack and 1 more | not dated |
| 2023-06-19published 2017-10-24 | GHSA-v9v4-7jp6-8c73CVE-2011-2197 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names actionpack | not dated |
| 2023-06-19published 2017-10-24 | GHSA-v9v4-7jp6-8c73CVE-2011-2197 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names activesupport | not dated |
| 2023-06-19published 2017-10-24 | GHSA-8qrh-h9m2-5fvfCVE-2009-3009 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names actionpack | not dated |
| 2023-06-19published 2017-10-24 | GHSA-8qrh-h9m2-5fvfCVE-2009-3009 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names activesupport | not dated |
| Mon 12 Jun 2023· 12 advisory changes | ||||
| 2023-06-12published 2022-05-17 | GHSA-95xq-v4m2-fq3rCVE-2013-4489 | moderate | not named as affected when the advisory was published, now names gitlab-grit | Days to revision 392 |
| 2023-06-12published 2022-10-13 | GHSA-599f-7c49-w659CVE-2022-42889 | critical | not named as affected when the advisory was published, now names com.guicedee.services:commons-text | not dated |
| 2023-06-12published 2020-06-15 | GHSA-6hgm-866r-3cjv | high | not named as affected when the advisory was published, now names net.sourceforge.collections:collections-generic and 2 more | not dated |
| 2023-06-12published 2020-06-15 | GHSA-6hgm-866r-3cjvCVE-2015-6420 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names net.sourceforge.collections:collections-generic | not dated |
| 2023-06-12published 2020-06-15 | GHSA-6hgm-866r-3cjvCVE-2015-6420 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.apache.servicemix.bundles:org.apache.servicemix.bundles.collections-generic | not dated |
| 2023-06-12published 2020-06-15 | GHSA-6hgm-866r-3cjvCVE-2015-6420 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.apache.servicemix.bundles:org.apache.servicemix.bundles.commons-collections | not dated |
| 2023-06-12published 2022-09-06 | GHSA-c4r9-r8fh-9vj2 | moderate | not named as affected when the advisory was published, now names be.cylab:snakeyaml and 5 more | not dated |
| 2023-06-12published 2022-09-06 | GHSA-c4r9-r8fh-9vj2CVE-2022-38749 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names be.cylab:snakeyaml | not dated |
| 2023-06-12published 2022-09-06 | GHSA-c4r9-r8fh-9vj2CVE-2022-38749 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names com.alipay.sofa.acts:acts-common-util | not dated |
| 2023-06-12published 2022-09-06 | GHSA-c4r9-r8fh-9vj2CVE-2022-38749 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names io.prometheus.jmx:jmx_prometheus_httpserver | not dated |
| 2023-06-12published 2022-09-06 | GHSA-c4r9-r8fh-9vj2CVE-2022-38749 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names io.prometheus.jmx:jmx_prometheus_httpserver_java6 | not dated |
| 2023-06-12published 2022-09-06 | GHSA-c4r9-r8fh-9vj2CVE-2022-38749 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.testifyproject.external:external-snakeyaml | not dated |
| 2023-06-12published 2022-09-06 | GHSA-c4r9-r8fh-9vj2CVE-2022-38749 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names pl.droidsonroids.yaml:snakeyaml | not dated |
| 2023-06-12published 2017-10-24 | GHSA-75w6-p6mg-vh8jCVE-2011-0446 | moderate | not named as affected when the advisory was published, now names actionview | not dated |
| Fri 9 Jun 2023· 4 advisory changes | ||||
| 2023-06-09published 2018-03-21 | GHSA-x7rv-cr6v-4vm4CVE-2018-8048 | moderate | not named as affected when the advisory was published, now names nokogiri | not dated |
| 2023-06-09published 2017-10-24 | 2 bands | not named as affected when the advisory was published, now names actionpack | not dated | |
| 2023-06-09published 2017-10-24 | GHSA-xrr4-p6fq-hjg7CVE-2016-0752 | same package registry as the line abovehigh | same change as the line above | not dated |
| 2023-06-09published 2017-10-24 | GHSA-vx9j-46rh-fqr8CVE-2016-2097 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-06-09published 2017-10-24 | GHSA-m46p-ggm5-5j83CVE-2014-0081 | same package registry as the line abovemoderate | same change as the line above | not dated |
| Wed 31 May 2023· 4 advisory changes | ||||
| 2023-05-31published 2018-01-22 to 2022-05-14 | moderate | not named as affected when the advisory was published, now names jquery | not dated | |
| 2023-05-31published 2020-04-29 | GHSA-jpcq-cgw6-v4j6CVE-2020-11023 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-05-31published 2022-05-14 | GHSA-579v-mp3v-rrw5CVE-2011-4969 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-05-31published 2020-09-01 | GHSA-2pqj-h3vj-pqgwCVE-2012-6708 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-05-31published 2018-01-22 | GHSA-rmxg-73gg-4p98CVE-2015-9251 | same package registry as the line abovemoderate | same change as the line above | not dated |
| Tue 30 May 2023· 5 advisory changes | ||||
| 2023-05-30published 2018-07-26 | GHSA-rch9-xh7r-mqgwCVE-2018-3717 | moderate | not named as affected when the advisory was published, now names connect | not dated |
| 2023-05-30published 2021-08-13 | GHSA-6xx3-rg99-gc3pCVE-2020-15522 | moderate | not named as affected when the advisory was published, now names bouncycastle | not dated |
| 2023-05-30published 2019-04-26 to 2020-05-20 | moderate | not named as affected when the advisory was published, now names jquery | not dated | |
| 2023-05-30published 2020-05-20 | GHSA-q4m3-2j7h-f7xwCVE-2020-7656 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-05-30published 2019-04-26 | GHSA-6c3j-c64m-qhgqCVE-2019-11358 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-05-30published 2019-04-26 | GHSA-6c3j-c64m-qhgqCVE-2019-11358 | moderate | not named as affected when the advisory was published, now names jquery-rails | not dated |
| Fri 26 May 2023· 9 advisory changes | ||||
| 2023-05-26published 2017-10-24 to 2022-04-22 | moderate | not named as affected when the advisory was published, now names actionpack | not dated | |
| 2023-05-26published 2022-04-22 | GHSA-q58j-fmvf-9rq6CVE-2011-1497 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-05-26published 2017-10-24 | GHSA-xxr8-833v-c7wcCVE-2011-4319 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-05-26published 2017-10-24 | GHSA-24fg-p96v-hxh8CVE-2011-0447 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-05-26published 2017-10-24 | GHSA-fg9w-g6m4-557jCVE-2009-3086 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-05-26published 2017-10-24 | GHSA-8fqx-7pv4-3jwmCVE-2008-7248 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-05-26published 2017-10-24 | GHSA-75w6-p6mg-vh8jCVE-2011-0446 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-05-26published 2017-10-24 | GHSA-fg9w-g6m4-557jCVE-2009-3086 | moderate | not named as affected when the advisory was published, now names activesupport | not dated |
| 2023-05-26published 2017-10-24 | 2 bands | not named as affected when the advisory was published, now names activerecord | not dated | |
| 2023-05-26published 2017-10-24 | GHSA-gjxw-5w2q-7grfCVE-2010-3933 | same package registry as the line abovemoderate | same change as the line above | not dated |
| 2023-05-26published 2017-10-24 | GHSA-xf96-32q2-9rw2CVE-2008-4094 | same package registry as the line abovehigh | same change as the line above | not dated |
| Wed 24 May 2023· 1 advisory change | ||||
| 2023-05-24published 2022-01-13 | GHSA-vqwg-4v6f-h6x5CVE-2022-20615 | moderate | not named as affected when the advisory was published, now names org.jenkins-ci.plugins:matrix-project | not dated |
| Mon 22 May 2023· 1 advisory change | ||||
| 2023-05-22published 2022-05-13 | GHSA-3wqf-4x89-9g79CVE-2018-14040 | moderate | not named as affected when the advisory was published, now names bootstrap | not dated |
| Thu 4 May 2023· 2 advisory changes | ||||
| 2023-05-04published 2020-02-20 | GHSA-cmcx-xhr8-3w9pCVE-2020-5243 | moderate | not named as affected when the advisory was published, now names user_agent_parser | not dated |
| 2023-05-04published 2020-04-29 | GHSA-jpcq-cgw6-v4j6CVE-2020-11023 | moderate | not named as affected when the advisory was published, now names jquery-rails | not dated |
| Tue 2 May 2023· 1 advisory change | ||||
| 2023-05-02published 2022-07-19 | GHSA-4x9r-j582-cgr8CVE-2022-33891 | high | not named as affected when the advisory was published, now names org.apache.spark:spark-parent_2.12 | not dated |
| Mon 1 May 2023· 2 advisory changes | ||||
| 2023-05-01published 2022-01-06 | GHSA-29mw-wpgm-hmr9 | moderate | not named as affected when the advisory was published, now names lodash.trim and 1 more | not dated |
| 2023-05-01published 2022-01-06 | GHSA-29mw-wpgm-hmr9CVE-2020-28500 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names lodash.trim | not dated |
| 2023-05-01published 2022-01-06 | GHSA-29mw-wpgm-hmr9CVE-2020-28500 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names lodash.trimend | not dated |
| Fri 21 Apr 2023· 1 advisory change | ||||
| 2023-04-21published 2021-10-12 | GHSA-q799-q27x-vp7wCVE-2019-5064 | high | not named as affected when the advisory was published, now names opencv-contrib-python-headless | not dated |
| Fri 14 Apr 2023· 1 advisory change | ||||
| 2023-04-14published 2022-12-30 | GHSA-w9rv-xmf7-x3ghCVE-2022-44621 | critical | not named as affected when the advisory was published, now names org.apache.kylin:kylin-server-base | Days to revision 105 |
Counted in advisories, never added to the CVE and KEV figures. This kind is counted once per advisory and per package, so one advisory that named four further packages counts four times. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.
Data sources and quality
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →