Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Thu 27 Jun 2024· 2 advisory changes
2024-06-27published 2022-02-10Package added to advisoryGHSA-8grg-q944-cch5CVE-2019-14900moderatenot named as affected when the advisory was published, now names org.hibernate:hibernate-corenot dated
2024-06-27published 2023-11-28Package added to advisoryGHSA-jjfh-589g-3hjxCVE-2023-34055moderatenot named as affected when the advisory was published, now names org.springframework.boot:spring-boot-actuatorDays to revision 212
Mon 24 Jun 2024· 1 advisory change
2024-06-24published 2022-12-22Advisory severity changedGHSA-8cf7-32gw-wr33CVE-2022-23539whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 551
Fri 21 Jun 2024· 1 advisory change
2024-06-21published 2024-06-18Advisory withdrawnGHSA-gmrm-8fx4-66x7whole advisorylowwithdrawn 2024-06-21Days to revision 3
Thu 20 Jun 2024· 1 advisory change
2024-06-20published 2024-06-07Advisory withdrawnGHSA-cr7j-rwmv-vgchCVE-2024-36811whole advisoryhighwithdrawn 2024-06-20Days to revision 13
Tue 18 Jun 2024· 1 advisory change
2024-06-18published 2024-02-27Advisory withdrawnGHSA-xxf8-fpmr-fw7vCVE-2024-25400whole advisorymoderatewithdrawn 2024-06-18Days to revision 112
Fri 14 Jun 2024· 1 advisory change
2024-06-14published 2024-06-06Package added to advisoryGHSA-3hjh-jh2h-vrg6CVE-2024-2965moderatenot named as affected when the advisory was published, now names langchain-communityDays to revision 8
Tue 11 Jun 2024· 1 advisory change
2024-06-11published 2024-06-05Advisory severity changedGHSA-q5mg-pc7r-r8crCVE-2024-5262whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
Mon 10 Jun 2024· 1 advisory change
2024-06-10published 2024-03-05Package added to advisoryGHSA-m4pq-fv2w-6hrwCVE-2024-27936highnot named as affected when the advisory was published, now names denoDays to revision 97
Thu 6 Jun 2024· 1 advisory change
2024-06-06published 2024-06-06Advisory severity changedGHSA-xgr7-jgq3-mhmcCVE-2024-37153whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 0
Wed 5 Jun 2024· 3 advisory changes
2024-06-05published 2020-06-10Advisory fix version movedGHSA-p66x-2cv9-qq3vCVE-2014-0114
mavencommons-beanutils:commons-beanutils
high
stated at publication 1.9.2, now states 1.9.4not dated
2024-06-05published 2024-06-05Advisory severity changedGHSA-c74f-6mfw-mm4vCVE-2024-36129whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 0
2024-06-05published 2024-04-06Advisory withdrawnGHSA-cr6f-gf5w-vhrcwhole advisorymoderatewithdrawn 2024-06-05Days to revision 60
Tue 4 Jun 2024· 2 advisory changes
2024-06-04published 2024-06-03Package added to advisoryGHSA-4w54-wwc9-x62cCVE-2024-36042criticalnot named as affected when the advisory was published, now names org.silverpeas.core:silverpeas-coreDays to revision 2
2024-06-04published 2022-02-10Advisory withdrawnGHSA-6hr9-4692-fch9CVE-2020-7624whole advisorycriticalwithdrawn 2024-06-04Days to revision 845
Mon 3 Jun 2024· 2 advisory changes
2024-06-03published 2024-05-07Package added to advisoryGHSA-qjqp-xr96-cj99CVE-2024-34341moderatenot named as affected when the advisory was published, now names actiontextDays to revision 27
2024-06-03published 2024-05-31Package added to advisoryGHSA-8hqg-whrw-pv92CVE-2024-37032moderatenot named as affected when the advisory was published, now names github.com/ollama/ollamaDays to revision 3
Fri 31 May 2024· 3 advisory changes
2024-05-31published 2022-05-13Package added to advisorymoderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins:kmap-jenkinsDays to revision 750
2024-05-31published 2022-05-13same kind of change as the line aboveGHSA-fvcf-wgxj-h7chCVE-2019-10292same package registry as the line abovemoderatesame change as the line aboveDays to revision 750
2024-05-31published 2022-05-13same kind of change as the line aboveGHSA-q5wm-qgxj-h9phCVE-2019-10293same package registry as the line abovemoderatesame change as the line aboveDays to revision 750
2024-05-31published 2024-03-07Package added to advisoryGHSA-c5q2-7r4c-mv6gCVE-2024-28180moderatenot named as affected when the advisory was published, now names gopkg.in/square/go-jose.v2Days to revision 85
Thu 30 May 2024· 5 advisory changes
2024-05-30published 2022-05-24Package added to advisoryGHSA-922h-x9qv-2274CVE-2019-10374moderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins:pegdown-formatterDays to revision 737
2024-05-30published 2022-05-24Package added to advisoryGHSA-g6h2-4x64-c59xCVE-2019-10337highnot named as affected when the advisory was published, now names org.jenkins-ci.plugins:token-macronot dated
2024-05-30published 2023-11-29Package added to advisorymoderatenot named as affected when the advisory was published, now names io.jenkins.plugins:neuvector-vulnerability-scannerDays to revision 183
2024-05-30published 2023-11-29same kind of change as the line aboveGHSA-ph87-4x2g-6hp4CVE-2023-49674same package registry as the line abovemoderatesame change as the line aboveDays to revision 183
2024-05-30published 2023-11-29same kind of change as the line aboveGHSA-wpfc-r5qq-7r7pCVE-2023-49673same package registry as the line abovemoderatesame change as the line aboveDays to revision 183
2024-05-30published 2024-05-30Package added to advisoryGHSA-vfm6-r2gc-pwwwmoderatenot named as affected when the advisory was published, now names symfony/symfonyDays to revision 0
Fri 24 May 2024· 1 advisory change
2024-05-24published 2021-01-06Advisory severity changedGHSA-395w-qhqr-9fr6CVE-2020-17519whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
Thu 23 May 2024· 3 advisory changes
2024-05-23published 2022-07-13Package added to advisoryGHSA-64x4-9hc6-r2h6CVE-2022-30187moderatenot named as affected when the advisory was published, now names com.azure:azure-storage-blobnot dated
2024-05-23published 2022-07-13Package added to advisoryGHSA-64x4-9hc6-r2h6moderatenot named as affected when the advisory was published, now names azure-storage-blob and 1 morenot dated
2024-05-23published 2022-07-13same kind of change as the line aboveGHSA-64x4-9hc6-r2h6CVE-2022-30187same package registry as the line abovemoderatenot named as affected when the advisory was published, now names azure-storage-blobnot dated
2024-05-23published 2022-07-13same kind of change as the line aboveGHSA-64x4-9hc6-r2h6CVE-2022-30187same package registry as the line abovemoderatenot named as affected when the advisory was published, now names azure-storage-queuenot dated
Tue 21 May 2024· 3 advisory changes
2024-05-21published 2024-05-14Package added to advisoryGHSA-jj54-5q2m-q7pjCVE-2021-32026lownot named as affected when the advisory was published, now names github.com/nats-io/nats-server/v2Days to revision 7
2024-05-21published 2022-02-15 to 2024-03-21Advisory withdrawnwhole advisory2 bandswithdrawn 2024-05-21Days to revision 61 to 827
2024-05-21published 2024-03-21same kind of change as the line aboveGHSA-3x9g-xfj5-fq84same package and registry as the line abovemoderatewithdrawn 2024-05-21Days to revision 61
2024-05-21published 2022-02-15same kind of change as the line aboveGHSA-9r5x-fjv3-q6h4same package and registry as the line abovehighwithdrawn 2024-05-21Days to revision 827
Mon 20 May 2024· 7 advisory changes
2024-05-20published 2022-05-14Package added to advisoryGHSA-927h-x4qj-r242CVE-2018-20744moderatenot named as affected when the advisory was published, now names github.com/rs/corsDays to revision 738
2024-05-20published 2024-02-23Package added to advisoryGHSA-rc6h-qwj9-2c53CVE-2024-23320highnot named as affected when the advisory was published, now names org.apache.dolphinscheduler:dolphinscheduler-masterDays to revision 87
2024-05-20published 2024-05-18Package added to advisoryGHSA-9328-gcfq-p269CVE-2024-35312highnot named as affected when the advisory was published, now names tor-circmgrDays to revision 3
2024-05-20published 2021-06-23 to 2024-05-16Advisory withdrawnwhole advisory2 bandswithdrawn 2024-05-20Days to revision 4 to 1,062
2024-05-20published 2021-06-23same kind of change as the line aboveGHSA-7jr6-prv4-5wf5same package and registry as the line abovemoderatewithdrawn 2024-05-20Days to revision 1,062
2024-05-20published 2022-02-12same kind of change as the line aboveGHSA-m658-p24x-p74rsame package and registry as the line abovemoderatewithdrawn 2024-05-20Days to revision 829
2024-05-20published 2024-05-16same kind of change as the line aboveGHSA-cqh9-jfqr-h9jjCVE-2024-4642same package and registry as the line abovehighwithdrawn 2024-05-20Days to revision 4
2024-05-20published 2021-06-23same kind of change as the line aboveGHSA-gq5r-cc4w-g8xfsame package and registry as the line abovehighwithdrawn 2024-05-20Days to revision 1,062
Fri 17 May 2024· 1 advisory change
2024-05-17published 2022-05-17Advisory withdrawnGHSA-cr9c-rhq6-vh53CVE-2022-29351whole advisorycriticalwithdrawn 2024-05-17Days to revision 732
Thu 16 May 2024· 1 advisory change
2024-05-16published 2024-05-14Advisory withdrawnGHSA-r3w4-36x6-7r99whole advisorylowwithdrawn 2024-05-16Days to revision 2
Wed 15 May 2024· 4 advisory changes
2024-05-15published 2021-12-01Advisory fix version movedGHSA-945q-ch46-pchgCVE-2021-22095
mavenorg.springframework.amqp:spring-amqp
moderate
stated at publication 2.2.19, now states 2.2.20not dated
2024-05-15published 2022-05-13Advisory fix version movedGHSA-xphj-m9cc-8fmqCVE-2016-6814
mavenorg.codehaus.groovy:groovy
critical
stated at publication 2.4.4, now states 2.4.8not dated
2024-05-15published 2019-12-05Advisory severity changedGHSA-24r8-fm9r-cpj2CVE-2019-16771whole advisorymoderatestated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
2024-05-15published 2023-06-26Advisory withdrawnGHSA-257q-pv89-v3xvCVE-2020-23064whole advisorymoderatewithdrawn 2024-05-15Days to revision 324
Tue 14 May 2024· 3 advisory changes
2024-05-14published 2024-02-03Package added to advisoryGHSA-mf74-qq7w-6j7vmoderatenot named as affected when the advisory was published, now names remark-images-downloadDays to revision 102
2024-05-14published 2024-01-31Package added to advisoryGHSA-3fwx-pjgw-3558CVE-2021-41091moderatenot named as affected when the advisory was published, now names github.com/docker/dockerDays to revision 104
2024-05-14published 2023-07-05Advisory withdrawnGHSA-9jx5-6pgf-crrpCVE-2023-25399whole advisorymoderatewithdrawn 2024-05-14Days to revision 314
Fri 10 May 2024· 3 advisory changes
2024-05-10published 2024-05-08Package added to advisoryGHSA-649x-hxfx-57j2CVE-2024-32886moderatenot named as affected when the advisory was published, now names vitess.io/vitessDays to revision 2
2024-05-10published 2022-05-13Package added to advisoryGHSA-cw54-59pw-4g8cCVE-2016-8735criticalnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina-jmx-remoteDays to revision 729
2024-05-10published 2024-04-22Advisory withdrawnGHSA-mw82-6m2g-qh6cwhole advisorymoderatewithdrawn 2024-05-10Days to revision 18
Tue 7 May 2024· 1 advisory change
2024-05-07published 2023-06-22Advisory withdrawnGHSA-w44m-8mv2-v78hwhole advisorymoderatewithdrawn 2024-05-07Days to revision 320
Mon 6 May 2024· 1 advisory change
2024-05-06published 2022-07-23Advisory withdrawnGHSA-m7gr-5w5g-36jfCVE-2022-34037whole advisoryhighwithdrawn 2024-05-06Days to revision 654
Fri 3 May 2024· 3 advisory changes
2024-05-03published 2024-02-28Advisory severity changedGHSA-22f2-v57c-j9cxCVE-2024-25126whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 65
2024-05-03published 2022-05-25 to 2023-07-06Advisory withdrawnwhole advisory2 bandswithdrawn 2024-05-03Days to revision 302 to 710
2024-05-03published 2022-05-25same kind of change as the line aboveGHSA-c9gm-7rfj-8w5hCVE-2021-42248same package and registry as the line abovehighwithdrawn 2024-05-03Days to revision 710
2024-05-03published 2023-07-06same kind of change as the line aboveGHSA-jrfm-2h82-xg28CVE-2023-29824same package and registry as the line abovecriticalwithdrawn 2024-05-03Days to revision 302
Tue 30 Apr 2024· 2 advisory changes
2024-04-30published 2022-05-14Package added to advisoryGHSA-9848-v244-962pCVE-2012-1007moderatenot named as affected when the advisory was published, now names org.apache.struts:struts-corenot dated
2024-04-30published 2024-04-26Advisory withdrawnGHSA-c5pj-mqfh-rvc3whole advisoryhighwithdrawn 2024-04-30Days to revision 4
Thu 25 Apr 2024· 4 advisory changes
2024-04-25published 2024-04-24Package added to advisoryGHSA-33c5-9fx5-fvjmCVE-2020-8559moderatenot named as affected when the advisory was published, now names k8s.io/kubernetesDays to revision 1
2024-04-25published 2024-04-17Advisory severity changedGHSA-j628-q885-8gr5CVE-2023-6484whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 8
2024-04-25published 2024-04-17Advisory severity changedGHSA-8rmm-gm28-pj8qCVE-2023-6717whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 8
2024-04-25published 2022-05-17Advisory withdrawnGHSA-8cp3-66vr-3r4cCVE-2022-29622whole advisorycriticalwithdrawn 2024-04-25Days to revision 710
Wed 24 Apr 2024· 4 advisory changes
2024-04-24published 2023-06-21 to 2023-07-06Package added to advisory4 rows, one per advisory and packagehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core and 1 moreDays to revision 293 to 308
2024-04-24published 2023-06-21same kind of change as the line aboveGHSA-mppv-79ch-vw6qCVE-2023-34981same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDays to revision 308
2024-04-24published 2023-06-21same kind of change as the line aboveGHSA-mppv-79ch-vw6qCVE-2023-34981same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 308
2024-04-24published 2023-07-06same kind of change as the line aboveGHSA-cx6h-86xw-9x34CVE-2023-28709same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDays to revision 293
2024-04-24published 2023-07-06same kind of change as the line aboveGHSA-cx6h-86xw-9x34CVE-2023-28709same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 293
Tue 23 Apr 2024· 8 advisory changes
2024-04-23published 2022-11-01 to 2024-01-19Package added to advisory7 rows, one per advisory and package2 bandsnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core and 3 moreDays to revision 95 to 476
2024-04-23published 2024-01-19same kind of change as the line aboveGHSA-f4qf-m5gf-8jm8CVE-2024-21733same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDays to revision 95
2024-04-23published 2024-01-19same kind of change as the line aboveGHSA-f4qf-m5gf-8jm8CVE-2024-21733same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 95
2024-04-23published 2023-01-03same kind of change as the line aboveGHSA-rq2w-37h9-vg94CVE-2022-45143same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDays to revision 476
2024-04-23published 2023-01-03same kind of change as the line aboveGHSA-rq2w-37h9-vg94CVE-2022-45143same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaDays to revision 476
2024-04-23published 2023-01-03same kind of change as the line aboveGHSA-rq2w-37h9-vg94CVE-2022-45143same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-utilDays to revision 476
2024-04-23published 2022-11-01same kind of change as the line aboveGHSA-p22x-g9px-3945CVE-2022-42252same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-corenot dated
2024-04-23published 2022-11-01same kind of change as the line aboveGHSA-p22x-g9px-3945CVE-2022-42252same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyotenot dated
2024-04-23published 2022-06-03Advisory severity changedGHSA-52vj-mr2j-f8jhCVE-2020-28246whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
Mon 22 Apr 2024· 9 advisory changes
2024-04-22published 2022-02-09Package added to advisoryGHSA-484q-784p-8m5hmoderatenot named as affected when the advisory was published, now names org.keycloak:keycloak-server-spi-private and 1 morenot dated
2024-04-22published 2022-02-09same kind of change as the line aboveGHSA-484q-784p-8m5hCVE-2020-10776same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.keycloak:keycloak-server-spi-privatenot dated
2024-04-22published 2022-02-09same kind of change as the line aboveGHSA-484q-784p-8m5hCVE-2020-10776same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.keycloak:keycloak-servicesnot dated
2024-04-22published 2024-01-31Package added to advisoryGHSA-6hwg-w5jg-9c6xCVE-2020-27534moderatenot named as affected when the advisory was published, now names github.com/docker/dockerDays to revision 82
2024-04-22published 2022-05-24Package added to advisoryGHSA-hf4p-4j9r-3cvxCVE-2019-16355moderatenot named as affected when the advisory was published, now names github.com/astaxie/beegoDays to revision 699
2024-04-22published 2018-07-26Advisory severity changedGHSA-fvqr-27wr-82fmCVE-2018-3721whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2024-04-22published 2022-02-09Advisory severity changedGHSA-rvfc-g8j5-9ccfCVE-2020-1717whole advisorylowstated at publication MODERATE, now states LOWThe severity label changed while the stated CVSS vectors stayed the same.not dated
2024-04-22published 2018-07-24Advisory severity changedGHSA-333w-rxj3-f55rCVE-2017-16021whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2024-04-22published 2024-02-03Advisory severity changedGHSA-f56g-chqp-22m9CVE-2018-25001whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 80
2024-04-22published 2022-10-18Advisory severity changedGHSA-c6w8-7mp3-34j9CVE-2022-24512whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
Fri 19 Apr 2024· 1 advisory change
2024-04-19published 2018-07-18Advisory withdrawnGHSA-85fq-56wq-gmcfCVE-2017-16046whole advisoryhighwithdrawn 2024-04-19Days to revision 2,102
Thu 18 Apr 2024· 9 advisory changes
2024-04-18published 2022-05-13 to 2023-02-20Package added to advisory9 rows, one per advisory and package2 bandsnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core and 5 moreDays to revision 423
2024-04-18published 2023-02-20same kind of change as the line aboveGHSA-hfrx-6qgj-fp6cCVE-2023-24998same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDays to revision 423
2024-04-18published 2023-02-20same kind of change as the line aboveGHSA-hfrx-6qgj-fp6cCVE-2023-24998same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 423
2024-04-18published 2022-05-13same kind of change as the line aboveGHSA-9hg2-395j-83rmCVE-2017-5651same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-corenot dated
2024-04-18published 2022-05-13same kind of change as the line aboveGHSA-9hg2-395j-83rmCVE-2017-5651same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyotenot dated
2024-04-18published 2022-05-13same kind of change as the line aboveGHSA-3vx3-xf6q-r5xpCVE-2017-5648same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-corenot dated
2024-04-18published 2022-05-13same kind of change as the line aboveGHSA-3vx3-xf6q-r5xpCVE-2017-5648same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinanot dated
2024-04-18published 2022-05-13same kind of change as the line aboveGHSA-4v3g-g84w-hv7rCVE-2016-5018same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-jaspernot dated
2024-04-18published 2022-05-13same kind of change as the line aboveGHSA-4v3g-g84w-hv7rCVE-2016-5018same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.tomcat:jaspernot dated
1 more row in this change is not listed here. Open all 9 rows
Wed 17 Apr 2024· 6 advisory changes
2024-04-17published 2022-05-13Package added to advisoryGHSA-cw54-59pw-4g8cCVE-2016-8735criticalnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaDays to revision 706
2024-04-17published 2021-05-06Package added to advisoryGHSA-35jh-r3h4-6jhmhighnot named as affected when the advisory was published, now names lodash-template and 1 morenot dated
2024-04-17published 2021-05-06same kind of change as the line aboveGHSA-35jh-r3h4-6jhmCVE-2021-23337same package registry as the line abovehighnot named as affected when the advisory was published, now names lodash-templatenot dated
2024-04-17published 2021-05-06same kind of change as the line aboveGHSA-35jh-r3h4-6jhmCVE-2021-23337same package registry as the line abovehighnot named as affected when the advisory was published, now names lodash.templatenot dated
2024-04-17published 2024-03-18Package added to advisoryGHSA-wjv8-pxr6-5f4rmoderatenot named as affected when the advisory was published, now names friendsofsymfony1/swiftmailer and 1 moreDays to revision 30
2024-04-17published 2024-03-18same kind of change as the line aboveGHSA-wjv8-pxr6-5f4rCVE-2024-28859same package registry as the line abovemoderatenot named as affected when the advisory was published, now names friendsofsymfony1/swiftmailerDays to revision 30
2024-04-17published 2024-03-18same kind of change as the line aboveGHSA-wjv8-pxr6-5f4rCVE-2024-28859same package registry as the line abovemoderatenot named as affected when the advisory was published, now names swiftmailer/swiftmailerDays to revision 30
2024-04-17published 2024-04-03Package added to advisoryGHSA-qjfw-cvjf-f4fmCVE-2024-2653highnot named as affected when the advisory was published, now names amphp/http-clientDays to revision 14
Tue 16 Apr 2024· 4 advisory changes
2024-04-16published 2022-05-13Package added to advisoryGHSA-7vpq-g998-qpv7CVE-2014-0193moderatenot named as affected when the advisory was published, now names io.netty:netty-allDays to revision 705
2024-04-16published 2024-04-15Advisory severity changedGHSA-5x7m-6737-26crCVE-2024-32036whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 1
2024-04-16published 2024-04-16Advisory withdrawnwhole advisoryhighwithdrawn 2024-04-16Days to revision 1
2024-04-16published 2024-04-16same kind of change as the line aboveGHSA-4q82-j5c2-g2c5same package and registry as the line abovehighwithdrawn 2024-04-16Days to revision 1
2024-04-16published 2024-04-16same kind of change as the line aboveGHSA-rmqv-7v3j-mr7psame package and registry as the line abovehighwithdrawn 2024-04-16Days to revision 1
Fri 12 Apr 2024· 3 advisory changes
2024-04-12published 2024-01-03Package added to advisoryGHSA-264p-99wq-f4j6CVE-2024-21634highnot named as affected when the advisory was published, now names software.amazon.ion:ion-javaDays to revision 100
2024-04-12published 2023-06-12Package added to advisoryGHSA-xm2m-2q6h-22jwCVE-2023-34468highnot named as affected when the advisory was published, now names org.apache.nifi:nifi-dbcp-service-narDays to revision 305
2024-04-12published 2024-02-21Advisory severity changedGHSA-4j93-fm92-rp4mwhole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 52
Thu 11 Apr 2024· 5 advisory changes
2024-04-11published 2024-03-13Package added to advisoryGHSA-7w75-32cg-r6g2CVE-2024-24549moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 29
2024-04-11published 2024-03-13Package added to advisoryGHSA-v682-8vv8-vpwrmoderatenot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocket and 1 moreDays to revision 29
2024-04-11published 2024-03-13same kind of change as the line aboveGHSA-v682-8vv8-vpwrCVE-2024-23672same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocketDays to revision 29
2024-04-11published 2024-03-13same kind of change as the line aboveGHSA-v682-8vv8-vpwrCVE-2024-23672same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-websocketDays to revision 29
2024-04-11published 2022-05-17Advisory severity changedGHSA-5xv2-q475-rwrhCVE-2012-3503whole advisorycriticalstated at publication LOW, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 695
2024-04-11published 2024-01-09Advisory withdrawnGHSA-8g9c-28fc-mcx2whole advisorymoderatewithdrawn 2024-04-11Days to revision 93
Wed 10 Apr 2024· 7 advisory changes
2024-04-10published 2024-03-19Package added to advisoryGHSA-9mg4-v392-8j68CVE-2023-50966moderatenot named as affected when the advisory was published, now names joseDays to revision 22
2024-04-10published 2024-03-22Package added to advisoryGHSA-f5x3-32g6-xq36CVE-2024-28863moderatenot named as affected when the advisory was published, now names tarDays to revision 19
2024-04-10published 2022-05-13Package added to advisoryGHSA-pjqh-2jcc-5j84CVE-2017-8028highnot named as affected when the advisory was published, now names org.springframework.ldap:spring-ldap-corenot dated
2024-04-10published 2023-10-16Package added to advisoryGHSA-67hx-6x53-jw92CVE-2023-45133criticalnot named as affected when the advisory was published, now names babel-traverseDays to revision 177
2024-04-10published 2024-03-06Advisory severity changedGHSA-c69x-5xmw-v44xCVE-2024-24767whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 35
2024-04-10published 2022-05-17Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 695
2024-04-10published 2022-05-17same kind of change as the line aboveGHSA-5964-pq8r-4q62CVE-2012-4399same package and registry as the line abovehighsame change as the line aboveDays to revision 695
2024-04-10published 2022-05-17same kind of change as the line aboveGHSA-7pg4-5233-82jvCVE-2012-3363same package and registry as the line abovehighsame change as the line aboveDays to revision 695
Tue 9 Apr 2024· 1 advisory change
2024-04-09published 2022-05-04Advisory withdrawnGHSA-xh97-72ww-2w58whole advisoryhighwithdrawn 2024-04-09Days to revision 707
Fri 5 Apr 2024· 1 advisory change
2024-04-05published 2024-03-26Advisory withdrawnGHSA-mh7p-8m2f-qrm6whole advisorymoderatewithdrawn 2024-04-05Days to revision 10
Wed 3 Apr 2024· 1 advisory change
2024-04-03published 2024-04-01Advisory withdrawnGHSA-r65j-6h5f-4f92CVE-2024-31033whole advisorymoderatewithdrawn 2024-04-03Days to revision 3
Tue 2 Apr 2024· 2 advisory changes
2024-04-02published 2024-02-03Advisory severity changedGHSA-vh55-786g-wjwjCVE-2022-34716whole advisorymoderatestated at publication CRITICAL, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 60
2024-04-02published 2022-08-10Advisory withdrawnGHSA-2m65-m22p-9wjwwhole advisorymoderatewithdrawn 2024-04-02Days to revision 602
Mon 1 Apr 2024· 5 advisory changes
2024-04-01published 2024-04-01Package added to advisoryGHSA-r65j-6h5f-4f92CVE-2024-31033moderatenot named as affected when the advisory was published, now names io.jsonwebtoken:jjwt-implDays to revision 1
2024-04-01published 2023-10-10Package added to advisoryGHSA-qppj-fm5r-hxr3moderatenot named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core and 3 moreDays to revision 174
2024-04-01published 2023-10-10same kind of change as the line aboveGHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.typesafe.akka:akka-http-coreDays to revision 174
2024-04-01published 2023-10-10same kind of change as the line aboveGHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core_2.11Days to revision 174
2024-04-01published 2023-10-10same kind of change as the line aboveGHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core_2.12Days to revision 174
2024-04-01published 2023-10-10same kind of change as the line aboveGHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core_2.13Days to revision 174
Fri 29 Mar 2024· 2 advisory changes
2024-03-29published 2023-05-15Advisory severity changedGHSA-8j28-34qq-gmchCVE-2022-47937whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 319
2024-03-29published 2024-02-22Advisory severity changedGHSA-hmx6-r76c-85g9CVE-2024-1729whole advisorymoderatestated at publication CRITICAL, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 36
Wed 27 Mar 2024· 3 advisory changes
2024-03-27published 2024-03-26Advisory fix version movedGHSA-q84m-rmw3-4382CVE-2024-1455
pypilangchain-core
moderate
stated at publication 0.1.34, now states 0.1.35Days to revision 1
2024-03-27published 2024-03-25 to 2024-03-27Advisory withdrawnwhole advisoryhighwithdrawn 2024-03-27Days to revision 0 to 3
2024-03-27published 2024-03-25same kind of change as the line aboveGHSA-87qp-7cw8-8q9csame package and registry as the line abovehighwithdrawn 2024-03-27Days to revision 3
2024-03-27published 2024-03-27same kind of change as the line aboveGHSA-xcgp-r7r8-2hc9CVE-2024-1540same package and registry as the line abovehighwithdrawn 2024-03-27Days to revision 0
Fri 22 Mar 2024· 1 advisory change
2024-03-22published 2023-11-16Advisory fix version movedGHSA-4hh5-2678-83fxCVE-2023-6022
pypiprefect
high
stated at publication 2.14.3, now states 2.16.5Days to revision 127
Wed 20 Mar 2024· 1 advisory change
2024-03-20published 2024-02-01Package added to advisoryGHSA-xw73-rw38-6vjcCVE-2024-24557moderatenot named as affected when the advisory was published, now names github.com/docker/dockerDays to revision 48

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →