Package added to advisory
What a record said when it was published, what it says now, and the commit that changed it.
1,695 advisory changes · newest first · grouped by day
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Advisory, Which advisory was edited, by its GHSA id. | Package, The package the advisory names, and the registry it comes from. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|
| Fri 14 Apr 2023· 6 changes | ||||
| 2023-04-14published 2022-11-22 | GHSA-cm43-f2pv-6v68CVE-2022-41131 | high | not named as affected when the advisory was published, now names apache-airflow-providers-apache-hive | Time to revision 143 days |
| 2023-04-14published 2021-05-21 | GHSA-hfg5-xpvw-c9x4 | high | not named as affected when the advisory was published, now names org.apache.camel:camel and 2 more | Duration unknown |
| 2023-04-14published 2021-05-21 | GHSA-hfg5-xpvw-c9x4CVE-2020-11971 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.apache.camel:camel | Duration unknown |
| 2023-04-14published 2021-05-21 | GHSA-hfg5-xpvw-c9x4CVE-2020-11971 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.apache.camel:camel-core | Duration unknown |
| 2023-04-14published 2021-05-21 | GHSA-hfg5-xpvw-c9x4CVE-2020-11971 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.apache.camel:camel-management | Duration unknown |
| 2023-04-14published 2022-12-13 | GHSA-3vqj-43w4-2q58CVE-2022-45688 | high | not named as affected when the advisory was published, now names org.json:json | Time to revision 122 days |
| 2023-04-14published 2022-01-06 | GHSA-gc67-crq6-hgh5CVE-2021-41561 | high | not named as affected when the advisory was published, now names org.apache.parquet:parquet | Duration unknown |
| Thu 13 Apr 2023· 1 change | ||||
| 2023-04-13published 2023-01-18 | GHSA-5pm2-9mr2-3frqCVE-2023-21893 | high | not named as affected when the advisory was published, now names oracle.manageddataaccess.core | Time to revision 86 days |
| Mon 10 Apr 2023· 1 change | ||||
| 2023-04-10published 2022-11-21 | GHSA-h6q3-vv32-2cq5CVE-2022-41894 | high | not named as affected when the advisory was published, now names tensorflow | Time to revision 140 days |
| Tue 4 Apr 2023· 1 change | ||||
| 2023-04-04published 2021-06-23 | GHSA-gq5r-cc4w-g8xf | high | not named as affected when the advisory was published, now names github.com/russellhaering/goxmldsig | Duration unknown |
| Thu 30 Mar 2023· 1 change | ||||
| 2023-03-30published 2021-09-20 | GHSA-mc22-5q92-8v85CVE-2021-39228 | moderate | not named as affected when the advisory was published, now names tremor-script | Duration unknown |
| Wed 29 Mar 2023· 1 change | ||||
| 2023-03-29published 2021-09-20 | GHSA-468q-v4jj-485hCVE-2021-3804 | high | not named as affected when the advisory was published, now names @tarojs/helper | Duration unknown |
| Mon 27 Mar 2023· 5 changes | ||||
| 2023-03-27published 2018-11-09 | moderate | not named as affected when the advisory was published, now names mapbox-rails | Duration unknown | |
| 2023-03-27published 2018-11-09 | GHSA-qr28-7j6p-9hmvCVE-2017-1000042 | same package registry as the line abovemoderate | same change as the line above | Duration unknown |
| 2023-03-27published 2018-11-09 | GHSA-q69p-5h74-w36fCVE-2017-1000043 | same package registry as the line abovemoderate | same change as the line above | Duration unknown |
| 2023-03-27published 2017-10-24 | GHSA-34r7-q49f-h37cCVE-2015-8857 | critical | not named as affected when the advisory was published, now names uglifier | Duration unknown |
| 2023-03-27published 2021-12-16 | GHSA-gv87-q66h-4277CVE-2021-43113 | critical | not named as affected when the advisory was published, now names com.itextpdf:itextpdf | Duration unknown |
| 2023-03-27published 2022-09-25 | GHSA-m7w4-q5vg-5xfpCVE-2022-3257 | moderate | not named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v6 | Duration unknown |
| Wed 22 Mar 2023· 1 change | ||||
| 2023-03-22published 2020-02-21 | GHSA-cqqj-4p63-rrmmCVE-2019-20444 | critical | not named as affected when the advisory was published, now names io.netty:netty-codec-http | Duration unknown |
| Thu 16 Mar 2023· 3 changes | ||||
| 2023-03-16published 2022-02-15 | GHSA-pf59-j7c2-rh6xCVE-2020-13597 | moderate | not named as affected when the advisory was published, now names github.com/projectcalico/calico | Duration unknown |
| 2023-03-16published 2022-01-06 | GHSA-w428-f65r-h4q2CVE-2021-45687 | critical | not named as affected when the advisory was published, now names raw-cpuid | Duration unknown |
| 2023-03-16published 2022-05-24 | GHSA-4rjr-3gj2-5crqCVE-2021-20332 | moderate | not named as affected when the advisory was published, now names mongodb | Duration unknown |
| Wed 8 Mar 2023· 2 changes | ||||
| 2023-03-08published 2022-01-07 | GHSA-wrxc-mr2w-cjpvCVE-2020-11529 | moderate | not named as affected when the advisory was published, now names getgrav/grav | Duration unknown |
| 2023-03-08published 2022-01-05 | GHSA-4w23-c97g-fq5vCVE-2021-4130 | high | not named as affected when the advisory was published, now names snipe/snipe-it | Duration unknown |
| Thu 2 Mar 2023· 2 changes | ||||
| 2023-03-02published 2021-01-13 | GHSA-jxwx-85vp-gvwmCVE-2021-21252 | high | not named as affected when the advisory was published, now names jquery.validation | Duration unknown |
| 2023-03-02published 2022-11-21 | GHSA-vqp6-rc3h-83cpCVE-2022-41924 | critical | not named as affected when the advisory was published, now names tailscale.com | Time to revision 101 days |
| Tue 28 Feb 2023· 6 changes | ||||
| 2023-02-28published 2018-10-17 | GHSA-p699-3wgc-7h72CVE-2018-1339 | moderate | not named as affected when the advisory was published, now names org.apache.tika:tika-parsers | Duration unknown |
| 2023-02-28published 2023-01-23 | GHSA-jqh6-9574-5x22 | critical | not named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.convertors and 4 more | Time to revision 36 days |
| 2023-02-28published 2023-01-23 | GHSA-jqh6-9574-5x22CVE-2023-24057 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.convertors | Time to revision 36 days |
| 2023-02-28published 2023-01-23 | GHSA-jqh6-9574-5x22CVE-2023-24057 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.r4b | Time to revision 36 days |
| 2023-02-28published 2023-01-23 | GHSA-jqh6-9574-5x22CVE-2023-24057 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.r5 | Time to revision 36 days |
| 2023-02-28published 2023-01-23 | GHSA-jqh6-9574-5x22CVE-2023-24057 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.utilities | Time to revision 36 days |
| 2023-02-28published 2023-01-23 | GHSA-jqh6-9574-5x22CVE-2023-24057 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.validation | Time to revision 36 days |
| Fri 24 Feb 2023· 1 change | ||||
| 2023-02-24published 2022-10-07 | GHSA-mqqv-chpx-vq25CVE-2020-7711 | high | not named as affected when the advisory was published, now names github.com/russellhaering/gosaml2 | Duration unknown |
| Wed 22 Feb 2023· 5 changes | ||||
| 2023-02-22published 2019-02-22 | GHSA-9v3m-8fp8-mj99 | moderate | not named as affected when the advisory was published, now names bootstrap and 1 more | Duration unknown |
| 2023-02-22published 2019-02-22 | GHSA-9v3m-8fp8-mj99CVE-2019-8331 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names bootstrap | Duration unknown |
| 2023-02-22published 2019-02-22 | GHSA-9v3m-8fp8-mj99CVE-2019-8331 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names bootstrap-sass | Duration unknown |
| 2023-02-22published 2019-02-22 | GHSA-9v3m-8fp8-mj99 | moderate | not named as affected when the advisory was published, now names bootstrap and 2 more | Duration unknown |
| 2023-02-22published 2019-02-22 | GHSA-9v3m-8fp8-mj99CVE-2019-8331 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names bootstrap | Duration unknown |
| 2023-02-22published 2019-02-22 | GHSA-9v3m-8fp8-mj99CVE-2019-8331 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names bootstrap.less | Duration unknown |
| 2023-02-22published 2019-02-22 | GHSA-9v3m-8fp8-mj99CVE-2019-8331 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names bootstrap.sass | Duration unknown |
| Fri 17 Feb 2023· 2 changes | ||||
| 2023-02-17published 2022-02-15 | GHSA-jp32-vmm6-3vf5CVE-2015-5305 | moderate | not named as affected when the advisory was published, now names k8s.io/kubernetes | Duration unknown |
| 2023-02-17published 2021-06-23 | GHSA-cjjc-xp8v-855wCVE-2020-7919 | high | not named as affected when the advisory was published, now names golang.org/x/crypto | Duration unknown |
| Thu 16 Feb 2023· 3 changes | ||||
| 2023-02-16published 2020-06-10 | GHSA-qr95-4mq5-r3fhCVE-2020-4043 | high | not named as affected when the advisory was published, now names maikuolan/phpmussel | Duration unknown |
| 2023-02-16published 2021-06-23 | GHSA-86r9-39j9-99wpCVE-2016-9121 | critical | not named as affected when the advisory was published, now names github.com/square/go-jose | Duration unknown |
| 2023-02-16published 2021-12-20 | GHSA-m9hp-7r99-94h5CVE-2020-26290 | critical | not named as affected when the advisory was published, now names github.com/russellhaering/goxmldsig | Duration unknown |
| Tue 14 Feb 2023· 2 changes | ||||
| 2023-02-14published 2022-08-18 | GHSA-8449-7gc2-pwrpCVE-2022-38149 | high | not named as affected when the advisory was published, now names github.com/hashicorp/consul-template | Duration unknown |
| 2023-02-14published 2022-09-29 | GHSA-c9qr-f6c8-rgxfCVE-2022-40082 | high | not named as affected when the advisory was published, now names github.com/cloudwego/hertz | Duration unknown |
| Mon 13 Feb 2023· 1 change | ||||
| 2023-02-13published 2022-02-22 | GHSA-fgv8-vj5c-2ppqCVE-2019-16884 | high | not named as affected when the advisory was published, now names github.com/opencontainers/selinux | Duration unknown |
| Thu 9 Feb 2023· 15 changes | ||||
| 2023-02-09published 2021-12-20 to 2022-12-28 | moderate | not named as affected when the advisory was published, now names github.com/go-yaml/yaml | Time to revision 44 days | |
| 2023-02-09published 2022-12-28 | GHSA-r88r-gmrh-7j83CVE-2021-4235 | same package registry as the line abovemoderate | same change as the line above | Time to revision 44 days |
| 2023-02-09published 2021-12-20 | GHSA-wxc4-f4m6-wwqvCVE-2019-11254 | same package registry as the line abovemoderate | same change as the line above | Duration unknown |
| 2023-02-09published 2022-08-30 | GHSA-grvv-h2f9-7v9cCVE-2022-36009 | moderate | not named as affected when the advisory was published, now names github.com/matrix-org/gomatrixserverlib | Duration unknown |
| 2023-02-09published 2021-06-29 | GHSA-mr6h-chqp-p9g2CVE-2014-8681 | moderate | not named as affected when the advisory was published, now names github.com/gogits/gogs | Duration unknown |
| 2023-02-09published 2021-06-29 | GHSA-jm5c-rv3w-w83mCVE-2020-26242 | moderate | not named as affected when the advisory was published, now names github.com/holiman/uint256 | Duration unknown |
| 2023-02-09published 2019-07-05 | GHSA-x64g-wjmw-w328CVE-2015-5306 | critical | not named as affected when the advisory was published, now names python-ironic-inspector-client | Duration unknown |
| 2023-02-09published 2021-08-25 | 2 bands | not named as affected when the advisory was published, now names tensorflow | Duration unknown | |
| 2023-02-09published 2021-08-25 | GHSA-cfpj-3q4c-jhvrCVE-2021-37680 | same package registry as the line abovemoderate | same change as the line above | Duration unknown |
| 2023-02-09published 2021-08-25 | GHSA-7xwj-5r4v-429pCVE-2021-37681 | same package registry as the line abovehigh | same change as the line above | Duration unknown |
| 2023-02-09published 2021-08-25 | GHSA-rhrq-64mq-hf9hCVE-2021-37683 | same package registry as the line abovemoderate | same change as the line above | Duration unknown |
| 2023-02-09published 2021-08-25 | GHSA-c545-c4f9-rf6vCVE-2021-37685 | same package registry as the line abovemoderate | same change as the line above | Duration unknown |
| 2023-02-09published 2021-08-25 | GHSA-jwf9-w5xm-f437CVE-2021-37687 | same package registry as the line abovemoderate | same change as the line above | Duration unknown |
| 2023-02-09published 2021-08-25 | GHSA-vcjj-9vg7-vf68CVE-2021-37688 | same package registry as the line abovehigh | same change as the line above | Duration unknown |
| 2023-02-09published 2021-08-25 | GHSA-wf5p-c75w-w3whCVE-2021-37689 | same package registry as the line abovehigh | same change as the line above | Duration unknown |
| 2023-02-09published 2021-08-25 | GHSA-4c4g-crqm-xrxwCVE-2021-37682 | same package registry as the line abovemoderate | same change as the line above | Duration unknown |
| 2023-02-09published 2022-04-30 | GHSA-66vw-v2x9-hw75CVE-2022-1227 | high | not named as affected when the advisory was published, now names github.com/containers/psgo | Duration unknown |
| Tue 7 Feb 2023· 4 changes | ||||
| 2023-02-07published 2022-12-14 | GHSA-53mm-hx32-6475CVE-2022-47406 | critical | not named as affected when the advisory was published, now names derhansen/fe_change_pwd | Time to revision 55 days |
| 2023-02-07published 2022-12-28 | GHSA-vp56-r7qv-783vCVE-2020-36559 | high | not named as affected when the advisory was published, now names aahframe.work | Time to revision 42 days |
| 2023-02-07published 2022-12-22 to 2022-12-25 | 2 bands | not named as affected when the advisory was published, now names code.sajari.com/docconv | Time to revision 44 to 48 days | |
| 2023-02-07published 2022-12-25 | GHSA-qvx2-59g8-8hphCVE-2022-4741 | same package registry as the line abovemoderate | same change as the line above | Time to revision 44 days |
| 2023-02-07published 2022-12-22 | GHSA-6m4h-hfpp-x8cxCVE-2022-4643 | same package registry as the line abovecritical | same change as the line above | Time to revision 48 days |
| Thu 2 Feb 2023· 2 changes | ||||
| 2023-02-02published 2021-01-06 | GHSA-w7jx-j77m-wp65CVE-2024-21911 | moderate | not named as affected when the advisory was published, now names tinymce | Duration unknown |
| 2023-02-02published 2021-01-06 | GHSA-w7jx-j77m-wp65CVE-2024-21911 | moderate | not named as affected when the advisory was published, now names tinymce/tinymce | Duration unknown |
| Mon 30 Jan 2023· 1 change | ||||
| 2023-01-30published 2020-02-19 | GHSA-mxhp-79qh-mcx6CVE-2019-10790 | high | not named as affected when the advisory was published, now names taffydb | Duration unknown |
| Thu 26 Jan 2023· 2 changes | ||||
| 2023-01-26published 2021-05-06 | GHSA-3c6g-pvg8-gqw2CVE-2020-7712 | high | not named as affected when the advisory was published, now names org.webjars.npm:json | Duration unknown |
| 2023-01-26published 2017-10-24 | GHSA-hpcf-8vf9-q4gjCVE-2016-7103 | moderate | not named as affected when the advisory was published, now names jquery-ui-rails | Duration unknown |
| Wed 25 Jan 2023· 1 change | ||||
| 2023-01-25published 2023-01-20 | GHSA-6g8q-qfpv-57wpCVE-2023-22727 | critical | not named as affected when the advisory was published, now names cakephp/database | Time to revision 5 days |
| Tue 10 Jan 2023· 1 change | ||||
| 2023-01-10published 2022-12-28 | GHSA-967g-cjx4-h7j6 | high | not named as affected when the advisory was published, now names github.com/ipld/go-codec-dagpb | Time to revision 14 days |
| Fri 6 Jan 2023· 3 changes | ||||
| 2023-01-06published 2022-11-22 | GHSA-g56w-cwg4-hxx9CVE-2022-4116 | critical | not named as affected when the advisory was published, now names io.quarkus:quarkus-vertx-http-deployment | Time to revision 45 days |
| 2023-01-06published 2022-02-15 | GHSA-wqv3-8cm6-h6wgCVE-2020-8558 | high | not named as affected when the advisory was published, now names k8s.io/kubernetes | Duration unknown |
| 2023-01-06published 2021-12-09 | GHSA-qrmm-w75w-3wpx | moderate | not named as affected when the advisory was published, now names swashbuckle.aspnetcore.swaggerui | Duration unknown |
| Tue 20 Dec 2022· 1 change | ||||
| 2022-12-20published 2022-12-20 | GHSA-54r5-wr8x-x5v3 | high | not named as affected when the advisory was published, now names io.apiman:apiman-manager-api-rest-impl | Time to revision 1 days |
| Mon 19 Dec 2022· 1 change | ||||
| 2022-12-19published 2022-11-10 | GHSA-4vrc-q7m6-vq7wCVE-2022-44244 | moderate | not named as affected when the advisory was published, now names io.github.talelin:lin-cms-core | Time to revision 39 days |
| Fri 16 Dec 2022· 8 changes | ||||
| 2022-12-16published 2022-05-24 to 2022-10-19 | 8 rows, one per advisory and package | 3 bands | not named as affected when the advisory was published, now names org.jenkins-ci.plugins:credentials-binding and 4 more | Time to revision 206 days |
| 2022-12-16published 2022-05-24 | GHSA-7ff8-qfwx-8gx5CVE-2020-2182 | same package registry as the line abovelow | not named as affected when the advisory was published, now names org.jenkins-ci.plugins:credentials-binding | Duration unknown |
| 2022-12-16published 2022-05-24 | GHSA-43j2-r4v3-m8jpCVE-2020-2181 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.jenkins-ci.plugins:credentials-binding | Duration unknown |
| 2022-12-16published 2022-05-24 | GHSA-xqpp-26pp-2365CVE-2021-21660 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names io.jenkins.plugins:markdown-formatter | Time to revision 206 days |
| 2022-12-16published 2022-10-19 | GHSA-7qw2-h9gj-hcvhCVE-2022-43406 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names io.jenkins.plugins:pipeline-groovy-lib | Duration unknown |
| 2022-12-16published 2022-10-19 | GHSA-4hjj-9gp7-4frgCVE-2022-43405 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names io.jenkins.plugins:pipeline-groovy-lib | Duration unknown |
| 2022-12-16published 2022-10-19 | GHSA-4hjj-9gp7-4frgCVE-2022-43405 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.jenkins-ci.plugins.workflow:workflow-cps-global-lib | Duration unknown |
| 2022-12-16published 2022-10-19 | GHSA-27rf-8mjp-r363CVE-2022-43404 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.jenkins-ci.plugins.workflow:workflow-cps | Duration unknown |
| 2022-12-16published 2022-10-19 | GHSA-7vr5-72w7-q6jcCVE-2022-43401 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.jenkins-ci.plugins.workflow:workflow-cps | Duration unknown |
| Tue 13 Dec 2022· 6 changes | ||||
| 2022-12-13published 2022-12-13 | 2 bands | not named as affected when the advisory was published, now names typo3/cms | Time to revision 0 days | |
| 2022-12-13published 2022-12-13 | GHSA-8w3p-qh3x-6gjrCVE-2022-23504 | same package registry as the line abovemoderate | same change as the line above | Time to revision 0 days |
| 2022-12-13published 2022-12-13 | GHSA-c5wx-6c2c-f7rmCVE-2022-23503 | same package registry as the line abovehigh | same change as the line above | Time to revision 0 days |
| 2022-12-13published 2022-12-13 | GHSA-mgj2-q8wp-29rrCVE-2022-23502 | same package registry as the line abovemoderate | same change as the line above | Time to revision 0 days |
| 2022-12-13published 2022-12-13 | GHSA-jfp7-79g7-89rfCVE-2022-23501 | same package registry as the line abovemoderate | same change as the line above | Time to revision 0 days |
| 2022-12-13published 2022-12-13 | GHSA-8c28-5mp7-v24hCVE-2022-23500 | same package registry as the line abovemoderate | same change as the line above | Time to revision 0 days |
| 2022-12-13published 2022-12-13 | GHSA-hvwx-qh2h-xcfjCVE-2022-23499 | same package registry as the line abovemoderate | same change as the line above | Time to revision 0 days |
| Fri 25 Nov 2022· 1 change | ||||
| 2022-11-25published 2022-01-19 | GHSA-f7vh-qwp3-x37mCVE-2022-23307 | critical | not named as affected when the advisory was published, now names log4j:log4j | Duration unknown |
| Fri 18 Nov 2022· 8 changes | ||||
| 2022-11-18published 2021-05-07 | critical | not named as affected when the advisory was published, now names org.odata4j:odata4j-dist | Duration unknown | |
| 2022-11-18published 2021-05-07 | GHSA-2382-qx5h-rvqhCVE-2016-11023 | same package registry as the line abovecritical | same change as the line above | Duration unknown |
| 2022-11-18published 2021-05-07 | GHSA-f96g-24cg-f24wCVE-2016-11024 | same package registry as the line abovecritical | same change as the line above | Duration unknown |
| 2022-11-18published 2021-05-07 | critical | not named as affected when the advisory was published, now names org.odata4j:odata4j-parent | Duration unknown | |
| 2022-11-18published 2021-05-07 | GHSA-2382-qx5h-rvqhCVE-2016-11023 | same package registry as the line abovecritical | same change as the line above | Duration unknown |
| 2022-11-18published 2021-05-07 | GHSA-f96g-24cg-f24wCVE-2016-11024 | same package registry as the line abovecritical | same change as the line above | Duration unknown |
| 2022-11-18published 2019-07-05 | GHSA-7v35-qwwj-p98gCVE-2019-9843 | high | not named as affected when the advisory was published, now names com.diffplug.spotless:spotless-maven-plugin | Duration unknown |
| 2022-11-18published 2019-06-27 | GHSA-v33x-prhc-gph5CVE-2019-11272 | high | not named as affected when the advisory was published, now names org.springframework.security:spring-security-cas | Duration unknown |
| 2022-11-18published 2019-05-29 | GHSA-h896-mx9x-g32gCVE-2019-0188 | high | not named as affected when the advisory was published, now names org.apache.camel:camel-xmljson | Duration unknown |
| 2022-11-18published 2018-12-20 | GHSA-27xw-p8v6-9jjrCVE-2018-15801 | high | not named as affected when the advisory was published, now names org.springframework.security:spring-security-oauth2-jose | Duration unknown |
| Thu 10 Nov 2022· 2 changes | ||||
| 2022-11-10published 2022-11-01 | GHSA-43xg-8wmj-cw8hCVE-2022-31777 | moderate | not named as affected when the advisory was published, now names pyspark | Time to revision 9 days |
| 2022-11-10published 2022-05-24 | GHSA-8cw2-jv5c-c825CVE-2019-12408 | high | not named as affected when the advisory was published, now names pyarrow | Time to revision 170 days |
| Tue 8 Nov 2022· 1 change | ||||
| 2022-11-08published 2022-10-26 | GHSA-g6hg-4v3c-6jq7CVE-2022-43766 | high | not named as affected when the advisory was published, now names apache-iotdb | Time to revision 13 days |
| Tue 1 Nov 2022· 137 changes | ||||
| 2022-11-01published 2022-05-24 to 2022-08-30 | 137 rows, one per advisory and package | 2 bands | not named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.osx-arm64 and 128 more | Time to revision 63 to 161 days |
| 2022-11-01published 2022-08-30 | GHSA-3rq8-h3gj-r5c6CVE-2022-29117 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.osx-arm64 | Time to revision 63 days |
| 2022-11-01published 2022-05-24 | GHSA-242j-2gm6-5rwxCVE-2021-1723 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-musl-arm | Time to revision 161 days |
| 2022-11-01published 2022-05-24 | GHSA-5v8v-66v8-mwm7CVE-2020-8927 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names microsoft.netcore.app.runtime.aot.linux-x64.cross.android-arm | Time to revision 161 days |
| 2022-11-01published 2022-05-24 | GHSA-5v8v-66v8-mwm7CVE-2020-8927 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names microsoft.netcore.app.runtime.aot.linux-x64.cross.android-arm64 | Time to revision 161 days |
| 2022-11-01published 2022-05-24 | GHSA-5v8v-66v8-mwm7CVE-2020-8927 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names microsoft.netcore.app.runtime.aot.linux-x64.cross.android-x64 | Time to revision 161 days |
| 2022-11-01published 2022-05-24 | GHSA-5v8v-66v8-mwm7CVE-2020-8927 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names microsoft.netcore.app.runtime.aot.linux-x64.cross.android-x86 | Time to revision 161 days |
| 2022-11-01published 2022-05-24 | GHSA-5v8v-66v8-mwm7CVE-2020-8927 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names microsoft.netcore.app.runtime.aot.linux-x64.cross.browser-wasm | Time to revision 161 days |
| 2022-11-01published 2022-05-24 | GHSA-5v8v-66v8-mwm7CVE-2020-8927 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names microsoft.netcore.app.runtime.aot.osx-x64.cross.android-arm | Time to revision 161 days |
| 129 more rows in this change are not listed here. Open all 137 rows → | ||||
| Tue 25 Oct 2022· 5 changes | ||||
| 2022-10-25published 2022-09-17 | 3 bands | not named as affected when the advisory was published, now names com.fasterxml.woodstox:woodstox-core | Time to revision 39 days | |
| 2022-10-25published 2022-09-17 | GHSA-3f7h-mf4q-vrm4CVE-2022-40152 | same package registry as the line abovemoderate | same change as the line above | Time to revision 39 days |
| 2022-10-25published 2022-09-17 | GHSA-4rv7-wj6m-6c6rCVE-2022-40156 | same package registry as the line abovelow | same change as the line above | Time to revision 39 days |
| 2022-10-25published 2022-09-17 | GHSA-5hc5-c3m9-8vcjCVE-2022-40155 | same package registry as the line abovelow | same change as the line above | Time to revision 39 days |
| 2022-10-25published 2022-09-17 | GHSA-9fwf-46g9-45rxCVE-2022-40154 | same package registry as the line abovelow | same change as the line above | Time to revision 39 days |
| 2022-10-25published 2022-09-17 | GHSA-fv22-xp26-mm9wCVE-2022-40153 | same package registry as the line abovehigh | same change as the line above | Time to revision 39 days |
| Thu 6 Oct 2022· 1 change | ||||
| 2022-10-06published 2022-09-30 | GHSA-f36p-42jv-8rh2 | high | not named as affected when the advisory was published, now names com.wire.bots:lithium | Time to revision 7 days |
| Tue 4 Oct 2022· 3 changes | ||||
| 2022-10-04published 2021-05-06 | GHSA-f2jv-r9rf-7988 | critical | not named as affected when the advisory was published, now names org.webjars.bowergithub.wycats:handlebars.js and 2 more | Time to revision 516 days |
| 2022-10-04published 2021-05-06 | GHSA-f2jv-r9rf-7988CVE-2021-23369 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.webjars.bowergithub.wycats:handlebars.js | Time to revision 516 days |
| 2022-10-04published 2021-05-06 | GHSA-f2jv-r9rf-7988CVE-2021-23369 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.webjars.npm:handlebars | Time to revision 516 days |
| 2022-10-04published 2021-05-06 | GHSA-f2jv-r9rf-7988CVE-2021-23369 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.webjars:handlebars | Time to revision 516 days |
| Mon 26 Sep 2022· 2 changes | ||||
| 2022-09-26published 2021-09-02 | GHSA-9j49-mfvp-vmhmCVE-2021-23406 | high | not named as affected when the advisory was published, now names degenerator | Time to revision 389 days |
| 2022-09-26published 2018-07-26 | GHSA-cqp5-m4pq-gfgpCVE-2018-3723 | high | not named as affected when the advisory was published, now names defaults-deep | Time to revision 1,523 days |
| Mon 19 Sep 2022· 1 change | ||||
| 2022-09-19published 2022-09-16 | GHSA-634p-93h9-92vhCVE-2022-39217 | moderate | not named as affected when the advisory was published, now names some-natalie/ghas-to-csv | Time to revision 3 days |
| Thu 15 Sep 2022· 1 change | ||||
| 2022-09-15published 2022-09-07 | GHSA-jj62-mc3m-j769CVE-2020-21516 | critical | not named as affected when the advisory was published, now names feehi/cms | Time to revision 9 days |
| Sun 11 Sep 2022· 1 change | ||||
| 2022-09-11published 2021-08-25 | GHSA-69fv-gw6g-8ccgCVE-2018-20998 | critical | not named as affected when the advisory was published, now names arrayfire | Time to revision 381 days |
| Fri 9 Sep 2022· 1 change | ||||
| 2022-09-09published 2021-05-17 | GHSA-jqh7-w5pr-cr56CVE-2020-8176 | moderate | not named as affected when the advisory was published, now names @shopify/koa-shopify-auth | Time to revision 480 days |
| Wed 7 Sep 2022· 1 change | ||||
| 2022-09-07published 2021-09-15 | GHSA-5vp3-v4hc-gx76CVE-2021-41264 | critical | not named as affected when the advisory was published, now names @openzeppelin/contracts-upgradeable | Time to revision 357 days |
| Tue 6 Sep 2022· 1 change | ||||
| 2022-09-06published 2022-05-24 | GHSA-hxrm-9w7p-39ccCVE-2020-1045 | high | not named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.win-arm64 | Time to revision 105 days |
| Thu 1 Sep 2022· 6 changes | ||||
| 2022-09-01published 2021-11-19 to 2022-06-17 | 2 bands | not named as affected when the advisory was published, now names opcfoundation.netstandard.opc.ua.core | Time to revision 76 to 286 days | |
| 2022-09-01published 2022-06-17 | GHSA-r7pq-3x6p-7jcmCVE-2022-29863 | same package registry as the line abovehigh | same change as the line above | Time to revision 76 days |
| 2022-09-01published 2022-06-17 | GHSA-vhfw-v69p-crcwCVE-2022-29864 | same package registry as the line abovehigh | same change as the line above | Time to revision 76 days |
| 2022-09-01published 2022-06-17 | GHSA-fvxf-r9fw-49pcCVE-2022-29865 | same package registry as the line abovehigh | same change as the line above | Time to revision 76 days |
| 2022-09-01published 2022-06-17 | GHSA-6fp8-cxc9-4fr9CVE-2022-29866 | same package registry as the line abovehigh | same change as the line above | Time to revision 76 days |
| 2022-09-01published 2021-11-19 | GHSA-mjww-934m-h4jwCVE-2020-29457 | same package registry as the line abovemoderate | same change as the line above | Time to revision 286 days |
| 2022-09-01published 2022-06-17 | GHSA-5q2v-6j86-5h9vCVE-2022-29862 | same package registry as the line abovehigh | same change as the line above | Time to revision 76 days |
| Fri 26 Aug 2022· 11 changes | ||||
| 2022-08-26published 2022-05-24 | GHSA-hxrm-9w7p-39cc | high | not named as affected when the advisory was published, now names microsoft.aspnetcore.app and 10 more | Time to revision 94 days |
| 2022-08-26published 2022-05-24 | GHSA-hxrm-9w7p-39ccCVE-2020-1045 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.aspnetcore.app | Time to revision 94 days |
| 2022-08-26published 2022-05-24 | GHSA-hxrm-9w7p-39ccCVE-2020-1045 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-arm | Time to revision 94 days |
| 2022-08-26published 2022-05-24 | GHSA-hxrm-9w7p-39ccCVE-2020-1045 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-arm64 | Time to revision 94 days |
| 2022-08-26published 2022-05-24 | GHSA-hxrm-9w7p-39ccCVE-2020-1045 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-musl-arm64 | Time to revision 94 days |
| 2022-08-26published 2022-05-24 | GHSA-hxrm-9w7p-39ccCVE-2020-1045 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-musl-x64 | Time to revision 94 days |
| 2022-08-26published 2022-05-24 | GHSA-hxrm-9w7p-39ccCVE-2020-1045 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-x64 | Time to revision 94 days |
| 2022-08-26published 2022-05-24 | GHSA-hxrm-9w7p-39ccCVE-2020-1045 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.osx-x64 | Time to revision 94 days |
| 2022-08-26published 2022-05-24 | GHSA-hxrm-9w7p-39ccCVE-2020-1045 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.win-arm | Time to revision 94 days |
| 3 more rows in this change are not listed here. Open all 11 rows → | ||||
| Fri 12 Aug 2022· 1 change | ||||
| 2022-08-12published 2022-02-09 | GHSA-jh6m-3pqw-242hCVE-2020-14359 | high | not named as affected when the advisory was published, now names github.com/keycloak/keycloak-gatekeeper | Time to revision 185 days |
| Wed 10 Aug 2022· 1 change | ||||
| 2022-08-10published 2022-07-19 | GHSA-4x9r-j582-cgr8CVE-2022-33891 | high | not named as affected when the advisory was published, now names pyspark | Time to revision 23 days |
| Fri 5 Aug 2022· 1 change | ||||
| 2022-08-05published 2022-05-24 | GHSA-cjw4-2w9r-r8mvCVE-2019-12410 | high | not named as affected when the advisory was published, now names pyarrow | Time to revision 73 days |
| Thu 4 Aug 2022· 1 change | ||||
| 2022-08-04published 2022-02-11 | GHSA-6qq8-5wq3-86rpCVE-2020-15129 | moderate | not named as affected when the advisory was published, now names github.com/containous/traefik/v2/pkg/api | Time to revision 174 days |
| Fri 29 Jul 2022· 1 change | ||||
| 2022-07-29published 2022-02-11 | GHSA-6qq8-5wq3-86rpCVE-2020-15129 | moderate | not named as affected when the advisory was published, now names github.com/containous/traefik/v2 | Time to revision 168 days |
| Tue 26 Jul 2022· 1 change | ||||
| 2022-07-26published 2022-05-14 | GHSA-2xjx-v99w-gqf3CVE-2019-0545 | high | not named as affected when the advisory was published, now names microsoft.netcore.app | Time to revision 74 days |
| Sat 16 Jul 2022· 4 changes | ||||
| 2022-07-16published 2022-07-06 | GHSA-f2gr-7299-487h | moderate | not named as affected when the advisory was published, now names github.com/ipfs/go-ipfs | Time to revision 9 days |
| 2022-07-16published 2021-08-30 | GHSA-7774-7vr3-cc8jCVE-2021-39155 | high | not named as affected when the advisory was published, now names istio.io/istio | Time to revision 320 days |
| 2022-07-16published 2022-06-17 | GHSA-75rw-34q6-72crCVE-2022-31053 | critical | not named as affected when the advisory was published, now names github.com/biscuit-auth/biscuit-go | Time to revision 29 days |
| 2022-07-16published 2021-09-02 | GHSA-7h6j-2268-fhcmCVE-2020-9321 | moderate | not named as affected when the advisory was published, now names github.com/traefik/traefik | Time to revision 316 days |
| Mon 11 Jul 2022· 11 changes | ||||
| 2022-07-11published 2022-06-28 | GHSA-m43h-hfrq-x8wxCVE-2022-26477 | high | not named as affected when the advisory was published, now names systemds | Time to revision 14 days |
| 2022-07-11published 2022-04-03 | GHSA-558x-2xjg-6232CVE-2022-22950 | moderate | not named as affected when the advisory was published, now names org.springframework:spring-expression | Time to revision 100 days |
| 2022-07-11published 2018-10-16 | GHSA-jc8g-xhw5-6x46 | high | not named as affected when the advisory was published, now names system.private.servicemodel and 5 more | Time to revision 1,364 days |
| 2022-07-11published 2018-10-16 | GHSA-jc8g-xhw5-6x46CVE-2018-0786 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names system.private.servicemodel | Time to revision 1,364 days |
| 2022-07-11published 2018-10-16 | GHSA-jc8g-xhw5-6x46CVE-2018-0786 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names system.servicemodel.duplex | Time to revision 1,364 days |
| 2022-07-11published 2018-10-16 | GHSA-jc8g-xhw5-6x46CVE-2018-0786 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names system.servicemodel.http | Time to revision 1,364 days |
| 2022-07-11published 2018-10-16 | GHSA-jc8g-xhw5-6x46CVE-2018-0786 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names system.servicemodel.nettcp | Time to revision 1,364 days |
| 2022-07-11published 2018-10-16 | GHSA-jc8g-xhw5-6x46CVE-2018-0786 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names system.servicemodel.primitives | Time to revision 1,364 days |
| 2022-07-11published 2018-10-16 | GHSA-jc8g-xhw5-6x46CVE-2018-0786 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names system.servicemodel.security | Time to revision 1,364 days |
| 2022-07-11published 2018-10-16 | GHSA-mv2r-q4g5-j8q5 | high | not named as affected when the advisory was published, now names microsoft.aspnetcore.all and 1 more | Time to revision 1,364 days |
| 2022-07-11published 2018-10-16 | GHSA-mv2r-q4g5-j8q5CVE-2018-8269 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.aspnetcore.all | Time to revision 1,364 days |
| 2022-07-11published 2018-10-16 | GHSA-mv2r-q4g5-j8q5CVE-2018-8269 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.aspnetcore.dataprotection.azurestorage | Time to revision 1,364 days |
| 2022-07-11published 2017-10-24 | GHSA-qrgf-jqqm-x7xvCVE-2013-5671 | high | not named as affected when the advisory was published, now names fog-dragonfly | Time to revision 1,721 days |
| Wed 29 Jun 2022· 1 change | ||||
| 2022-06-29published 2022-05-24 | GHSA-72gx-qq2m-6xr2CVE-2019-10431 | critical | not named as affected when the advisory was published, now names org.jenkins-ci.plugins:script-security | Time to revision 36 days |
| Fri 17 Jun 2022· 2 changes | ||||
| 2022-06-17published 2021-11-30 | GHSA-fwf6-rw69-hhj4CVE-2021-23654 | moderate | not named as affected when the advisory was published, now names html-to-csv | Time to revision 199 days |
| 2022-06-17published 2021-04-13 | GHSA-53xj-v576-3ch2CVE-2019-10802 | critical | not named as affected when the advisory was published, now names giting | Time to revision 430 days |
Counted in advisories, never added to the CVE and KEV figures. This kind is counted once per advisory and per package, so one advisory that named four further packages counts four times. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.
What this page cannot see
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →
Paste your closed CVE tickets and see which of these changes hit them →