Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Fri 4 Aug 2023· 15 advisory changes
2023-08-04published 2019-10-11 to 2021-12-09Package added to advisory3 bandsnot named as affected when the advisory was published, now names org.jboss.netty:nettynot dated
2023-08-04published 2021-12-09same kind of change as the line aboveGHSA-wx5j-54mm-rqqqCVE-2021-43797same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-04published 2021-09-09same kind of change as the line aboveGHSA-9vjp-v76f-g363CVE-2021-37137same package registry as the line abovehighsame change as the line abovenot dated
2023-08-04published 2021-09-09same kind of change as the line aboveGHSA-grg4-wf29-r9vvCVE-2021-37136same package registry as the line abovehighsame change as the line abovenot dated
2023-08-04published 2021-03-30same kind of change as the line aboveGHSA-f256-j965-7f32CVE-2021-21409same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-04published 2021-03-09same kind of change as the line aboveGHSA-wm47-8v5p-wjpjCVE-2021-21295same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-04published 2021-02-08same kind of change as the line aboveGHSA-5mcr-gq6c-3hq2CVE-2021-21290same package registry as the line abovemoderatesame change as the line abovenot dated
2023-08-04published 2020-02-21same kind of change as the line aboveGHSA-cqqj-4p63-rrmmCVE-2019-20444same package registry as the line abovecriticalsame change as the line abovenot dated
2023-08-04published 2020-02-21same kind of change as the line aboveGHSA-p2v9-g2qv-p635CVE-2019-20445same package registry as the line abovemoderatesame change as the line abovenot dated
2 more rows in this change are not listed here. Open all 10 rows
2023-08-04published 2020-06-30Package added to advisoryGHSA-xfv3-rrfm-f2rvCVE-2015-2156highnot named as affected when the advisory was published, now names io.netty:netty-parentnot dated
2023-08-04published 2023-07-31Advisory severity changedGHSA-p6hw-wm59-3g5gCVE-2023-38686whole advisorycriticalstated at publication LOW, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 4
2023-08-04published 2023-08-01 to 2023-08-03Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 1 to 3
2023-08-04published 2023-08-03same kind of change as the line aboveGHSA-jj95-55cr-9597CVE-2023-36480same package and registry as the line abovecriticalsame change as the line aboveDays to revision 1
2023-08-04published 2023-08-01same kind of change as the line aboveGHSA-7c28-wg7r-pg6fCVE-2022-39986same package and registry as the line abovecriticalsame change as the line aboveDays to revision 3
2023-08-04published 2023-08-01Advisory severity changedGHSA-7r88-wjhj-jr8mCVE-2022-39987whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 3
Thu 3 Aug 2023· 15 advisory changes
2023-08-03published 2022-05-24Package added to advisoryGHSA-c3mp-9vx3-2rvvhighnot named as affected when the advisory was published, now names org.opennms.features:org.opennms.features.measurements and 2 moreDays to revision 436
2023-08-03published 2022-05-24same kind of change as the line aboveGHSA-c3mp-9vx3-2rvvCVE-2021-3396same package registry as the line abovehighnot named as affected when the advisory was published, now names org.opennms.features:org.opennms.features.measurementsDays to revision 436
2023-08-03published 2022-05-24same kind of change as the line aboveGHSA-c3mp-9vx3-2rvvCVE-2021-3396same package registry as the line abovehighnot named as affected when the advisory was published, now names org.opennms:opennms-provisionDays to revision 436
2023-08-03published 2022-05-24same kind of change as the line aboveGHSA-c3mp-9vx3-2rvvCVE-2021-3396same package registry as the line abovehighnot named as affected when the advisory was published, now names org.opennms:opennms-utilDays to revision 436
2023-08-03published 2022-05-13Package added to advisoryGHSA-hmx6-gc2p-5p82CVE-2019-5919criticalnot named as affected when the advisory was published, now names com.nablarch.framework:nablarch-fw-webDays to revision 448
2023-08-03published 2023-07-29Advisory severity changedGHSA-r969-8v3h-23v9CVE-2023-36542whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
2023-08-03published 2023-07-25 to 2023-07-28Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6 to 9
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-859m-2pfx-fwhfCVE-2023-39022same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-fx3v-4w3w-wpwrCVE-2023-39021same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-2h26-qfxm-r3pqCVE-2023-37754same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-353m-jh2m-72v4CVE-2023-39020same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-99p5-qpqx-mhwcCVE-2023-39010same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-grvq-vjqr-x8vmCVE-2023-39015same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-p83q-99rc-vfmvCVE-2023-39013same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-08-03published 2023-07-28same kind of change as the line aboveGHSA-wp6c-29r3-jqw9CVE-2023-38992same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
1 more row in this change is not listed here. Open all 9 rows
2023-08-03published 2023-07-25Advisory severity changedGHSA-xqr8-7jwr-rhp7CVE-2023-37920whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
Tue 1 Aug 2023· 2 advisory changes
2023-08-01published 2023-07-24Advisory severity changedGHSA-pmhc-2g4f-85cgCVE-2023-34478whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-08-01published 2022-05-13Advisory withdrawnGHSA-6hvf-xvwm-vrw4CVE-2019-9628whole advisoryhighwithdrawn 2023-08-01Days to revision 446
Mon 31 Jul 2023· 4 advisory changes
2023-07-31published 2022-01-06Package added to advisoryGHSA-7q8g-gpfp-v8gxhighnot named as affected when the advisory was published, now names org.apache.nifi:nifi-framework-core and 1 morenot dated
2023-07-31published 2022-01-06same kind of change as the line aboveGHSA-7q8g-gpfp-v8gxCVE-2020-1942same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.nifi:nifi-framework-corenot dated
2023-07-31published 2022-01-06same kind of change as the line aboveGHSA-7q8g-gpfp-v8gxCVE-2020-1942same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.nifi:nifi-security-utilsnot dated
2023-07-31published 2023-03-16Package added to advisoryGHSA-p8p7-x288-28g6CVE-2023-28155moderatenot named as affected when the advisory was published, now names @cypress/requestDays to revision 137
2023-07-31published 2022-03-11Advisory withdrawnGHSA-29vr-79w7-p649CVE-2021-44597whole advisorycriticalwithdrawn 2023-07-31Days to revision 508
Fri 28 Jul 2023· 4 advisory changes
2023-07-28published 2022-06-15 to 2022-10-26Package added to advisory2 bandsnot named as affected when the advisory was published, now names org.apache.flume.flume-ng-sources:flume-jms-sourcenot dated
2023-07-28published 2022-10-26same kind of change as the line aboveGHSA-9w4g-fp9h-3q2vCVE-2022-42468same package registry as the line abovecriticalsame change as the line abovenot dated
2023-07-28published 2022-06-15same kind of change as the line aboveGHSA-x5m7-rwfx-w7qmCVE-2022-25167same package registry as the line abovehighsame change as the line abovenot dated
2023-07-28published 2023-07-19Advisory severity changedGHSA-3cxh-xp3g-jxjmCVE-2023-28754whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2023-07-28published 2021-10-22Advisory severity changedGHSA-pjwm-rvh2-c87wCVE-2021-4229whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.not dated
Thu 27 Jul 2023· 3 advisory changes
2023-07-27published 2023-07-14 to 2023-07-18Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9 to 13
2023-07-27published 2023-07-14same kind of change as the line aboveGHSA-7gj7-224w-vpr3CVE-2023-38286same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-07-27published 2023-07-18same kind of change as the line aboveGHSA-4r8x-2p26-976pCVE-2023-37788same package and registry as the line abovehighsame change as the line aboveDays to revision 9
2023-07-27published 2023-07-15same kind of change as the line aboveGHSA-vc79-65pr-q82vCVE-2023-38337same package and registry as the line abovehighsame change as the line aboveDays to revision 13
Wed 26 Jul 2023· 3 advisory changes
2023-07-26published 2023-07-20Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
2023-07-26published 2023-07-20same kind of change as the line aboveGHSA-45g2-r339-pjwfCVE-2023-37650same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-07-26published 2023-07-20same kind of change as the line aboveGHSA-9r25-4j77-9wc7CVE-2023-37649same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-07-26published 2023-07-16Advisory severity changedGHSA-hx4h-676r-j3qpCVE-2023-3691whole advisorymoderatestated at publication LOW, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 10
Tue 25 Jul 2023· 2 advisory changes
2023-07-25published 2023-03-31Package added to advisoryGHSA-5c9c-6x87-f9vmCVE-2022-4899highnot named as affected when the advisory was published, now names zstdDays to revision 116
2023-07-25published 2023-07-13Advisory severity changedGHSA-4q2q-q5pw-2342CVE-2023-37415whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 12
Mon 24 Jul 2023· 2 advisory changes
2023-07-24published 2022-05-14Package added to advisoryGHSA-43q7-q5vp-3g68CVE-2018-14371highnot named as affected when the advisory was published, now names org.glassfish:mojarra-parentnot dated
2023-07-24published 2022-01-12Advisory severity changedGHSA-7w54-gp8x-f33mCVE-2022-21671whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
Fri 21 Jul 2023· 3 advisory changes
2023-07-21published 2022-08-16Package added to advisoryGHSA-8wj3-cpmr-8whpCVE-2022-2818highnot named as affected when the advisory was published, now names cockpit-hq/cockpitnot dated
2023-07-21published 2023-07-19Package added to advisoryGHSA-9436-3gmp-4f53CVE-2023-37897highnot named as affected when the advisory was published, now names getgrav/gravDays to revision 2
2023-07-21published 2022-01-08Advisory severity changedGHSA-9fj5-jg6f-qg5rCVE-2021-45458whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
Thu 20 Jul 2023· 12 advisory changes
2023-07-20published 2023-07-11 to 2023-07-12Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8 to 9
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-74mc-g2xv-pch2CVE-2023-37579same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-07-20published 2023-07-11same kind of change as the line aboveGHSA-469h-mqg8-535rCVE-2023-32693same package and registry as the line abovemoderatesame change as the line aboveDays to revision 9
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-wvgr-5wgr-c6fjCVE-2023-37952same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-g4c3-4f3v-84x8CVE-2023-37942same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-m9jj-p947-m8xvCVE-2023-37953same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-07-20published 2023-07-12Advisory severity changedGHSA-j927-w6g7-7c7wCVE-2023-32200whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8
2023-07-20published 2023-07-12Advisory severity changedGHSA-gpq8-963w-8qc9CVE-2023-37582whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-07-20published 2023-07-12Advisory severity changedGHSA-g8c3-6fj2-87w7CVE-2023-37943whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2023-07-20published 2023-07-12Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-7jrr-fwhw-762vCVE-2023-37958same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-wgvx-9rh5-4g4mCVE-2023-37962same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-p756-66w2-35g7CVE-2023-37961same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-07-20published 2023-07-12same kind of change as the line aboveGHSA-5v46-54vj-4mjqCVE-2023-37964same package and registry as the line abovehighsame change as the line aboveDays to revision 8
Wed 19 Jul 2023· 7 advisory changes
2023-07-19published 2023-07-11Advisory fix version moved4 rows, one per advisory and package
rubygems2 packages
2 bands
stated at publication 0.26.6, now states 0.26.7Days to revision 8
2023-07-19published 2023-07-11Advisory fix version movedGHSA-5652-92r9-3fx9CVE-2023-34089
rubygemsdecidim
high
same change as the line aboveDays to revision 8
2023-07-19published 2023-07-11Advisory fix version movedGHSA-5652-92r9-3fx9CVE-2023-34089
rubygemsdecidim-core
high
same change as the line aboveDays to revision 8
2023-07-19published 2023-07-11Advisory fix version movedGHSA-469h-mqg8-535rCVE-2023-32693
rubygemsdecidim
moderate
same change as the line aboveDays to revision 8
2023-07-19published 2023-07-11Advisory fix version movedGHSA-469h-mqg8-535rCVE-2023-32693
rubygemsdecidim-core
moderate
same change as the line aboveDays to revision 8
2023-07-19published 2022-05-24Package added to advisoryGHSA-gfwj-fwqj-fp3vCVE-2021-22118highnot named as affected when the advisory was published, now names org.springframework:spring-webnot dated
2023-07-19published 2023-07-10Advisory severity changedGHSA-6qq7-3hqc-p5w4CVE-2023-3566whole advisorymoderatestated at publication LOW, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 9
2023-07-19published 2023-07-10Advisory severity changedGHSA-6g2w-257v-3c9fCVE-2023-34442whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 9
Tue 18 Jul 2023· 4 advisory changes
2023-07-18published 2023-07-14Package added to advisoryGHSA-7gj7-224w-vpr3CVE-2023-38286highnot named as affected when the advisory was published, now names de.codecentric:spring-boot-admin-serverDays to revision 5
2023-07-18published 2023-07-05Advisory severity changedGHSA-mvj3-qrqh-cjvrCVE-2023-34450whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 13
2023-07-18published 2023-07-11Advisory severity changedGHSA-jx3q-5rgf-vrrrCVE-2023-37659whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-07-18published 2023-01-13Advisory withdrawnGHSA-vhvq-jh34-3fc8whole advisorymoderatewithdrawn 2023-07-18Days to revision 187
Sat 15 Jul 2023· 2 advisory changes
2023-07-15published 2023-07-06Package added to advisorymoderatenot named as affected when the advisory was published, now names github.com/zinclabs/zincDays to revision 8
2023-07-15published 2023-07-06same kind of change as the line aboveGHSA-4fgv-8448-gf82CVE-2022-32171same package registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-07-15published 2023-07-06same kind of change as the line aboveGHSA-7j6x-42mm-p7jmCVE-2022-32172same package registry as the line abovemoderatesame change as the line aboveDays to revision 8
Fri 14 Jul 2023· 1 advisory change
2023-07-14published 2023-07-08Advisory severity changedGHSA-2rhg-hqq9-8xjhCVE-2023-3553whole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 6
Thu 13 Jul 2023· 1 advisory change
2023-07-13published 2023-07-07Advisory withdrawnGHSA-f7xj-rg7h-mc87whole advisorylowwithdrawn 2023-07-13Days to revision 6
Wed 12 Jul 2023· 2 advisory changes
2023-07-12published 2023-07-06Advisory severity changedGHSA-57fc-8q82-gfp3CVE-2023-36188whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6
2023-07-12published 2023-07-05Advisory severity changedGHSA-9jx5-6pgf-crrpCVE-2023-25399whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7
Tue 11 Jul 2023· 3 advisory changes
2023-07-11published 2023-07-10Advisory fix version movedGHSA-q9w4-w667-qqj4CVE-2023-37905
npmckeditor-wordcount-plugin
moderate
stated at publication 1.17.11, now states 1.17.12Days to revision 1
2023-07-11published 2023-07-03Advisory severity changedGHSA-jh3w-4vvf-mjgrCVE-2023-36053whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8
2023-07-11published 2023-07-03Advisory severity changedGHSA-hg6c-qqcm-r79rCVE-2023-35797whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
Mon 10 Jul 2023· 2 advisory changes
2023-07-10published 2023-07-03Advisory severity changedGHSA-2qmj-7962-cjq8CVE-2023-36258whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-07-10published 2023-06-30Advisory severity changedGHSA-v4f4-23wc-99mhCVE-2023-31543whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 10
Fri 7 Jul 2023· 3 advisory changes
2023-07-07published 2023-06-30Advisory severity changedGHSA-3p62-6fjh-3p5hCVE-2022-4361whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-07-07published 2023-06-29Advisory severity changedGHSA-vv6q-6hwp-vrgpCVE-2020-26710whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8
2023-07-07published 2022-01-27Advisory severity changedGHSA-m36x-mgfh-8g78CVE-2023-36474whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
Thu 6 Jul 2023· 5 advisory changes
2023-07-06published 2023-06-30Package added to advisoryGHSA-fmrf-p77g-vv5cCVE-2023-37302moderatenot named as affected when the advisory was published, now names wikibase/wikibaseDays to revision 6
2023-07-06published 2023-06-27 to 2023-06-29Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7 to 9
2023-07-06published 2023-06-29same kind of change as the line aboveGHSA-ccrc-9x59-3vc4CVE-2020-26708same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-07-06published 2023-06-29same kind of change as the line aboveGHSA-j6v2-mwxm-f952CVE-2020-26709same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-07-06published 2023-06-29same kind of change as the line aboveGHSA-mm87-c3x2-6f89CVE-2023-22886same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-07-06published 2023-06-27same kind of change as the line aboveGHSA-9766-v29c-4vm7CVE-2023-34395same package and registry as the line abovehighsame change as the line aboveDays to revision 9
Wed 5 Jul 2023· 7 advisory changes
2023-07-05published 2022-12-28Advisory fix version movedGHSA-6jvc-q2x7-pchvCVE-2022-2582
gogithub.com/aws/aws-sdk-go
moderate
stated at publication 1.33.0, now states 1.34.0Days to revision 44
2023-07-05published 2018-01-22 to 2020-09-01Package added to advisorymoderatenot named as affected when the advisory was published, now names jquery-railsnot dated
2023-07-05published 2020-09-01same kind of change as the line aboveGHSA-2pqj-h3vj-pqgwCVE-2012-6708same package registry as the line abovemoderatesame change as the line abovenot dated
2023-07-05published 2018-01-22same kind of change as the line aboveGHSA-rmxg-73gg-4p98CVE-2015-9251same package registry as the line abovemoderatesame change as the line abovenot dated
2023-07-05published 2020-05-20same kind of change as the line aboveGHSA-q4m3-2j7h-f7xwCVE-2020-7656same package registry as the line abovemoderatesame change as the line abovenot dated
2023-07-05published 2022-09-17Advisory severity changedGHSA-3f7h-mf4q-vrm4CVE-2022-40152whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-07-05published 2023-06-26Advisory severity changedGHSA-cgmm-c2m9-ff7rCVE-2021-31635whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9
2023-07-05published 2023-06-23Advisory severity changedGHSA-pm73-x2h5-cmj3CVE-2023-31469whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 12
Tue 4 Jul 2023· 1 advisory change
2023-07-04published 2018-08-08Advisory severity changedGHSA-pxqr-8v54-m2hjCVE-2016-10522whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
Mon 3 Jul 2023· 3 advisory changes
2023-07-03published 2022-02-15Package added to advisoryGHSA-x5m6-jh4r-34mvCVE-2014-0177moderatenot named as affected when the advisory was published, now names hubnot dated
2023-07-03published 2023-06-22Advisory severity changedGHSA-w65q-jcmv-28gjCVE-2023-32571whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 11
2023-07-03published 2023-06-23Advisory severity changedGHSA-hhqm-f4m4-pq39CVE-2023-30260whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
Fri 30 Jun 2023· 9 advisory changes
2023-06-30published 2023-06-16Advisory severity changedGHSA-xc8m-28vv-4pjcCVE-2023-2431whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 15
2023-06-30published 2021-11-23Advisory severity changedGHSA-g3p2-hfqr-9m25CVE-2021-22968whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-06-30published 2021-05-11Advisory severity changedGHSA-23x4-m842-fmwfCVE-2021-21428whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-06-30published 2023-06-21 to 2023-06-22Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8 to 9
2023-06-30published 2023-06-22same kind of change as the line aboveGHSA-xxp4-mf4h-6cwmCVE-2023-35133same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-06-30published 2023-06-21same kind of change as the line aboveGHSA-mppv-79ch-vw6qCVE-2023-34981same package and registry as the line abovehighsame change as the line aboveDays to revision 9
2023-06-30published 2023-06-22Advisory severity changedGHSA-q2fp-jw87-86pxCVE-2023-29931whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-06-30published 2023-06-23Advisory severity changedGHSA-hm75-8w6h-4f8fCVE-2023-3302whole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 7
2023-06-30published 2022-03-12 to 2023-05-26Advisory withdrawnwhole advisory2 bandswithdrawn 2023-06-30Days to revision 35 to 476
2023-06-30published 2022-03-12same kind of change as the line aboveGHSA-65f3-3278-7m65same package and registry as the line abovehighwithdrawn 2023-06-30Days to revision 476
2023-06-30published 2023-05-26same kind of change as the line aboveGHSA-c892-cwq6-qrqfsame package and registry as the line abovemoderatewithdrawn 2023-06-30Days to revision 35
Wed 28 Jun 2023· 6 advisory changes
2023-06-28published 2023-06-21Advisory severity changedGHSA-fqhp-rhm6-8rrjCVE-2023-33289whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-06-28published 2023-06-21 to 2023-06-22Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6 to 7
2023-06-28published 2023-06-22same kind of change as the line aboveGHSA-5m3m-q8cq-77g4CVE-2023-36097same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-06-28published 2023-06-21same kind of change as the line aboveGHSA-hp5w-w29m-vg63CVE-2023-34340same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-06-28published 2023-06-20Advisory severity changedGHSA-h7cw-44vp-jq7hCVE-2023-35166whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2023-06-28published 2023-06-23Advisory severity changedGHSA-vmxg-wx6c-4f3rCVE-2023-3303whole advisorylowstated at publication MODERATE, now states LOWCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 5
2023-06-28published 2023-06-13Advisory withdrawnGHSA-3x74-v64j-qc3fCVE-2023-30179whole advisoryhighwithdrawn 2023-06-28Days to revision 15
Tue 27 Jun 2023· 16 advisory changes
2023-06-27published 2023-06-19 to 2023-06-20Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7 to 9
2023-06-27published 2023-06-20same kind of change as the line aboveGHSA-6643-h7h5-x9whCVE-2023-34541same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-06-27published 2023-06-20same kind of change as the line aboveGHSA-6vf2-mfmr-qqqwCVE-2020-21489same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-06-27published 2023-06-20same kind of change as the line aboveGHSA-q3q5-qvh5-cmw5CVE-2020-21174same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-06-27published 2023-06-19same kind of change as the line aboveGHSA-7q8c-49f4-4c8qCVE-2023-35839same package and registry as the line abovecriticalsame change as the line aboveDays to revision 9
2023-06-27published 2023-06-20Advisory severity changedGHSA-4cw3-rhqx-vqwrCVE-2020-20726whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-06-27published 2022-03-11Advisory severity changedGHSA-jr9c-h74f-2v28CVE-2022-0905whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-06-27published 2023-06-14Advisory severity changedwhole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 13
2023-06-27published 2023-06-14same kind of change as the line aboveGHSA-p4c9-x742-qh8cCVE-2023-34616same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-06-27published 2023-06-14same kind of change as the line aboveGHSA-75r3-38rh-pmxvCVE-2023-34613same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-06-27published 2023-06-14same kind of change as the line aboveGHSA-5wfc-hjrc-gq87CVE-2023-34620same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-06-27published 2023-06-14same kind of change as the line aboveGHSA-66gv-5m8q-rrjcCVE-2023-34614same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-06-27published 2023-06-14same kind of change as the line aboveGHSA-75m3-f4hr-2vh9CVE-2023-35110same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-06-27published 2023-06-14same kind of change as the line aboveGHSA-779h-3r69-4f5pCVE-2023-34610same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-06-27published 2023-06-14same kind of change as the line aboveGHSA-mx27-gg24-h2jcCVE-2023-34612same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-06-27published 2020-07-07Advisory severity changedGHSA-vjv6-gq77-3mjwCVE-2020-15232whole advisorycriticalstated at publication LOW, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-06-27published 2023-06-16Advisory severity changedGHSA-934g-fvcc-4833CVE-2023-34659whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 11
2023-06-27published 2021-05-06Advisory withdrawnGHSA-p7j5-4mwm-hv86whole advisorymoderatewithdrawn 2023-06-27Days to revision 782
Mon 26 Jun 2023· 3 advisory changes
2023-06-26published 2023-06-15Advisory severity changedGHSA-p2qf-9vp6-3jjqCVE-2023-3276whole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 11
2023-06-26published 2023-06-14Advisory severity changedGHSA-jv4x-j47q-6qvpCVE-2023-34624whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 12
2023-06-26published 2020-09-01Advisory severity changedGHSA-2pqj-h3vj-pqgwCVE-2012-6708whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
Fri 23 Jun 2023· 2 advisory changes
2023-06-23published 2023-01-18 to 2023-06-14Advisory severity changedwhole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9 to 156
2023-06-23published 2023-06-14same kind of change as the line aboveGHSA-fj64-qprx-q7vqCVE-2023-34617same package and registry as the line abovehighsame change as the line aboveDays to revision 9
2023-06-23published 2023-01-18same kind of change as the line aboveGHSA-65f5-mfpf-vfhjCVE-2022-44570same package and registry as the line abovehighsame change as the line aboveDays to revision 156
Wed 21 Jun 2023· 4 advisory changes
2023-06-21published 2023-06-14Advisory severity changedGHSA-4g42-gqrg-4633CVE-2023-34396whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2023-06-21published 2023-06-13Advisory severity changedGHSA-7mcw-xmx3-7p8mCVE-2023-33695whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8
2023-06-21published 2023-06-12Advisory severity changedGHSA-65wh-g8x8-gm2hCVE-2023-34212whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 9
2023-06-21published 2017-12-28Advisory withdrawnGHSA-7fpw-cfc4-3p2cwhole advisoryhighwithdrawn 2023-06-21Days to revision 2,001
Tue 20 Jun 2023· 1 advisory change
2023-06-20published 2019-03-14Advisory severity changedGHSA-77rv-6vfw-x4gcCVE-2019-3778whole advisorymoderatestated at publication CRITICAL, now states MODERATENo CVSS vector was stated in the first observed version.not dated
Mon 19 Jun 2023· 4 advisory changes
2023-06-19published 2017-10-24Package added to advisory4 rows, one per advisory and packagemoderatenot named as affected when the advisory was published, now names actionpack and 1 morenot dated
2023-06-19published 2017-10-24same kind of change as the line aboveGHSA-v9v4-7jp6-8c73CVE-2011-2197same package registry as the line abovemoderatenot named as affected when the advisory was published, now names actionpacknot dated
2023-06-19published 2017-10-24same kind of change as the line aboveGHSA-v9v4-7jp6-8c73CVE-2011-2197same package registry as the line abovemoderatenot named as affected when the advisory was published, now names activesupportnot dated
2023-06-19published 2017-10-24same kind of change as the line aboveGHSA-8qrh-h9m2-5fvfCVE-2009-3009same package registry as the line abovemoderatenot named as affected when the advisory was published, now names actionpacknot dated
2023-06-19published 2017-10-24same kind of change as the line aboveGHSA-8qrh-h9m2-5fvfCVE-2009-3009same package registry as the line abovemoderatenot named as affected when the advisory was published, now names activesupportnot dated
Fri 16 Jun 2023· 6 advisory changes
2023-06-16published 2023-06-12Advisory severity changedGHSA-3w3w-pxmm-2w2jCVE-2020-36732whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 5
2023-06-16published 2023-06-07Advisory severity changedGHSA-v3v9-3jf4-5pxxCVE-2023-33510whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2023-06-16published 2023-06-06Advisory severity changedGHSA-9m3v-v4r5-ppx7CVE-2023-33957whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 10
2023-06-16published 2023-06-10Advisory severity changedGHSA-p7xm-g427-jxfcCVE-2023-3190whole advisorymoderatestated at publication LOW, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 6
2023-06-16published 2023-06-10Advisory severity changedGHSA-qmw8-x364-xxxmCVE-2023-3191whole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 6
2023-06-16published 2023-06-07Advisory severity changedGHSA-c29g-q3h3-mwcfCVE-2023-33496whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →