Skip to content

Package added to advisory

What a record said when it was published, what it says now, and the commit that changed it.

1,695 advisory changes · newest first · grouped by day

SinceClear all
ChangedSourceRows
Counted changes of "Package added to advisory", newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.Advisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Fri 14 Apr 2023· 6 changes
2023-04-14published 2022-11-22GHSA-cm43-f2pv-6v68CVE-2022-41131highnot named as affected when the advisory was published, now names apache-airflow-providers-apache-hiveTime to revision 143 days
2023-04-14published 2021-05-21GHSA-hfg5-xpvw-c9x4highnot named as affected when the advisory was published, now names org.apache.camel:camel and 2 moreDuration unknown
2023-04-14published 2021-05-21GHSA-hfg5-xpvw-c9x4CVE-2020-11971same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.camel:camelDuration unknown
2023-04-14published 2021-05-21GHSA-hfg5-xpvw-c9x4CVE-2020-11971same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.camel:camel-coreDuration unknown
2023-04-14published 2021-05-21GHSA-hfg5-xpvw-c9x4CVE-2020-11971same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.camel:camel-managementDuration unknown
2023-04-14published 2022-12-13GHSA-3vqj-43w4-2q58CVE-2022-45688highnot named as affected when the advisory was published, now names org.json:jsonTime to revision 122 days
2023-04-14published 2022-01-06GHSA-gc67-crq6-hgh5CVE-2021-41561highnot named as affected when the advisory was published, now names org.apache.parquet:parquetDuration unknown
Thu 13 Apr 2023· 1 change
2023-04-13published 2023-01-18GHSA-5pm2-9mr2-3frqCVE-2023-21893highnot named as affected when the advisory was published, now names oracle.manageddataaccess.coreTime to revision 86 days
Mon 10 Apr 2023· 1 change
2023-04-10published 2022-11-21GHSA-h6q3-vv32-2cq5CVE-2022-41894highnot named as affected when the advisory was published, now names tensorflowTime to revision 140 days
Tue 4 Apr 2023· 1 change
2023-04-04published 2021-06-23GHSA-gq5r-cc4w-g8xfhighnot named as affected when the advisory was published, now names github.com/russellhaering/goxmldsigDuration unknown
Thu 30 Mar 2023· 1 change
2023-03-30published 2021-09-20GHSA-mc22-5q92-8v85CVE-2021-39228moderatenot named as affected when the advisory was published, now names tremor-scriptDuration unknown
Wed 29 Mar 2023· 1 change
2023-03-29published 2021-09-20GHSA-468q-v4jj-485hCVE-2021-3804highnot named as affected when the advisory was published, now names @tarojs/helperDuration unknown
Mon 27 Mar 2023· 5 changes
2023-03-27published 2018-11-09moderatenot named as affected when the advisory was published, now names mapbox-railsDuration unknown
2023-03-27published 2018-11-09GHSA-qr28-7j6p-9hmvCVE-2017-1000042same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2023-03-27published 2018-11-09GHSA-q69p-5h74-w36fCVE-2017-1000043same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2023-03-27published 2017-10-24GHSA-34r7-q49f-h37cCVE-2015-8857criticalnot named as affected when the advisory was published, now names uglifierDuration unknown
2023-03-27published 2021-12-16GHSA-gv87-q66h-4277CVE-2021-43113criticalnot named as affected when the advisory was published, now names com.itextpdf:itextpdfDuration unknown
2023-03-27published 2022-09-25GHSA-m7w4-q5vg-5xfpCVE-2022-3257moderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v6Duration unknown
Wed 22 Mar 2023· 1 change
2023-03-22published 2020-02-21GHSA-cqqj-4p63-rrmmCVE-2019-20444criticalnot named as affected when the advisory was published, now names io.netty:netty-codec-httpDuration unknown
Thu 16 Mar 2023· 3 changes
2023-03-16published 2022-02-15GHSA-pf59-j7c2-rh6xCVE-2020-13597moderatenot named as affected when the advisory was published, now names github.com/projectcalico/calicoDuration unknown
2023-03-16published 2022-01-06GHSA-w428-f65r-h4q2CVE-2021-45687criticalnot named as affected when the advisory was published, now names raw-cpuidDuration unknown
2023-03-16published 2022-05-24GHSA-4rjr-3gj2-5crqCVE-2021-20332moderatenot named as affected when the advisory was published, now names mongodbDuration unknown
Wed 8 Mar 2023· 2 changes
2023-03-08published 2022-01-07GHSA-wrxc-mr2w-cjpvCVE-2020-11529moderatenot named as affected when the advisory was published, now names getgrav/gravDuration unknown
2023-03-08published 2022-01-05GHSA-4w23-c97g-fq5vCVE-2021-4130highnot named as affected when the advisory was published, now names snipe/snipe-itDuration unknown
Thu 2 Mar 2023· 2 changes
2023-03-02published 2021-01-13GHSA-jxwx-85vp-gvwmCVE-2021-21252highnot named as affected when the advisory was published, now names jquery.validationDuration unknown
2023-03-02published 2022-11-21GHSA-vqp6-rc3h-83cpCVE-2022-41924criticalnot named as affected when the advisory was published, now names tailscale.comTime to revision 101 days
Tue 28 Feb 2023· 6 changes
2023-02-28published 2018-10-17GHSA-p699-3wgc-7h72CVE-2018-1339moderatenot named as affected when the advisory was published, now names org.apache.tika:tika-parsersDuration unknown
2023-02-28published 2023-01-23GHSA-jqh6-9574-5x22criticalnot named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.convertors and 4 moreTime to revision 36 days
2023-02-28published 2023-01-23GHSA-jqh6-9574-5x22CVE-2023-24057same package registry as the line abovecriticalnot named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.convertorsTime to revision 36 days
2023-02-28published 2023-01-23GHSA-jqh6-9574-5x22CVE-2023-24057same package registry as the line abovecriticalnot named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.r4bTime to revision 36 days
2023-02-28published 2023-01-23GHSA-jqh6-9574-5x22CVE-2023-24057same package registry as the line abovecriticalnot named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.r5Time to revision 36 days
2023-02-28published 2023-01-23GHSA-jqh6-9574-5x22CVE-2023-24057same package registry as the line abovecriticalnot named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.utilitiesTime to revision 36 days
2023-02-28published 2023-01-23GHSA-jqh6-9574-5x22CVE-2023-24057same package registry as the line abovecriticalnot named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.validationTime to revision 36 days
Fri 24 Feb 2023· 1 change
2023-02-24published 2022-10-07GHSA-mqqv-chpx-vq25CVE-2020-7711highnot named as affected when the advisory was published, now names github.com/russellhaering/gosaml2Duration unknown
Wed 22 Feb 2023· 5 changes
2023-02-22published 2019-02-22GHSA-9v3m-8fp8-mj99moderatenot named as affected when the advisory was published, now names bootstrap and 1 moreDuration unknown
2023-02-22published 2019-02-22GHSA-9v3m-8fp8-mj99CVE-2019-8331same package registry as the line abovemoderatenot named as affected when the advisory was published, now names bootstrapDuration unknown
2023-02-22published 2019-02-22GHSA-9v3m-8fp8-mj99CVE-2019-8331same package registry as the line abovemoderatenot named as affected when the advisory was published, now names bootstrap-sassDuration unknown
2023-02-22published 2019-02-22GHSA-9v3m-8fp8-mj99moderatenot named as affected when the advisory was published, now names bootstrap and 2 moreDuration unknown
2023-02-22published 2019-02-22GHSA-9v3m-8fp8-mj99CVE-2019-8331same package registry as the line abovemoderatenot named as affected when the advisory was published, now names bootstrapDuration unknown
2023-02-22published 2019-02-22GHSA-9v3m-8fp8-mj99CVE-2019-8331same package registry as the line abovemoderatenot named as affected when the advisory was published, now names bootstrap.lessDuration unknown
2023-02-22published 2019-02-22GHSA-9v3m-8fp8-mj99CVE-2019-8331same package registry as the line abovemoderatenot named as affected when the advisory was published, now names bootstrap.sassDuration unknown
Fri 17 Feb 2023· 2 changes
2023-02-17published 2022-02-15GHSA-jp32-vmm6-3vf5CVE-2015-5305moderatenot named as affected when the advisory was published, now names k8s.io/kubernetesDuration unknown
2023-02-17published 2021-06-23GHSA-cjjc-xp8v-855wCVE-2020-7919highnot named as affected when the advisory was published, now names golang.org/x/cryptoDuration unknown
Thu 16 Feb 2023· 3 changes
2023-02-16published 2020-06-10GHSA-qr95-4mq5-r3fhCVE-2020-4043highnot named as affected when the advisory was published, now names maikuolan/phpmusselDuration unknown
2023-02-16published 2021-06-23GHSA-86r9-39j9-99wpCVE-2016-9121criticalnot named as affected when the advisory was published, now names github.com/square/go-joseDuration unknown
2023-02-16published 2021-12-20GHSA-m9hp-7r99-94h5CVE-2020-26290criticalnot named as affected when the advisory was published, now names github.com/russellhaering/goxmldsigDuration unknown
Tue 14 Feb 2023· 2 changes
2023-02-14published 2022-08-18GHSA-8449-7gc2-pwrpCVE-2022-38149highnot named as affected when the advisory was published, now names github.com/hashicorp/consul-templateDuration unknown
2023-02-14published 2022-09-29GHSA-c9qr-f6c8-rgxfCVE-2022-40082highnot named as affected when the advisory was published, now names github.com/cloudwego/hertzDuration unknown
Mon 13 Feb 2023· 1 change
2023-02-13published 2022-02-22GHSA-fgv8-vj5c-2ppqCVE-2019-16884highnot named as affected when the advisory was published, now names github.com/opencontainers/selinuxDuration unknown
Thu 9 Feb 2023· 15 changes
2023-02-09published 2021-12-20 to 2022-12-28moderatenot named as affected when the advisory was published, now names github.com/go-yaml/yamlTime to revision 44 days
2023-02-09published 2022-12-28GHSA-r88r-gmrh-7j83CVE-2021-4235same package registry as the line abovemoderatesame change as the line aboveTime to revision 44 days
2023-02-09published 2021-12-20GHSA-wxc4-f4m6-wwqvCVE-2019-11254same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2023-02-09published 2022-08-30GHSA-grvv-h2f9-7v9cCVE-2022-36009moderatenot named as affected when the advisory was published, now names github.com/matrix-org/gomatrixserverlibDuration unknown
2023-02-09published 2021-06-29GHSA-mr6h-chqp-p9g2CVE-2014-8681moderatenot named as affected when the advisory was published, now names github.com/gogits/gogsDuration unknown
2023-02-09published 2021-06-29GHSA-jm5c-rv3w-w83mCVE-2020-26242moderatenot named as affected when the advisory was published, now names github.com/holiman/uint256Duration unknown
2023-02-09published 2019-07-05GHSA-x64g-wjmw-w328CVE-2015-5306criticalnot named as affected when the advisory was published, now names python-ironic-inspector-clientDuration unknown
2023-02-09published 2021-08-252 bandsnot named as affected when the advisory was published, now names tensorflowDuration unknown
2023-02-09published 2021-08-25GHSA-cfpj-3q4c-jhvrCVE-2021-37680same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2023-02-09published 2021-08-25GHSA-7xwj-5r4v-429pCVE-2021-37681same package registry as the line abovehighsame change as the line aboveDuration unknown
2023-02-09published 2021-08-25GHSA-rhrq-64mq-hf9hCVE-2021-37683same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2023-02-09published 2021-08-25GHSA-c545-c4f9-rf6vCVE-2021-37685same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2023-02-09published 2021-08-25GHSA-jwf9-w5xm-f437CVE-2021-37687same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2023-02-09published 2021-08-25GHSA-vcjj-9vg7-vf68CVE-2021-37688same package registry as the line abovehighsame change as the line aboveDuration unknown
2023-02-09published 2021-08-25GHSA-wf5p-c75w-w3whCVE-2021-37689same package registry as the line abovehighsame change as the line aboveDuration unknown
2023-02-09published 2021-08-25GHSA-4c4g-crqm-xrxwCVE-2021-37682same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2023-02-09published 2022-04-30GHSA-66vw-v2x9-hw75CVE-2022-1227highnot named as affected when the advisory was published, now names github.com/containers/psgoDuration unknown
Tue 7 Feb 2023· 4 changes
2023-02-07published 2022-12-14GHSA-53mm-hx32-6475CVE-2022-47406criticalnot named as affected when the advisory was published, now names derhansen/fe_change_pwdTime to revision 55 days
2023-02-07published 2022-12-28GHSA-vp56-r7qv-783vCVE-2020-36559highnot named as affected when the advisory was published, now names aahframe.workTime to revision 42 days
2023-02-07published 2022-12-22 to 2022-12-252 bandsnot named as affected when the advisory was published, now names code.sajari.com/docconvTime to revision 44 to 48 days
2023-02-07published 2022-12-25GHSA-qvx2-59g8-8hphCVE-2022-4741same package registry as the line abovemoderatesame change as the line aboveTime to revision 44 days
2023-02-07published 2022-12-22GHSA-6m4h-hfpp-x8cxCVE-2022-4643same package registry as the line abovecriticalsame change as the line aboveTime to revision 48 days
Thu 2 Feb 2023· 2 changes
2023-02-02published 2021-01-06GHSA-w7jx-j77m-wp65CVE-2024-21911moderatenot named as affected when the advisory was published, now names tinymceDuration unknown
2023-02-02published 2021-01-06GHSA-w7jx-j77m-wp65CVE-2024-21911moderatenot named as affected when the advisory was published, now names tinymce/tinymceDuration unknown
Mon 30 Jan 2023· 1 change
2023-01-30published 2020-02-19GHSA-mxhp-79qh-mcx6CVE-2019-10790highnot named as affected when the advisory was published, now names taffydbDuration unknown
Thu 26 Jan 2023· 2 changes
2023-01-26published 2021-05-06GHSA-3c6g-pvg8-gqw2CVE-2020-7712highnot named as affected when the advisory was published, now names org.webjars.npm:jsonDuration unknown
2023-01-26published 2017-10-24GHSA-hpcf-8vf9-q4gjCVE-2016-7103moderatenot named as affected when the advisory was published, now names jquery-ui-railsDuration unknown
Wed 25 Jan 2023· 1 change
2023-01-25published 2023-01-20GHSA-6g8q-qfpv-57wpCVE-2023-22727criticalnot named as affected when the advisory was published, now names cakephp/databaseTime to revision 5 days
Tue 10 Jan 2023· 1 change
2023-01-10published 2022-12-28GHSA-967g-cjx4-h7j6highnot named as affected when the advisory was published, now names github.com/ipld/go-codec-dagpbTime to revision 14 days
Fri 6 Jan 2023· 3 changes
2023-01-06published 2022-11-22GHSA-g56w-cwg4-hxx9CVE-2022-4116criticalnot named as affected when the advisory was published, now names io.quarkus:quarkus-vertx-http-deploymentTime to revision 45 days
2023-01-06published 2022-02-15GHSA-wqv3-8cm6-h6wgCVE-2020-8558highnot named as affected when the advisory was published, now names k8s.io/kubernetesDuration unknown
2023-01-06published 2021-12-09GHSA-qrmm-w75w-3wpxmoderatenot named as affected when the advisory was published, now names swashbuckle.aspnetcore.swaggeruiDuration unknown
Tue 20 Dec 2022· 1 change
2022-12-20published 2022-12-20GHSA-54r5-wr8x-x5v3highnot named as affected when the advisory was published, now names io.apiman:apiman-manager-api-rest-implTime to revision 1 days
Mon 19 Dec 2022· 1 change
2022-12-19published 2022-11-10GHSA-4vrc-q7m6-vq7wCVE-2022-44244moderatenot named as affected when the advisory was published, now names io.github.talelin:lin-cms-coreTime to revision 39 days
Fri 16 Dec 2022· 8 changes
2022-12-16published 2022-05-24 to 2022-10-198 rows, one per advisory and package3 bandsnot named as affected when the advisory was published, now names org.jenkins-ci.plugins:credentials-binding and 4 moreTime to revision 206 days
2022-12-16published 2022-05-24GHSA-7ff8-qfwx-8gx5CVE-2020-2182same package registry as the line abovelownot named as affected when the advisory was published, now names org.jenkins-ci.plugins:credentials-bindingDuration unknown
2022-12-16published 2022-05-24GHSA-43j2-r4v3-m8jpCVE-2020-2181same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins:credentials-bindingDuration unknown
2022-12-16published 2022-05-24GHSA-xqpp-26pp-2365CVE-2021-21660same package registry as the line abovemoderatenot named as affected when the advisory was published, now names io.jenkins.plugins:markdown-formatterTime to revision 206 days
2022-12-16published 2022-10-19GHSA-7qw2-h9gj-hcvhCVE-2022-43406same package registry as the line abovehighnot named as affected when the advisory was published, now names io.jenkins.plugins:pipeline-groovy-libDuration unknown
2022-12-16published 2022-10-19GHSA-4hjj-9gp7-4frgCVE-2022-43405same package registry as the line abovehighnot named as affected when the advisory was published, now names io.jenkins.plugins:pipeline-groovy-libDuration unknown
2022-12-16published 2022-10-19GHSA-4hjj-9gp7-4frgCVE-2022-43405same package registry as the line abovehighnot named as affected when the advisory was published, now names org.jenkins-ci.plugins.workflow:workflow-cps-global-libDuration unknown
2022-12-16published 2022-10-19GHSA-27rf-8mjp-r363CVE-2022-43404same package registry as the line abovehighnot named as affected when the advisory was published, now names org.jenkins-ci.plugins.workflow:workflow-cpsDuration unknown
2022-12-16published 2022-10-19GHSA-7vr5-72w7-q6jcCVE-2022-43401same package registry as the line abovehighnot named as affected when the advisory was published, now names org.jenkins-ci.plugins.workflow:workflow-cpsDuration unknown
Tue 13 Dec 2022· 6 changes
2022-12-13published 2022-12-132 bandsnot named as affected when the advisory was published, now names typo3/cmsTime to revision 0 days
2022-12-13published 2022-12-13GHSA-8w3p-qh3x-6gjrCVE-2022-23504same package registry as the line abovemoderatesame change as the line aboveTime to revision 0 days
2022-12-13published 2022-12-13GHSA-c5wx-6c2c-f7rmCVE-2022-23503same package registry as the line abovehighsame change as the line aboveTime to revision 0 days
2022-12-13published 2022-12-13GHSA-mgj2-q8wp-29rrCVE-2022-23502same package registry as the line abovemoderatesame change as the line aboveTime to revision 0 days
2022-12-13published 2022-12-13GHSA-jfp7-79g7-89rfCVE-2022-23501same package registry as the line abovemoderatesame change as the line aboveTime to revision 0 days
2022-12-13published 2022-12-13GHSA-8c28-5mp7-v24hCVE-2022-23500same package registry as the line abovemoderatesame change as the line aboveTime to revision 0 days
2022-12-13published 2022-12-13GHSA-hvwx-qh2h-xcfjCVE-2022-23499same package registry as the line abovemoderatesame change as the line aboveTime to revision 0 days
Fri 25 Nov 2022· 1 change
2022-11-25published 2022-01-19GHSA-f7vh-qwp3-x37mCVE-2022-23307criticalnot named as affected when the advisory was published, now names log4j:log4jDuration unknown
Fri 18 Nov 2022· 8 changes
2022-11-18published 2021-05-07criticalnot named as affected when the advisory was published, now names org.odata4j:odata4j-distDuration unknown
2022-11-18published 2021-05-07GHSA-2382-qx5h-rvqhCVE-2016-11023same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2022-11-18published 2021-05-07GHSA-f96g-24cg-f24wCVE-2016-11024same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2022-11-18published 2021-05-07criticalnot named as affected when the advisory was published, now names org.odata4j:odata4j-parentDuration unknown
2022-11-18published 2021-05-07GHSA-2382-qx5h-rvqhCVE-2016-11023same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2022-11-18published 2021-05-07GHSA-f96g-24cg-f24wCVE-2016-11024same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2022-11-18published 2019-07-05GHSA-7v35-qwwj-p98gCVE-2019-9843highnot named as affected when the advisory was published, now names com.diffplug.spotless:spotless-maven-pluginDuration unknown
2022-11-18published 2019-06-27GHSA-v33x-prhc-gph5CVE-2019-11272highnot named as affected when the advisory was published, now names org.springframework.security:spring-security-casDuration unknown
2022-11-18published 2019-05-29GHSA-h896-mx9x-g32gCVE-2019-0188highnot named as affected when the advisory was published, now names org.apache.camel:camel-xmljsonDuration unknown
2022-11-18published 2018-12-20GHSA-27xw-p8v6-9jjrCVE-2018-15801highnot named as affected when the advisory was published, now names org.springframework.security:spring-security-oauth2-joseDuration unknown
Thu 10 Nov 2022· 2 changes
2022-11-10published 2022-11-01GHSA-43xg-8wmj-cw8hCVE-2022-31777moderatenot named as affected when the advisory was published, now names pysparkTime to revision 9 days
2022-11-10published 2022-05-24GHSA-8cw2-jv5c-c825CVE-2019-12408highnot named as affected when the advisory was published, now names pyarrowTime to revision 170 days
Tue 8 Nov 2022· 1 change
2022-11-08published 2022-10-26GHSA-g6hg-4v3c-6jq7CVE-2022-43766highnot named as affected when the advisory was published, now names apache-iotdbTime to revision 13 days
Tue 1 Nov 2022· 137 changes
2022-11-01published 2022-05-24 to 2022-08-30137 rows, one per advisory and package2 bandsnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.osx-arm64 and 128 moreTime to revision 63 to 161 days
2022-11-01published 2022-08-30GHSA-3rq8-h3gj-r5c6CVE-2022-29117same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.osx-arm64Time to revision 63 days
2022-11-01published 2022-05-24GHSA-242j-2gm6-5rwxCVE-2021-1723same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-musl-armTime to revision 161 days
2022-11-01published 2022-05-24GHSA-5v8v-66v8-mwm7CVE-2020-8927same package registry as the line abovemoderatenot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.aot.linux-x64.cross.android-armTime to revision 161 days
2022-11-01published 2022-05-24GHSA-5v8v-66v8-mwm7CVE-2020-8927same package registry as the line abovemoderatenot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.aot.linux-x64.cross.android-arm64Time to revision 161 days
2022-11-01published 2022-05-24GHSA-5v8v-66v8-mwm7CVE-2020-8927same package registry as the line abovemoderatenot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.aot.linux-x64.cross.android-x64Time to revision 161 days
2022-11-01published 2022-05-24GHSA-5v8v-66v8-mwm7CVE-2020-8927same package registry as the line abovemoderatenot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.aot.linux-x64.cross.android-x86Time to revision 161 days
2022-11-01published 2022-05-24GHSA-5v8v-66v8-mwm7CVE-2020-8927same package registry as the line abovemoderatenot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.aot.linux-x64.cross.browser-wasmTime to revision 161 days
2022-11-01published 2022-05-24GHSA-5v8v-66v8-mwm7CVE-2020-8927same package registry as the line abovemoderatenot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.aot.osx-x64.cross.android-armTime to revision 161 days
129 more rows in this change are not listed here. Open all 137 rows
Tue 25 Oct 2022· 5 changes
2022-10-25published 2022-09-173 bandsnot named as affected when the advisory was published, now names com.fasterxml.woodstox:woodstox-coreTime to revision 39 days
2022-10-25published 2022-09-17GHSA-3f7h-mf4q-vrm4CVE-2022-40152same package registry as the line abovemoderatesame change as the line aboveTime to revision 39 days
2022-10-25published 2022-09-17GHSA-4rv7-wj6m-6c6rCVE-2022-40156same package registry as the line abovelowsame change as the line aboveTime to revision 39 days
2022-10-25published 2022-09-17GHSA-5hc5-c3m9-8vcjCVE-2022-40155same package registry as the line abovelowsame change as the line aboveTime to revision 39 days
2022-10-25published 2022-09-17GHSA-9fwf-46g9-45rxCVE-2022-40154same package registry as the line abovelowsame change as the line aboveTime to revision 39 days
2022-10-25published 2022-09-17GHSA-fv22-xp26-mm9wCVE-2022-40153same package registry as the line abovehighsame change as the line aboveTime to revision 39 days
Thu 6 Oct 2022· 1 change
2022-10-06published 2022-09-30GHSA-f36p-42jv-8rh2highnot named as affected when the advisory was published, now names com.wire.bots:lithiumTime to revision 7 days
Tue 4 Oct 2022· 3 changes
2022-10-04published 2021-05-06GHSA-f2jv-r9rf-7988criticalnot named as affected when the advisory was published, now names org.webjars.bowergithub.wycats:handlebars.js and 2 moreTime to revision 516 days
2022-10-04published 2021-05-06GHSA-f2jv-r9rf-7988CVE-2021-23369same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.webjars.bowergithub.wycats:handlebars.jsTime to revision 516 days
2022-10-04published 2021-05-06GHSA-f2jv-r9rf-7988CVE-2021-23369same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.webjars.npm:handlebarsTime to revision 516 days
2022-10-04published 2021-05-06GHSA-f2jv-r9rf-7988CVE-2021-23369same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.webjars:handlebarsTime to revision 516 days
Mon 26 Sep 2022· 2 changes
2022-09-26published 2021-09-02GHSA-9j49-mfvp-vmhmCVE-2021-23406highnot named as affected when the advisory was published, now names degeneratorTime to revision 389 days
2022-09-26published 2018-07-26GHSA-cqp5-m4pq-gfgpCVE-2018-3723highnot named as affected when the advisory was published, now names defaults-deepTime to revision 1,523 days
Mon 19 Sep 2022· 1 change
2022-09-19published 2022-09-16GHSA-634p-93h9-92vhCVE-2022-39217moderatenot named as affected when the advisory was published, now names some-natalie/ghas-to-csvTime to revision 3 days
Thu 15 Sep 2022· 1 change
2022-09-15published 2022-09-07GHSA-jj62-mc3m-j769CVE-2020-21516criticalnot named as affected when the advisory was published, now names feehi/cmsTime to revision 9 days
Sun 11 Sep 2022· 1 change
2022-09-11published 2021-08-25GHSA-69fv-gw6g-8ccgCVE-2018-20998criticalnot named as affected when the advisory was published, now names arrayfireTime to revision 381 days
Fri 9 Sep 2022· 1 change
2022-09-09published 2021-05-17GHSA-jqh7-w5pr-cr56CVE-2020-8176moderatenot named as affected when the advisory was published, now names @shopify/koa-shopify-authTime to revision 480 days
Wed 7 Sep 2022· 1 change
2022-09-07published 2021-09-15GHSA-5vp3-v4hc-gx76CVE-2021-41264criticalnot named as affected when the advisory was published, now names @openzeppelin/contracts-upgradeableTime to revision 357 days
Tue 6 Sep 2022· 1 change
2022-09-06published 2022-05-24GHSA-hxrm-9w7p-39ccCVE-2020-1045highnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.win-arm64Time to revision 105 days
Thu 1 Sep 2022· 6 changes
2022-09-01published 2021-11-19 to 2022-06-172 bandsnot named as affected when the advisory was published, now names opcfoundation.netstandard.opc.ua.coreTime to revision 76 to 286 days
2022-09-01published 2022-06-17GHSA-r7pq-3x6p-7jcmCVE-2022-29863same package registry as the line abovehighsame change as the line aboveTime to revision 76 days
2022-09-01published 2022-06-17GHSA-vhfw-v69p-crcwCVE-2022-29864same package registry as the line abovehighsame change as the line aboveTime to revision 76 days
2022-09-01published 2022-06-17GHSA-fvxf-r9fw-49pcCVE-2022-29865same package registry as the line abovehighsame change as the line aboveTime to revision 76 days
2022-09-01published 2022-06-17GHSA-6fp8-cxc9-4fr9CVE-2022-29866same package registry as the line abovehighsame change as the line aboveTime to revision 76 days
2022-09-01published 2021-11-19GHSA-mjww-934m-h4jwCVE-2020-29457same package registry as the line abovemoderatesame change as the line aboveTime to revision 286 days
2022-09-01published 2022-06-17GHSA-5q2v-6j86-5h9vCVE-2022-29862same package registry as the line abovehighsame change as the line aboveTime to revision 76 days
Fri 26 Aug 2022· 11 changes
2022-08-26published 2022-05-24GHSA-hxrm-9w7p-39cchighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app and 10 moreTime to revision 94 days
2022-08-26published 2022-05-24GHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.appTime to revision 94 days
2022-08-26published 2022-05-24GHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-armTime to revision 94 days
2022-08-26published 2022-05-24GHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-arm64Time to revision 94 days
2022-08-26published 2022-05-24GHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-musl-arm64Time to revision 94 days
2022-08-26published 2022-05-24GHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-musl-x64Time to revision 94 days
2022-08-26published 2022-05-24GHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-x64Time to revision 94 days
2022-08-26published 2022-05-24GHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.osx-x64Time to revision 94 days
2022-08-26published 2022-05-24GHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.win-armTime to revision 94 days
3 more rows in this change are not listed here. Open all 11 rows
Fri 12 Aug 2022· 1 change
2022-08-12published 2022-02-09GHSA-jh6m-3pqw-242hCVE-2020-14359highnot named as affected when the advisory was published, now names github.com/keycloak/keycloak-gatekeeperTime to revision 185 days
Wed 10 Aug 2022· 1 change
2022-08-10published 2022-07-19GHSA-4x9r-j582-cgr8CVE-2022-33891highnot named as affected when the advisory was published, now names pysparkTime to revision 23 days
Fri 5 Aug 2022· 1 change
2022-08-05published 2022-05-24GHSA-cjw4-2w9r-r8mvCVE-2019-12410highnot named as affected when the advisory was published, now names pyarrowTime to revision 73 days
Thu 4 Aug 2022· 1 change
2022-08-04published 2022-02-11GHSA-6qq8-5wq3-86rpCVE-2020-15129moderatenot named as affected when the advisory was published, now names github.com/containous/traefik/v2/pkg/apiTime to revision 174 days
Fri 29 Jul 2022· 1 change
2022-07-29published 2022-02-11GHSA-6qq8-5wq3-86rpCVE-2020-15129moderatenot named as affected when the advisory was published, now names github.com/containous/traefik/v2Time to revision 168 days
Tue 26 Jul 2022· 1 change
2022-07-26published 2022-05-14GHSA-2xjx-v99w-gqf3CVE-2019-0545highnot named as affected when the advisory was published, now names microsoft.netcore.appTime to revision 74 days
Sat 16 Jul 2022· 4 changes
2022-07-16published 2022-07-06GHSA-f2gr-7299-487hmoderatenot named as affected when the advisory was published, now names github.com/ipfs/go-ipfsTime to revision 9 days
2022-07-16published 2021-08-30GHSA-7774-7vr3-cc8jCVE-2021-39155highnot named as affected when the advisory was published, now names istio.io/istioTime to revision 320 days
2022-07-16published 2022-06-17GHSA-75rw-34q6-72crCVE-2022-31053criticalnot named as affected when the advisory was published, now names github.com/biscuit-auth/biscuit-goTime to revision 29 days
2022-07-16published 2021-09-02GHSA-7h6j-2268-fhcmCVE-2020-9321moderatenot named as affected when the advisory was published, now names github.com/traefik/traefikTime to revision 316 days
Mon 11 Jul 2022· 11 changes
2022-07-11published 2022-06-28GHSA-m43h-hfrq-x8wxCVE-2022-26477highnot named as affected when the advisory was published, now names systemdsTime to revision 14 days
2022-07-11published 2022-04-03GHSA-558x-2xjg-6232CVE-2022-22950moderatenot named as affected when the advisory was published, now names org.springframework:spring-expressionTime to revision 100 days
2022-07-11published 2018-10-16GHSA-jc8g-xhw5-6x46highnot named as affected when the advisory was published, now names system.private.servicemodel and 5 moreTime to revision 1,364 days
2022-07-11published 2018-10-16GHSA-jc8g-xhw5-6x46CVE-2018-0786same package registry as the line abovehighnot named as affected when the advisory was published, now names system.private.servicemodelTime to revision 1,364 days
2022-07-11published 2018-10-16GHSA-jc8g-xhw5-6x46CVE-2018-0786same package registry as the line abovehighnot named as affected when the advisory was published, now names system.servicemodel.duplexTime to revision 1,364 days
2022-07-11published 2018-10-16GHSA-jc8g-xhw5-6x46CVE-2018-0786same package registry as the line abovehighnot named as affected when the advisory was published, now names system.servicemodel.httpTime to revision 1,364 days
2022-07-11published 2018-10-16GHSA-jc8g-xhw5-6x46CVE-2018-0786same package registry as the line abovehighnot named as affected when the advisory was published, now names system.servicemodel.nettcpTime to revision 1,364 days
2022-07-11published 2018-10-16GHSA-jc8g-xhw5-6x46CVE-2018-0786same package registry as the line abovehighnot named as affected when the advisory was published, now names system.servicemodel.primitivesTime to revision 1,364 days
2022-07-11published 2018-10-16GHSA-jc8g-xhw5-6x46CVE-2018-0786same package registry as the line abovehighnot named as affected when the advisory was published, now names system.servicemodel.securityTime to revision 1,364 days
2022-07-11published 2018-10-16GHSA-mv2r-q4g5-j8q5highnot named as affected when the advisory was published, now names microsoft.aspnetcore.all and 1 moreTime to revision 1,364 days
2022-07-11published 2018-10-16GHSA-mv2r-q4g5-j8q5CVE-2018-8269same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.allTime to revision 1,364 days
2022-07-11published 2018-10-16GHSA-mv2r-q4g5-j8q5CVE-2018-8269same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.dataprotection.azurestorageTime to revision 1,364 days
2022-07-11published 2017-10-24GHSA-qrgf-jqqm-x7xvCVE-2013-5671highnot named as affected when the advisory was published, now names fog-dragonflyTime to revision 1,721 days
Wed 29 Jun 2022· 1 change
2022-06-29published 2022-05-24GHSA-72gx-qq2m-6xr2CVE-2019-10431criticalnot named as affected when the advisory was published, now names org.jenkins-ci.plugins:script-securityTime to revision 36 days
Fri 17 Jun 2022· 2 changes
2022-06-17published 2021-11-30GHSA-fwf6-rw69-hhj4CVE-2021-23654moderatenot named as affected when the advisory was published, now names html-to-csvTime to revision 199 days
2022-06-17published 2021-04-13GHSA-53xj-v576-3ch2CVE-2019-10802criticalnot named as affected when the advisory was published, now names gitingTime to revision 430 days

Counted in advisories, never added to the CVE and KEV figures. This kind is counted once per advisory and per package, so one advisory that named four further packages counts four times. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

What this page cannot see

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Paste your closed CVE tickets and see which of these changes hit them →