Skip to content

Package added to advisory

What a record said when it was published, what it says now, and the commit that changed it.

1,695 advisory changes · newest first · grouped by day

SinceClear all
ChangedSourceRows
Counted changes of "Package added to advisory", newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.Advisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Wed 27 Sep 2023· 1 advisory change
2023-09-27published 2022-02-09GHSA-f268-65qc-98vgCVE-2020-13943moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyotenot dated
Tue 26 Sep 2023· 37 advisory changes
2023-09-26published 2017-10-24 to 2022-07-1828 rows, one per advisory and package3 bandsnot named as affected when the advisory was published, now names org.webjars.npm:jquery and 19 moreDays to revision 490
2023-09-26published 2019-04-26GHSA-6c3j-c64m-qhgqCVE-2019-11358same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.webjars.npm:jquerynot dated
2023-09-26published 2018-07-27GHSA-g8q2-24jh-5hpcsame package registry as the line abovehighnot named as affected when the advisory was published, now names org.webjars.npm:jquery-uinot dated
2023-09-26published 2020-05-20GHSA-q4m3-2j7h-f7xwCVE-2020-7656same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.webjars.npm:jquerynot dated
2023-09-26published 2022-05-14GHSA-579v-mp3v-rrw5CVE-2011-4969same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.webjars.npm:jquerynot dated
2023-09-26published 2022-07-18GHSA-h6gj-6jjq-h8g9CVE-2022-31160same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.webjars.npm:jquery-uinot dated
2023-09-26published 2017-10-24GHSA-qqxp-xp9v-vvx6CVE-2012-6662same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.webjars.npm:jquery-uinot dated
2023-09-26published 2017-10-24GHSA-wcm2-9c89-wmfmCVE-2010-5312same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.webjars.npm:jquery-uinot dated
2023-09-26published 2017-10-24GHSA-hpcf-8vf9-q4gjCVE-2016-7103same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.webjars.npm:jquery-uinot dated
20 more rows in this change are not listed here. Open all 28 rows
2023-09-26published 2017-10-24 to 2022-07-182 bandsnot named as affected when the advisory was published, now names jquery.ui.combinednot dated
2023-09-26published 2018-07-27GHSA-g8q2-24jh-5hpcsame package registry as the line abovehighsame change as the line abovenot dated
2023-09-26published 2022-07-18GHSA-h6gj-6jjq-h8g9CVE-2022-31160same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-26published 2017-10-24GHSA-qqxp-xp9v-vvx6CVE-2012-6662same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-26published 2017-10-24GHSA-wcm2-9c89-wmfmCVE-2010-5312same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-26published 2017-10-24GHSA-hpcf-8vf9-q4gjCVE-2016-7103same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-26published 2017-10-24 to 2022-07-182 bandsnot named as affected when the advisory was published, now names jquery-ui-railsnot dated
2023-09-26published 2018-07-27GHSA-g8q2-24jh-5hpcsame package registry as the line abovehighsame change as the line abovenot dated
2023-09-26published 2022-07-18GHSA-h6gj-6jjq-h8g9CVE-2022-31160same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-26published 2017-10-24GHSA-qqxp-xp9v-vvx6CVE-2012-6662same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-26published 2017-10-24GHSA-wcm2-9c89-wmfmCVE-2010-5312same package registry as the line abovemoderatesame change as the line abovenot dated
Mon 25 Sep 2023· 37 advisory changes
2023-09-25published 2018-01-22 to 2022-04-1923 rows, one per advisory and package3 bandsnot named as affected when the advisory was published, now names org.webjars.npm:jquery-ui and 16 morenot dated
2023-09-25published 2021-10-26GHSA-gpqq-952q-5327CVE-2021-41184same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.webjars.npm:jquery-uinot dated
2023-09-25published 2021-10-26GHSA-j7qv-pgf6-hvh4CVE-2021-41183same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.webjars.npm:jquery-uinot dated
2023-09-25published 2021-10-26GHSA-9gj3-hwp5-pmwcCVE-2021-41182same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.webjars.npm:jquery-uinot dated
2023-09-25published 2018-01-22GHSA-mhpp-875w-9cpvCVE-2016-10707same package registry as the line abovehighnot named as affected when the advisory was published, now names org.webjars.npm:jquerynot dated
2023-09-25published 2018-01-22GHSA-rmxg-73gg-4p98CVE-2015-9251same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.webjars.npm:jquerynot dated
2023-09-25published 2020-04-29GHSA-gxr4-xjj5-5px2CVE-2020-11022same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.webjars.npm:jquerynot dated
