Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Thu 7 Sep 2023· 3 advisory changes
2023-09-07published 2021-02-10Advisory severity changedGHSA-7ggw-h8pp-r95rCVE-2021-3311whole advisorycriticalstated at publication LOW, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-09-07published 2022-12-13Advisory severity changedGHSA-3w37-5p3p-jv92CVE-2022-46363whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 268
2023-09-07published 2021-05-06Advisory severity changedGHSA-36fm-v9wv-56jfCVE-2020-10596whole advisorymoderatestated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
Wed 6 Sep 2023· 5 advisory changes
2023-09-06published 2018-07-20Advisory severity changedGHSA-rvj9-8cvx-3vq9CVE-2017-16007whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-09-06published 2023-08-31Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-09-06published 2023-08-31same kind of change as the line aboveGHSA-g454-wj9r-jpg4CVE-2023-39135same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-09-06published 2023-08-31same kind of change as the line aboveGHSA-c2cc-3569-6jh2CVE-2023-39138same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-09-06published 2023-09-01Advisory severity changedGHSA-f73w-4m7g-ch9xCVE-2023-39631whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5
2023-09-06published 2023-08-08Advisory severity changedGHSA-rg2c-cfxv-qp6fCVE-2023-3894whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 29
Tue 5 Sep 2023· 13 advisory changes
2023-09-05published 2021-09-23Package added to advisoryGHSA-3j6g-hxx5-3q26moderatenot named as affected when the advisory was published, now names org.apache.kafka:kafka-clients and 3 morenot dated
2023-09-05published 2021-09-23same kind of change as the line aboveGHSA-3j6g-hxx5-3q26CVE-2021-38153same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.kafka:kafka-clientsnot dated
2023-09-05published 2021-09-23same kind of change as the line aboveGHSA-3j6g-hxx5-3q26CVE-2021-38153same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.11not dated
2023-09-05published 2021-09-23same kind of change as the line aboveGHSA-3j6g-hxx5-3q26CVE-2021-38153same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.12not dated
2023-09-05published 2021-09-23same kind of change as the line aboveGHSA-3j6g-hxx5-3q26CVE-2021-38153same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.13not dated
2023-09-05published 2022-01-06Package added to advisoryGHSA-2h63-qp69-fwvwCVE-2020-11987highnot named as affected when the advisory was published, now names org.apache.xmlgraphics:batik-svgbrowsernot dated
2023-09-05published 2023-07-05Package added to advisoryGHSA-hr8g-6v94-x4m9moderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-debug-jdk15on and 2 moreDays to revision 63
2023-09-05published 2023-07-05same kind of change as the line aboveGHSA-hr8g-6v94-x4m9CVE-2023-33201same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-debug-jdk15onDays to revision 63
2023-09-05published 2023-07-05same kind of change as the line aboveGHSA-hr8g-6v94-x4m9CVE-2023-33201same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-ext-jdk15onDays to revision 63
2023-09-05published 2023-07-05same kind of change as the line aboveGHSA-hr8g-6v94-x4m9CVE-2023-33201same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onDays to revision 63
2023-09-05published 2019-04-10Package added to advisoryGHSA-f6f2-pwrj-64h3CVE-2019-10868highnot named as affected when the advisory was published, now names trytondnot dated
2023-09-05published 2019-04-26Package added to advisoryGHSA-6c3j-c64m-qhgqCVE-2019-11358moderatenot named as affected when the advisory was published, now names djangonot dated
2023-09-05published 2021-09-01Advisory severity changedGHSA-h97f-5258-5593CVE-2021-38384whole advisorycriticalstated at publication MODERATE, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-09-05published 2022-02-09Advisory severity changedGHSA-mqgv-67vx-g4m5CVE-2020-28442whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-09-05published 2021-12-10Advisory severity changedGHSA-hg2p-2cvq-4ppvCVE-2020-7642whole advisorymoderatestated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
