Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Thu 14 May 2026· 5 changes
2026-05-14published 2022-05-17Advisory fix version movedGHSA-4j5j-58j7-6c3wCVE-2014-9706
pypidulwich
critical
stated at publication 0.9.9, now states 0.9.10Time to revision 1,459 days
2026-05-14published 2024-12-02Package added to advisoryGHSA-4cx5-89vm-833xlownot named as affected when the advisory was published, now names org.verapdf:library and 2 moreTime to revision 528 days
2026-05-14published 2024-12-02same kind of change as the line aboveGHSA-4cx5-89vm-833xCVE-2024-52800same package registry as the line abovelownot named as affected when the advisory was published, now names org.verapdf:libraryTime to revision 528 days
2026-05-14published 2024-12-02same kind of change as the line aboveGHSA-4cx5-89vm-833xCVE-2024-52800same package registry as the line abovelownot named as affected when the advisory was published, now names org.verapdf:library-arlingtonTime to revision 528 days
2026-05-14published 2024-12-02same kind of change as the line aboveGHSA-4cx5-89vm-833xCVE-2024-52800same package registry as the line abovelownot named as affected when the advisory was published, now names org.verapdf:library-jakartaTime to revision 528 days
2026-05-14published 2022-05-14Advisory withdrawnGHSA-9848-v244-962pCVE-2012-1007whole advisorymoderatewithdrawn 2026-05-14Time to revision 1,461 days
Wed 13 May 2026· 1 change
2026-05-13published 2026-05-05Advisory severity changedGHSA-wv26-88m5-6h59CVE-2026-42875whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Time to revision 8 days
Tue 12 May 2026· 5 changes
2026-05-12published 2026-05-04Advisory severity changedGHSA-wppj-c6mr-83jjCVE-2026-44112whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 8 days
2026-05-12published 2026-04-25Advisory severity changedGHSA-c4qg-j8jg-42q5CVE-2026-44117whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 17 days
2026-05-12published 2026-04-25Advisory severity changedGHSA-hxvm-xjvf-93f3CVE-2026-44114whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 17 days
2026-05-12published 2026-04-17Advisory severity changedGHSA-xmxx-7p24-h892CVE-2026-43585whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 25 days
2026-05-12published 2026-04-13Advisory withdrawnGHSA-rp7w-624x-95qvwhole advisorymoderatewithdrawn 2026-05-12Time to revision 29 days
Mon 11 May 2026· 1 change
2026-05-11published 2026-02-03Advisory withdrawnGHSA-2r8f-cf6w-x5vqwhole advisoryhighwithdrawn 2026-05-11Time to revision 97 days
Fri 8 May 2026· 15 changes
2026-05-08published 2026-05-04Advisory severity changedGHSA-67wx-r9xr-x75xCVE-2026-41648whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Time to revision 4 days
2026-05-08published 2026-05-04 to 2026-05-05Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.Time to revision 3 to 4 days
2026-05-08published 2026-05-04same kind of change as the line aboveGHSA-4m88-wxj4-9qj6CVE-2026-40251same package and registry as the line abovehighsame change as the line aboveTime to revision 4 days
2026-05-08published 2026-05-04same kind of change as the line aboveGHSA-r7w7-mmxr-47r9CVE-2026-40197same package and registry as the line abovehighsame change as the line aboveTime to revision 4 days
2026-05-08published 2026-05-04same kind of change as the line aboveGHSA-gc7j-g665-rxr9CVE-2026-40195same package and registry as the line abovehighsame change as the line aboveTime to revision 4 days
2026-05-08published 2026-05-05same kind of change as the line aboveGHSA-5mrq-x3x5-8v8fCVE-2026-40934same package and registry as the line abovehighsame change as the line aboveTime to revision 3 days
2026-05-08published 2026-05-04Advisory severity changedGHSA-78fc-9688-w8xwCVE-2026-40076whole advisorycriticalstated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.Time to revision 4 days
2026-05-08published 2026-03-31 to 2026-04-17Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 20 to 38 days
2026-05-08published 2026-03-31same kind of change as the line aboveGHSA-5h2w-qmfp-ggp6CVE-2026-41344same package and registry as the line abovemoderatesame change as the line aboveTime to revision 38 days
2026-05-08published 2026-04-17same kind of change as the line aboveGHSA-mr34-9552-qr95CVE-2026-41389same package and registry as the line abovemoderatesame change as the line aboveTime to revision 20 days
2026-05-08published 2026-04-07Advisory severity changedGHSA-767m-xrhc-fxm7CVE-2026-41359whole advisoryhighstated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 31 days
2026-05-08published 2026-05-05Advisory severity changedGHSA-gwfr-jfjf-92vvCVE-2026-7317whole advisorylowstated at publication HIGH, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 3 days
2026-05-08published 2026-04-30Advisory severity changedGHSA-5vh4-rgv7-p9g4CVE-2026-39383whole advisorymoderatestated at publication HIGH, now states MODERATEA CVSS version was added; the existing vectors stayed the same.Time to revision 8 days
2026-05-08published 2026-04-30Advisory severity changedGHSA-5q7p-7jgv-ww56CVE-2026-40280whole advisoryhighstated at publication CRITICAL, now states HIGHA CVSS version was added; the existing vectors stayed the same.Time to revision 8 days
2026-05-08published 2026-04-29Advisory severity changedGHSA-q4q6-r8wh-5cghCVE-2026-34084whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Time to revision 9 days
2026-05-08published 2023-11-27 to 2024-03-02Advisory withdrawnwhole advisoryhighwithdrawn 2026-05-08Time to revision 798 to 893 days
2026-05-08published 2023-11-27same kind of change as the line aboveGHSA-jpr7-q523-hx25same package and registry as the line abovehighwithdrawn 2026-05-08Time to revision 893 days
2026-05-08published 2024-03-02same kind of change as the line aboveGHSA-jr22-8qgm-4q87same package and registry as the line abovehighwithdrawn 2026-05-08Time to revision 798 days
Thu 7 May 2026· 8 changes
2026-05-07published 2025-07-11 to 2025-08-08Package added to advisory2 bandsnot named as affected when the advisory was published, now names github.com/pytorch/executorchTime to revision 273 to 300 days
2026-05-07published 2025-08-08same kind of change as the line aboveGHSA-hj95-mhgf-jxc4CVE-2025-30404same package registry as the line abovecriticalsame change as the line aboveTime to revision 273 days
2026-05-07published 2025-08-08same kind of change as the line aboveGHSA-xc7w-r669-48pfCVE-2025-54951same package registry as the line abovecriticalsame change as the line aboveTime to revision 273 days
2026-05-07published 2025-08-08same kind of change as the line aboveGHSA-84m3-f99p-cqx5CVE-2025-30405same package registry as the line abovecriticalsame change as the line aboveTime to revision 273 days
2026-05-07published 2025-08-08same kind of change as the line aboveGHSA-9m39-3mf3-xwchCVE-2025-54949same package registry as the line abovecriticalsame change as the line aboveTime to revision 273 days
2026-05-07published 2025-08-08same kind of change as the line aboveGHSA-f9hx-c6jf-3qxmCVE-2025-54950same package registry as the line abovecriticalsame change as the line aboveTime to revision 273 days
2026-05-07published 2025-07-11same kind of change as the line aboveGHSA-h952-963h-rv99CVE-2025-30402same package registry as the line abovehighsame change as the line aboveTime to revision 300 days
2026-05-07published 2026-03-16Package added to advisoryGHSA-6jj5-j4j8-8473CVE-2026-28499moderatenot named as affected when the advisory was published, now names github.com/vapor/leaf-kitTime to revision 52 days
2026-05-07published 2026-05-07Advisory withdrawnGHSA-j7w6-vpvq-j3gmCVE-2026-44827whole advisoryhighwithdrawn 2026-05-07Time to revision 0 days
Wed 6 May 2026· 22 changes
2026-05-06published 2026-04-18Advisory fix version movedGHSA-8m29-fpq5-89jjCVE-2026-41583
crates.iozebra-script
critical
stated at publication 5.0.1, now states 5.0.2Time to revision 19 days
2026-05-06published 2025-11-13Package added to advisoryGHSA-7wq2-32h4-9hc9highnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/auth-helpers and 8 moreTime to revision 174 days
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/auth-helpersTime to revision 174 days
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/aws-secrets-managerTime to revision 174 days
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/federated-authTime to revision 174 days
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/iamTime to revision 174 days
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/mysql-driverTime to revision 174 days
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/oktaTime to revision 174 days
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/otlpTime to revision 174 days
2026-05-06published 2025-11-13same kind of change as the line aboveGHSA-7wq2-32h4-9hc9same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/pgx-driverTime to revision 174 days
1 more row in this change is not listed here. Open all 9 rows
2026-05-06published 2026-04-03Advisory severity changedwhole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 34 to 34 days
2026-05-06published 2026-04-03same kind of change as the line aboveGHSA-6336-qqw9-v6x6CVE-2026-41341same package and registry as the line abovelowsame change as the line aboveTime to revision 34 days
2026-05-06published 2026-04-03same kind of change as the line aboveGHSA-rvvf-6vh3-9j43CVE-2026-41348same package and registry as the line abovelowsame change as the line aboveTime to revision 34 days
2026-05-06published 2026-04-03same kind of change as the line aboveGHSA-mhr7-2xmv-4c4qCVE-2026-41347same package and registry as the line abovelowsame change as the line aboveTime to revision 34 days
2026-05-06published 2026-04-02 to 2026-04-03Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 34 to 34 days
2026-05-06published 2026-04-03same kind of change as the line aboveGHSA-37v6-fxx8-xjmxCVE-2026-41351same package and registry as the line abovemoderatesame change as the line aboveTime to revision 34 days
2026-05-06published 2026-04-02same kind of change as the line aboveGHSA-89r3-6x4j-v7wfCVE-2026-41337same package and registry as the line abovemoderatesame change as the line aboveTime to revision 34 days
2026-05-06published 2026-04-02 to 2026-04-03Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 34 to 34 days
2026-05-06published 2026-04-03same kind of change as the line aboveGHSA-cg7q-fg22-4g98CVE-2026-41369same package and registry as the line abovehighsame change as the line aboveTime to revision 34 days
2026-05-06published 2026-04-02same kind of change as the line aboveGHSA-fv94-qvg8-xqpwCVE-2026-41364same package and registry as the line abovehighsame change as the line aboveTime to revision 34 days
2026-05-06published 2026-04-03Advisory severity changedGHSA-p464-m8x6-vhv8CVE-2026-41405whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 33 days
2026-05-06published 2026-03-31Advisory severity changedGHSA-j7p2-qcwm-94v4CVE-2026-41387whole advisoryhighstated at publication CRITICAL, now states HIGHA CVSS version was added; the existing vectors stayed the same.Time to revision 35 days
2026-05-06published 2024-03-02 to 2026-05-06Advisory withdrawnwhole advisoryhighwithdrawn 2026-05-06Time to revision 0 to 796 days
2026-05-06published 2026-01-15same kind of change as the line aboveGHSA-xfhx-r7ww-5995same package and registry as the line abovehighwithdrawn 2026-05-06Time to revision 111 days
2026-05-06published 2026-05-06same kind of change as the line aboveGHSA-hjph-f4mc-wx4csame package and registry as the line abovehighwithdrawn 2026-05-06Time to revision 0 days
2026-05-06published 2024-03-02same kind of change as the line aboveGHSA-hg35-mp25-qf6hsame package and registry as the line abovehighwithdrawn 2026-05-06Time to revision 796 days
Tue 5 May 2026· 12 changes
2026-05-05published 2025-05-27Advisory fix version movedGHSA-8r88-6cj9-9fh5CVE-2025-48370
npm@supabase/auth-js
low
stated at publication 2.69.1, now states 2.70.0Time to revision 343 days
2026-05-05published 2025-09-03Package added to advisoryGHSA-qww7-89xh-x7m7CVE-2025-55747criticalnot named as affected when the advisory was published, now names org.xwiki.platform:xwiki-platform-webjarsTime to revision 244 days
2026-05-05published 2026-04-18Advisory severity changedGHSA-6ffj-2wg2-w45jCVE-2026-25917whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 17 days
2026-05-05published 2026-04-23Advisory severity changedGHSA-q2pw-xx38-p64jCVE-2026-29051whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 12 days
2026-05-05published 2026-04-15 to 2026-04-23Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 12 to 20 days
2026-05-05published 2026-04-23same kind of change as the line aboveGHSA-9mv3-2cwr-p262CVE-2026-40372same package and registry as the line abovecriticalsame change as the line aboveTime to revision 12 days
2026-05-05published 2026-04-15same kind of change as the line aboveGHSA-hv5g-26jg-pc45CVE-2026-6290same package and registry as the line abovecriticalsame change as the line aboveTime to revision 20 days
2026-05-05published 2026-04-10Advisory severity changedGHSA-2rhw-gw3f-477jCVE-2026-40306whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Time to revision 25 days
2026-05-05published 2026-04-02Advisory severity changedGHSA-v569-hp3g-36wrCVE-2026-34230whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 33 days
2026-05-05published 2026-04-02Advisory severity changedGHSA-vgpv-f759-9wx3CVE-2026-26961whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 33 days
2026-05-05published 2026-03-30 to 2026-04-01Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 34 to 36 days
2026-05-05published 2026-04-01same kind of change as the line aboveGHSA-gcfj-cf7j-vwgjCVE-2026-34561same package and registry as the line abovecriticalsame change as the line aboveTime to revision 34 days
2026-05-05published 2026-03-30same kind of change as the line aboveGHSA-66m2-v9v9-95c3CVE-2026-27599same package and registry as the line abovecriticalsame change as the line aboveTime to revision 36 days
2026-05-05published 2025-07-28Advisory withdrawnGHSA-c2fv-2fmj-9xrxwhole advisoryhighwithdrawn 2026-05-05Time to revision 282 days
Thu 30 Apr 2026· 1 change
2026-04-30published 2026-03-27Advisory withdrawnGHSA-cw7v-45wm-mcf2CVE-2026-29905whole advisorymoderatewithdrawn 2026-04-30Time to revision 34 days
Tue 28 Apr 2026· 2 changes
2026-04-28published 2022-02-08 to 2026-04-09Package added to advisoryhighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 18 days
2026-04-28published 2026-04-09same kind of change as the line aboveGHSA-563x-q5rq-57qpCVE-2026-24880same package registry as the line abovehighsame change as the line aboveTime to revision 18 days
2026-04-28published 2022-02-08same kind of change as the line aboveGHSA-vf77-8h7g-gghpCVE-2020-13934same package registry as the line abovehighsame change as the line aboveDuration unknown
Fri 24 Apr 2026· 2 changes
2026-04-24published 2026-04-08Advisory severity changedGHSA-pr46-2v3c-5356CVE-2026-39847whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 17 days
2026-04-24published 2026-04-07Advisory severity changedGHSA-hfpq-x728-986jCVE-2026-35406whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 17 days
Wed 22 Apr 2026· 1 change
2026-04-22published 2026-02-19Package added to advisoryGHSA-4hfh-fch3-5q7pCVE-2026-27120moderatenot named as affected when the advisory was published, now names github.com/vapor/leaf-kitTime to revision 62 days
Sat 18 Apr 2026· 5 changes
2026-04-18published 2026-03-26Advisory severity changedGHSA-mp66-rf4f-mhh8CVE-2026-35622whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 22 days
2026-04-18published 2026-03-26Advisory severity changedGHSA-xhq5-45pm-2gjrCVE-2026-35624whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 22 days
2026-04-18published 2026-03-29Advisory severity changedGHSA-52q4-3xjc-6778CVE-2026-35617whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Time to revision 19 days
2026-04-18published 2026-03-29Advisory severity changedGHSA-h4jx-hjr3-fhgcCVE-2026-35645whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Time to revision 19 days
2026-04-18published 2026-03-26Advisory severity changedGHSA-7xr2-q9vf-x4r5CVE-2026-35632whole advisorymoderatestated at publication HIGH, now states MODERATEA CVSS version was added; the existing vectors stayed the same.Time to revision 22 days
Fri 17 Apr 2026· 2 changes
2026-04-17published 2022-05-14Package added to advisoryGHSA-6r5v-hp32-fjqwCVE-2015-0227moderatenot named as affected when the advisory was published, now names wss4j:wss4jDuration unknown
2026-04-17published 2024-05-03Package added to advisoryGHSA-4h8f-2wvx-gg5wCVE-2024-34447moderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onTime to revision 714 days
Thu 16 Apr 2026· 6 changes
2026-04-16published 2022-04-22Package added to advisoryGHSA-4qqf-hmv6-r6whCVE-2011-2487moderatenot named as affected when the advisory was published, now names wss4j:wss4jDuration unknown
2026-04-16published 2025-07-21Package added to advisoryGHSA-9342-92gg-6v29CVE-2025-7962moderatenot named as affected when the advisory was published, now names com.sun.mail:jakarta.mailTime to revision 269 days
2026-04-16published 2024-10-04Package added to advisoryGHSA-wwcp-26wc-3fxmCVE-2024-47855moderatenot named as affected when the advisory was published, now names net.sf.json-lib:json-libTime to revision 560 days
2026-04-16published 2022-05-13Package added to advisoryGHSA-jwwr-fjgh-cv2xCVE-2014-3004moderatenot named as affected when the advisory was published, now names castor:castorDuration unknown
2026-04-16published 2026-04-09 to 2026-04-10Advisory severity changedwhole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 6 to 7 days
2026-04-16published 2026-04-10same kind of change as the line aboveGHSA-fvcv-3m26-pcqxCVE-2026-40175same package and registry as the line abovemoderatesame change as the line aboveTime to revision 6 days
2026-04-16published 2026-04-09same kind of change as the line aboveGHSA-3p68-rc4w-qgx5CVE-2025-62718same package and registry as the line abovemoderatesame change as the line aboveTime to revision 7 days
Wed 15 Apr 2026· 6 changes
2026-04-15published 2026-04-09Advisory fix version movedGHSA-h468-7pvh-8vr8CVE-2026-29146
mavenorg.apache.tomcat:tomcat
high
stated at publication 11.0.19, now states 11.0.20Time to revision 6 days
2026-04-15published 2026-04-09Package added to advisoryGHSA-8mc5-53m5-3qj2CVE-2026-32990moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 6 days
2026-04-15published 2026-04-09Package added to advisoryhighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-tribesTime to revision 6 days
2026-04-15published 2026-04-09same kind of change as the line aboveGHSA-69r9-qgr7-g2wjCVE-2026-34486same package registry as the line abovehighsame change as the line aboveTime to revision 6 days
2026-04-15published 2026-04-09same kind of change as the line aboveGHSA-h468-7pvh-8vr8CVE-2026-29146same package registry as the line abovehighsame change as the line aboveTime to revision 6 days
2026-04-15published 2026-04-14Advisory severity changedwhole advisoryhighstated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 1 days
2026-04-15published 2026-04-14same kind of change as the line aboveGHSA-37gx-xxp4-5rgxCVE-2026-33116same package and registry as the line abovehighsame change as the line aboveTime to revision 1 days
2026-04-15published 2026-04-14same kind of change as the line aboveGHSA-w3x6-4m5h-cxqfCVE-2026-26171same package and registry as the line abovehighsame change as the line aboveTime to revision 1 days
Tue 14 Apr 2026· 2 changes
2026-04-14published 2026-03-30 to 2026-04-08Advisory withdrawnwhole advisory2 bandswithdrawn 2026-04-14Time to revision 5 to 15 days
2026-04-14published 2026-03-30same kind of change as the line aboveGHSA-qqrv-2hch-83q4same package and registry as the line abovemoderatewithdrawn 2026-04-14Time to revision 15 days
2026-04-14published 2026-04-08same kind of change as the line aboveGHSA-gc59-r5jq-98qwsame package and registry as the line abovehighwithdrawn 2026-04-14Time to revision 5 days
Mon 13 Apr 2026· 1 change
2026-04-13published 2026-04-06Advisory withdrawnGHSA-6jwv-w5xf-7j27CVE-2026-33817whole advisorymoderatewithdrawn 2026-04-13Time to revision 7 days
Fri 10 Apr 2026· 5 changes
2026-04-10published 2026-03-11Package added to advisoryGHSA-fvcw-9w9r-pxc7CVE-2026-31829highnot named as affected when the advisory was published, now names flowise-componentsTime to revision 31 days
2026-04-10published 2026-03-26Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 15 to 15 days
2026-04-10published 2026-03-26same kind of change as the line aboveGHSA-wv46-v6xc-2qhfCVE-2026-35670same package and registry as the line abovemoderatesame change as the line aboveTime to revision 15 days
2026-04-10published 2026-03-26same kind of change as the line aboveGHSA-74wf-h43j-vvmjCVE-2026-35655same package and registry as the line abovemoderatesame change as the line aboveTime to revision 15 days
2026-04-10published 2026-03-26Advisory severity changedGHSA-wj55-88gf-x564CVE-2026-35648whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 15 days
2026-04-10published 2026-01-29Advisory severity changedGHSA-h5qv-qjv4-pc5mCVE-2026-40036whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 71 days
Wed 8 Apr 2026· 3 changes
2026-04-08published 2026-04-03Advisory fix version movedGHSA-rp9m-7r4c-75qgCVE-2026-35039
npmfast-jwt
critical
stated at publication 6.1.0, now states 6.2.0Time to revision 5 days
2026-04-08published 2026-03-20Package added to advisoryGHSA-687q-32c6-8x68CVE-2026-33478criticalnot named as affected when the advisory was published, now names wwbn/avideoTime to revision 19 days
2026-04-08published 2026-03-03Advisory severity changedGHSA-8fmp-37rc-p5g7CVE-2026-22177whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 36 days
Tue 7 Apr 2026· 1 change
2026-04-07published 2022-05-17Advisory severity changedGHSA-qvpr-qm6w-6rccCVE-2012-5571whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Time to revision 1,422 days
Mon 6 Apr 2026· 3 changes
2026-04-06published 2026-03-30Package added to advisoryGHSA-jjwv-57xh-xr6rCVE-2026-27018highnot named as affected when the advisory was published, now names github.com/gotenberg/gotenberg/v7Time to revision 7 days
2026-04-06published 2026-03-31Advisory severity changedGHSA-hc5h-pmr3-3497CVE-2026-33579whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 6 days
2026-04-06published 2026-03-31Advisory severity changedGHSA-8prr-286p-4w7jCVE-2026-34400whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Time to revision 6 days
Wed 1 Apr 2026· 1 change
2026-04-01published 2024-11-12Advisory withdrawnGHSA-g5vp-j278-8pjhwhole advisoryhighwithdrawn 2026-04-01Time to revision 504 days
Mon 30 Mar 2026· 16 changes
2026-03-30published 2025-06-28Advisory severity changedGHSA-m964-fjrh-xxq2CVE-2025-32897whole advisorylowstated at publication CRITICAL, now states LOWCVSS versions were removed or replaced; no shared version's vector was rescored.Time to revision 275 days
2026-03-30published 2026-03-03Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.Time to revision 27 to 28 days
2026-03-30published 2026-03-03same kind of change as the line aboveGHSA-h9xm-j4qg-fvpgCVE-2026-32007same package and registry as the line abovehighsame change as the line aboveTime to revision 27 days
2026-03-30published 2026-03-03same kind of change as the line aboveGHSA-2fgq-7j6h-9rm4CVE-2026-32003same package and registry as the line abovehighsame change as the line aboveTime to revision 28 days
2026-03-30published 2026-03-02 to 2026-03-03Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 27 to 28 days
2026-03-30published 2026-03-03same kind of change as the line aboveGHSA-25gx-x37c-7pphCVE-2026-32064same package and registry as the line abovehighsame change as the line aboveTime to revision 27 days
2026-03-30published 2026-03-02same kind of change as the line aboveGHSA-rxxp-482v-7mrhCVE-2026-32049same package and registry as the line abovehighsame change as the line aboveTime to revision 28 days
2026-03-30published 2026-03-03same kind of change as the line aboveGHSA-v865-p3gq-hw6mCVE-2026-32004same package and registry as the line abovehighsame change as the line aboveTime to revision 27 days
2026-03-30published 2026-03-02same kind of change as the line aboveGHSA-vpj2-69hf-rppwCVE-2026-32041same package and registry as the line abovehighsame change as the line aboveTime to revision 28 days
2026-03-30published 2026-03-02 to 2026-03-03Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 27 to 28 days
2026-03-30published 2026-03-02same kind of change as the line aboveGHSA-hwpq-rrpf-pgcqCVE-2026-32065same package and registry as the line abovemoderatesame change as the line aboveTime to revision 28 days
2026-03-30published 2026-03-03same kind of change as the line aboveGHSA-6rcp-vxwf-3mfpCVE-2026-32052same package and registry as the line abovemoderatesame change as the line aboveTime to revision 27 days
2026-03-30published 2026-03-03same kind of change as the line aboveGHSA-mwcg-wfq3-4gjcCVE-2026-32043same package and registry as the line abovemoderatesame change as the line aboveTime to revision 27 days
2026-03-30published 2026-03-03same kind of change as the line aboveGHSA-4gc7-qcvf-38wgCVE-2026-32010same package and registry as the line abovemoderatesame change as the line aboveTime to revision 27 days
2026-03-30published 2026-03-03Advisory severity changedGHSA-vvgp-4c28-m3jmCVE-2026-32057whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 27 days
2026-03-30published 2026-03-02 to 2026-03-09Advisory severity changedwhole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 21 to 28 days
2026-03-30published 2026-03-02same kind of change as the line aboveGHSA-hjvp-qhm6-wrh2CVE-2026-32058same package and registry as the line abovelowsame change as the line aboveTime to revision 28 days
2026-03-30published 2026-03-09same kind of change as the line aboveGHSA-r6qf-8968-wj9qCVE-2026-27183same package and registry as the line abovelowsame change as the line aboveTime to revision 21 days
2026-03-30published 2026-03-03same kind of change as the line aboveGHSA-2ww6-868g-2c56CVE-2026-32040same package and registry as the line abovelowsame change as the line aboveTime to revision 27 days
2026-03-30published 2026-03-19Advisory withdrawnGHSA-x6gf-mpr2-68h6CVE-2026-4427whole advisoryhighwithdrawn 2026-03-30Time to revision 11 days
Fri 27 Mar 2026· 8 changes
2026-03-27published 2026-03-24Advisory fix version movedGHSA-x4ff-q6h8-v7gwCVE-2026-32948
mavenorg.scala-sbt:sbt
moderate
stated at publication 1.12.7, now states 1.12.8Time to revision 3 days
2026-03-27published 2026-03-13Package added to advisoryGHSA-q926-c743-49qjlownot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v3 and 2 moreTime to revision 14 days
2026-03-27published 2026-03-13same kind of change as the line aboveGHSA-q926-c743-49qjsame package registry as the line abovelownot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v3Time to revision 14 days
2026-03-27published 2026-03-13same kind of change as the line aboveGHSA-q926-c743-49qjsame package registry as the line abovelownot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v4Time to revision 14 days
2026-03-27published 2026-03-13same kind of change as the line aboveGHSA-q926-c743-49qjsame package registry as the line abovelownot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v5Time to revision 14 days
2026-03-27published 2026-03-13Package added to advisoryGHSA-j77h-rr39-c552criticalnot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v3 and 2 moreTime to revision 14 days
2026-03-27published 2026-03-13same kind of change as the line aboveGHSA-j77h-rr39-c552CVE-2026-32301same package registry as the line abovecriticalnot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v3Time to revision 14 days
2026-03-27published 2026-03-13same kind of change as the line aboveGHSA-j77h-rr39-c552CVE-2026-32301same package registry as the line abovecriticalnot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v4Time to revision 14 days
2026-03-27published 2026-03-13same kind of change as the line aboveGHSA-j77h-rr39-c552CVE-2026-32301same package registry as the line abovecriticalnot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v5Time to revision 14 days
2026-03-27published 2026-02-28Advisory severity changedGHSA-72hv-8253-57qqCVE-2026-18401whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 28 days
Wed 25 Mar 2026· 6 changes
2026-03-25published 2026-03-01Advisory fix version movedGHSA-cpv7-q2wx-m8rwCVE-2026-28425
packagiststatamic/cms
high
stated at publication 5.73.11, now states 5.73.16Time to revision 25 days
2026-03-25published 2026-03-01Advisory fix version movedGHSA-cpv7-q2wx-m8rwCVE-2026-28425
packagiststatamic/cms
high
stated at publication 6.4.0, now states 6.7.2Time to revision 25 days
2026-03-25published 2026-02-13Advisory severity changedGHSA-g433-pq76-6cmfwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 40 days
2026-03-25published 2026-03-03Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 22 days
2026-03-25published 2026-03-03same kind of change as the line aboveGHSA-f8mp-vj46-cq8vCVE-2026-32032same package and registry as the line abovehighsame change as the line aboveTime to revision 22 days
2026-03-25published 2026-03-03same kind of change as the line aboveGHSA-jv6r-27ww-4gw4CVE-2026-32027same package and registry as the line abovehighsame change as the line aboveTime to revision 22 days
2026-03-25published 2026-03-17Advisory severity changedGHSA-6gx3-4362-rf54CVE-2026-32766whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Time to revision 8 days
Fri 20 Mar 2026· 1 change
2026-03-20published 2026-03-07Advisory withdrawnGHSA-6f6w-6j58-rq76CVE-2026-30916whole advisorylowwithdrawn 2026-03-20Time to revision 14 days
Thu 19 Mar 2026· 4 changes
2026-03-19published 2026-02-24Advisory fix version movedGHSA-jxq9-79vj-rgvwCVE-2026-27593
packagiststatamic/cms
critical
stated at publication 6.3.3, now states 6.7.1Time to revision 23 days
2026-03-19published 2026-02-09Advisory fix version movedGHSA-87r5-mp6g-5w5jCVE-2026-1615
npmjsonpath
high
stated at publication 1.2.1, now states 1.3.0Time to revision 9 days
2026-03-19published 2026-03-03Advisory severity changedGHSA-9p38-94jf-hgjjCVE-2026-22179whole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Time to revision 16 days
2026-03-19published 2026-03-03Advisory severity changedGHSA-8mvx-p2r9-r375CVE-2026-22181whole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Time to revision 16 days
Tue 17 Mar 2026· 1 change
2026-03-17published 2026-03-16Advisory severity changedGHSA-cc7p-2j3x-x7xfCVE-2026-32267whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 1 days
Fri 13 Mar 2026· 1 change
2026-03-13published 2026-03-11Package added to advisoryGHSA-8q2w-wr49-whqjCVE-2026-29777moderatenot named as affected when the advisory was published, now names github.com/traefik/traefik/v2Time to revision 2 days
Thu 12 Mar 2026· 1 change
2026-03-12published 2026-03-10Package added to advisoryGHSA-hhfx-wfvq-7g9cCVE-2026-26118highnot named as affected when the advisory was published, now names @azure/mcpTime to revision 2 days

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

What this page cannot see

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Paste your closed CVE tickets and see which of these changes hit them →