Package added to advisory
Compare earlier and later source statements, with the dates and evidence behind each measured change.
1,695 advisory changes · newest first · grouped by day
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Advisory, Which advisory was edited, by its GHSA id. | Package, The package the advisory names, and the registry it comes from. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|
| Tue 1 Sep 2026· 2 changes | ||||
| 2026-09-01published 2026-06-16 | GHSA-5r4w-85f3-pw66 | high | not named as affected when the advisory was published, now names github.com/traefik/traefik/v2 and 1 more | Time to revision 77 days |
| 2026-09-01published 2026-06-16 | GHSA-5r4w-85f3-pw66CVE-2026-48491 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/traefik/traefik/v2 | Time to revision 77 days |
| 2026-09-01published 2026-06-16 | GHSA-5r4w-85f3-pw66CVE-2026-48491 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/traefik/traefik/v3 | Time to revision 77 days |
| Mon 31 Aug 2026· 1 change | ||||
| 2026-08-31published 2026-05-12 | GHSA-r29c-68gh-xp6xCVE-2026-41293 | critical | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 111 days |
| Fri 14 Aug 2026· 2 changes | ||||
| 2026-08-14published 2026-02-19 | GHSA-p6jf-79j3-33f3CVE-2025-13590 | critical | not named as affected when the advisory was published, now names org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1 | Time to revision 176 days |
| 2026-08-14published 2026-04-29 | GHSA-w22p-4x9f-486vCVE-2026-42523 | critical | not named as affected when the advisory was published, now names com.coravy.hudson.plugins.github:github | Time to revision 107 days |
| Tue 4 Aug 2026· 2 changes | ||||
| 2026-08-04published 2026-06-03 | GHSA-2j2x-hqr9-3h42CVE-2026-40181 | moderate | not named as affected when the advisory was published, now names @remix-run/router | Time to revision 62 days |
| 2026-08-04published 2026-07-21 | GHSA-w5pg-649r-p6ggCVE-2026-58439 | high | not named as affected when the advisory was published, now names code.gitea.io/gitea | Time to revision 13 days |
| Fri 31 Jul 2026· 1 change | ||||
| 2026-07-31published 2026-07-21 | GHSA-m4p7-r5rc-7g4jCVE-2026-59884 | high | not named as affected when the advisory was published, now names pyasn1 | Time to revision 10 days |
| Thu 30 Jul 2026· 2 changes | ||||
| 2026-07-30published 2025-05-13 | GHSA-qqcr-9jfc-35c4 | high | not named as affected when the advisory was published, now names oxid-esales/oxideshop-metapackage-ce and 1 more | Time to revision 443 days |
| 2026-07-30published 2025-05-13 | GHSA-qqcr-9jfc-35c4CVE-2024-56526 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names oxid-esales/oxideshop-metapackage-ce | Time to revision 443 days |
| 2026-07-30published 2025-05-13 | GHSA-qqcr-9jfc-35c4CVE-2024-56526 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names oxid-esales/smarty-component | Time to revision 443 days |
| Fri 24 Jul 2026· 1 change | ||||
| 2026-07-24published 2026-05-06 | GHSA-rwm7-x88c-3g2pCVE-2026-42577 | high | not named as affected when the advisory was published, now names io.netty:netty-transport-classes-epoll | Time to revision 79 days |
| Tue 21 Jul 2026· 3 changes | ||||
| 2026-07-21published 2026-05-07 | GHSA-g924-cjx7-2rjwCVE-2026-42597 | moderate | not named as affected when the advisory was published, now names github.com/gotenberg/gotenberg/v7 | Time to revision 76 days |
| 2026-07-21published 2026-04-14 | GHSA-2hx3-vp6r-mg3f | high | not named as affected when the advisory was published, now names microsoft.openapi.kiota and 1 more | Time to revision 98 days |
| 2026-07-21published 2026-04-14 | GHSA-2hx3-vp6r-mg3fCVE-2026-41134 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.openapi.kiota | Time to revision 98 days |
| 2026-07-21published 2026-04-14 | GHSA-2hx3-vp6r-mg3fCVE-2026-41134 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.openapi.kiota.builder | Time to revision 98 days |
| Thu 16 Jul 2026· 1 change | ||||
| 2026-07-16published 2024-05-30 | GHSA-22q7-cg4r-p9mx | moderate | not named as affected when the advisory was published, now names typo3/cms-fluid | Time to revision 777 days |
| Wed 15 Jul 2026· 1 change | ||||
| 2026-07-15published 2025-12-01 | GHSA-rcmh-qjqh-p98vCVE-2025-14874 | high | not named as affected when the advisory was published, now names org.webjars.npm:nodemailer | Time to revision 226 days |
| Tue 7 Jul 2026· 1 change | ||||
| 2026-07-07published 2026-05-08 | GHSA-mx76-r943-rf8gCVE-2026-8149 | moderate | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-lts8on | Time to revision 61 days |
| Mon 6 Jul 2026· 15 changes | ||||
| 2026-07-06published 2026-06-18 | GHSA-jc38-x7x8-2xc8 | high | not named as affected when the advisory was published, now names web-token/jwt-bundle and 1 more | Time to revision 18 days |
| 2026-07-06published 2026-06-18 | GHSA-jc38-x7x8-2xc8 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names web-token/jwt-bundle | Time to revision 18 days |
| 2026-07-06published 2026-06-18 | GHSA-jc38-x7x8-2xc8 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names web-token/jwt-experimental | Time to revision 18 days |
| 2026-07-06published 2026-03-19 to 2026-06-26 | 3 bands | not named as affected when the advisory was published, now names scriban.signed | Time to revision 10 to 109 days | |
| 2026-07-06published 2026-06-26 | GHSA-6q7j-xr26-3h2c | same package registry as the line abovemoderate | same change as the line above | Time to revision 10 days |
| 2026-07-06published 2026-03-24 | GHSA-xw6w-9jjh-p9cr | same package registry as the line abovemoderate | same change as the line above | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | GHSA-m2p3-hwv5-xpqw | same package registry as the line abovemoderate | same change as the line above | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | GHSA-xcx6-vp38-8hr5 | same package registry as the line abovehigh | same change as the line above | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | GHSA-v66j-x4hw-fv9g | same package registry as the line abovehigh | same change as the line above | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | GHSA-5wr9-m6jw-xx44 | same package registry as the line abovecritical | same change as the line above | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | GHSA-x6m9-38vm-2xhf | same package registry as the line abovehigh | same change as the line above | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | GHSA-p6q4-fgr8-vx4p | same package registry as the line abovehigh | same change as the line above | Time to revision 104 days |
| 5 more rows in this change are not listed here. Open all 13 rows → | ||||
| Wed 1 Jul 2026· 5 changes | ||||
| 2026-07-01published 2024-11-07 to 2025-08-13 | 2 bands | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | Time to revision 322 to 601 days | |
| 2026-07-01published 2024-11-07 | GHSA-7jqf-v358-p8g7CVE-2024-38286 | same package registry as the line abovehigh | same change as the line above | Time to revision 601 days |
| 2026-07-01published 2025-08-13 | GHSA-23hv-mwm6-g8jfCVE-2025-55668 | same package registry as the line abovemoderate | same change as the line above | Time to revision 322 days |
| 2026-07-01published 2025-07-10 | GHSA-4j3c-42xv-3f84CVE-2025-52434 | same package registry as the line abovemoderate | same change as the line above | Time to revision 356 days |
| 2026-07-01published 2024-11-07 to 2025-07-10 | 2 bands | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 356 to 601 days | |
| 2026-07-01published 2024-11-07 | GHSA-7jqf-v358-p8g7CVE-2024-38286 | same package registry as the line abovehigh | same change as the line above | Time to revision 601 days |
| 2026-07-01published 2025-07-10 | GHSA-4j3c-42xv-3f84CVE-2025-52434 | same package registry as the line abovemoderate | same change as the line above | Time to revision 356 days |
| Mon 29 Jun 2026· 3 changes | ||||
| 2026-06-29published 2026-02-17 | GHSA-qq5r-98hh-rxc9CVE-2026-24733 | low | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 132 days |
| 2026-06-29published 2026-05-19 | GHSA-24c8-4792-22hx | high | not named as affected when the advisory was published, now names scriban.signed | Time to revision 41 days |
| 2026-06-29published 2019-10-11 | GHSA-p979-4mfw-53vgCVE-2019-16869 | high | not named as affected when the advisory was published, now names io.netty:netty | Duration unknown |
| Fri 26 Jun 2026· 2 changes | ||||
| 2026-06-26published 2026-05-29 | GHSA-6x26-5727-rrm9CVE-2026-47268 | moderate | not named as affected when the advisory was published, now names github.com/naiba/nezha | Time to revision 28 days |
| 2026-06-26published 2026-06-10 | GHSA-8h84-fhqq-q58vCVE-2026-48025 | moderate | not named as affected when the advisory was published, now names github.com/forgekeep/nebula-mesh | Time to revision 16 days |
| Thu 18 Jun 2026· 7 changes | ||||
| 2026-06-18published 2024-01-19 | GHSA-f4qf-m5gf-8jm8CVE-2024-21733 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat.experimental:tomcat-embed-programmatic | Time to revision 881 days |
| 2026-06-18published 2026-04-09 | GHSA-x4m4-345f-5h5gCVE-2026-34487 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-tribes | Time to revision 70 days |
| 2026-06-18published 2024-11-18 | GHSA-f632-9449-3j4wCVE-2024-52318 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-jasper | Time to revision 577 days |
| 2026-06-18published 2019-05-30 to 2024-11-18 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat | Time to revision 577 days | |
| 2026-06-18published 2024-11-18 | GHSA-f632-9449-3j4wCVE-2024-52318 | same package registry as the line abovemoderate | same change as the line above | Time to revision 577 days |
| 2026-06-18published 2019-05-30 | GHSA-jjpq-gp5q-8q6wCVE-2019-0221 | same package registry as the line abovemoderate | same change as the line above | Duration unknown |
| 2026-06-18published 2019-05-30 to 2023-02-20 | 2 bands | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina | Time to revision 1,214 days | |
| 2026-06-18published 2023-02-20 | GHSA-hfrx-6qgj-fp6cCVE-2023-24998 | same package registry as the line abovehigh | same change as the line above | Time to revision 1,214 days |
| 2026-06-18published 2019-05-30 | GHSA-jjpq-gp5q-8q6wCVE-2019-0221 | same package registry as the line abovemoderate | same change as the line above | Duration unknown |
| Fri 12 Jun 2026· 4 changes | ||||
| 2026-06-12published 2023-10-10 to 2026-02-17 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 115 to 976 days | |
| 2026-06-12published 2023-10-10 | GHSA-r6j3-px5g-cq3xCVE-2023-45648 | same package registry as the line abovemoderate | same change as the line above | Time to revision 976 days |
| 2026-06-12published 2026-02-17 | GHSA-fpj8-gq4v-p354CVE-2025-66614 | same package registry as the line abovemoderate | same change as the line above | Time to revision 115 days |
| 2026-06-12published 2023-10-10 | GHSA-g8pj-r55q-5c2v | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina and 1 more | Time to revision 976 days |
| 2026-06-12published 2023-10-10 | GHSA-g8pj-r55q-5c2vCVE-2023-42795 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina | Time to revision 976 days |
| 2026-06-12published 2023-10-10 | GHSA-g8pj-r55q-5c2vCVE-2023-42795 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-util | Time to revision 976 days |
| Thu 11 Jun 2026· 4 changes | ||||
| 2026-06-11published 2026-05-07 | GHSA-2mh5-3cw6-hrrqCVE-2026-40981 | high | not named as affected when the advisory was published, now names org.springframework.cloud:spring-cloud-config-server | Time to revision 35 days |
| 2026-06-11published 2022-02-08 | GHSA-m7jv-hq7h-mq7c | high | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocket and 1 more | Duration unknown |
| 2026-06-11published 2022-02-08 | GHSA-m7jv-hq7h-mq7cCVE-2020-13935 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocket | Duration unknown |
| 2026-06-11published 2022-02-08 | GHSA-m7jv-hq7h-mq7cCVE-2020-13935 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-websocket | Duration unknown |
| 2026-06-11published 2022-02-09 | GHSA-53hp-jpwq-2jgqCVE-2020-11996 | high | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | Duration unknown |
| Tue 9 Jun 2026· 1 change | ||||
| 2026-06-09published 2026-06-01 | GHSA-q53q-5r4j-5729CVE-2026-47425 | moderate | not named as affected when the advisory was published, now names py-rattler | Time to revision 8 days |
| Mon 8 Jun 2026· 4 changes | ||||
| 2026-06-08published 2026-05-15 | GHSA-w42g-jj8w-fj77 | high | not named as affected when the advisory was published, now names thorsten/phpmyfaq | Time to revision 24 days |
| 2026-06-08published 2021-04-13 | GHSA-3pcr-4982-548m | moderate | not named as affected when the advisory was published, now names shopware/shopware | Duration unknown |
| 2026-06-08published 2025-10-15 | GHSA-6p6v-m64v-jx8qCVE-2025-55039 | low | not named as affected when the advisory was published, now names pyspark | Time to revision 236 days |
| 2026-06-08published 2026-03-25 | GHSA-7h8w-hj9j-8rjwCVE-2026-33718 | high | not named as affected when the advisory was published, now names openhands-ai | Time to revision 75 days |
| Fri 5 Jun 2026· 4 changes | ||||
| 2026-06-05published 2023-08-25 | GHSA-q3mw-pvr8-9ggcCVE-2023-41080 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina | Time to revision 1,015 days |
| 2026-06-05published 2021-06-16 | GHSA-j39c-c8hj-x4j3CVE-2021-25122 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Duration unknown |
| 2026-06-05published 2026-04-18 | GHSA-w9r4-94fj-xp69CVE-2026-32690 | low | not named as affected when the advisory was published, now names apache-airflow | Time to revision 48 days |
| 2026-06-05published 2025-09-24 | GHSA-776q-jw43-fhjxCVE-2025-48459 | critical | not named as affected when the advisory was published, now names apache-iotdb | Time to revision 254 days |
| Mon 1 Jun 2026· 2 changes | ||||
| 2026-06-01published 2026-05-18 | GHSA-v549-xx3c-6pc8 | moderate | not named as affected when the advisory was published, now names github.com/mattermost/mattermost-server and 1 more | Time to revision 14 days |
| 2026-06-01published 2026-05-18 | GHSA-v549-xx3c-6pc8CVE-2026-3637 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names github.com/mattermost/mattermost-server | Time to revision 14 days |
| 2026-06-01published 2026-05-18 | GHSA-v549-xx3c-6pc8CVE-2026-3637 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names github.com/mattermost/mattermost/server/v8 | Time to revision 14 days |
| Fri 29 May 2026· 1 change | ||||
| 2026-05-29published 2026-04-22 | GHSA-ffq5-qpvf-xq7xCVE-2026-42086 | moderate | not named as affected when the advisory was published, now names openc3 | Time to revision 37 days |
| Wed 20 May 2026· 8 changes | ||||
| 2026-05-20published 2023-06-14 | GHSA-5wfc-hjrc-gq87CVE-2023-34620 | high | not named as affected when the advisory was published, now names github.com/hjson/hjson-go/v4 | Time to revision 1,071 days |
| 2026-05-20published 2023-06-14 | GHSA-5wfc-hjrc-gq87CVE-2023-34620 | high | not named as affected when the advisory was published, now names laktak/hjson | Time to revision 1,071 days |
| 2026-05-20published 2020-06-15 to 2026-04-09 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 41 days | |
| 2026-05-20published 2026-04-09 | GHSA-69cc-cv78-qc8gCVE-2026-29129 | same package registry as the line abovehigh | same change as the line above | Time to revision 41 days |
| 2026-05-20published 2020-06-15 | GHSA-qcxh-w3j9-58qrCVE-2019-0199 | same package registry as the line abovehigh | same change as the line above | Duration unknown |
| 2026-05-20published 2026-04-09 | 2 bands | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote-ffm | Time to revision 40 to 41 days | |
| 2026-05-20published 2026-04-09 | GHSA-95jq-rwvf-vjx4CVE-2026-29145 | same package registry as the line abovecritical | same change as the line above | Time to revision 41 days |
| 2026-05-20published 2026-04-09 | GHSA-24j9-x2wg-9qv6CVE-2026-34500 | same package registry as the line abovemoderate | same change as the line above | Time to revision 40 days |
| 2026-05-20published 2024-12-17 | GHSA-653p-vg55-5652CVE-2024-54677 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat | Time to revision 519 days |
| 2026-05-20published 2026-03-31 | GHSA-rvhj-8chj-8v3cCVE-2026-0596 | critical | not named as affected when the advisory was published, now names mlflow | Time to revision 49 days |
| Thu 14 May 2026· 3 changes | ||||
| 2026-05-14published 2024-12-02 | GHSA-4cx5-89vm-833x | low | not named as affected when the advisory was published, now names org.verapdf:library and 2 more | Time to revision 528 days |
| 2026-05-14published 2024-12-02 | GHSA-4cx5-89vm-833xCVE-2024-52800 | same package registry as the line abovelow | not named as affected when the advisory was published, now names org.verapdf:library | Time to revision 528 days |
| 2026-05-14published 2024-12-02 | GHSA-4cx5-89vm-833xCVE-2024-52800 | same package registry as the line abovelow | not named as affected when the advisory was published, now names org.verapdf:library-arlington | Time to revision 528 days |
| 2026-05-14published 2024-12-02 | GHSA-4cx5-89vm-833xCVE-2024-52800 | same package registry as the line abovelow | not named as affected when the advisory was published, now names org.verapdf:library-jakarta | Time to revision 528 days |
| Thu 7 May 2026· 7 changes | ||||
| 2026-05-07published 2025-07-11 to 2025-08-08 | 2 bands | not named as affected when the advisory was published, now names github.com/pytorch/executorch | Time to revision 273 to 300 days | |
| 2026-05-07published 2025-08-08 | GHSA-hj95-mhgf-jxc4CVE-2025-30404 | same package registry as the line abovecritical | same change as the line above | Time to revision 273 days |
| 2026-05-07published 2025-08-08 | GHSA-xc7w-r669-48pfCVE-2025-54951 | same package registry as the line abovecritical | same change as the line above | Time to revision 273 days |
| 2026-05-07published 2025-08-08 | GHSA-84m3-f99p-cqx5CVE-2025-30405 | same package registry as the line abovecritical | same change as the line above | Time to revision 273 days |
| 2026-05-07published 2025-08-08 | GHSA-9m39-3mf3-xwchCVE-2025-54949 | same package registry as the line abovecritical | same change as the line above | Time to revision 273 days |
| 2026-05-07published 2025-08-08 | GHSA-f9hx-c6jf-3qxmCVE-2025-54950 | same package registry as the line abovecritical | same change as the line above | Time to revision 273 days |
| 2026-05-07published 2025-07-11 | GHSA-h952-963h-rv99CVE-2025-30402 | same package registry as the line abovehigh | same change as the line above | Time to revision 300 days |
| 2026-05-07published 2026-03-16 | GHSA-6jj5-j4j8-8473CVE-2026-28499 | moderate | not named as affected when the advisory was published, now names github.com/vapor/leaf-kit | Time to revision 52 days |
| Wed 6 May 2026· 9 changes | ||||
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | high | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/auth-helpers and 8 more | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/auth-helpers | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/aws-secrets-manager | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/federated-auth | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/iam | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/mysql-driver | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/okta | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/otlp | Time to revision 174 days |
| 2026-05-06published 2025-11-13 | GHSA-7wq2-32h4-9hc9 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/pgx-driver | Time to revision 174 days |
| 1 more row in this change is not listed here. Open all 9 rows → | ||||
| Tue 5 May 2026· 1 change | ||||
| 2026-05-05published 2025-09-03 | GHSA-qww7-89xh-x7m7CVE-2025-55747 | critical | not named as affected when the advisory was published, now names org.xwiki.platform:xwiki-platform-webjars | Time to revision 244 days |
| Tue 28 Apr 2026· 2 changes | ||||
| 2026-04-28published 2022-02-08 to 2026-04-09 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 18 days | |
| 2026-04-28published 2026-04-09 | GHSA-563x-q5rq-57qpCVE-2026-24880 | same package registry as the line abovehigh | same change as the line above | Time to revision 18 days |
| 2026-04-28published 2022-02-08 | GHSA-vf77-8h7g-gghpCVE-2020-13934 | same package registry as the line abovehigh | same change as the line above | Duration unknown |
| Wed 22 Apr 2026· 1 change | ||||
| 2026-04-22published 2026-02-19 | GHSA-4hfh-fch3-5q7pCVE-2026-27120 | moderate | not named as affected when the advisory was published, now names github.com/vapor/leaf-kit | Time to revision 62 days |
| Fri 17 Apr 2026· 2 changes | ||||
| 2026-04-17published 2022-05-14 | GHSA-6r5v-hp32-fjqwCVE-2015-0227 | moderate | not named as affected when the advisory was published, now names wss4j:wss4j | Duration unknown |
| 2026-04-17published 2024-05-03 | GHSA-4h8f-2wvx-gg5wCVE-2024-34447 | moderate | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | Time to revision 714 days |
| Thu 16 Apr 2026· 4 changes | ||||
| 2026-04-16published 2022-04-22 | GHSA-4qqf-hmv6-r6whCVE-2011-2487 | moderate | not named as affected when the advisory was published, now names wss4j:wss4j | Duration unknown |
| 2026-04-16published 2025-07-21 | GHSA-9342-92gg-6v29CVE-2025-7962 | moderate | not named as affected when the advisory was published, now names com.sun.mail:jakarta.mail | Time to revision 269 days |
| 2026-04-16published 2024-10-04 | GHSA-wwcp-26wc-3fxmCVE-2024-47855 | moderate | not named as affected when the advisory was published, now names net.sf.json-lib:json-lib | Time to revision 560 days |
| 2026-04-16published 2022-05-13 | GHSA-jwwr-fjgh-cv2xCVE-2014-3004 | moderate | not named as affected when the advisory was published, now names castor:castor | Duration unknown |
| Wed 15 Apr 2026· 3 changes | ||||
| 2026-04-15published 2026-04-09 | GHSA-8mc5-53m5-3qj2CVE-2026-32990 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 6 days |
| 2026-04-15published 2026-04-09 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-tribes | Time to revision 6 days | |
| 2026-04-15published 2026-04-09 | GHSA-69r9-qgr7-g2wjCVE-2026-34486 | same package registry as the line abovehigh | same change as the line above | Time to revision 6 days |
| 2026-04-15published 2026-04-09 | GHSA-h468-7pvh-8vr8CVE-2026-29146 | same package registry as the line abovehigh | same change as the line above | Time to revision 6 days |
| Fri 10 Apr 2026· 1 change | ||||
| 2026-04-10published 2026-03-11 | GHSA-fvcw-9w9r-pxc7CVE-2026-31829 | high | not named as affected when the advisory was published, now names flowise-components | Time to revision 31 days |
| Wed 8 Apr 2026· 1 change | ||||
| 2026-04-08published 2026-03-20 | GHSA-687q-32c6-8x68CVE-2026-33478 | critical | not named as affected when the advisory was published, now names wwbn/avideo | Time to revision 19 days |
| Mon 6 Apr 2026· 1 change | ||||
| 2026-04-06published 2026-03-30 | GHSA-jjwv-57xh-xr6rCVE-2026-27018 | high | not named as affected when the advisory was published, now names github.com/gotenberg/gotenberg/v7 | Time to revision 7 days |
| Fri 27 Mar 2026· 6 changes | ||||
| 2026-03-27published 2026-03-13 | GHSA-q926-c743-49qj | low | not named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v3 and 2 more | Time to revision 14 days |
| 2026-03-27published 2026-03-13 | GHSA-q926-c743-49qj | same package registry as the line abovelow | not named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v3 | Time to revision 14 days |
| 2026-03-27published 2026-03-13 | GHSA-q926-c743-49qj | same package registry as the line abovelow | not named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v4 | Time to revision 14 days |
| 2026-03-27published 2026-03-13 | GHSA-q926-c743-49qj | same package registry as the line abovelow | not named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v5 | Time to revision 14 days |
| 2026-03-27published 2026-03-13 | GHSA-j77h-rr39-c552 | critical | not named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v3 and 2 more | Time to revision 14 days |
| 2026-03-27published 2026-03-13 | GHSA-j77h-rr39-c552CVE-2026-32301 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v3 | Time to revision 14 days |
| 2026-03-27published 2026-03-13 | GHSA-j77h-rr39-c552CVE-2026-32301 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v4 | Time to revision 14 days |
| 2026-03-27published 2026-03-13 | GHSA-j77h-rr39-c552CVE-2026-32301 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v5 | Time to revision 14 days |
| Fri 13 Mar 2026· 1 change | ||||
| 2026-03-13published 2026-03-11 | GHSA-8q2w-wr49-whqjCVE-2026-29777 | moderate | not named as affected when the advisory was published, now names github.com/traefik/traefik/v2 | Time to revision 2 days |
| Thu 12 Mar 2026· 2 changes | ||||
| 2026-03-12published 2026-03-10 | GHSA-hhfx-wfvq-7g9cCVE-2026-26118 | high | not named as affected when the advisory was published, now names @azure/mcp | Time to revision 2 days |
| 2026-03-12published 2026-03-10 | GHSA-hhfx-wfvq-7g9cCVE-2026-26118 | high | not named as affected when the advisory was published, now names msmcp-azure | Time to revision 2 days |
| Fri 6 Mar 2026· 2 changes | ||||
| 2026-03-06published 2025-07-10 | high | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | Time to revision 239 days | |
| 2026-03-06published 2025-07-10 | GHSA-wr62-c79q-cv37CVE-2025-52520 | same package registry as the line abovehigh | same change as the line above | Time to revision 239 days |
| 2026-03-06published 2025-07-10 | GHSA-25xr-qj8w-c4vfCVE-2025-53506 | same package registry as the line abovehigh | same change as the line above | Time to revision 239 days |
| Tue 24 Feb 2026· 1 change | ||||
| 2026-02-24published 2025-03-20 | GHSA-j3wr-m6xh-64hgCVE-2024-12704 | high | not named as affected when the advisory was published, now names llama-index-core | Time to revision 341 days |
| Thu 19 Feb 2026· 2 changes | ||||
| 2026-02-19published 2026-02-13 | GHSA-rp46-r563-jrc7CVE-2025-33042 | moderate | not named as affected when the advisory was published, now names org.apache.avro:avro-compiler | Time to revision 6 days |
| 2026-02-19published 2025-10-16 | GHSA-fwxx-wv44-7qfgCVE-2025-41253 | high | not named as affected when the advisory was published, now names org.springframework.cloud:spring-cloud-gateway-server | Time to revision 126 days |
| Tue 17 Feb 2026· 2 changes | ||||
| 2026-02-17published 2025-12-04 | GHSA-2cgv-28vr-rv6j | high | not named as affected when the advisory was published, now names libcrux-ml-dsa and 1 more | Time to revision 75 days |
| 2026-02-17published 2025-12-04 | GHSA-2cgv-28vr-rv6j | same package registry as the line abovehigh | not named as affected when the advisory was published, now names libcrux-ml-dsa | Time to revision 75 days |
| 2026-02-17published 2025-12-04 | GHSA-2cgv-28vr-rv6j | same package registry as the line abovehigh | not named as affected when the advisory was published, now names libcrux-ml-kem | Time to revision 75 days |
| Mon 2 Feb 2026· 2 changes | ||||
| 2026-02-02published 2024-03-15 | GHSA-qmgx-j96g-4428CVE-2024-28752 | critical | not named as affected when the advisory was published, now names org.apache.cxf:cxf-rt-databinding-aegis | Time to revision 689 days |
| 2026-02-02published 2025-12-12 | GHSA-vx9q-rhv9-3jvgCVE-2025-67721 | high | not named as affected when the advisory was published, now names io.airlift:aircompressor | Time to revision 52 days |
| Wed 21 Jan 2026· 1 change | ||||
| 2026-01-21published 2025-05-07 | GHSA-72qj-48g4-5xgxCVE-2025-46551 | moderate | not named as affected when the advisory was published, now names jruby-openssl | Time to revision 259 days |
| Fri 16 Jan 2026· 1 change | ||||
| 2026-01-16published 2025-10-21 | GHSA-j5gw-2vrg-8fgxCVE-2025-62518 | high | not named as affected when the advisory was published, now names tokio-tar | Time to revision 87 days |
| Tue 6 Jan 2026· 2 changes | ||||
| 2026-01-06published 2025-12-31 | GHSA-mrfv-m5wm-5w6w | moderate | not named as affected when the advisory was published, now names hdwallet and 1 more | Time to revision 7 days |
| 2026-01-06published 2025-12-31 | GHSA-mrfv-m5wm-5w6wCVE-2025-69277 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names hdwallet | Time to revision 7 days |
| 2026-01-06published 2025-12-31 | GHSA-mrfv-m5wm-5w6wCVE-2025-69277 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names pynacl | Time to revision 7 days |
| Mon 5 Jan 2026· 1 change | ||||
| 2026-01-05published 2026-01-02 | GHSA-c5cp-vx83-jhqxCVE-2026-21445 | high | not named as affected when the advisory was published, now names langflow | Time to revision 2 days |
| Mon 22 Dec 2025· 1 change | ||||
| 2025-12-22published 2022-01-06 | GHSA-x8rq-rc7x-5fg5CVE-2022-0086 | high | not named as affected when the advisory was published, now names @uppy/companion | Duration unknown |
| Thu 18 Dec 2025· 5 changes | ||||
| 2025-12-18published 2022-11-01 | GHSA-43xg-8wmj-cw8h | moderate | not named as affected when the advisory was published, now names org.apache.spark:spark-core_2.10 and 4 more | Duration unknown |
| 2025-12-18published 2022-11-01 | GHSA-43xg-8wmj-cw8hCVE-2022-31777 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.spark:spark-core_2.10 | Duration unknown |
| 2025-12-18published 2022-11-01 | GHSA-43xg-8wmj-cw8hCVE-2022-31777 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.spark:spark-core_2.11 | Duration unknown |
| 2025-12-18published 2022-11-01 | GHSA-43xg-8wmj-cw8hCVE-2022-31777 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.spark:spark-core_2.12 | Duration unknown |
| 2025-12-18published 2022-11-01 | GHSA-43xg-8wmj-cw8hCVE-2022-31777 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.spark:spark-core_2.13 | Duration unknown |
| 2025-12-18published 2022-11-01 | GHSA-43xg-8wmj-cw8hCVE-2022-31777 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.spark:spark-core_2.9.3 | Duration unknown |
| Tue 16 Dec 2025· 18 changes | ||||
| 2025-12-16published 2022-01-06 | GHSA-vc89-hccf-rq55 | moderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_0.25 and 17 more | Duration unknown |
| 2025-12-16published 2022-01-06 | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_0.25 | Duration unknown |
| 2025-12-16published 2022-01-06 | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_0.27 | Duration unknown |
| 2025-12-16published 2022-01-06 | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.10 | Duration unknown |
| 2025-12-16published 2022-01-06 | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.11 | Duration unknown |
| 2025-12-16published 2022-01-06 | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.12 | Duration unknown |
| 2025-12-16published 2022-01-06 | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.13 | Duration unknown |
| 2025-12-16published 2022-01-06 | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.13.0-m5 | Duration unknown |
| 2025-12-16published 2022-01-06 | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.13.0-rc1 | Duration unknown |
| 10 more rows in this change are not listed here. Open all 18 rows → | ||||
| Thu 11 Dec 2025· 32 changes | ||||
| 2025-12-11published 2021-09-02 to 2025-06-10 | 32 rows, one per advisory and package | 2 bands | not named as affected when the advisory was published, now names org.http4s:http4s-server_2.10 and 22 more | Time to revision 185 to 1,070 days |
| 2025-12-11published 2021-09-02 | GHSA-52cf-226f-rhr6CVE-2021-39185 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.http4s:http4s-server_2.10 | Duration unknown |
| 2025-12-11published 2021-09-02 | GHSA-52cf-226f-rhr6CVE-2021-39185 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.http4s:http4s-server_2.11 | Duration unknown |
| 2025-12-11published 2021-09-02 | GHSA-52cf-226f-rhr6CVE-2021-39185 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.http4s:http4s-server_2.12 | Duration unknown |
| 2025-12-11published 2021-09-02 | GHSA-52cf-226f-rhr6CVE-2021-39185 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.http4s:http4s-server_2.13 | Duration unknown |
| 2025-12-11published 2021-09-02 | GHSA-52cf-226f-rhr6CVE-2021-39185 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.http4s:http4s-server_2.13.0-m5 | Duration unknown |
| 2025-12-11published 2021-09-02 | GHSA-52cf-226f-rhr6CVE-2021-39185 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.http4s:http4s-server_3 | Duration unknown |
| 2025-12-11published 2021-09-22 | GHSA-5vcm-3xc3-w7x3CVE-2021-41084 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.http4s:http4s-client_2.12 | Duration unknown |
| 2025-12-11published 2021-09-22 | GHSA-5vcm-3xc3-w7x3CVE-2021-41084 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.http4s:http4s-client_2.13 | Duration unknown |
| 24 more rows in this change are not listed here. Open all 32 rows → | ||||
| Thu 4 Dec 2025· 1 change | ||||
| 2025-12-04published 2022-05-17 | GHSA-wwq7-pxwc-p4rcCVE-2012-5785 | moderate | not named as affected when the advisory was published, now names org.apache.axis2:axis2-transport-http | Duration unknown |
| Tue 18 Nov 2025· 1 change | ||||
| 2025-11-18published 2025-11-13 | GHSA-3g2j-vm47-x4mj | high | not named as affected when the advisory was published, now names github.com/canonical/lxd | Time to revision 5 days |
| Mon 17 Nov 2025· 4 changes | ||||
| 2025-11-17published 2025-11-06 | moderate | not named as affected when the advisory was published, now names kubevirt.io/kubevirt | Time to revision 11 days | |
| 2025-11-17published 2025-11-06 | GHSA-7xgm-5prm-v5gcCVE-2025-64436 | same package registry as the line abovemoderate | same change as the line above | Time to revision 11 days |
| 2025-11-17published 2025-11-06 | GHSA-9m94-w2vq-hcf9CVE-2025-64435 | same package registry as the line abovemoderate | same change as the line above | Time to revision 11 days |
| 2025-11-17published 2025-11-06 | GHSA-2r4r-5x78-mvqfCVE-2025-64437 | same package registry as the line abovemoderate | same change as the line above | Time to revision 11 days |
| 2025-11-17published 2025-11-06 | GHSA-qw6q-3pgr-5cwqCVE-2025-64433 | same package registry as the line abovemoderate | same change as the line above | Time to revision 11 days |
| Sat 15 Nov 2025· 1 change | ||||
| 2025-11-15published 2025-11-07 | GHSA-46xp-26xh-hpqhCVE-2025-64324 | high | not named as affected when the advisory was published, now names kubevirt.io/kubevirt | Time to revision 7 days |
| Thu 13 Nov 2025· 2 changes | ||||
| 2025-11-13published 2025-11-03 | GHSA-399j-vxmf-hjvrCVE-2025-11953 | critical | not named as affected when the advisory was published, now names @react-native-community/cli-server-api | Time to revision 10 days |
| 2025-11-13published 2025-07-30 | GHSA-cx25-xg7c-xfm5CVE-2025-54656 | moderate | not named as affected when the advisory was published, now names struts:struts | Time to revision 106 days |
| Fri 7 Nov 2025· 1 change | ||||
| 2025-11-07published 2025-10-31 | GHSA-2qfp-q593-8484CVE-2025-6176 | high | not named as affected when the advisory was published, now names scrapy | Time to revision 8 days |
| Tue 4 Nov 2025· 2 changes | ||||
| 2025-11-04published 2023-12-01 | GHSA-qw4h-3xjj-84cc | high | not named as affected when the advisory was published, now names org.apache.struts:struts-tiles and 1 more | Time to revision 705 days |
| 2025-11-04published 2023-12-01 | GHSA-qw4h-3xjj-84ccCVE-2023-49735 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.apache.struts:struts-tiles | Time to revision 705 days |
| 2025-11-04published 2023-12-01 | GHSA-qw4h-3xjj-84ccCVE-2023-49735 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names struts:struts | Time to revision 705 days |
| Thu 30 Oct 2025· 1 change | ||||
| 2025-10-30published 2025-10-21 | GHSA-qqj3-g7mx-5p4wCVE-2025-54470 | high | not named as affected when the advisory was published, now names github.com/neuvector/neuvector | Time to revision 9 days |
| Wed 29 Oct 2025· 1 change | ||||
| 2025-10-29published 2025-08-20 | GHSA-p72g-pv48-7w9xCVE-2025-54988 | critical | not named as affected when the advisory was published, now names org.apache.tika:tika-parsers | Time to revision 70 days |
| Mon 20 Oct 2025· 1 change | ||||
| 2025-10-20published 2021-04-13 | GHSA-r96p-v3cr-gfv8CVE-2020-28470 | high | not named as affected when the advisory was published, now names @scullyio/ng-lib | Duration unknown |
| Wed 15 Oct 2025· 1 change | ||||
| 2025-10-15published 2025-05-21 | GHSA-9pp5-9c7g-4r83CVE-2025-41232 | critical | not named as affected when the advisory was published, now names org.springframework.security:spring-security-core | Time to revision 147 days |
Counted in advisories, never added to the CVE and KEV figures. This kind is counted once per advisory and per package, so one advisory that named four further packages counts four times. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.
What this page cannot see
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →
Paste your closed CVE tickets and see which of these changes hit them →