Mon 4 Sep 2023· 2 advisory changes
2023-09-04published 2022-01-12Advisory severity changedGHSA-pw3c-h7wp-cvhxCVE-2022-22815whole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2023-09-04published 2021-03-18Advisory severity changedGHSA-hf64-x4gq-p99hCVE-2020-35655whole advisorymoderatestated at publication HIGH, now states MODERATEA CVSS version was added; the existing vectors stayed the same.not dated
Fri 1 Sep 2023· 9 advisory changes
2023-09-01published 2019-01-04Advisory severity changedGHSA-38rv-5jqc-m2cvCVE-2017-0906whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-09-01published 2023-08-21 to 2023-08-28Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 4 to 11
2023-09-01published 2023-08-22same kind of change as the line aboveGHSA-j55r-787p-m549CVE-2023-40185same package and registry as the line abovehighsame change as the line aboveDays to revision 10
2023-09-01published 2023-08-28same kind of change as the line aboveGHSA-8q28-pw9g-w82cCVE-2023-40195same package and registry as the line abovehighsame change as the line aboveDays to revision 4
2023-09-01published 2023-08-28same kind of change as the line aboveGHSA-g3m9-pr5m-4cvpCVE-2023-27604same package and registry as the line abovehighsame change as the line aboveDays to revision 4
2023-09-01published 2023-08-21same kind of change as the line aboveGHSA-v6c8-pwhq-288mCVE-2023-39106same package and registry as the line abovehighsame change as the line aboveDays to revision 11
2023-09-01published 2023-08-23Advisory severity changedGHSA-4f8m-7h83-9f6mCVE-2023-40572whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 9
2023-09-01published 2023-08-23Advisory severity changedGHSA-v86x-5fm3-5p7jCVE-2023-40577whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 9
2023-09-01published 2023-04-25Advisory severity changedGHSA-xv83-x443-7rmwCVE-2023-30609whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 129
2023-09-01published 2023-08-29Advisory severity changedGHSA-mhp6-jvpx-2p4mCVE-2023-40889whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 2
Thu 31 Aug 2023· 9 advisory changes
2023-08-31published 2021-04-20Advisory severity changedGHSA-893h-35v4-mxqxCVE-2020-1737whole advisoryhighstated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.not dated
2023-08-31published 2023-08-22 to 2023-08-24Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7 to 8
2023-08-31published 2023-08-24same kind of change as the line aboveGHSA-3x59-vrmc-5mx6CVE-2023-41167same package and registry as the line abovemoderatesame change as the line aboveDays to revision 7
2023-08-31published 2023-08-22same kind of change as the line aboveGHSA-5pv6-rprw-82wvCVE-2022-45582same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-08-31published 2023-08-25Advisory severity changedGHSA-q3mw-pvr8-9ggcCVE-2023-41080whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 6
2023-08-31published 2023-08-21 to 2023-08-22Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9 to 10
2023-08-31published 2023-08-21same kind of change as the line aboveGHSA-2jc4-r94c-rp7hCVE-2022-46751same package and registry as the line abovehighsame change as the line aboveDays to revision 10
2023-08-31published 2023-08-22same kind of change as the line aboveGHSA-65rp-cv85-263xCVE-2022-34038same package and registry as the line abovehighsame change as the line aboveDays to revision 9
2023-08-31published 2023-07-06Advisory severity changedGHSA-g96c-x7rh-99r3CVE-2023-41045whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 56
2023-08-31published 2021-01-13Advisory severity changedGHSA-jxwx-85vp-gvwmCVE-2021-21252whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-08-31published 2023-08-23Advisory severity changedGHSA-c8xw-vjgf-94hrCVE-2023-40025whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 7
Wed 30 Aug 2023· 8 advisory changes
2023-08-30published 2022-11-15Package added to advisoryGHSA-prjq-f4q3-fvfrCVE-2020-7731highnot named as affected when the advisory was published, now names github.com/russellhaering/goxmldsignot dated
2023-08-30published 2021-04-07Advisory severity changedGHSA-fjq3-5pxw-4wj4CVE-2020-7965whole advisoryhighstated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.not dated
2023-08-30published 2021-05-06Advisory severity changedGHSA-3vcg-8p79-jpcvCVE-2020-10799whole advisorycriticalstated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.not dated
2023-08-30published 2021-05-21Advisory severity changedGHSA-j756-f273-xhp4whole advisoryhighstated at publication CRITICAL, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-08-30published 2021-05-21Advisory severity changedGHSA-hmm9-r2m2-qg9wwhole advisoryhighstated at publication LOW, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-08-30published 2022-02-11Advisory severity changedGHSA-h2x7-2ff6-v32pCVE-2022-2583whole advisorylowstated at publication HIGH, now states LOWNo CVSS vector was stated in the first observed version.not dated
2023-08-30published 2022-04-08Advisory severity changedGHSA-g3vv-g2j5-45f2CVE-2022-2584whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-08-30published 2023-08-22Advisory severity changedGHSA-gq5f-xv48-2365CVE-2022-44729whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8
Tue 29 Aug 2023· 7 advisory changes
2023-08-29published 2023-08-21Advisory severity changedGHSA-h8cm-3v5f-rgp6CVE-2023-40176whole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2023-08-29published 2021-08-02Advisory severity changedGHSA-fp52-qw33-mfmwCVE-2020-16250whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2023-08-29published 2023-08-23Advisory severity changedGHSA-5f35-pq34-c87qCVE-2023-39441whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 6
2023-08-29published 2023-08-23Advisory severity changedGHSA-pm87-24wq-r8w9CVE-2023-40273whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
2023-08-29published 2023-08-23Advisory severity changedGHSA-x2mh-8fmc-rqghCVE-2023-37379whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
2023-08-29published 2023-08-24Advisory severity changedGHSA-crqf-q9fp-hwjwCVE-2023-34040whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 5
2023-08-29published 2022-05-17Advisory severity changedGHSA-hxvp-655x-xxqvCVE-2014-0135whole advisorylowstated at publication MODERATE, now states LOWThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 469
Mon 28 Aug 2023· 4 advisory changes
2023-08-28published 2019-04-09Package added to advisorymoderatenot named as affected when the advisory was published, now names @materializecss/materializenot dated
2023-08-28published 2019-04-09same kind of change as the line aboveGHSA-7752-f4gf-94gcCVE-2019-11003same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-28published 2019-04-09same kind of change as the line aboveGHSA-98f7-p5rc-jx67CVE-2019-11002same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-28published 2019-04-09same kind of change as the line aboveGHSA-rg3q-jxmp-pvjjCVE-2019-11004same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-28published 2018-11-15Advisory severity changedGHSA-hg78-4f6x-99wqCVE-2018-16470whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
Fri 25 Aug 2023· 4 advisory changes
2023-08-25published 2023-08-23Advisory severity changedGHSA-8rj5-2857-877jCVE-2022-25024whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 2
2023-08-25published 2023-08-25Advisory severity changedGHSA-jcf2-mxr2-gmqpCVE-2023-40579whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 0
2023-08-25published 2023-08-25Advisory severity changedGHSA-j8g2-6fc7-q8f8CVE-2023-40587whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 0
2023-08-25published 2023-08-22Advisory severity changedGHSA-7ch3-7pp7-7cpqCVE-2023-40570whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 3
Thu 24 Aug 2023· 6 advisory changes
2023-08-24published 2022-06-01Package added to advisoryGHSA-qw3f-w4pf-jh5fCVE-2022-30973moderatenot named as affected when the advisory was published, now names org.apache.tika:tika-corenot dated
2023-08-24published 2023-08-15 to 2023-08-18Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 3 to 9
2023-08-24published 2023-08-18same kind of change as the line aboveGHSA-68xg-gqqm-vgj8CVE-2023-40175same package and registry as the line abovecriticalsame change as the line aboveDays to revision 3
2023-08-24published 2023-08-17same kind of change as the line aboveGHSA-5p42-m6f3-hpmjCVE-2023-38894same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
2023-08-24published 2023-08-15same kind of change as the line aboveGHSA-xrrh-h86w-pwfjCVE-2023-38889same package and registry as the line abovecriticalsame change as the line aboveDays to revision 9
2023-08-24published 2023-08-22Advisory severity changedGHSA-8697-479h-5mfpCVE-2023-38976whole advisoryhighstated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 2
2023-08-24published 2023-08-17Advisory severity changedGHSA-r2f6-6928-fh8fCVE-2023-40272whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
Wed 23 Aug 2023· 5 advisory changes
2023-08-23published 2022-05-24Package added to advisoryGHSA-w6g9-xccc-347hCVE-2020-7941criticalnot named as affected when the advisory was published, now names plone.app.contenttypesDays to revision 456
2023-08-23published 2023-04-19Advisory severity changedGHSA-x873-6rgc-94jcCVE-2023-20862whole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 126
2023-08-23published 2023-08-17Advisory severity changedGHSA-443m-3fr6-w8wjCVE-2023-36106whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
2023-08-23published 2020-02-04Advisory severity changedGHSA-73m2-3pwg-5fgcCVE-2020-5236whole advisorymoderatestated at publication CRITICAL, now states MODERATEA CVSS version was added; the existing vectors stayed the same.not dated
2023-08-23published 2022-05-24Advisory withdrawnGHSA-jw82-xjgr-g6f8CVE-2020-1742whole advisoryhighwithdrawn 2023-08-23Days to revision 456
Tue 22 Aug 2023· 6 advisory changes
2023-08-22published 2022-05-24Package added to advisoryGHSA-qcch-9268-59jwCVE-2020-14297moderatenot named as affected when the advisory was published, now names org.jboss:jboss-ejb-clientDays to revision 455
2023-08-22published 2023-08-14Advisory severity changedGHSA-xvv9-5j67-3rpqCVE-2023-40274whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2023-08-22published 2023-08-15Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-08-22published 2023-08-15same kind of change as the line aboveGHSA-prgp-w7vf-ch62CVE-2023-39659same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-08-22published 2023-08-15same kind of change as the line aboveGHSA-fj32-q626-pjjcCVE-2023-38860same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-08-22published 2023-08-15same kind of change as the line aboveGHSA-92j5-3459-qgp4CVE-2023-38896same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-08-22published 2023-08-21Advisory withdrawnGHSA-ch6w-mc6c-g65gwhole advisorymoderatewithdrawn 2023-08-22Days to revision 1
Mon 21 Aug 2023· 6 advisory changes
2023-08-21published 2022-05-24Package added to advisoryGHSA-853f-x27w-8r74CVE-2020-12760highnot named as affected when the advisory was published, now names org.opennms.core:org.opennms.core.daemonDays to revision 454
2023-08-21published 2023-07-10Package added to advisoryGHSA-mjmq-gwgm-5qhmCVE-2023-35887moderatenot named as affected when the advisory was published, now names org.apache.sshd:sshd-coreDays to revision 42
2023-08-21published 2023-08-15Advisory severity changedGHSA-xvhg-w6qc-m3qqCVE-2023-40023whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 6
2023-08-21published 2023-08-11Advisory severity changedGHSA-mq4v-6vg4-796cCVE-2023-39553whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2023-08-21published 2023-08-11Advisory severity changedGHSA-cx3j-qqxj-9597CVE-2023-3481whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 10
2023-08-21published 2022-05-24Advisory withdrawnGHSA-f478-xwv9-p93qwhole advisoryhighwithdrawn 2023-08-21Days to revision 454
Fri 18 Aug 2023· 6 advisory changes
2023-08-18published 2022-11-16Package added to advisoryGHSA-fhw8-8j55-vwgqCVE-2022-45047criticalnot named as affected when the advisory was published, now names org.apache.sshd:sshd-coreDays to revision 275
2023-08-18published 2018-10-17Package added to advisoryGHSA-4446-656p-f54gCVE-2018-1000613criticalnot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onnot dated
2023-08-18published 2023-08-11Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-08-18published 2023-08-11same kind of change as the line aboveGHSA-5x64-925v-h4gvCVE-2020-35141same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-08-18published 2023-08-11same kind of change as the line aboveGHSA-4987-5p3p-9r27CVE-2020-35139same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-08-18published 2023-08-11Advisory severity changedGHSA-pr76-5cm5-w9cjCVE-2023-40267whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-08-18published 2022-05-13Advisory withdrawnGHSA-m833-87vf-576cCVE-2017-15113whole advisorymoderatewithdrawn 2023-08-18Days to revision 463
Thu 17 Aug 2023· 1 advisory change
2023-08-17published 2023-08-11Advisory severity changedGHSA-jp5r-4x9q-4vcfCVE-2020-24922whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
Wed 16 Aug 2023· 2 advisory changes
2023-08-16published 2023-08-11Advisory severity changedGHSA-g3vf-47fv-8f3cCVE-2021-26505whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5
2023-08-16published 2023-08-11Advisory severity changedGHSA-7rvp-xqj7-rxf2CVE-2020-24950whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 5
Tue 15 Aug 2023· 6 advisory changes
2023-08-15published 2023-08-09Package added to advisoryGHSA-vmch-3w2x-vhgqhighnot named as affected when the advisory was published, now names microsoft.aspnetcore.server.kestrel.transport.libuv and 1 moreDays to revision 6
2023-08-15published 2023-08-09same kind of change as the line aboveGHSA-vmch-3w2x-vhgqCVE-2023-38180same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.server.kestrel.transport.libuvDays to revision 6
2023-08-15published 2023-08-09same kind of change as the line aboveGHSA-vmch-3w2x-vhgqCVE-2023-38180same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.server.kestrel.transport.socketsDays to revision 6
2023-08-15published 2021-06-16Package added to advisoryGHSA-2f88-5hg8-9x2xcriticalnot named as affected when the advisory was published, now names org.apache.maven:maven-compat and 1 morenot dated
2023-08-15published 2021-06-16same kind of change as the line aboveGHSA-2f88-5hg8-9x2xCVE-2021-26291same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.maven:maven-compatnot dated
2023-08-15published 2021-06-16same kind of change as the line aboveGHSA-2f88-5hg8-9x2xCVE-2021-26291same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.maven:maven-corenot dated
2023-08-15published 2023-07-05Advisory severity changedGHSA-h755-8qp9-cq85CVE-2023-36665whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 41
2023-08-15published 2023-07-14Advisory severity changedGHSA-cf7p-gm2m-833mCVE-2023-38325whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 32
Mon 14 Aug 2023· 2 advisory changes
2023-08-14published 2023-07-18Package added to advisoryGHSA-p9xf-74xh-mhw5CVE-2023-37477highnot named as affected when the advisory was published, now names github.com/1panel-dev/1panelDays to revision 27
2023-08-14published 2023-04-04Advisory withdrawnGHSA-gq63-p39p-jrjfCVE-2023-26750whole advisorycriticalwithdrawn 2023-08-14Days to revision 132
Wed 9 Aug 2023· 3 advisory changes
2023-08-09published 2023-08-05Advisory severity changedGHSA-269x-pg5c-5xgmCVE-2023-39508whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 5
2023-08-09published 2023-08-05Advisory severity changedGHSA-gwqq-6vq7-5j86CVE-2023-36095whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5
2023-08-09published 2023-08-04Advisory severity changedGHSA-w7vm-4v3j-vgpwCVE-2023-29689whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5
Tue 8 Aug 2023· 7 advisory changes
2023-08-08published 2022-12-14Advisory severity changedGHSA-995x-33wq-8gc9CVE-2022-24377whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 238
2023-08-08published 2022-09-21Advisory severity changedGHSA-crf8-h2wq-2h9xCVE-2022-39974whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-08-08published 2022-02-08Advisory severity changedGHSA-g6w6-r76c-28j7CVE-2022-24450whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-08-08published 2021-11-19Advisory severity changedGHSA-vhrp-8qx4-vr6cCVE-2021-43996whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-08-08published 2021-10-05Advisory severity changedGHSA-cr3f-r24j-3chwCVE-2021-40325whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-08-08published 2021-02-05Advisory severity changedGHSA-f5c9-x9j6-87qpCVE-2021-25912whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-08-08published 2022-10-16Advisory severity changedGHSA-w596-4wvx-j9j6CVE-2022-42969whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
Mon 7 Aug 2023· 14 advisory changes
2023-08-07published 2020-02-21 to 2021-12-09Package added to advisory3 bandsnot named as affected when the advisory was published, now names io.netty:nettynot dated
2023-08-07published 2021-09-09same kind of change as the line aboveGHSA-9vjp-v76f-g363CVE-2021-37137same package registry as the line abovehighsame change as the line abovenot dated
2023-08-07published 2021-03-09same kind of change as the line aboveGHSA-wm47-8v5p-wjpjCVE-2021-21295same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-07published 2021-12-09same kind of change as the line aboveGHSA-wx5j-54mm-rqqqCVE-2021-43797same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-07published 2021-09-09same kind of change as the line aboveGHSA-grg4-wf29-r9vvCVE-2021-37136same package registry as the line abovehighsame change as the line abovenot dated
2023-08-07published 2021-03-30same kind of change as the line aboveGHSA-f256-j965-7f32CVE-2021-21409same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-07published 2021-02-08same kind of change as the line aboveGHSA-5mcr-gq6c-3hq2CVE-2021-21290same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-07published 2020-02-21same kind of change as the line aboveGHSA-cqqj-4p63-rrmmCVE-2019-20444same package registry as the line abovecriticalsame change as the line abovenot dated
2023-08-07published 2020-02-21same kind of change as the line aboveGHSA-p2v9-g2qv-p635CVE-2019-20445same package registry as the line abovemoderatesame change as the line abovenot dated
1 more row in this change is not listed here. Open all 9 rows
2023-08-07published 2022-01-27Package added to advisoryGHSA-77rm-9x9h-xj3gCVE-2021-22570highnot named as affected when the advisory was published, now names com.google.protobuf:protobuf-javanot dated
2023-08-07published 2023-07-31Advisory severity changedGHSA-36xx-7vf6-7mv3CVE-2023-32302whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 7
2023-08-07published 2019-03-25Advisory severity changedGHSA-gcm4-q2pg-xw89CVE-2019-7539whole advisorycriticalstated at publication HIGH, now states CRITICALCVSS versions were removed or replaced; no shared version's vector was rescored.not dated
2023-08-07published 2022-05-24Advisory withdrawnwhole advisory2 bandswithdrawn 2023-08-07Days to revision 440
2023-08-07published 2022-05-24same kind of change as the line aboveGHSA-6q5m-22mq-q2xvCVE-2021-31920same package and registry as the line abovemoderatewithdrawn 2023-08-07Days to revision 440
2023-08-07published 2022-05-24same kind of change as the line aboveGHSA-39mj-fpg2-3jrgCVE-2021-28667same package and registry as the line abovehighwithdrawn 2023-08-07Days to revision 440
Fri 4 Aug 2023· 1 advisory change
2023-08-04published 2022-05-24Package added to advisoryGHSA-hr65-qq6p-87r4CVE-2021-22137moderatenot named as affected when the advisory was published, now names org.elasticsearch:elasticsearchnot dated

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →