Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Tue 19 Mar 2024· 2 advisory changes
2024-03-19published 2022-05-14Advisory fix version movedGHSA-3gv7-3h64-78cmCVE-2017-5647
mavenorg.apache.tomcat:tomcat
high
stated at publication 8.0.42, now states 8.0.43not dated
2024-03-19published 2024-01-12Advisory withdrawnGHSA-chcr-x7hc-8fp8CVE-2024-0227whole advisorymoderatewithdrawn 2024-03-19Days to revision 67
Fri 15 Mar 2024· 1 advisory change
2024-03-15published 2019-01-04Advisory severity changedGHSA-c8hm-7hpq-7jhgCVE-2018-19362whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
Thu 14 Mar 2024· 34 advisory changes
2024-03-14published 2022-05-04Advisory fix version movedGHSA-hxqq-w4mr-mc62CVE-2012-0393
mavenorg.apache.struts:struts2-core
moderate
stated at publication 2.2.3.1, now states 2.3.1.1Days to revision 681
2024-03-14published 2024-03-04Package added to advisoryGHSA-h59x-p739-982cCVE-2024-28088lownot named as affected when the advisory was published, now names langchain-coreDays to revision 11
2024-03-14published 2019-05-14 to 2024-01-06Package added to advisory19 rows, one per advisory and package3 bandsnot named as affected when the advisory was published, now names org.apache.activemq:activemq-web-demo and 12 moreDays to revision 68 to 668
2024-03-14published 2022-05-17same kind of change as the line aboveGHSA-34fp-xvxp-rg22CVE-2012-6551same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.activemq:activemq-web-demoDays to revision 668
2024-03-14published 2022-05-17same kind of change as the line aboveGHSA-34fp-xvxp-rg22CVE-2012-6551same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.activemq:apache-activemqDays to revision 668
2024-03-14published 2022-04-22same kind of change as the line aboveGHSA-c2cp-3xj9-97w9CVE-2022-22969same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.springframework.security.oauth:spring-security-oauth2not dated
2024-03-14published 2023-11-23same kind of change as the line aboveGHSA-wjxj-5m7g-mg7qCVE-2023-33202same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-ext-jdk15onDays to revision 112
2024-03-14published 2023-11-23same kind of change as the line aboveGHSA-wjxj-5m7g-mg7qCVE-2023-33202same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-ext-jdk16Days to revision 112
2024-03-14published 2023-11-23same kind of change as the line aboveGHSA-wjxj-5m7g-mg7qCVE-2023-33202same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk14Days to revision 112
2024-03-14published 2023-11-23same kind of change as the line aboveGHSA-wjxj-5m7g-mg7qCVE-2023-33202same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15Days to revision 112
2024-03-14published 2023-11-23same kind of change as the line aboveGHSA-wjxj-5m7g-mg7qCVE-2023-33202same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onDays to revision 112
11 more rows in this change are not listed here. Open all 19 rows
2024-03-14published 2024-03-12Package added to advisoryGHSA-5fxj-whcv-crrchighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.linux-arm and 11 moreDays to revision 2
2024-03-14published 2024-03-12same kind of change as the line aboveGHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.linux-armDays to revision 2
2024-03-14published 2024-03-12same kind of change as the line aboveGHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.linux-arm64Days to revision 2
2024-03-14published 2024-03-12same kind of change as the line aboveGHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.linux-musl-armDays to revision 2
2024-03-14published 2024-03-12same kind of change as the line aboveGHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.linux-musl-arm64Days to revision 2
2024-03-14published 2024-03-12same kind of change as the line aboveGHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.linux-musl-x64Days to revision 2
2024-03-14published 2024-03-12same kind of change as the line aboveGHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.linux-x64Days to revision 2
2024-03-14published 2024-03-12same kind of change as the line aboveGHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.osx-arm64Days to revision 2
2024-03-14published 2024-03-12same kind of change as the line aboveGHSA-5fxj-whcv-crrcCVE-2024-21392same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.netcore.app.runtime.osx-x64Days to revision 2
4 more rows in this change are not listed here. Open all 12 rows
2024-03-14published 2024-03-07Advisory severity changedGHSA-rj98-crf4-g69wCVE-2024-2044whole advisorycriticalstated at publication MODERATE, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 4
Tue 12 Mar 2024· 1 advisory change
2024-03-12published 2024-02-09Package added to advisoryGHSA-xrj7-x7gp-wwqrCVE-2023-50298moderatenot named as affected when the advisory was published, now names org.apache.solr:solr-solrjDays to revision 32
Mon 11 Mar 2024· 4 advisory changes
2024-03-11published 2022-02-08Advisory fix version movedGHSA-m7jv-hq7h-mq7cCVE-2020-13935
mavenorg.apache.tomcat:tomcat
high
stated at publication 7.0.104, now states 7.0.105not dated
2024-03-11published 2022-02-08Advisory fix version movedGHSA-m7jv-hq7h-mq7cCVE-2020-13935
mavenorg.apache.tomcat:tomcat
high
stated at publication 8.5.56, now states 8.5.57not dated
2024-03-11published 2022-02-08Advisory fix version movedGHSA-m7jv-hq7h-mq7cCVE-2020-13935
mavenorg.apache.tomcat:tomcat
high
stated at publication 9.0.36, now states 9.0.37not dated
2024-03-11published 2019-06-26Advisory fix version movedGHSA-q4hg-rmq2-52q9CVE-2019-10072
mavenorg.apache.tomcat.embed:tomcat-embed-core
high
stated at publication 8.5.40, now states 8.5.41not dated
Wed 6 Mar 2024· 6 advisory changes
2024-03-06published 2023-10-24Package added to advisoryGHSA-cqpc-x2c6-2gmfCVE-2023-41339moderatenot named as affected when the advisory was published, now names org.geoserver.web:gs-web-appDays to revision 134
2024-03-06published 2022-05-13Package added to advisoryGHSA-86p9-x5pw-94qxCVE-2017-9096highnot named as affected when the advisory was published, now names com.lowagie:itextnot dated
2024-03-06published 2024-03-06Package added to advisoryGHSA-m757-p8rv-4q93CVE-2023-50740moderatenot named as affected when the advisory was published, now names org.apache.linkis:linkisDays to revision 0
2024-03-06published 2024-02-10Package added to advisoryGHSA-4w4v-5hc9-xrr2highnot named as affected when the advisory was published, now names org.webjars.bower:angular and 1 moreDays to revision 25
2024-03-06published 2024-02-10same kind of change as the line aboveGHSA-4w4v-5hc9-xrr2CVE-2024-21490same package registry as the line abovehighnot named as affected when the advisory was published, now names org.webjars.bower:angularDays to revision 25
2024-03-06published 2024-02-10same kind of change as the line aboveGHSA-4w4v-5hc9-xrr2CVE-2024-21490same package registry as the line abovehighnot named as affected when the advisory was published, now names org.webjars.npm:angularDays to revision 25
2024-03-06published 2024-03-04Advisory severity changedGHSA-fqg8-vfv7-8fj8CVE-2024-27307whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 2
Tue 5 Mar 2024· 13 advisory changes
2024-03-05published 2022-05-17Advisory fix version movedGHSA-p4mx-p49m-8rw4CVE-2013-4378
mavennet.bull.javamelody:javamelody-core
moderate
stated at publication 1.46.0, now states 1.47.0not dated
2024-03-05published 2023-10-10Package added to advisoryGHSA-qppj-fm5r-hxr3moderatenot named as affected when the advisory was published, now names org.eclipse.jetty.http2:http2-common and 3 moreDays to revision 147
2024-03-05published 2023-10-10same kind of change as the line aboveGHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.jetty.http2:http2-commonDays to revision 147
2024-03-05published 2023-10-10same kind of change as the line aboveGHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.jetty.http2:http2-serverDays to revision 147
2024-03-05published 2023-10-10same kind of change as the line aboveGHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.jetty.http2:jetty-http2-commonDays to revision 147
2024-03-05published 2023-10-10same kind of change as the line aboveGHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.jetty.http2:jetty-http2-serverDays to revision 147
2024-03-05published 2023-11-30Package added to advisoryGHSA-j24h-xcpc-9jw8moderatenot named as affected when the advisory was published, now names org.eclipse.jdt:org.eclipse.jdt.ui and 7 moreDays to revision 96
2024-03-05published 2023-11-30same kind of change as the line aboveGHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.jdt:org.eclipse.jdt.uiDays to revision 96
2024-03-05published 2023-11-30same kind of change as the line aboveGHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.core.runtimeDays to revision 96
2024-03-05published 2023-11-30same kind of change as the line aboveGHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.jfaceDays to revision 96
2024-03-05published 2023-11-30same kind of change as the line aboveGHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.platformDays to revision 96
2024-03-05published 2023-11-30same kind of change as the line aboveGHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.ui.formsDays to revision 96
2024-03-05published 2023-11-30same kind of change as the line aboveGHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.ui.ideDays to revision 96
2024-03-05published 2023-11-30same kind of change as the line aboveGHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.ui.workbenchDays to revision 96
2024-03-05published 2023-11-30same kind of change as the line aboveGHSA-j24h-xcpc-9jw8CVE-2023-4218same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.urischemeDays to revision 96
Mon 4 Mar 2024· 4 advisory changes
2024-03-04published 2018-10-16Advisory fix version movedGHSA-7xr3-rgwh-pw22CVE-2018-8030
mavenorg.apache.qpid:apache-qpid-broker-j
high
stated at publication 7.0.5, now states 7.1.0not dated
2024-03-04published 2022-05-14Advisory fix version movedGHSA-m643-2pfv-xwm8CVE-2018-19413
mavenorg.sonarsource.sonarqube:sonar-plugin-api
moderate
stated at publication 7.4, now states 7.5not dated
2024-03-04published 2018-10-17Advisory fix version movedGHSA-3pph-2595-cgfhCVE-2018-1308
mavenorg.apache.solr:solr-core
high
stated at publication 7.2.1, now states 7.3.0not dated
2024-03-04published 2024-02-27Package added to advisoryGHSA-p5q9-86w4-2xr5CVE-2023-51747highnot named as affected when the advisory was published, now names org.apache.james:james-serverDays to revision 6
Fri 1 Mar 2024· 7 advisory changes
2024-03-01published 2024-02-28Advisory fix version movedGHSA-8mq4-9jjh-9xrcCVE-2024-27285moderatestated at publication 0.9.35, now states 0.9.36Days to revision 2
2024-03-01published 2024-02-27Package added to advisory2 bandsnot named as affected when the advisory was published, now names actionpackDays to revision 3
2024-03-01published 2024-02-27same kind of change as the line aboveGHSA-9822-6m93-xqf4CVE-2024-26143same package registry as the line abovemoderatesame change as the line aboveDays to revision 3
2024-03-01published 2024-02-27same kind of change as the line aboveGHSA-jjhx-jhvp-74wqCVE-2024-26142same package registry as the line abovelowsame change as the line aboveDays to revision 3
2024-03-01published 2024-02-27Package added to advisoryGHSA-8h22-8cf7-hq6gCVE-2024-26144moderatenot named as affected when the advisory was published, now names activestorageDays to revision 3
2024-03-01published 2018-10-16Package added to advisoryGHSA-r53v-vm87-f72cCVE-2014-3596moderatenot named as affected when the advisory was published, now names axis:axisnot dated
2024-03-01published 2023-12-28Advisory severity changedGHSA-wpmx-564x-h2mhCVE-2023-52081whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 64
2024-03-01published 2023-07-18Advisory severity changedGHSA-vghm-8cjp-hjw6CVE-2018-25088whole advisorycriticalstated at publication MODERATE, now states CRITICALCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 227
Thu 29 Feb 2024· 1 advisory change
2024-02-29published 2024-02-27Advisory fix version movedGHSA-vf7j-cmrj-pmmmCVE-2024-25723
pypizenml
high
stated at publication 0.44.1, now states 0.44.4Days to revision 2
Mon 26 Feb 2024· 5 advisory changes
2024-02-26published 2021-05-13Advisory fix version movedGHSA-5pv8-ppvj-4h68CVE-2021-21424
packagistsymfony/security
moderate
stated at publication 3.4.48, now states 3.4.49not dated
2024-02-26published 2021-05-13Advisory fix version movedGHSA-5pv8-ppvj-4h68CVE-2021-21424
packagistsymfony/security
moderate
stated at publication 4.4.23, now states 4.4.24not dated
2024-02-26published 2021-05-13Package added to advisoryGHSA-5pv8-ppvj-4h68moderatenot named as affected when the advisory was published, now names lexik/jwt-authentication-bundle and 2 morenot dated
2024-02-26published 2021-05-13same kind of change as the line aboveGHSA-5pv8-ppvj-4h68CVE-2021-21424same package registry as the line abovemoderatenot named as affected when the advisory was published, now names lexik/jwt-authentication-bundlenot dated
2024-02-26published 2021-05-13same kind of change as the line aboveGHSA-5pv8-ppvj-4h68CVE-2021-21424same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/maker-bundlenot dated
2024-02-26published 2021-05-13same kind of change as the line aboveGHSA-5pv8-ppvj-4h68CVE-2021-21424same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/symfonynot dated
Fri 23 Feb 2024· 2 advisory changes
2024-02-23published 2024-02-05Advisory severity changedGHSA-3ww4-gg4f-jr7fCVE-2023-50782whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 17
2024-02-23published 2022-05-24Advisory withdrawnGHSA-gmg5-r3c4-3fm9CVE-2019-10226whole advisorymoderatewithdrawn 2024-02-23Days to revision 640
Thu 22 Feb 2024· 2 advisory changes
2024-02-22published 2024-02-22Package added to advisoryGHSA-97m3-52wr-xvv2criticalnot named as affected when the advisory was published, now names phenx/php-svg-libDays to revision 0
2024-02-22published 2021-08-03Package added to advisoryGHSA-5fg8-2547-mr8qCVE-2021-32796moderatenot named as affected when the advisory was published, now names @xmldom/xmldomnot dated
Wed 21 Feb 2024· 3 advisory changes
2024-02-21published 2022-01-06Advisory severity changedGHSA-76w9-p8mg-j927CVE-2021-45707whole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2024-02-21published 2022-06-16 to 2024-02-19Advisory withdrawnwhole advisory2 bandswithdrawn 2024-02-21Days to revision 2 to 615
2024-02-21published 2024-02-19same kind of change as the line aboveGHSA-xfg6-62px-cxc2same package and registry as the line abovecriticalwithdrawn 2024-02-21Days to revision 2
2024-02-21published 2022-06-16same kind of change as the line aboveGHSA-xvc9-xwgj-4cq9CVE-2019-25008same package and registry as the line abovehighwithdrawn 2024-02-21Days to revision 615
Tue 20 Feb 2024· 2 advisory changes
2024-02-20published 2024-02-07Package added to advisoryGHSA-fq6h-4g8v-qqvmCVE-2024-24815moderatenot named as affected when the advisory was published, now names ckeditor/ckeditorDays to revision 13
2024-02-20published 2024-02-13Advisory severity changedGHSA-cmh9-rx85-xj38CVE-2024-25122whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 7
Fri 16 Feb 2024· 3 advisory changes
2024-02-16published 2023-12-21Advisory severity changedGHSA-6qm2-wpxq-7qh2CVE-2023-51449whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 57
2024-02-16published 2024-02-05Advisory withdrawnwhole advisoryhighwithdrawn 2024-02-16Days to revision 11
2024-02-16published 2024-02-05same kind of change as the line aboveGHSA-qf9m-vfgh-m389same package and registry as the line abovehighwithdrawn 2024-02-16Days to revision 11
2024-02-16published 2024-02-05same kind of change as the line aboveGHSA-93gm-qmq6-w238same package and registry as the line abovehighwithdrawn 2024-02-16Days to revision 11
Thu 15 Feb 2024· 2 advisory changes
2024-02-15published 2024-02-08Advisory severity changedGHSA-qwj8-qgpr-8crmCVE-2024-25148whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 7
2024-02-15published 2024-02-08Advisory severity changedGHSA-c352-x843-ggpqCVE-2024-24113whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
Wed 14 Feb 2024· 12 advisory changes
2024-02-14published 2021-04-26Package added to advisoryGHSA-gwrp-pvrq-jmwvmoderatenot named as affected when the advisory was published, now names com.cosium.vet:vet and 8 morenot dated
2024-02-14published 2021-04-26same kind of change as the line aboveGHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.cosium.vet:vetnot dated
2024-02-14published 2021-04-26same kind of change as the line aboveGHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.diamondq.common:common-thirdparty.jcasbinnot dated
2024-02-14published 2021-04-26same kind of change as the line aboveGHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.liferay:com.liferay.sass.compiler.jsassnot dated
2024-02-14published 2021-04-26same kind of change as the line aboveGHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.virjar:ratel-apinot dated
2024-02-14published 2021-04-26same kind of change as the line aboveGHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.hasor:cobble-langnot dated
2024-02-14published 2021-04-26same kind of change as the line aboveGHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.commons:commons-ionot dated
2024-02-14published 2021-04-26same kind of change as the line aboveGHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.servicemix.bundles:org.apache.servicemix.bundles.commons-ionot dated
2024-02-14published 2021-04-26same kind of change as the line aboveGHSA-gwrp-pvrq-jmwvCVE-2021-29425same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.checkerframework.annotatedlib:commons-ionot dated
1 more row in this change is not listed here. Open all 9 rows
2024-02-14published 2019-11-12Package added to advisoryGHSA-g996-q5r8-w7g2CVE-2019-10909moderatenot named as affected when the advisory was published, now names drupal/drupalnot dated
2024-02-14published 2022-05-17Advisory severity changedGHSA-5jc8-8xhv-g8qmCVE-2012-5817whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2024-02-14published 2022-05-02Advisory withdrawnGHSA-cgr9-h9qq-x9fxCVE-2010-1022whole advisoryhighwithdrawn 2024-02-14Days to revision 653
Tue 13 Feb 2024· 3 advisory changes
2024-02-13published 2017-10-24Advisory severity changedGHSA-rxq3-gm4p-5fj4CVE-2009-2422whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2024-02-13published 2023-12-25 to 2024-02-01Advisory withdrawnwhole advisory2 bandswithdrawn 2024-02-13Days to revision 12 to 51
2024-02-13published 2023-12-25same kind of change as the line aboveGHSA-3gjc-mp82-fj4qsame package and registry as the line abovemoderatewithdrawn 2024-02-13Days to revision 51
2024-02-13published 2024-02-01same kind of change as the line aboveGHSA-2cjh-75gp-34gcCVE-2024-22859same package and registry as the line abovehighwithdrawn 2024-02-13Days to revision 12
Mon 12 Feb 2024· 8 advisory changes
2024-02-12published 2022-05-24Package added to advisory2 bandsnot named as affected when the advisory was published, now names magento/product-community-editionDays to revision 629
2024-02-12published 2022-05-24same kind of change as the line aboveGHSA-wmrg-w9vg-7jqxCVE-2019-7865same package registry as the line abovehighsame change as the line aboveDays to revision 629
2024-02-12published 2022-05-24same kind of change as the line aboveGHSA-6qh6-v99h-vh4cCVE-2019-7876same package registry as the line abovehighsame change as the line aboveDays to revision 629
2024-02-12published 2022-05-24same kind of change as the line aboveGHSA-mgfr-44wv-hqv6CVE-2019-7938same package registry as the line abovemoderatesame change as the line aboveDays to revision 629
2024-02-12published 2022-05-24Package added to advisoryGHSA-mgfr-44wv-hqv6moderatenot named as affected when the advisory was published, now names magento/magento1ce and 1 moreDays to revision 629
2024-02-12published 2022-05-24same kind of change as the line aboveGHSA-mgfr-44wv-hqv6CVE-2019-7938same package registry as the line abovemoderatenot named as affected when the advisory was published, now names magento/magento1ceDays to revision 629
2024-02-12published 2022-05-24same kind of change as the line aboveGHSA-mgfr-44wv-hqv6CVE-2019-7938same package registry as the line abovemoderatenot named as affected when the advisory was published, now names magento/magento1eeDays to revision 629
2024-02-12published 2024-02-02Advisory severity changedGHSA-v269-rrr6-cx6rCVE-2023-51838whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2024-02-12published 2024-02-02Advisory severity changedGHSA-9gh8-877r-g477CVE-2024-22533whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 11
2024-02-12published 2022-02-15Advisory severity changedGHSA-vfp4-xx6m-7vf6CVE-2020-7010whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
Fri 9 Feb 2024· 10 advisory changes
2024-02-09published 2023-06-09 to 2023-10-10Package added to advisory2 bandsnot named as affected when the advisory was published, now names github.com/apple/swift-nio-http2Days to revision 121 to 244
2024-02-09published 2023-10-10same kind of change as the line aboveGHSA-qppj-fm5r-hxr3CVE-2023-44487same package registry as the line abovemoderatesame change as the line aboveDays to revision 121
2024-02-09published 2023-06-09same kind of change as the line aboveGHSA-q36x-r5x4-h4q6CVE-2022-0618same package registry as the line abovehighsame change as the line aboveDays to revision 244
2024-02-09published 2023-10-05 to 2024-01-03Package added to advisorymoderatenot named as affected when the advisory was published, now names github.com/vapor/vaporDays to revision 36 to 126
2024-02-09published 2023-10-05same kind of change as the line aboveGHSA-3mwq-h3g6-ffhmCVE-2023-44386same package registry as the line abovemoderatesame change as the line aboveDays to revision 126
2024-02-09published 2024-01-03same kind of change as the line aboveGHSA-r6r4-5pr8-gjcpCVE-2024-21631same package registry as the line abovemoderatesame change as the line aboveDays to revision 36
2024-02-09published 2023-08-31Package added to advisoryGHSA-c2cc-3569-6jh2CVE-2023-39138highnot named as affected when the advisory was published, now names github.com/weichsel/zipfoundationDays to revision 162
2024-02-09published 2023-08-31Package added to advisoryGHSA-g454-wj9r-jpg4CVE-2023-39135highnot named as affected when the advisory was published, now names github.com/marmelroy/zipDays to revision 162
2024-02-09published 2023-08-29Package added to advisoryGHSA-vxvm-qww3-2fh7CVE-2021-32050moderatenot named as affected when the advisory was published, now names github.com/mongodb/mongo-swift-driverDays to revision 163
2024-02-09published 2023-07-14Package added to advisoryGHSA-jq43-q8mx-r7mqCVE-2022-23465highnot named as affected when the advisory was published, now names github.com/migueldeicaza/swifttermDays to revision 209
2024-02-09published 2023-06-09Package added to advisoryGHSA-r6ww-5963-7r95CVE-2022-24777highnot named as affected when the advisory was published, now names github.com/grpc/grpc-swiftDays to revision 244
2024-02-09published 2023-12-06Package added to advisoryGHSA-5844-q3fc-56rhCVE-2023-26154moderatenot named as affected when the advisory was published, now names github.com/pubnub/swiftDays to revision 65
Thu 8 Feb 2024· 18 advisory changes
2024-02-08published 2021-06-21 to 2022-05-24Package added to advisory18 rows, one per advisory and package4 bandsnot named as affected when the advisory was published, now names symfony/security and 8 moreDays to revision 625 to 645
2024-02-08published 2022-05-24same kind of change as the line aboveGHSA-q87v-q8fw-gmj5CVE-2017-11365same package registry as the line abovecriticalnot named as affected when the advisory was published, now names symfony/securityDays to revision 625
2024-02-08published 2022-05-24same kind of change as the line aboveGHSA-q87v-q8fw-gmj5CVE-2017-11365same package registry as the line abovecriticalnot named as affected when the advisory was published, now names symfony/security-coreDays to revision 625
2024-02-08published 2022-05-05same kind of change as the line aboveGHSA-22pv-7v9j-hqxpCVE-2013-4752same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/http-foundationDays to revision 645
2024-02-08published 2022-05-17same kind of change as the line aboveGHSA-jjx5-fq5g-8xpcCVE-2016-1902same package registry as the line abovehighnot named as affected when the advisory was published, now names symfony/securityDays to revision 633
2024-02-08published 2022-05-17same kind of change as the line aboveGHSA-jjx5-fq5g-8xpcCVE-2016-1902same package registry as the line abovehighnot named as affected when the advisory was published, now names symfony/security-coreDays to revision 633
2024-02-08published 2022-05-13same kind of change as the line aboveGHSA-8wgj-6wx8-h5hqCVE-2018-14773same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/symfonyDays to revision 637
2024-02-08published 2022-05-14same kind of change as the line aboveGHSA-g4g7-q726-v5hgCVE-2018-11406same package registry as the line abovehighnot named as affected when the advisory was published, now names symfony/securityDays to revision 636
2024-02-08published 2022-05-14same kind of change as the line aboveGHSA-g4g7-q726-v5hgCVE-2018-11406same package registry as the line abovehighnot named as affected when the advisory was published, now names symfony/security-bundleDays to revision 636
10 more rows in this change are not listed here. Open all 18 rows
Wed 7 Feb 2024· 25 advisory changes
2024-02-07published 2019-11-12 to 2022-05-24Package added to advisory21 rows, one per advisory and package3 bandsnot named as affected when the advisory was published, now names symfony/yaml and 11 moreDays to revision 624 to 644
2024-02-07published 2022-05-17same kind of change as the line aboveGHSA-7w53-hfpw-rg3gCVE-2013-1397same package registry as the line abovehighnot named as affected when the advisory was published, now names symfony/yamlDays to revision 632
2024-02-07published 2022-05-24same kind of change as the line aboveGHSA-v59p-p692-v382CVE-2015-0270same package registry as the line abovecriticalnot named as affected when the advisory was published, now names zendframework/zend-dbDays to revision 624
2024-02-07published 2022-05-17same kind of change as the line aboveGHSA-xp8p-9rq5-4wgvCVE-2015-5161same package registry as the line abovemoderatenot named as affected when the advisory was published, now names zendframework/zendframework1Days to revision 632
2024-02-07published 2022-05-05same kind of change as the line aboveGHSA-q8j7-fjh7-25v5CVE-2013-4751same package registry as the line abovehighnot named as affected when the advisory was published, now names symfony/symfonyDays to revision 644
2024-02-07published 2022-05-14same kind of change as the line aboveGHSA-p9hp-3gpv-52w3CVE-2016-6233same package registry as the line abovecriticalnot named as affected when the advisory was published, now names zendframework/zendframework1Days to revision 635
2024-02-07published 2022-05-13same kind of change as the line aboveGHSA-j6c3-3c4w-qv8pCVE-2013-7341same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsDays to revision 636
2024-02-07published 2021-08-19same kind of change as the line aboveGHSA-c5c9-8c6m-727vCVE-2021-32768same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-07published 2022-05-24same kind of change as the line aboveGHSA-r6fv-56gp-j3r4CVE-2019-12748same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsDays to revision 624
13 more rows in this change are not listed here. Open all 21 rows
2024-02-07published 2022-09-25Package added to advisoryGHSA-c429-5p7v-vgjpCVE-2020-36604highnot named as affected when the advisory was published, now names hoeknot dated
2024-02-07published 2020-11-18Advisory severity changedGHSA-hpjm-3ww5-6cpfCVE-2020-26216whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2024-02-07published 2021-06-22Advisory severity changedGHSA-77mr-wc79-m8j3CVE-2021-3603whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2024-02-07published 2023-11-16Advisory withdrawnGHSA-hxjc-9j8v-v9prwhole advisorymoderatewithdrawn 2024-02-07Days to revision 83
Tue 6 Feb 2024· 26 advisory changes
2024-02-06published 2024-02-02Advisory fix version movedGHSA-34q3-p352-c7q8CVE-2024-1143
mavencom.linecorp.centraldogma:centraldogma-server
critical
stated at publication 0.64.0, now states 0.64.1Days to revision 4
2024-02-06published 2022-05-13Advisory fix version movedGHSA-3qhm-qfj3-4rrxCVE-2019-6257
packagiststudio-42/elfinder
high
stated at publication 2.1.46, now states 2.1.49Days to revision 635
2024-02-06published 2024-02-02Package added to advisoryGHSA-9gh8-877r-g477CVE-2024-22533criticalnot named as affected when the advisory was published, now names com.ibeetl:beetl-coreDays to revision 5
2024-02-06published 2019-10-10 to 2022-05-24Package added to advisory19 rows, one per advisory and package3 bandsnot named as affected when the advisory was published, now names symfony/form and 11 moreDays to revision 623 to 634
2024-02-06published 2022-05-14same kind of change as the line aboveGHSA-x3cf-w64x-4cp2CVE-2018-19789same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/formDays to revision 634
2024-02-06published 2022-05-17same kind of change as the line aboveGHSA-83c3-qx27-2rwrCVE-2012-6431same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/http-foundationDays to revision 630
2024-02-06published 2022-05-17same kind of change as the line aboveGHSA-83c3-qx27-2rwrCVE-2012-6431same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/routingDays to revision 630
2024-02-06published 2022-05-17same kind of change as the line aboveGHSA-83c3-qx27-2rwrCVE-2012-6431same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/securityDays to revision 630
2024-02-06published 2020-03-30same kind of change as the line aboveGHSA-m884-279h-32v2CVE-2020-5274same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/error-handlernot dated
2024-02-06published 2020-03-30same kind of change as the line aboveGHSA-m884-279h-32v2CVE-2020-5274same package registry as the line abovemoderatenot named as affected when the advisory was published, now names symfony/symfonynot dated
2024-02-06published 2022-05-17same kind of change as the line aboveGHSA-5qp6-78pr-gv8cCVE-2013-4701same package registry as the line abovehighnot named as affected when the advisory was published, now names typo3/cmsDays to revision 630
2024-02-06published 2022-05-17same kind of change as the line aboveGHSA-vc74-c4m6-9979CVE-2013-7082same package registry as the line abovemoderatenot named as affected when the advisory was published, now names neos/flowDays to revision 631
11 more rows in this change are not listed here. Open all 19 rows
2024-02-06published 2024-01-29 to 2024-02-01Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 5 to 8
2024-02-06published 2024-02-01same kind of change as the line aboveGHSA-2cjh-75gp-34gcCVE-2024-22859same package and registry as the line abovehighsame change as the line aboveDays to revision 5
2024-02-06published 2024-01-29same kind of change as the line aboveGHSA-wpxw-5xfm-x22vCVE-2023-51842same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2024-02-06published 2022-05-17Advisory severity changedGHSA-v7mh-3jgf-r26cCVE-2012-4406whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 631
2024-02-06published 2022-05-24Advisory severity changedGHSA-m648-hpf8-qcjwCVE-2020-13663whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 623
Mon 5 Feb 2024· 51 advisory changes
2024-02-05published 2018-09-13 to 2022-10-06Package added to advisory46 rows, one per advisory and package4 bandsnot named as affected when the advisory was published, now names yiisoft/yii2-elasticsearch and 15 moreDays to revision 622 to 632
2024-02-05published 2022-05-24same kind of change as the line aboveGHSA-m2p5-fwp2-qcw2CVE-2018-8074same package registry as the line abovehighnot named as affected when the advisory was published, now names yiisoft/yii2-elasticsearchDays to revision 622
2024-02-05published 2018-11-21same kind of change as the line aboveGHSA-g68x-vvqq-pvw3CVE-2018-17960same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-05published 2018-11-21same kind of change as the line aboveGHSA-g68x-vvqq-pvw3CVE-2018-17960same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cms-corenot dated
2024-02-05published 2018-09-13same kind of change as the line aboveGHSA-pj7m-g53m-7638CVE-2018-14041same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-05published 2018-09-13same kind of change as the line aboveGHSA-pj7m-g53m-7638CVE-2018-14041same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cms-corenot dated
2024-02-05published 2021-10-05same kind of change as the line aboveGHSA-657m-v5vm-f6rwCVE-2021-41113same package registry as the line abovehighnot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-05published 2021-10-05same kind of change as the line aboveGHSA-m2jh-fxw4-gphmCVE-2021-41114same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-05published 2021-07-22same kind of change as the line aboveGHSA-rgcg-28xm-8mmwCVE-2021-32669same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
38 more rows in this change are not listed here. Open all 46 rows
2024-02-05published 2024-01-30Advisory severity changedGHSA-6p78-f7h9-6838CVE-2023-36260whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2024-02-05published 2024-01-30Advisory severity changedGHSA-8xw6-9h78-c89jCVE-2023-51837whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2024-02-05published 2021-10-05Advisory severity changedGHSA-657m-v5vm-f6rwCVE-2021-41113whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2024-02-05published 2021-06-21Advisory severity changedGHSA-rfcf-m67m-jcrqCVE-2021-32693whole advisorymoderatestated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
2024-02-05published 2020-07-29Advisory severity changedGHSA-4h44-w6fm-548gCVE-2020-15086whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
Fri 2 Feb 2024· 17 advisory changes
2024-02-02published 2023-03-23 to 2023-04-13Package added to advisory2 bandsnot named as affected when the advisory was published, now names org.springframework:spring-expressionDays to revision 295 to 316
2024-02-02published 2023-04-13same kind of change as the line aboveGHSA-wxqc-pxw9-g2p8CVE-2023-20863same package registry as the line abovehighsame change as the line aboveDays to revision 295
2024-02-02published 2023-03-23same kind of change as the line aboveGHSA-564r-hj7v-mcr5CVE-2023-20861same package registry as the line abovemoderatesame change as the line aboveDays to revision 316
2024-02-02published 2022-04-15Package added to advisoryGHSA-g5mm-vmx4-3rg7CVE-2022-22968highnot named as affected when the advisory was published, now names org.springframework:spring-contextnot dated
2024-02-02published 2022-05-13Package added to advisoryGHSA-hh26-6xwr-ggv7CVE-2022-22970highnot named as affected when the advisory was published, now names org.springframework:spring-beansnot dated
2024-02-02published 2022-05-13Package added to advisoryGHSA-rqph-vqwm-22vcCVE-2022-22971moderatenot named as affected when the advisory was published, now names org.springframework:spring-messagingnot dated
2024-02-02published 2021-03-23Package added to advisory2 bandsnot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-02published 2021-03-23same kind of change as the line aboveGHSA-x79j-wgqv-g8h2CVE-2021-21358same package registry as the line abovemoderatesame change as the line abovenot dated
2024-02-02published 2021-03-23same kind of change as the line aboveGHSA-qx3w-4864-94chCVE-2021-21339same package registry as the line abovemoderatesame change as the line abovenot dated
2024-02-02published 2021-03-23same kind of change as the line aboveGHSA-x7hc-x7fm-f7qhCVE-2021-21370same package registry as the line abovemoderatesame change as the line abovenot dated
2024-02-02published 2021-03-23same kind of change as the line aboveGHSA-2r6j-862c-m2v2CVE-2021-21355same package registry as the line abovehighsame change as the line abovenot dated
2024-02-02published 2021-03-23same kind of change as the line aboveGHSA-fjh3-g8gq-9q92CVE-2021-21340same package registry as the line abovemoderatesame change as the line abovenot dated
2024-02-02published 2021-03-23Package added to advisory2 bandsnot named as affected when the advisory was published, now names typo3/cms-corenot dated
2024-02-02published 2021-03-23same kind of change as the line aboveGHSA-x79j-wgqv-g8h2CVE-2021-21358same package registry as the line abovemoderatesame change as the line abovenot dated
2024-02-02published 2021-03-23same kind of change as the line aboveGHSA-x7hc-x7fm-f7qhCVE-2021-21370same package registry as the line abovemoderatesame change as the line abovenot dated
2024-02-02published 2021-03-23same kind of change as the line aboveGHSA-2r6j-862c-m2v2CVE-2021-21355same package registry as the line abovehighsame change as the line abovenot dated
2024-02-02published 2021-03-23same kind of change as the line aboveGHSA-fjh3-g8gq-9q92CVE-2021-21340same package registry as the line abovemoderatesame change as the line abovenot dated
2024-02-02published 2021-03-23Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2024-02-02published 2021-03-23same kind of change as the line aboveGHSA-x7hc-x7fm-f7qhCVE-2021-21370same package and registry as the line abovemoderatesame change as the line abovenot dated
2024-02-02published 2021-03-23same kind of change as the line aboveGHSA-fjh3-g8gq-9q92CVE-2021-21340same package and registry as the line abovemoderatesame change as the line abovenot dated
2024-02-02published 2024-01-29Advisory severity changedGHSA-3vvc-v8c2-43r7CVE-2023-29055whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 4
Thu 1 Feb 2024· 10 advisory changes
2024-02-01published 2020-10-08 to 2022-05-24Package added to advisory8 rows, one per advisory and package2 bandsnot named as affected when the advisory was published, now names zendframework/zend-http and 3 moreDays to revision 618
2024-02-01published 2022-05-24same kind of change as the line aboveGHSA-5957-5crx-79jxCVE-2015-3154same package registry as the line abovemoderatenot named as affected when the advisory was published, now names zendframework/zend-httpDays to revision 618
2024-02-01published 2022-05-24same kind of change as the line aboveGHSA-5957-5crx-79jxCVE-2015-3154same package registry as the line abovemoderatenot named as affected when the advisory was published, now names zendframework/zendframework1Days to revision 618
2024-02-01published 2021-03-23same kind of change as the line aboveGHSA-4jhw-2p6j-5wmpCVE-2021-21338same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-01published 2021-03-23same kind of change as the line aboveGHSA-3vg7-jw9m-pc3fCVE-2021-21357same package registry as the line abovehighnot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-01published 2021-03-23same kind of change as the line aboveGHSA-3vg7-jw9m-pc3fCVE-2021-21357same package registry as the line abovehighnot named as affected when the advisory was published, now names typo3/cms-corenot dated
2024-02-01published 2020-12-21same kind of change as the line aboveGHSA-vqqx-jw6p-q3rfCVE-2020-26227same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-01published 2020-10-08same kind of change as the line aboveGHSA-7733-hjv6-4h47CVE-2020-15241same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cmsnot dated
2024-02-01published 2020-10-08same kind of change as the line aboveGHSA-7733-hjv6-4h47CVE-2020-15241same package registry as the line abovemoderatenot named as affected when the advisory was published, now names typo3/cms-corenot dated
2024-02-01published 2024-01-31Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 1
2024-02-01published 2024-01-31same kind of change as the line aboveGHSA-wr6v-9f75-vh2gCVE-2024-23653same package and registry as the line abovecriticalsame change as the line aboveDays to revision 1
2024-02-01published 2024-01-31same kind of change as the line aboveGHSA-4v98-7qmw-rqr8CVE-2024-23652same package and registry as the line abovecriticalsame change as the line aboveDays to revision 1
Wed 31 Jan 2024· 2 advisory changes
2024-01-31published 2024-01-24Advisory severity changedGHSA-mg2x-mggj-6955CVE-2023-51702whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7
2024-01-31published 2024-01-30Advisory severity changedGHSA-7mgx-gvjw-m3w3CVE-2023-51982whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 1
Tue 30 Jan 2024· 2 advisory changes
2024-01-30published 2024-01-24Advisory severity changedGHSA-2cvg-w29m-j8xcCVE-2023-24676whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
2024-01-30published 2024-01-29Advisory severity changedGHSA-8qpw-xqxj-h4r2CVE-2024-23829whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 1
Mon 29 Jan 2024· 3 advisory changes
2024-01-29published 2024-01-21 to 2024-01-22Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2024-01-29published 2024-01-22same kind of change as the line aboveGHSA-5g73-69p4-7gvxCVE-2024-23752same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
2024-01-29published 2024-01-22same kind of change as the line aboveGHSA-2jxw-4hm4-6w87CVE-2024-23751same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
2024-01-29published 2024-01-21same kind of change as the line aboveGHSA-297x-2qf3-jrj3CVE-2024-23730same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →