Skip to content

Package added to advisory

Compare earlier and later source statements, with the dates and evidence behind each measured change.

1,695 advisory changes · newest first · grouped by day

SinceClear all
ChangedSourceRows
Counted changes of "Package added to advisory", newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.Advisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Tue 1 Sep 2026· 2 changes
2026-09-01published 2026-06-16GHSA-5r4w-85f3-pw66highnot named as affected when the advisory was published, now names github.com/traefik/traefik/v2 and 1 moreTime to revision 77 days
2026-09-01published 2026-06-16GHSA-5r4w-85f3-pw66CVE-2026-48491same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/traefik/traefik/v2Time to revision 77 days
2026-09-01published 2026-06-16GHSA-5r4w-85f3-pw66CVE-2026-48491same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/traefik/traefik/v3Time to revision 77 days
Mon 31 Aug 2026· 1 change
2026-08-31published 2026-05-12GHSA-r29c-68gh-xp6xCVE-2026-41293criticalnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 111 days
Fri 14 Aug 2026· 2 changes
2026-08-14published 2026-02-19GHSA-p6jf-79j3-33f3CVE-2025-13590criticalnot named as affected when the advisory was published, now names org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1Time to revision 176 days
2026-08-14published 2026-04-29GHSA-w22p-4x9f-486vCVE-2026-42523criticalnot named as affected when the advisory was published, now names com.coravy.hudson.plugins.github:githubTime to revision 107 days
Tue 4 Aug 2026· 2 changes
2026-08-04published 2026-06-03GHSA-2j2x-hqr9-3h42CVE-2026-40181moderatenot named as affected when the advisory was published, now names @remix-run/routerTime to revision 62 days
2026-08-04published 2026-07-21GHSA-w5pg-649r-p6ggCVE-2026-58439highnot named as affected when the advisory was published, now names code.gitea.io/giteaTime to revision 13 days
Fri 31 Jul 2026· 1 change
2026-07-31published 2026-07-21GHSA-m4p7-r5rc-7g4jCVE-2026-59884highnot named as affected when the advisory was published, now names pyasn1Time to revision 10 days
Thu 30 Jul 2026· 2 changes
2026-07-30published 2025-05-13GHSA-qqcr-9jfc-35c4highnot named as affected when the advisory was published, now names oxid-esales/oxideshop-metapackage-ce and 1 moreTime to revision 443 days
2026-07-30published 2025-05-13GHSA-qqcr-9jfc-35c4CVE-2024-56526same package registry as the line abovehighnot named as affected when the advisory was published, now names oxid-esales/oxideshop-metapackage-ceTime to revision 443 days
2026-07-30published 2025-05-13GHSA-qqcr-9jfc-35c4CVE-2024-56526same package registry as the line abovehighnot named as affected when the advisory was published, now names oxid-esales/smarty-componentTime to revision 443 days
Fri 24 Jul 2026· 1 change
2026-07-24published 2026-05-06GHSA-rwm7-x88c-3g2pCVE-2026-42577highnot named as affected when the advisory was published, now names io.netty:netty-transport-classes-epollTime to revision 79 days
Tue 21 Jul 2026· 3 changes
2026-07-21published 2026-05-07GHSA-g924-cjx7-2rjwCVE-2026-42597moderatenot named as affected when the advisory was published, now names github.com/gotenberg/gotenberg/v7Time to revision 76 days
2026-07-21published 2026-04-14GHSA-2hx3-vp6r-mg3fhighnot named as affected when the advisory was published, now names microsoft.openapi.kiota and 1 moreTime to revision 98 days
2026-07-21published 2026-04-14GHSA-2hx3-vp6r-mg3fCVE-2026-41134same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.openapi.kiotaTime to revision 98 days
2026-07-21published 2026-04-14GHSA-2hx3-vp6r-mg3fCVE-2026-41134same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.openapi.kiota.builderTime to revision 98 days
Thu 16 Jul 2026· 1 change
2026-07-16published 2024-05-30GHSA-22q7-cg4r-p9mxmoderatenot named as affected when the advisory was published, now names typo3/cms-fluidTime to revision 777 days
Wed 15 Jul 2026· 1 change
2026-07-15published 2025-12-01GHSA-rcmh-qjqh-p98vCVE-2025-14874highnot named as affected when the advisory was published, now names org.webjars.npm:nodemailerTime to revision 226 days
Tue 7 Jul 2026· 1 change
2026-07-07published 2026-05-08GHSA-mx76-r943-rf8gCVE-2026-8149moderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-lts8onTime to revision 61 days
Mon 6 Jul 2026· 15 changes
2026-07-06published 2026-06-18GHSA-jc38-x7x8-2xc8highnot named as affected when the advisory was published, now names web-token/jwt-bundle and 1 moreTime to revision 18 days
2026-07-06published 2026-06-18GHSA-jc38-x7x8-2xc8same package registry as the line abovehighnot named as affected when the advisory was published, now names web-token/jwt-bundleTime to revision 18 days
2026-07-06published 2026-06-18GHSA-jc38-x7x8-2xc8same package registry as the line abovehighnot named as affected when the advisory was published, now names web-token/jwt-experimentalTime to revision 18 days
2026-07-06published 2026-03-19 to 2026-06-263 bandsnot named as affected when the advisory was published, now names scriban.signedTime to revision 10 to 109 days
2026-07-06published 2026-06-26GHSA-6q7j-xr26-3h2csame package registry as the line abovemoderatesame change as the line aboveTime to revision 10 days
2026-07-06published 2026-03-24GHSA-xw6w-9jjh-p9crsame package registry as the line abovemoderatesame change as the line aboveTime to revision 104 days
2026-07-06published 2026-03-24GHSA-m2p3-hwv5-xpqwsame package registry as the line abovemoderatesame change as the line aboveTime to revision 104 days
2026-07-06published 2026-03-24GHSA-xcx6-vp38-8hr5same package registry as the line abovehighsame change as the line aboveTime to revision 104 days
2026-07-06published 2026-03-24GHSA-v66j-x4hw-fv9gsame package registry as the line abovehighsame change as the line aboveTime to revision 104 days
2026-07-06published 2026-03-24GHSA-5wr9-m6jw-xx44same package registry as the line abovecriticalsame change as the line aboveTime to revision 104 days
2026-07-06published 2026-03-24GHSA-x6m9-38vm-2xhfsame package registry as the line abovehighsame change as the line aboveTime to revision 104 days
2026-07-06published 2026-03-24GHSA-p6q4-fgr8-vx4psame package registry as the line abovehighsame change as the line aboveTime to revision 104 days
5 more rows in this change are not listed here. Open all 13 rows
Wed 1 Jul 2026· 5 changes
2026-07-01published 2024-11-07 to 2025-08-132 bandsnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreTime to revision 322 to 601 days
2026-07-01published 2024-11-07GHSA-7jqf-v358-p8g7CVE-2024-38286same package registry as the line abovehighsame change as the line aboveTime to revision 601 days
2026-07-01published 2025-08-13GHSA-23hv-mwm6-g8jfCVE-2025-55668same package registry as the line abovemoderatesame change as the line aboveTime to revision 322 days
2026-07-01published 2025-07-10GHSA-4j3c-42xv-3f84CVE-2025-52434same package registry as the line abovemoderatesame change as the line aboveTime to revision 356 days
2026-07-01published 2024-11-07 to 2025-07-102 bandsnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 356 to 601 days
2026-07-01published 2024-11-07GHSA-7jqf-v358-p8g7CVE-2024-38286same package registry as the line abovehighsame change as the line aboveTime to revision 601 days
2026-07-01published 2025-07-10GHSA-4j3c-42xv-3f84CVE-2025-52434same package registry as the line abovemoderatesame change as the line aboveTime to revision 356 days
Mon 29 Jun 2026· 3 changes
2026-06-29published 2026-02-17GHSA-qq5r-98hh-rxc9CVE-2026-24733lownot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 132 days
2026-06-29published 2026-05-19GHSA-24c8-4792-22hxhighnot named as affected when the advisory was published, now names scriban.signedTime to revision 41 days
2026-06-29published 2019-10-11GHSA-p979-4mfw-53vgCVE-2019-16869highnot named as affected when the advisory was published, now names io.netty:nettyDuration unknown
Fri 26 Jun 2026· 2 changes
2026-06-26published 2026-05-29GHSA-6x26-5727-rrm9CVE-2026-47268moderatenot named as affected when the advisory was published, now names github.com/naiba/nezhaTime to revision 28 days
2026-06-26published 2026-06-10GHSA-8h84-fhqq-q58vCVE-2026-48025moderatenot named as affected when the advisory was published, now names github.com/forgekeep/nebula-meshTime to revision 16 days
Thu 18 Jun 2026· 7 changes
2026-06-18published 2024-01-19GHSA-f4qf-m5gf-8jm8CVE-2024-21733moderatenot named as affected when the advisory was published, now names org.apache.tomcat.experimental:tomcat-embed-programmaticTime to revision 881 days
2026-06-18published 2026-04-09GHSA-x4m4-345f-5h5gCVE-2026-34487highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-tribesTime to revision 70 days
2026-06-18published 2024-11-18GHSA-f632-9449-3j4wCVE-2024-52318moderatenot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-jasperTime to revision 577 days
2026-06-18published 2019-05-30 to 2024-11-18moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcatTime to revision 577 days
2026-06-18published 2024-11-18GHSA-f632-9449-3j4wCVE-2024-52318same package registry as the line abovemoderatesame change as the line aboveTime to revision 577 days
2026-06-18published 2019-05-30GHSA-jjpq-gp5q-8q6wCVE-2019-0221same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2026-06-18published 2019-05-30 to 2023-02-202 bandsnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaTime to revision 1,214 days
2026-06-18published 2023-02-20GHSA-hfrx-6qgj-fp6cCVE-2023-24998same package registry as the line abovehighsame change as the line aboveTime to revision 1,214 days
2026-06-18published 2019-05-30GHSA-jjpq-gp5q-8q6wCVE-2019-0221same package registry as the line abovemoderatesame change as the line aboveDuration unknown
Fri 12 Jun 2026· 4 changes
2026-06-12published 2023-10-10 to 2026-02-17moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 115 to 976 days
2026-06-12published 2023-10-10GHSA-r6j3-px5g-cq3xCVE-2023-45648same package registry as the line abovemoderatesame change as the line aboveTime to revision 976 days
2026-06-12published 2026-02-17GHSA-fpj8-gq4v-p354CVE-2025-66614same package registry as the line abovemoderatesame change as the line aboveTime to revision 115 days
2026-06-12published 2023-10-10GHSA-g8pj-r55q-5c2vmoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina and 1 moreTime to revision 976 days
2026-06-12published 2023-10-10GHSA-g8pj-r55q-5c2vCVE-2023-42795same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaTime to revision 976 days
2026-06-12published 2023-10-10GHSA-g8pj-r55q-5c2vCVE-2023-42795same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-utilTime to revision 976 days
Thu 11 Jun 2026· 4 changes
2026-06-11published 2026-05-07GHSA-2mh5-3cw6-hrrqCVE-2026-40981highnot named as affected when the advisory was published, now names org.springframework.cloud:spring-cloud-config-serverTime to revision 35 days
2026-06-11published 2022-02-08GHSA-m7jv-hq7h-mq7chighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocket and 1 moreDuration unknown
2026-06-11published 2022-02-08GHSA-m7jv-hq7h-mq7cCVE-2020-13935same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocketDuration unknown
2026-06-11published 2022-02-08GHSA-m7jv-hq7h-mq7cCVE-2020-13935same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-websocketDuration unknown
2026-06-11published 2022-02-09GHSA-53hp-jpwq-2jgqCVE-2020-11996highnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDuration unknown
Tue 9 Jun 2026· 1 change
2026-06-09published 2026-06-01GHSA-q53q-5r4j-5729CVE-2026-47425moderatenot named as affected when the advisory was published, now names py-rattlerTime to revision 8 days
Mon 8 Jun 2026· 4 changes
2026-06-08published 2026-05-15GHSA-w42g-jj8w-fj77highnot named as affected when the advisory was published, now names thorsten/phpmyfaqTime to revision 24 days
2026-06-08published 2021-04-13GHSA-3pcr-4982-548mmoderatenot named as affected when the advisory was published, now names shopware/shopwareDuration unknown
2026-06-08published 2025-10-15GHSA-6p6v-m64v-jx8qCVE-2025-55039lownot named as affected when the advisory was published, now names pysparkTime to revision 236 days
2026-06-08published 2026-03-25GHSA-7h8w-hj9j-8rjwCVE-2026-33718highnot named as affected when the advisory was published, now names openhands-aiTime to revision 75 days
Fri 5 Jun 2026· 4 changes
2026-06-05published 2023-08-25GHSA-q3mw-pvr8-9ggcCVE-2023-41080moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaTime to revision 1,015 days
2026-06-05published 2021-06-16GHSA-j39c-c8hj-x4j3CVE-2021-25122highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDuration unknown
2026-06-05published 2026-04-18GHSA-w9r4-94fj-xp69CVE-2026-32690lownot named as affected when the advisory was published, now names apache-airflowTime to revision 48 days
2026-06-05published 2025-09-24GHSA-776q-jw43-fhjxCVE-2025-48459criticalnot named as affected when the advisory was published, now names apache-iotdbTime to revision 254 days
Mon 1 Jun 2026· 2 changes
2026-06-01published 2026-05-18GHSA-v549-xx3c-6pc8moderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server and 1 moreTime to revision 14 days
2026-06-01published 2026-05-18GHSA-v549-xx3c-6pc8CVE-2026-3637same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost-serverTime to revision 14 days
2026-06-01published 2026-05-18GHSA-v549-xx3c-6pc8CVE-2026-3637same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost/server/v8Time to revision 14 days
Fri 29 May 2026· 1 change
2026-05-29published 2026-04-22GHSA-ffq5-qpvf-xq7xCVE-2026-42086moderatenot named as affected when the advisory was published, now names openc3Time to revision 37 days
Wed 20 May 2026· 8 changes
2026-05-20published 2023-06-14GHSA-5wfc-hjrc-gq87CVE-2023-34620highnot named as affected when the advisory was published, now names github.com/hjson/hjson-go/v4Time to revision 1,071 days
2026-05-20published 2023-06-14GHSA-5wfc-hjrc-gq87CVE-2023-34620highnot named as affected when the advisory was published, now names laktak/hjsonTime to revision 1,071 days
2026-05-20published 2020-06-15 to 2026-04-09highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 41 days
2026-05-20published 2026-04-09GHSA-69cc-cv78-qc8gCVE-2026-29129same package registry as the line abovehighsame change as the line aboveTime to revision 41 days
2026-05-20published 2020-06-15GHSA-qcxh-w3j9-58qrCVE-2019-0199same package registry as the line abovehighsame change as the line aboveDuration unknown
2026-05-20published 2026-04-092 bandsnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote-ffmTime to revision 40 to 41 days
2026-05-20published 2026-04-09GHSA-95jq-rwvf-vjx4CVE-2026-29145same package registry as the line abovecriticalsame change as the line aboveTime to revision 41 days
2026-05-20published 2026-04-09GHSA-24j9-x2wg-9qv6CVE-2026-34500same package registry as the line abovemoderatesame change as the line aboveTime to revision 40 days
2026-05-20published 2024-12-17GHSA-653p-vg55-5652CVE-2024-54677moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcatTime to revision 519 days
2026-05-20published 2026-03-31GHSA-rvhj-8chj-8v3cCVE-2026-0596criticalnot named as affected when the advisory was published, now names mlflowTime to revision 49 days
Thu 14 May 2026· 3 changes
2026-05-14published 2024-12-02GHSA-4cx5-89vm-833xlownot named as affected when the advisory was published, now names org.verapdf:library and 2 moreTime to revision 528 days
2026-05-14published 2024-12-02GHSA-4cx5-89vm-833xCVE-2024-52800same package registry as the line abovelownot named as affected when the advisory was published, now names org.verapdf:libraryTime to revision 528 days
2026-05-14published 2024-12-02GHSA-4cx5-89vm-833xCVE-2024-52800same package registry as the line abovelownot named as affected when the advisory was published, now names org.verapdf:library-arlingtonTime to revision 528 days
2026-05-14published 2024-12-02GHSA-4cx5-89vm-833xCVE-2024-52800same package registry as the line abovelownot named as affected when the advisory was published, now names org.verapdf:library-jakartaTime to revision 528 days
Thu 7 May 2026· 7 changes
2026-05-07published 2025-07-11 to 2025-08-082 bandsnot named as affected when the advisory was published, now names github.com/pytorch/executorchTime to revision 273 to 300 days
2026-05-07published 2025-08-08GHSA-hj95-mhgf-jxc4CVE-2025-30404same package registry as the line abovecriticalsame change as the line aboveTime to revision 273 days
2026-05-07published 2025-08-08GHSA-xc7w-r669-48pfCVE-2025-54951same package registry as the line abovecriticalsame change as the line aboveTime to revision 273 days
2026-05-07published 2025-08-08GHSA-84m3-f99p-cqx5CVE-2025-30405same package registry as the line abovecriticalsame change as the line aboveTime to revision 273 days
2026-05-07published 2025-08-08GHSA-9m39-3mf3-xwchCVE-2025-54949same package registry as the line abovecriticalsame change as the line aboveTime to revision 273 days
2026-05-07published 2025-08-08GHSA-f9hx-c6jf-3qxmCVE-2025-54950same package registry as the line abovecriticalsame change as the line aboveTime to revision 273 days
2026-05-07published 2025-07-11GHSA-h952-963h-rv99CVE-2025-30402same package registry as the line abovehighsame change as the line aboveTime to revision 300 days
2026-05-07published 2026-03-16GHSA-6jj5-j4j8-8473CVE-2026-28499moderatenot named as affected when the advisory was published, now names github.com/vapor/leaf-kitTime to revision 52 days
Wed 6 May 2026· 9 changes
2026-05-06published 2025-11-13GHSA-7wq2-32h4-9hc9highnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/auth-helpers and 8 moreTime to revision 174 days
2026-05-06published 2025-11-13GHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/auth-helpersTime to revision 174 days
2026-05-06published 2025-11-13GHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/aws-secrets-managerTime to revision 174 days
2026-05-06published 2025-11-13GHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/federated-authTime to revision 174 days
2026-05-06published 2025-11-13GHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/iamTime to revision 174 days
2026-05-06published 2025-11-13GHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/mysql-driverTime to revision 174 days
2026-05-06published 2025-11-13GHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/oktaTime to revision 174 days
2026-05-06published 2025-11-13GHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/otlpTime to revision 174 days
2026-05-06published 2025-11-13GHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/pgx-driverTime to revision 174 days
1 more row in this change is not listed here. Open all 9 rows
Tue 5 May 2026· 1 change
2026-05-05published 2025-09-03GHSA-qww7-89xh-x7m7CVE-2025-55747criticalnot named as affected when the advisory was published, now names org.xwiki.platform:xwiki-platform-webjarsTime to revision 244 days
Tue 28 Apr 2026· 2 changes
2026-04-28published 2022-02-08 to 2026-04-09highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 18 days
2026-04-28published 2026-04-09GHSA-563x-q5rq-57qpCVE-2026-24880same package registry as the line abovehighsame change as the line aboveTime to revision 18 days
2026-04-28published 2022-02-08GHSA-vf77-8h7g-gghpCVE-2020-13934same package registry as the line abovehighsame change as the line aboveDuration unknown
Wed 22 Apr 2026· 1 change
2026-04-22published 2026-02-19GHSA-4hfh-fch3-5q7pCVE-2026-27120moderatenot named as affected when the advisory was published, now names github.com/vapor/leaf-kitTime to revision 62 days
Fri 17 Apr 2026· 2 changes
2026-04-17published 2022-05-14GHSA-6r5v-hp32-fjqwCVE-2015-0227moderatenot named as affected when the advisory was published, now names wss4j:wss4jDuration unknown
2026-04-17published 2024-05-03GHSA-4h8f-2wvx-gg5wCVE-2024-34447moderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onTime to revision 714 days
Thu 16 Apr 2026· 4 changes
2026-04-16published 2022-04-22GHSA-4qqf-hmv6-r6whCVE-2011-2487moderatenot named as affected when the advisory was published, now names wss4j:wss4jDuration unknown
2026-04-16published 2025-07-21GHSA-9342-92gg-6v29CVE-2025-7962moderatenot named as affected when the advisory was published, now names com.sun.mail:jakarta.mailTime to revision 269 days
2026-04-16published 2024-10-04GHSA-wwcp-26wc-3fxmCVE-2024-47855moderatenot named as affected when the advisory was published, now names net.sf.json-lib:json-libTime to revision 560 days
2026-04-16published 2022-05-13GHSA-jwwr-fjgh-cv2xCVE-2014-3004moderatenot named as affected when the advisory was published, now names castor:castorDuration unknown
Wed 15 Apr 2026· 3 changes
2026-04-15published 2026-04-09GHSA-8mc5-53m5-3qj2CVE-2026-32990moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 6 days
2026-04-15published 2026-04-09highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-tribesTime to revision 6 days
2026-04-15published 2026-04-09GHSA-69r9-qgr7-g2wjCVE-2026-34486same package registry as the line abovehighsame change as the line aboveTime to revision 6 days
2026-04-15published 2026-04-09GHSA-h468-7pvh-8vr8CVE-2026-29146same package registry as the line abovehighsame change as the line aboveTime to revision 6 days
Fri 10 Apr 2026· 1 change
2026-04-10published 2026-03-11GHSA-fvcw-9w9r-pxc7CVE-2026-31829highnot named as affected when the advisory was published, now names flowise-componentsTime to revision 31 days
Wed 8 Apr 2026· 1 change
2026-04-08published 2026-03-20GHSA-687q-32c6-8x68CVE-2026-33478criticalnot named as affected when the advisory was published, now names wwbn/avideoTime to revision 19 days
Mon 6 Apr 2026· 1 change
2026-04-06published 2026-03-30GHSA-jjwv-57xh-xr6rCVE-2026-27018highnot named as affected when the advisory was published, now names github.com/gotenberg/gotenberg/v7Time to revision 7 days
Fri 27 Mar 2026· 6 changes
2026-03-27published 2026-03-13GHSA-q926-c743-49qjlownot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v3 and 2 moreTime to revision 14 days
2026-03-27published 2026-03-13GHSA-q926-c743-49qjsame package registry as the line abovelownot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v3Time to revision 14 days
2026-03-27published 2026-03-13GHSA-q926-c743-49qjsame package registry as the line abovelownot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v4Time to revision 14 days
2026-03-27published 2026-03-13GHSA-q926-c743-49qjsame package registry as the line abovelownot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v5Time to revision 14 days
2026-03-27published 2026-03-13GHSA-j77h-rr39-c552criticalnot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v3 and 2 moreTime to revision 14 days
2026-03-27published 2026-03-13GHSA-j77h-rr39-c552CVE-2026-32301same package registry as the line abovecriticalnot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v3Time to revision 14 days
2026-03-27published 2026-03-13GHSA-j77h-rr39-c552CVE-2026-32301same package registry as the line abovecriticalnot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v4Time to revision 14 days
2026-03-27published 2026-03-13GHSA-j77h-rr39-c552CVE-2026-32301same package registry as the line abovecriticalnot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v5Time to revision 14 days
Fri 13 Mar 2026· 1 change
2026-03-13published 2026-03-11GHSA-8q2w-wr49-whqjCVE-2026-29777moderatenot named as affected when the advisory was published, now names github.com/traefik/traefik/v2Time to revision 2 days
Thu 12 Mar 2026· 2 changes
2026-03-12published 2026-03-10GHSA-hhfx-wfvq-7g9cCVE-2026-26118highnot named as affected when the advisory was published, now names @azure/mcpTime to revision 2 days
2026-03-12published 2026-03-10GHSA-hhfx-wfvq-7g9cCVE-2026-26118highnot named as affected when the advisory was published, now names msmcp-azureTime to revision 2 days
Fri 6 Mar 2026· 2 changes
2026-03-06published 2025-07-10highnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreTime to revision 239 days
2026-03-06published 2025-07-10GHSA-wr62-c79q-cv37CVE-2025-52520same package registry as the line abovehighsame change as the line aboveTime to revision 239 days
2026-03-06published 2025-07-10GHSA-25xr-qj8w-c4vfCVE-2025-53506same package registry as the line abovehighsame change as the line aboveTime to revision 239 days
Tue 24 Feb 2026· 1 change
2026-02-24published 2025-03-20GHSA-j3wr-m6xh-64hgCVE-2024-12704highnot named as affected when the advisory was published, now names llama-index-coreTime to revision 341 days
Thu 19 Feb 2026· 2 changes
2026-02-19published 2026-02-13GHSA-rp46-r563-jrc7CVE-2025-33042moderatenot named as affected when the advisory was published, now names org.apache.avro:avro-compilerTime to revision 6 days
2026-02-19published 2025-10-16GHSA-fwxx-wv44-7qfgCVE-2025-41253highnot named as affected when the advisory was published, now names org.springframework.cloud:spring-cloud-gateway-serverTime to revision 126 days
Tue 17 Feb 2026· 2 changes
2026-02-17published 2025-12-04GHSA-2cgv-28vr-rv6jhighnot named as affected when the advisory was published, now names libcrux-ml-dsa and 1 moreTime to revision 75 days
2026-02-17published 2025-12-04GHSA-2cgv-28vr-rv6jsame package registry as the line abovehighnot named as affected when the advisory was published, now names libcrux-ml-dsaTime to revision 75 days
2026-02-17published 2025-12-04GHSA-2cgv-28vr-rv6jsame package registry as the line abovehighnot named as affected when the advisory was published, now names libcrux-ml-kemTime to revision 75 days
Mon 2 Feb 2026· 2 changes
2026-02-02published 2024-03-15GHSA-qmgx-j96g-4428CVE-2024-28752criticalnot named as affected when the advisory was published, now names org.apache.cxf:cxf-rt-databinding-aegisTime to revision 689 days
2026-02-02published 2025-12-12GHSA-vx9q-rhv9-3jvgCVE-2025-67721highnot named as affected when the advisory was published, now names io.airlift:aircompressorTime to revision 52 days
Wed 21 Jan 2026· 1 change
2026-01-21published 2025-05-07GHSA-72qj-48g4-5xgxCVE-2025-46551moderatenot named as affected when the advisory was published, now names jruby-opensslTime to revision 259 days
Fri 16 Jan 2026· 1 change
2026-01-16published 2025-10-21GHSA-j5gw-2vrg-8fgxCVE-2025-62518highnot named as affected when the advisory was published, now names tokio-tarTime to revision 87 days
Tue 6 Jan 2026· 2 changes
2026-01-06published 2025-12-31GHSA-mrfv-m5wm-5w6wmoderatenot named as affected when the advisory was published, now names hdwallet and 1 moreTime to revision 7 days
2026-01-06published 2025-12-31GHSA-mrfv-m5wm-5w6wCVE-2025-69277same package registry as the line abovemoderatenot named as affected when the advisory was published, now names hdwalletTime to revision 7 days
2026-01-06published 2025-12-31GHSA-mrfv-m5wm-5w6wCVE-2025-69277same package registry as the line abovemoderatenot named as affected when the advisory was published, now names pynaclTime to revision 7 days
Mon 5 Jan 2026· 1 change
2026-01-05published 2026-01-02GHSA-c5cp-vx83-jhqxCVE-2026-21445highnot named as affected when the advisory was published, now names langflowTime to revision 2 days
Mon 22 Dec 2025· 1 change
2025-12-22published 2022-01-06GHSA-x8rq-rc7x-5fg5CVE-2022-0086highnot named as affected when the advisory was published, now names @uppy/companionDuration unknown
Thu 18 Dec 2025· 5 changes
2025-12-18published 2022-11-01GHSA-43xg-8wmj-cw8hmoderatenot named as affected when the advisory was published, now names org.apache.spark:spark-core_2.10 and 4 moreDuration unknown
2025-12-18published 2022-11-01GHSA-43xg-8wmj-cw8hCVE-2022-31777same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.spark:spark-core_2.10Duration unknown
2025-12-18published 2022-11-01GHSA-43xg-8wmj-cw8hCVE-2022-31777same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.spark:spark-core_2.11Duration unknown
2025-12-18published 2022-11-01GHSA-43xg-8wmj-cw8hCVE-2022-31777same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.spark:spark-core_2.12Duration unknown
2025-12-18published 2022-11-01GHSA-43xg-8wmj-cw8hCVE-2022-31777same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.spark:spark-core_2.13Duration unknown
2025-12-18published 2022-11-01GHSA-43xg-8wmj-cw8hCVE-2022-31777same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.spark:spark-core_2.9.3Duration unknown
Tue 16 Dec 2025· 18 changes
2025-12-16published 2022-01-06GHSA-vc89-hccf-rq55moderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_0.25 and 17 moreDuration unknown
2025-12-16published 2022-01-06GHSA-vc89-hccf-rq55CVE-2022-21653same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_0.25Duration unknown
2025-12-16published 2022-01-06GHSA-vc89-hccf-rq55CVE-2022-21653same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_0.27Duration unknown
2025-12-16published 2022-01-06GHSA-vc89-hccf-rq55CVE-2022-21653same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.10Duration unknown
2025-12-16published 2022-01-06GHSA-vc89-hccf-rq55CVE-2022-21653same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.11Duration unknown
2025-12-16published 2022-01-06GHSA-vc89-hccf-rq55CVE-2022-21653same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.12Duration unknown
2025-12-16published 2022-01-06GHSA-vc89-hccf-rq55CVE-2022-21653same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.13Duration unknown
2025-12-16published 2022-01-06GHSA-vc89-hccf-rq55CVE-2022-21653same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.13.0-m5Duration unknown
2025-12-16published 2022-01-06GHSA-vc89-hccf-rq55CVE-2022-21653same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.13.0-rc1Duration unknown
10 more rows in this change are not listed here. Open all 18 rows
Thu 11 Dec 2025· 32 changes
2025-12-11published 2021-09-02 to 2025-06-1032 rows, one per advisory and package2 bandsnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.10 and 22 moreTime to revision 185 to 1,070 days
2025-12-11published 2021-09-02GHSA-52cf-226f-rhr6CVE-2021-39185same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.10Duration unknown
2025-12-11published 2021-09-02GHSA-52cf-226f-rhr6CVE-2021-39185same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.11Duration unknown
2025-12-11published 2021-09-02GHSA-52cf-226f-rhr6CVE-2021-39185same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.12Duration unknown
2025-12-11published 2021-09-02GHSA-52cf-226f-rhr6CVE-2021-39185same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.13Duration unknown
2025-12-11published 2021-09-02GHSA-52cf-226f-rhr6CVE-2021-39185same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.http4s:http4s-server_2.13.0-m5Duration unknown
2025-12-11published 2021-09-02GHSA-52cf-226f-rhr6CVE-2021-39185same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.http4s:http4s-server_3Duration unknown
2025-12-11published 2021-09-22GHSA-5vcm-3xc3-w7x3CVE-2021-41084same package registry as the line abovehighnot named as affected when the advisory was published, now names org.http4s:http4s-client_2.12Duration unknown
2025-12-11published 2021-09-22GHSA-5vcm-3xc3-w7x3CVE-2021-41084same package registry as the line abovehighnot named as affected when the advisory was published, now names org.http4s:http4s-client_2.13Duration unknown
24 more rows in this change are not listed here. Open all 32 rows
Thu 4 Dec 2025· 1 change
2025-12-04published 2022-05-17GHSA-wwq7-pxwc-p4rcCVE-2012-5785moderatenot named as affected when the advisory was published, now names org.apache.axis2:axis2-transport-httpDuration unknown
Tue 18 Nov 2025· 1 change
2025-11-18published 2025-11-13GHSA-3g2j-vm47-x4mjhighnot named as affected when the advisory was published, now names github.com/canonical/lxdTime to revision 5 days
Mon 17 Nov 2025· 4 changes
2025-11-17published 2025-11-06moderatenot named as affected when the advisory was published, now names kubevirt.io/kubevirtTime to revision 11 days
2025-11-17published 2025-11-06GHSA-7xgm-5prm-v5gcCVE-2025-64436same package registry as the line abovemoderatesame change as the line aboveTime to revision 11 days
2025-11-17published 2025-11-06GHSA-9m94-w2vq-hcf9CVE-2025-64435same package registry as the line abovemoderatesame change as the line aboveTime to revision 11 days
2025-11-17published 2025-11-06GHSA-2r4r-5x78-mvqfCVE-2025-64437same package registry as the line abovemoderatesame change as the line aboveTime to revision 11 days
2025-11-17published 2025-11-06GHSA-qw6q-3pgr-5cwqCVE-2025-64433same package registry as the line abovemoderatesame change as the line aboveTime to revision 11 days
Sat 15 Nov 2025· 1 change
2025-11-15published 2025-11-07GHSA-46xp-26xh-hpqhCVE-2025-64324highnot named as affected when the advisory was published, now names kubevirt.io/kubevirtTime to revision 7 days
Thu 13 Nov 2025· 2 changes
2025-11-13published 2025-11-03GHSA-399j-vxmf-hjvrCVE-2025-11953criticalnot named as affected when the advisory was published, now names @react-native-community/cli-server-apiTime to revision 10 days
2025-11-13published 2025-07-30GHSA-cx25-xg7c-xfm5CVE-2025-54656moderatenot named as affected when the advisory was published, now names struts:strutsTime to revision 106 days
Fri 7 Nov 2025· 1 change
2025-11-07published 2025-10-31GHSA-2qfp-q593-8484CVE-2025-6176highnot named as affected when the advisory was published, now names scrapyTime to revision 8 days
Tue 4 Nov 2025· 2 changes
2025-11-04published 2023-12-01GHSA-qw4h-3xjj-84cchighnot named as affected when the advisory was published, now names org.apache.struts:struts-tiles and 1 moreTime to revision 705 days
2025-11-04published 2023-12-01GHSA-qw4h-3xjj-84ccCVE-2023-49735same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.struts:struts-tilesTime to revision 705 days
2025-11-04published 2023-12-01GHSA-qw4h-3xjj-84ccCVE-2023-49735same package registry as the line abovehighnot named as affected when the advisory was published, now names struts:strutsTime to revision 705 days
Thu 30 Oct 2025· 1 change
2025-10-30published 2025-10-21GHSA-qqj3-g7mx-5p4wCVE-2025-54470highnot named as affected when the advisory was published, now names github.com/neuvector/neuvectorTime to revision 9 days
Wed 29 Oct 2025· 1 change
2025-10-29published 2025-08-20GHSA-p72g-pv48-7w9xCVE-2025-54988criticalnot named as affected when the advisory was published, now names org.apache.tika:tika-parsersTime to revision 70 days
Mon 20 Oct 2025· 1 change
2025-10-20published 2021-04-13GHSA-r96p-v3cr-gfv8CVE-2020-28470highnot named as affected when the advisory was published, now names @scullyio/ng-libDuration unknown
Wed 15 Oct 2025· 1 change
2025-10-15published 2025-05-21GHSA-9pp5-9c7g-4r83CVE-2025-41232criticalnot named as affected when the advisory was published, now names org.springframework.security:spring-security-coreTime to revision 147 days

Counted in advisories, never added to the CVE and KEV figures. This kind is counted once per advisory and per package, so one advisory that named four further packages counts four times. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Use arrow keys to move between days, Home or End to reach either end, and Enter to open a day.
4,561 record edits in the 52 weeks to 2026-09-07. Scroll for earlier dates.fewermore

What this page cannot see

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Paste your closed CVE tickets and see which of these changes hit them →