2023-09-25published 2020-04-29GHSA-jpcq-cgw6-v4j6CVE-2020-11023same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.webjars.npm:jquerynot dated
2023-09-25published 2019-04-23GHSA-wv67-q8rr-grjpCVE-2019-5428same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.webjars.npm:jquerynot dated
15 more rows in this change are not listed here. Open all 23 rows
2023-09-25published 2021-10-26moderatenot named as affected when the advisory was published, now names jquery.ui.combinednot dated
2023-09-25published 2021-10-26GHSA-gpqq-952q-5327CVE-2021-41184same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-25published 2021-10-26GHSA-j7qv-pgf6-hvh4CVE-2021-41183same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-25published 2021-10-26GHSA-9gj3-hwp5-pmwcCVE-2021-41182same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-25published 2021-10-26moderatenot named as affected when the advisory was published, now names jquery-ui-railsnot dated
2023-09-25published 2021-10-26GHSA-gpqq-952q-5327CVE-2021-41184same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-25published 2021-10-26GHSA-j7qv-pgf6-hvh4CVE-2021-41183same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-25published 2021-10-26GHSA-9gj3-hwp5-pmwcCVE-2021-41182same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-25published 2018-01-22 to 2022-05-142 bandsnot named as affected when the advisory was published, now names jquery-railsnot dated
2023-09-25published 2018-01-22GHSA-mhpp-875w-9cpvCVE-2016-10707same package registry as the line abovehighsame change as the line abovenot dated
2023-09-25published 2020-04-29GHSA-gxr4-xjj5-5px2CVE-2020-11022same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-25published 2019-04-23GHSA-wv67-q8rr-grjpCVE-2019-5428same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-25published 2022-05-14GHSA-579v-mp3v-rrw5CVE-2011-4969same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-25published 2019-04-23 to 2020-04-29moderatenot named as affected when the advisory was published, now names jquerynot dated
2023-09-25published 2020-04-29GHSA-gxr4-xjj5-5px2CVE-2020-11022same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-25published 2019-04-23GHSA-wv67-q8rr-grjpCVE-2019-5428same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-25published 2022-05-24GHSA-fp37-c92q-4pwqCVE-2019-11247highnot named as affected when the advisory was published, now names k8s.io/apiextensions-apiserverDays to revision 489
2023-09-25published 2021-07-26GHSA-h8jc-jmrf-9h8fCVE-2020-8828highnot named as affected when the advisory was published, now names github.com/argoproj/argo-cdnot dated
Thu 21 Sep 2023· 5 advisory changes
2023-09-21published 2020-04-15GHSA-rc5r-697f-28x6moderatenot named as affected when the advisory was published, now names sylius/grid-bundle and 1 morenot dated
2023-09-21published 2020-04-15GHSA-rc5r-697f-28x6CVE-2019-12186same package registry as the line abovemoderatenot named as affected when the advisory was published, now names sylius/grid-bundlenot dated
2023-09-21published 2020-04-15GHSA-rc5r-697f-28x6CVE-2019-12186same package registry as the line abovemoderatenot named as affected when the advisory was published, now names sylius/syliusnot dated
2023-09-21published 2023-09-12GHSA-j7hp-h8jx-5pprCVE-2023-4863highnot named as affected when the advisory was published, now names github.com/chai2010/webpDays to revision 9
2023-09-21published 2023-09-12GHSA-j7hp-h8jx-5pprCVE-2023-4863highnot named as affected when the advisory was published, now names skiasharpDays to revision 9
2023-09-21published 2021-09-08GHSA-7q44-gfvq-6g93CVE-2020-18155criticalnot named as affected when the advisory was published, now names intelliants/subrionnot dated
Wed 20 Sep 2023· 1 advisory change
2023-09-20published 2023-06-12GHSA-59x6-g4jr-4hxcCVE-2023-35042criticalnot named as affected when the advisory was published, now names org.geoserver:gs-wpsDays to revision 100
Tue 19 Sep 2023· 3 advisory changes
2023-09-19published 2021-12-10GHSA-jfh8-c2jp-5v3qcriticalnot named as affected when the advisory was published, now names com.guicedee.services:log4j-core and 2 morenot dated
2023-09-19published 2021-12-10GHSA-jfh8-c2jp-5v3qCVE-2021-44228same package registry as the line abovecriticalnot named as affected when the advisory was published, now names com.guicedee.services:log4j-corenot dated
2023-09-19published 2021-12-10GHSA-jfh8-c2jp-5v3qCVE-2021-44228same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.xbib.elasticsearch:log4jnot dated
2023-09-19published 2021-12-10GHSA-jfh8-c2jp-5v3qCVE-2021-44228same package registry as the line abovecriticalnot named as affected when the advisory was published, now names uk.co.nichesolutions.logging.log4j:log4j-corenot dated
Mon 18 Sep 2023· 8 advisory changes
2023-09-18published 2021-05-18 to 2022-02-15moderatenot named as affected when the advisory was published, now names k8s.io/kubernetesnot dated
2023-09-18published 2022-02-15GHSA-qhm4-jxv7-j9pqCVE-2020-8551same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-18published 2022-02-15GHSA-x6mj-w4jf-jmgwCVE-2020-8555same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-18published 2021-05-18GHSA-6qfg-8799-r575CVE-2019-11251same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-18published 2022-02-15GHSA-34jx-wx69-9x8vCVE-2019-1002101same package registry as the line abovemoderatesame change as the line abovenot dated
2023-09-18published 2022-02-15GHSA-82hx-w2r5-c2wqCVE-2020-8552moderatenot named as affected when the advisory was published, now names k8s.io/apiservernot dated
2023-09-18published 2022-02-15GHSA-2575-pghm-6qqxCVE-2019-11244moderatenot named as affected when the advisory was published, now names k8s.io/client-gonot dated
2023-09-18published 2023-09-12GHSA-j7hp-h8jx-5pprCVE-2023-4863highnot named as affected when the advisory was published, now names libwebp-sysDays to revision 6
2023-09-18published 2023-09-12GHSA-j7hp-h8jx-5pprCVE-2023-4863highnot named as affected when the advisory was published, now names electronDays to revision 6
Thu 14 Sep 2023· 1 advisory change
2023-09-14published 2020-08-31GHSA-4mv4-gmmf-q382CVE-2015-6584highnot named as affected when the advisory was published, now names datatables/datatablesnot dated
Tue 12 Sep 2023· 6 advisory changes
2023-09-12published 2022-05-14GHSA-42wx-65g4-5cxvCVE-2018-1309criticalnot named as affected when the advisory was published, now names org.apache.nifi:nifi-standard-processorsnot dated
2023-09-12published 2021-02-25GHSA-pr5m-4w22-8483CVE-2020-13697moderatenot named as affected when the advisory was published, now names org.nanohttpd:nanohttpd-nanoletsnot dated
2023-09-12published 2018-10-17GHSA-ccjp-w723-2jf2CVE-2015-3271moderatenot named as affected when the advisory was published, now names org.apache.tika:tika-servernot dated
2023-09-12published 2022-01-06GHSA-g644-pr5v-vppfCVE-2020-9486highnot named as affected when the advisory was published, now names org.apache.nifi:nifi-statelessnot dated
2023-09-12published 2018-10-18GHSA-v6wr-fch2-vm5wCVE-2015-2913moderatenot named as affected when the advisory was published, now names com.orientechnologies:orientdb-servernot dated
2023-09-12published 2022-05-17GHSA-r6fx-55x3-f9x6CVE-2021-23267highnot named as affected when the advisory was published, now names org.craftercms:crafter-studionot dated
Mon 11 Sep 2023· 8 advisory changes
2023-09-11published 2019-01-07GHSA-92wj-x78c-m4fxCVE-2018-11788criticalnot named as affected when the advisory was published, now names org.apache.karaf.specs:org.apache.karaf.specs.java.xmlnot dated
2023-09-11published 2022-09-14GHSA-2jv3-v37p-65w3CVE-2022-40634highnot named as affected when the advisory was published, now names org.craftercms:crafter-studionot dated
2023-09-11published 2021-06-16GHSA-q7fr-vqhq-v5xrCVE-2021-26118highnot named as affected when the advisory was published, now names org.apache.activemq:artemis-openwire-protocolnot dated
2023-09-11published 2022-05-01GHSA-h7mf-qrm9-2848CVE-2007-4556moderatenot named as affected when the advisory was published, now names opensymphony:xworknot dated
2023-09-11published 2018-12-20GHSA-43fp-vwwg-qgv6CVE-2018-17194highnot named as affected when the advisory was published, now names org.apache.nifi:nifi-framework-clusternot dated
2023-09-11published 2022-05-24GHSA-9x5v-8352-244gCVE-2019-10357moderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins.workflow:workflow-cps-global-libnot dated
2023-09-11published 2018-12-19GHSA-8j39-fgfp-vxh8CVE-2018-20094highnot named as affected when the advisory was published, now names com.xuxueli:xxl-conf-adminnot dated
2023-09-11published 2019-08-27GHSA-f5f4-m7qp-w6gcCVE-2019-15477moderatenot named as affected when the advisory was published, now names org.jooby:joobynot dated
Fri 8 Sep 2023· 1 advisory change
2023-09-08published 2019-11-12GHSA-g996-q5r8-w7g2CVE-2019-10909moderatenot named as affected when the advisory was published, now names drupal/corenot dated
Thu 7 Sep 2023· 5 advisory changes
2023-09-07published 2020-06-15GHSA-mvr2-9pj6-7w5jmoderatenot named as affected when the advisory was published, now names com.google.guava:guava-jdk5 and 4 morenot dated
2023-09-07published 2020-06-15GHSA-mvr2-9pj6-7w5jCVE-2018-10237same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.google.guava:guava-jdk5not dated
2023-09-07published 2020-06-15GHSA-mvr2-9pj6-7w5jCVE-2018-10237same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.googlecode.guava-osgi:guava-osginot dated
2023-09-07published 2020-06-15GHSA-mvr2-9pj6-7w5jCVE-2018-10237same package registry as the line abovemoderatenot named as affected when the advisory was published, now names de.mhus.ports:vaadin-shared-depsnot dated
2023-09-07published 2020-06-15GHSA-mvr2-9pj6-7w5jCVE-2018-10237same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.hudsonci.lib.guava:guavanot dated
2023-09-07published 2020-06-15GHSA-mvr2-9pj6-7w5jCVE-2018-10237same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.sonatype.sisu:sisu-guavanot dated
Tue 5 Sep 2023· 10 advisory changes
2023-09-05published 2021-09-23GHSA-3j6g-hxx5-3q26moderatenot named as affected when the advisory was published, now names org.apache.kafka:kafka-clients and 3 morenot dated
2023-09-05published 2021-09-23GHSA-3j6g-hxx5-3q26CVE-2021-38153same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.kafka:kafka-clientsnot dated
2023-09-05published 2021-09-23GHSA-3j6g-hxx5-3q26CVE-2021-38153same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.11not dated
2023-09-05published 2021-09-23GHSA-3j6g-hxx5-3q26CVE-2021-38153same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.12not dated
2023-09-05published 2021-09-23GHSA-3j6g-hxx5-3q26CVE-2021-38153same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.13not dated
2023-09-05published 2022-01-06GHSA-2h63-qp69-fwvwCVE-2020-11987highnot named as affected when the advisory was published, now names org.apache.xmlgraphics:batik-svgbrowsernot dated
2023-09-05published 2023-07-05GHSA-hr8g-6v94-x4m9moderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-debug-jdk15on and 2 moreDays to revision 63
2023-09-05published 2023-07-05GHSA-hr8g-6v94-x4m9CVE-2023-33201same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-debug-jdk15onDays to revision 63
2023-09-05published 2023-07-05GHSA-hr8g-6v94-x4m9CVE-2023-33201same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-ext-jdk15onDays to revision 63
2023-09-05published 2023-07-05GHSA-hr8g-6v94-x4m9CVE-2023-33201same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onDays to revision 63
2023-09-05published 2019-04-10GHSA-f6f2-pwrj-64h3CVE-2019-10868highnot named as affected when the advisory was published, now names trytondnot dated
2023-09-05published 2019-04-26GHSA-6c3j-c64m-qhgqCVE-2019-11358moderatenot named as affected when the advisory was published, now names djangonot dated
Wed 30 Aug 2023· 1 advisory change
2023-08-30published 2022-11-15GHSA-prjq-f4q3-fvfrCVE-2020-7731highnot named as affected when the advisory was published, now names github.com/russellhaering/goxmldsignot dated
Mon 28 Aug 2023· 3 advisory changes
2023-08-28published 2019-04-09moderatenot named as affected when the advisory was published, now names @materializecss/materializenot dated
2023-08-28published 2019-04-09GHSA-7752-f4gf-94gcCVE-2019-11003same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-28published 2019-04-09GHSA-98f7-p5rc-jx67CVE-2019-11002same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-28published 2019-04-09GHSA-rg3q-jxmp-pvjjCVE-2019-11004same package registry as the line abovemoderatesame change as the line abovenot dated
Thu 24 Aug 2023· 1 advisory change
2023-08-24published 2022-06-01GHSA-qw3f-w4pf-jh5fCVE-2022-30973moderatenot named as affected when the advisory was published, now names org.apache.tika:tika-corenot dated
Wed 23 Aug 2023· 1 advisory change
2023-08-23published 2022-05-24GHSA-w6g9-xccc-347hCVE-2020-7941criticalnot named as affected when the advisory was published, now names plone.app.contenttypesDays to revision 456
Tue 22 Aug 2023· 1 advisory change
2023-08-22published 2022-05-24GHSA-qcch-9268-59jwCVE-2020-14297moderatenot named as affected when the advisory was published, now names org.jboss:jboss-ejb-clientDays to revision 455
Mon 21 Aug 2023· 2 advisory changes
2023-08-21published 2022-05-24GHSA-853f-x27w-8r74CVE-2020-12760highnot named as affected when the advisory was published, now names org.opennms.core:org.opennms.core.daemonDays to revision 454
2023-08-21published 2023-07-10GHSA-mjmq-gwgm-5qhmCVE-2023-35887moderatenot named as affected when the advisory was published, now names org.apache.sshd:sshd-coreDays to revision 42
Fri 18 Aug 2023· 2 advisory changes
2023-08-18published 2022-11-16GHSA-fhw8-8j55-vwgqCVE-2022-45047criticalnot named as affected when the advisory was published, now names org.apache.sshd:sshd-coreDays to revision 275
2023-08-18published 2018-10-17GHSA-4446-656p-f54gCVE-2018-1000613criticalnot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onnot dated
Tue 15 Aug 2023· 4 advisory changes
2023-08-15published 2023-08-09GHSA-vmch-3w2x-vhgqhighnot named as affected when the advisory was published, now names microsoft.aspnetcore.server.kestrel.transport.libuv and 1 moreDays to revision 6
2023-08-15published 2023-08-09GHSA-vmch-3w2x-vhgqCVE-2023-38180same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.server.kestrel.transport.libuvDays to revision 6
2023-08-15published 2023-08-09GHSA-vmch-3w2x-vhgqCVE-2023-38180same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.server.kestrel.transport.socketsDays to revision 6
2023-08-15published 2021-06-16GHSA-2f88-5hg8-9x2xcriticalnot named as affected when the advisory was published, now names org.apache.maven:maven-compat and 1 morenot dated
2023-08-15published 2021-06-16GHSA-2f88-5hg8-9x2xCVE-2021-26291same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.maven:maven-compatnot dated
2023-08-15published 2021-06-16GHSA-2f88-5hg8-9x2xCVE-2021-26291same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.maven:maven-corenot dated
Mon 14 Aug 2023· 1 advisory change
2023-08-14published 2023-07-18GHSA-p9xf-74xh-mhw5CVE-2023-37477highnot named as affected when the advisory was published, now names github.com/1panel-dev/1panelDays to revision 27
Mon 7 Aug 2023· 10 advisory changes
2023-08-07published 2020-02-21 to 2021-12-093 bandsnot named as affected when the advisory was published, now names io.netty:nettynot dated
2023-08-07published 2021-09-09GHSA-9vjp-v76f-g363CVE-2021-37137same package registry as the line abovehighsame change as the line abovenot dated
2023-08-07published 2021-03-09GHSA-wm47-8v5p-wjpjCVE-2021-21295same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-07published 2021-12-09GHSA-wx5j-54mm-rqqqCVE-2021-43797same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-07published 2021-09-09GHSA-grg4-wf29-r9vvCVE-2021-37136same package registry as the line abovehighsame change as the line abovenot dated
2023-08-07published 2021-03-30GHSA-f256-j965-7f32CVE-2021-21409same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-07published 2021-02-08GHSA-5mcr-gq6c-3hq2CVE-2021-21290same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-07published 2020-02-21GHSA-cqqj-4p63-rrmmCVE-2019-20444same package registry as the line abovecriticalsame change as the line abovenot dated
2023-08-07published 2020-02-21GHSA-p2v9-g2qv-p635CVE-2019-20445same package registry as the line abovemoderatesame change as the line abovenot dated
1 more row in this change is not listed here. Open all 9 rows
2023-08-07published 2022-01-27GHSA-77rm-9x9h-xj3gCVE-2021-22570highnot named as affected when the advisory was published, now names com.google.protobuf:protobuf-javanot dated
Fri 4 Aug 2023· 12 advisory changes
2023-08-04published 2022-05-24GHSA-hr65-qq6p-87r4CVE-2021-22137moderatenot named as affected when the advisory was published, now names org.elasticsearch:elasticsearchnot dated
2023-08-04published 2019-10-11 to 2021-12-093 bandsnot named as affected when the advisory was published, now names org.jboss.netty:nettynot dated
2023-08-04published 2021-12-09GHSA-wx5j-54mm-rqqqCVE-2021-43797same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-04published 2021-09-09GHSA-9vjp-v76f-g363CVE-2021-37137same package registry as the line abovehighsame change as the line abovenot dated
2023-08-04published 2021-09-09GHSA-grg4-wf29-r9vvCVE-2021-37136same package registry as the line abovehighsame change as the line abovenot dated
2023-08-04published 2021-03-30GHSA-f256-j965-7f32CVE-2021-21409same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-04published 2021-03-09GHSA-wm47-8v5p-wjpjCVE-2021-21295same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-04published 2021-02-08GHSA-5mcr-gq6c-3hq2CVE-2021-21290same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-04published 2020-02-21GHSA-cqqj-4p63-rrmmCVE-2019-20444same package registry as the line abovecriticalsame change as the line abovenot dated
2023-08-04published 2020-02-21GHSA-p2v9-g2qv-p635CVE-2019-20445same package registry as the line abovemoderatesame change as the line abovenot dated
2 more rows in this change are not listed here. Open all 10 rows
2023-08-04published 2020-06-30GHSA-xfv3-rrfm-f2rvCVE-2015-2156highnot named as affected when the advisory was published, now names io.netty:netty-parentnot dated
Thu 3 Aug 2023· 4 advisory changes
2023-08-03published 2022-05-24GHSA-c3mp-9vx3-2rvvhighnot named as affected when the advisory was published, now names org.opennms.features:org.opennms.features.measurements and 2 moreDays to revision 436
2023-08-03published 2022-05-24GHSA-c3mp-9vx3-2rvvCVE-2021-3396same package registry as the line abovehighnot named as affected when the advisory was published, now names org.opennms.features:org.opennms.features.measurementsDays to revision 436
2023-08-03published 2022-05-24GHSA-c3mp-9vx3-2rvvCVE-2021-3396same package registry as the line abovehighnot named as affected when the advisory was published, now names org.opennms:opennms-provisionDays to revision 436
2023-08-03published 2022-05-24GHSA-c3mp-9vx3-2rvvCVE-2021-3396same package registry as the line abovehighnot named as affected when the advisory was published, now names org.opennms:opennms-utilDays to revision 436
2023-08-03published 2022-05-13GHSA-hmx6-gc2p-5p82CVE-2019-5919criticalnot named as affected when the advisory was published, now names com.nablarch.framework:nablarch-fw-webDays to revision 448
Mon 31 Jul 2023· 3 advisory changes
2023-07-31published 2022-01-06GHSA-7q8g-gpfp-v8gxhighnot named as affected when the advisory was published, now names org.apache.nifi:nifi-framework-core and 1 morenot dated
2023-07-31published 2022-01-06GHSA-7q8g-gpfp-v8gxCVE-2020-1942same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.nifi:nifi-framework-corenot dated
2023-07-31published 2022-01-06GHSA-7q8g-gpfp-v8gxCVE-2020-1942same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.nifi:nifi-security-utilsnot dated
2023-07-31published 2023-03-16GHSA-p8p7-x288-28g6CVE-2023-28155moderatenot named as affected when the advisory was published, now names @cypress/requestDays to revision 137
Fri 28 Jul 2023· 2 advisory changes
2023-07-28published 2022-06-15 to 2022-10-262 bandsnot named as affected when the advisory was published, now names org.apache.flume.flume-ng-sources:flume-jms-sourcenot dated
2023-07-28published 2022-10-26GHSA-9w4g-fp9h-3q2vCVE-2022-42468same package registry as the line abovecriticalsame change as the line abovenot dated
2023-07-28published 2022-06-15GHSA-x5m7-rwfx-w7qmCVE-2022-25167same package registry as the line abovehighsame change as the line abovenot dated
Tue 25 Jul 2023· 1 advisory change
2023-07-25published 2023-03-31GHSA-5c9c-6x87-f9vmCVE-2022-4899highnot named as affected when the advisory was published, now names zstdDays to revision 116
Mon 24 Jul 2023· 1 advisory change
2023-07-24published 2022-05-14GHSA-43q7-q5vp-3g68CVE-2018-14371highnot named as affected when the advisory was published, now names org.glassfish:mojarra-parentnot dated
Fri 21 Jul 2023· 2 advisory changes
2023-07-21published 2022-08-16GHSA-8wj3-cpmr-8whpCVE-2022-2818highnot named as affected when the advisory was published, now names cockpit-hq/cockpitnot dated
2023-07-21published 2023-07-19GHSA-9436-3gmp-4f53CVE-2023-37897highnot named as affected when the advisory was published, now names getgrav/gravDays to revision 2
Wed 19 Jul 2023· 1 advisory change
2023-07-19published 2022-05-24GHSA-gfwj-fwqj-fp3vCVE-2021-22118highnot named as affected when the advisory was published, now names org.springframework:spring-webnot dated
Tue 18 Jul 2023· 1 advisory change
2023-07-18published 2023-07-14GHSA-7gj7-224w-vpr3CVE-2023-38286highnot named as affected when the advisory was published, now names de.codecentric:spring-boot-admin-serverDays to revision 5
Sat 15 Jul 2023· 2 advisory changes
2023-07-15published 2023-07-06moderatenot named as affected when the advisory was published, now names github.com/zinclabs/zincDays to revision 8
2023-07-15published 2023-07-06GHSA-4fgv-8448-gf82CVE-2022-32171same package registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-07-15published 2023-07-06GHSA-7j6x-42mm-p7jmCVE-2022-32172same package registry as the line abovemoderatesame change as the line aboveDays to revision 8
Thu 6 Jul 2023· 1 advisory change
2023-07-06published 2023-06-30GHSA-fmrf-p77g-vv5cCVE-2023-37302moderatenot named as affected when the advisory was published, now names wikibase/wikibaseDays to revision 6
Wed 5 Jul 2023· 3 advisory changes
2023-07-05published 2018-01-22 to 2020-09-01moderatenot named as affected when the advisory was published, now names jquery-railsnot dated
2023-07-05published 2020-09-01GHSA-2pqj-h3vj-pqgwCVE-2012-6708same package registry as the line abovemoderatesame change as the line abovenot dated
2023-07-05published 2018-01-22GHSA-rmxg-73gg-4p98CVE-2015-9251same package registry as the line abovemoderatesame change as the line abovenot dated
2023-07-05published 2020-05-20GHSA-q4m3-2j7h-f7xwCVE-2020-7656same package registry as the line abovemoderatesame change as the line abovenot dated
Mon 3 Jul 2023· 1 advisory change
2023-07-03published 2022-02-15GHSA-x5m6-jh4r-34mvCVE-2014-0177moderatenot named as affected when the advisory was published, now names hubnot dated
Mon 19 Jun 2023· 4 advisory changes
2023-06-19published 2017-10-244 rows, one per advisory and packagemoderatenot named as affected when the advisory was published, now names actionpack and 1 morenot dated
2023-06-19published 2017-10-24GHSA-v9v4-7jp6-8c73CVE-2011-2197same package registry as the line abovemoderatenot named as affected when the advisory was published, now names actionpacknot dated
2023-06-19published 2017-10-24GHSA-v9v4-7jp6-8c73CVE-2011-2197same package registry as the line abovemoderatenot named as affected when the advisory was published, now names activesupportnot dated
2023-06-19published 2017-10-24GHSA-8qrh-h9m2-5fvfCVE-2009-3009same package registry as the line abovemoderatenot named as affected when the advisory was published, now names actionpacknot dated
2023-06-19published 2017-10-24GHSA-8qrh-h9m2-5fvfCVE-2009-3009same package registry as the line abovemoderatenot named as affected when the advisory was published, now names activesupportnot dated
Mon 12 Jun 2023· 12 advisory changes
2023-06-12published 2022-05-17GHSA-95xq-v4m2-fq3rCVE-2013-4489moderatenot named as affected when the advisory was published, now names gitlab-gritDays to revision 392
2023-06-12published 2022-10-13GHSA-599f-7c49-w659CVE-2022-42889criticalnot named as affected when the advisory was published, now names com.guicedee.services:commons-textnot dated
2023-06-12published 2020-06-15GHSA-6hgm-866r-3cjvhighnot named as affected when the advisory was published, now names net.sourceforge.collections:collections-generic and 2 morenot dated
2023-06-12published 2020-06-15GHSA-6hgm-866r-3cjvCVE-2015-6420same package registry as the line abovehighnot named as affected when the advisory was published, now names net.sourceforge.collections:collections-genericnot dated
2023-06-12published 2020-06-15GHSA-6hgm-866r-3cjvCVE-2015-6420same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.servicemix.bundles:org.apache.servicemix.bundles.collections-genericnot dated
2023-06-12published 2020-06-15GHSA-6hgm-866r-3cjvCVE-2015-6420same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.servicemix.bundles:org.apache.servicemix.bundles.commons-collectionsnot dated
2023-06-12published 2022-09-06GHSA-c4r9-r8fh-9vj2moderatenot named as affected when the advisory was published, now names be.cylab:snakeyaml and 5 morenot dated
2023-06-12published 2022-09-06GHSA-c4r9-r8fh-9vj2CVE-2022-38749same package registry as the line abovemoderatenot named as affected when the advisory was published, now names be.cylab:snakeyamlnot dated
2023-06-12published 2022-09-06GHSA-c4r9-r8fh-9vj2CVE-2022-38749same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.alipay.sofa.acts:acts-common-utilnot dated
2023-06-12published 2022-09-06GHSA-c4r9-r8fh-9vj2CVE-2022-38749same package registry as the line abovemoderatenot named as affected when the advisory was published, now names io.prometheus.jmx:jmx_prometheus_httpservernot dated
2023-06-12published 2022-09-06GHSA-c4r9-r8fh-9vj2CVE-2022-38749same package registry as the line abovemoderatenot named as affected when the advisory was published, now names io.prometheus.jmx:jmx_prometheus_httpserver_java6not dated
2023-06-12published 2022-09-06GHSA-c4r9-r8fh-9vj2CVE-2022-38749same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.testifyproject.external:external-snakeyamlnot dated
2023-06-12published 2022-09-06GHSA-c4r9-r8fh-9vj2CVE-2022-38749same package registry as the line abovemoderatenot named as affected when the advisory was published, now names pl.droidsonroids.yaml:snakeyamlnot dated
2023-06-12published 2017-10-24GHSA-75w6-p6mg-vh8jCVE-2011-0446moderatenot named as affected when the advisory was published, now names actionviewnot dated
Fri 9 Jun 2023· 4 advisory changes
2023-06-09published 2018-03-21GHSA-x7rv-cr6v-4vm4CVE-2018-8048moderatenot named as affected when the advisory was published, now names nokogirinot dated
2023-06-09published 2017-10-242 bandsnot named as affected when the advisory was published, now names actionpacknot dated
2023-06-09published 2017-10-24GHSA-xrr4-p6fq-hjg7CVE-2016-0752same package registry as the line abovehighsame change as the line abovenot dated
2023-06-09published 2017-10-24GHSA-vx9j-46rh-fqr8CVE-2016-2097same package registry as the line abovemoderatesame change as the line abovenot dated
2023-06-09published 2017-10-24GHSA-m46p-ggm5-5j83CVE-2014-0081same package registry as the line abovemoderatesame change as the line abovenot dated
Wed 31 May 2023· 4 advisory changes
2023-05-31published 2018-01-22 to 2022-05-14moderatenot named as affected when the advisory was published, now names jquerynot dated
2023-05-31published 2020-04-29GHSA-jpcq-cgw6-v4j6CVE-2020-11023same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-31published 2022-05-14GHSA-579v-mp3v-rrw5CVE-2011-4969same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-31published 2020-09-01GHSA-2pqj-h3vj-pqgwCVE-2012-6708same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-31published 2018-01-22GHSA-rmxg-73gg-4p98CVE-2015-9251same package registry as the line abovemoderatesame change as the line abovenot dated
Tue 30 May 2023· 5 advisory changes
2023-05-30published 2018-07-26GHSA-rch9-xh7r-mqgwCVE-2018-3717moderatenot named as affected when the advisory was published, now names connectnot dated
2023-05-30published 2021-08-13GHSA-6xx3-rg99-gc3pCVE-2020-15522moderatenot named as affected when the advisory was published, now names bouncycastlenot dated
2023-05-30published 2019-04-26 to 2020-05-20moderatenot named as affected when the advisory was published, now names jquerynot dated
2023-05-30published 2020-05-20GHSA-q4m3-2j7h-f7xwCVE-2020-7656same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-30published 2019-04-26GHSA-6c3j-c64m-qhgqCVE-2019-11358same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-30published 2019-04-26GHSA-6c3j-c64m-qhgqCVE-2019-11358moderatenot named as affected when the advisory was published, now names jquery-railsnot dated
Fri 26 May 2023· 9 advisory changes
2023-05-26published 2017-10-24 to 2022-04-22moderatenot named as affected when the advisory was published, now names actionpacknot dated
2023-05-26published 2022-04-22GHSA-q58j-fmvf-9rq6CVE-2011-1497same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24GHSA-xxr8-833v-c7wcCVE-2011-4319same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24GHSA-24fg-p96v-hxh8CVE-2011-0447same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24GHSA-fg9w-g6m4-557jCVE-2009-3086same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24GHSA-8fqx-7pv4-3jwmCVE-2008-7248same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24GHSA-75w6-p6mg-vh8jCVE-2011-0446same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24GHSA-fg9w-g6m4-557jCVE-2009-3086moderatenot named as affected when the advisory was published, now names activesupportnot dated
2023-05-26published 2017-10-242 bandsnot named as affected when the advisory was published, now names activerecordnot dated
2023-05-26published 2017-10-24GHSA-gjxw-5w2q-7grfCVE-2010-3933same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24GHSA-xf96-32q2-9rw2CVE-2008-4094same package registry as the line abovehighsame change as the line abovenot dated
Wed 24 May 2023· 1 advisory change
2023-05-24published 2022-01-13GHSA-vqwg-4v6f-h6x5CVE-2022-20615moderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins:matrix-projectnot dated
Mon 22 May 2023· 1 advisory change
2023-05-22published 2022-05-13GHSA-3wqf-4x89-9g79CVE-2018-14040moderatenot named as affected when the advisory was published, now names bootstrapnot dated
Thu 4 May 2023· 2 advisory changes
2023-05-04published 2020-02-20GHSA-cmcx-xhr8-3w9pCVE-2020-5243moderatenot named as affected when the advisory was published, now names user_agent_parsernot dated
2023-05-04published 2020-04-29GHSA-jpcq-cgw6-v4j6CVE-2020-11023moderatenot named as affected when the advisory was published, now names jquery-railsnot dated
Tue 2 May 2023· 1 advisory change
2023-05-02published 2022-07-19GHSA-4x9r-j582-cgr8CVE-2022-33891highnot named as affected when the advisory was published, now names org.apache.spark:spark-parent_2.12not dated
Mon 1 May 2023· 2 advisory changes
2023-05-01published 2022-01-06GHSA-29mw-wpgm-hmr9moderatenot named as affected when the advisory was published, now names lodash.trim and 1 morenot dated
2023-05-01published 2022-01-06GHSA-29mw-wpgm-hmr9CVE-2020-28500same package registry as the line abovemoderatenot named as affected when the advisory was published, now names lodash.trimnot dated
2023-05-01published 2022-01-06GHSA-29mw-wpgm-hmr9CVE-2020-28500same package registry as the line abovemoderatenot named as affected when the advisory was published, now names lodash.trimendnot dated
Fri 21 Apr 2023· 1 advisory change
2023-04-21published 2021-10-12GHSA-q799-q27x-vp7wCVE-2019-5064highnot named as affected when the advisory was published, now names opencv-contrib-python-headlessnot dated
Fri 14 Apr 2023· 1 advisory change
2023-04-14published 2022-12-30GHSA-w9rv-xmf7-x3ghCVE-2022-44621criticalnot named as affected when the advisory was published, now names org.apache.kylin:kylin-server-baseDays to revision 105

Counted in advisories, never added to the CVE and KEV figures. This kind is counted once per advisory and per package, so one advisory that named four further packages counts four times. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →