Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Fri 16 Jun 2023· 1 advisory change
2023-06-16published 2023-03-14Advisory severity changedGHSA-hw7c-3rfg-p46jCVE-2023-24535whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 94
Wed 14 Jun 2023· 2 advisory changes
2023-06-14published 2023-06-09Advisory severity changedGHSA-ghqq-jfx7-f6m9CVE-2023-3172whole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 6
2023-06-14published 2023-06-07Advisory severity changedGHSA-fqcv-rfp6-wv92CVE-2023-3142whole advisorymoderatestated at publication LOW, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 7
Tue 13 Jun 2023· 3 advisory changes
2023-06-13published 2023-06-07Advisory severity changedGHSA-hh54-53m7-7ffjCVE-2023-33498whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
2023-06-13published 2021-08-25Advisory severity changedGHSA-xwxc-j97j-84gfwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-06-13published 2021-08-25Advisory severity changedGHSA-4x25-pvhw-5224CVE-2019-16143whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
Mon 12 Jun 2023· 15 advisory changes
2023-06-12published 2022-05-17Package added to advisoryGHSA-95xq-v4m2-fq3rCVE-2013-4489moderatenot named as affected when the advisory was published, now names gitlab-gritDays to revision 392
2023-06-12published 2022-10-13Package added to advisoryGHSA-599f-7c49-w659CVE-2022-42889criticalnot named as affected when the advisory was published, now names com.guicedee.services:commons-textnot dated
2023-06-12published 2020-06-15Package added to advisoryGHSA-6hgm-866r-3cjvhighnot named as affected when the advisory was published, now names net.sourceforge.collections:collections-generic and 2 morenot dated
2023-06-12published 2020-06-15same kind of change as the line aboveGHSA-6hgm-866r-3cjvCVE-2015-6420same package registry as the line abovehighnot named as affected when the advisory was published, now names net.sourceforge.collections:collections-genericnot dated
2023-06-12published 2020-06-15same kind of change as the line aboveGHSA-6hgm-866r-3cjvCVE-2015-6420same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.servicemix.bundles:org.apache.servicemix.bundles.collections-genericnot dated
2023-06-12published 2020-06-15same kind of change as the line aboveGHSA-6hgm-866r-3cjvCVE-2015-6420same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.servicemix.bundles:org.apache.servicemix.bundles.commons-collectionsnot dated
2023-06-12published 2022-09-06Package added to advisoryGHSA-c4r9-r8fh-9vj2moderatenot named as affected when the advisory was published, now names be.cylab:snakeyaml and 5 morenot dated
2023-06-12published 2022-09-06same kind of change as the line aboveGHSA-c4r9-r8fh-9vj2CVE-2022-38749same package registry as the line abovemoderatenot named as affected when the advisory was published, now names be.cylab:snakeyamlnot dated
2023-06-12published 2022-09-06same kind of change as the line aboveGHSA-c4r9-r8fh-9vj2CVE-2022-38749same package registry as the line abovemoderatenot named as affected when the advisory was published, now names com.alipay.sofa.acts:acts-common-utilnot dated
2023-06-12published 2022-09-06same kind of change as the line aboveGHSA-c4r9-r8fh-9vj2CVE-2022-38749same package registry as the line abovemoderatenot named as affected when the advisory was published, now names io.prometheus.jmx:jmx_prometheus_httpservernot dated
2023-06-12published 2022-09-06same kind of change as the line aboveGHSA-c4r9-r8fh-9vj2CVE-2022-38749same package registry as the line abovemoderatenot named as affected when the advisory was published, now names io.prometheus.jmx:jmx_prometheus_httpserver_java6not dated
2023-06-12published 2022-09-06same kind of change as the line aboveGHSA-c4r9-r8fh-9vj2CVE-2022-38749same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.testifyproject.external:external-snakeyamlnot dated
2023-06-12published 2022-09-06same kind of change as the line aboveGHSA-c4r9-r8fh-9vj2CVE-2022-38749same package registry as the line abovemoderatenot named as affected when the advisory was published, now names pl.droidsonroids.yaml:snakeyamlnot dated
2023-06-12published 2017-10-24Package added to advisoryGHSA-75w6-p6mg-vh8jCVE-2011-0446moderatenot named as affected when the advisory was published, now names actionviewnot dated
2023-06-12published 2022-12-25Advisory severity changedGHSA-8gh8-hqwg-xf34CVE-2021-4279whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 169
2023-06-12published 2023-06-05 to 2023-06-06Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6 to 8
2023-06-12published 2023-06-06same kind of change as the line aboveGHSA-qcm3-vfq5-wfr2CVE-2023-31606same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-06-12published 2023-06-05same kind of change as the line aboveGHSA-7gf7-jv65-wjmhCVE-2023-34411same package and registry as the line abovehighsame change as the line aboveDays to revision 8
Fri 9 Jun 2023· 9 advisory changes
2023-06-09published 2018-03-21Package added to advisoryGHSA-x7rv-cr6v-4vm4CVE-2018-8048moderatenot named as affected when the advisory was published, now names nokogirinot dated
2023-06-09published 2017-10-24Package added to advisory2 bandsnot named as affected when the advisory was published, now names actionpacknot dated
2023-06-09published 2017-10-24same kind of change as the line aboveGHSA-xrr4-p6fq-hjg7CVE-2016-0752same package registry as the line abovehighsame change as the line abovenot dated
2023-06-09published 2017-10-24same kind of change as the line aboveGHSA-vx9j-46rh-fqr8CVE-2016-2097same package registry as the line abovemoderatesame change as the line abovenot dated
2023-06-09published 2017-10-24same kind of change as the line aboveGHSA-m46p-ggm5-5j83CVE-2014-0081same package registry as the line abovemoderatesame change as the line abovenot dated
2023-06-09published 2017-10-24Advisory severity changedGHSA-9hx9-w2j6-rw76CVE-2013-2105whole advisorymoderatestated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-06-09published 2019-03-13Advisory severity changedGHSA-m63j-wh5w-c252CVE-2019-5419whole advisoryhighstated at publication CRITICAL, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-06-09published 2023-06-03Advisory severity changedGHSA-c6fv-3jm9-6r8fCVE-2023-3083whole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 6
2023-06-09published 2023-06-01 to 2023-06-06Advisory withdrawnwhole advisory2 bandswithdrawn 2023-06-09Days to revision 3 to 9
2023-06-09published 2023-06-06same kind of change as the line aboveGHSA-wm7r-3qxj-5xgqsame package and registry as the line abovemoderatewithdrawn 2023-06-09Days to revision 3
2023-06-09published 2023-06-01same kind of change as the line aboveGHSA-qj8w-rv5x-2v9hsame package and registry as the line abovehighwithdrawn 2023-06-09Days to revision 9
Thu 8 Jun 2023· 2 advisory changes
2023-06-08published 2023-05-26Advisory severity changedGHSA-xf96-w227-r7c4CVE-2023-20883whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 13
2023-06-08published 2023-06-01Advisory severity changedGHSA-qj8w-rv5x-2v9hwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
Wed 7 Jun 2023· 3 advisory changes
2023-06-07published 2023-05-30Advisory severity changedGHSA-jqvr-j2vg-gjrvCVE-2023-34205whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9
2023-06-07published 2023-05-31Advisory severity changedGHSA-h5g9-2p35-54c7CVE-2023-3009whole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 7
2023-06-07published 2023-06-06Advisory severity changedGHSA-26c5-ppr8-f33pCVE-2023-32682whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 1
Tue 6 Jun 2023· 6 advisory changes
2023-06-06published 2023-05-26 to 2023-05-29Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8 to 11
2023-06-06published 2023-05-29same kind of change as the line aboveGHSA-9wqr-5jp4-mjmhCVE-2023-30253same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-06-06published 2023-05-26same kind of change as the line aboveGHSA-9mmj-64jh-ph9cCVE-2023-33779same package and registry as the line abovehighsame change as the line aboveDays to revision 11
2023-06-06published 2023-05-08Advisory severity changedGHSA-jchm-fm4q-c2fpCVE-2023-25754whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 29
2023-06-06published 2023-05-26Advisory severity changedGHSA-c892-cwq6-qrqfwhole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
2023-06-06published 2022-12-06 to 2023-05-12Advisory withdrawnwhole advisory2 bandswithdrawn 2023-06-06Days to revision 26 to 183
2023-06-06published 2023-05-12same kind of change as the line aboveGHSA-6mhc-hqr3-w466CVE-2023-31508same package and registry as the line abovemoderatewithdrawn 2023-06-06Days to revision 26
2023-06-06published 2022-12-06same kind of change as the line aboveGHSA-7vx2-5349-qj99CVE-2022-46464same package and registry as the line abovehighwithdrawn 2023-06-06Days to revision 183
Sat 3 Jun 2023· 4 advisory changes
2023-06-03published 2023-05-24Advisory severity changedGHSA-w6f8-mxf5-4vf8CVE-2023-33948whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 9
2023-06-03published 2023-05-24Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 9
2023-06-03published 2023-05-24same kind of change as the line aboveGHSA-769c-p92r-xgxjCVE-2023-33947same package and registry as the line abovemoderatesame change as the line aboveDays to revision 9
2023-06-03published 2023-05-24same kind of change as the line aboveGHSA-2868-ff44-43qvCVE-2023-33946same package and registry as the line abovemoderatesame change as the line aboveDays to revision 9
2023-06-03published 2023-05-26Advisory severity changedGHSA-x487-866m-p8hrCVE-2023-30145whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
Fri 2 Jun 2023· 4 advisory changes
2023-06-02published 2023-05-22Advisory severity changedGHSA-2h44-x2wx-49f4CVE-2023-30851whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 11
2023-06-02published 2023-05-22 to 2023-05-24Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 9 to 11
2023-06-02published 2023-05-24same kind of change as the line aboveGHSA-863x-868h-968xCVE-2021-25748same package and registry as the line abovemoderatesame change as the line aboveDays to revision 9
2023-06-02published 2023-05-22same kind of change as the line aboveGHSA-x7c2-7wvg-jpx7CVE-2023-32686same package and registry as the line abovemoderatesame change as the line aboveDays to revision 11
2023-06-02published 2023-05-24Advisory severity changedGHSA-g7vw-43xg-8m4hCVE-2023-33945whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 9
Thu 1 Jun 2023· 3 advisory changes
2023-06-01published 2022-05-24Advisory severity changedGHSA-4wrc-f8pq-fpqpCVE-2016-1000027whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-06-01published 2022-01-06Advisory severity changedGHSA-9w7f-m4j4-j3xwCVE-2021-43857whole advisorycriticalstated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.not dated
2023-06-01published 2023-05-26Advisory severity changedGHSA-jv3f-7m33-qp65CVE-2023-33955whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 6
Wed 31 May 2023· 4 advisory changes
2023-05-31published 2018-01-22 to 2022-05-14Package added to advisorymoderatenot named as affected when the advisory was published, now names jquerynot dated
2023-05-31published 2020-04-29same kind of change as the line aboveGHSA-jpcq-cgw6-v4j6CVE-2020-11023same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-31published 2022-05-14same kind of change as the line aboveGHSA-579v-mp3v-rrw5CVE-2011-4969same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-31published 2020-09-01same kind of change as the line aboveGHSA-2pqj-h3vj-pqgwCVE-2012-6708same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-31published 2018-01-22same kind of change as the line aboveGHSA-rmxg-73gg-4p98CVE-2015-9251same package registry as the line abovemoderatesame change as the line abovenot dated
Tue 30 May 2023· 9 advisory changes
2023-05-30published 2019-10-24Advisory fix version movedGHSA-c9cg-q8r2-xvjqCVE-2019-16929
nugetauth0.authenticationapi
high
stated at publication 6.5.3, now states 6.5.4not dated
2023-05-30published 2018-07-26Package added to advisoryGHSA-rch9-xh7r-mqgwCVE-2018-3717moderatenot named as affected when the advisory was published, now names connectnot dated
2023-05-30published 2021-08-13Package added to advisoryGHSA-6xx3-rg99-gc3pCVE-2020-15522moderatenot named as affected when the advisory was published, now names bouncycastlenot dated
2023-05-30published 2019-04-26 to 2020-05-20Package added to advisorymoderatenot named as affected when the advisory was published, now names jquerynot dated
2023-05-30published 2020-05-20same kind of change as the line aboveGHSA-q4m3-2j7h-f7xwCVE-2020-7656same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-30published 2019-04-26same kind of change as the line aboveGHSA-6c3j-c64m-qhgqCVE-2019-11358same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-30published 2019-04-26Package added to advisoryGHSA-6c3j-c64m-qhgqCVE-2019-11358moderatenot named as affected when the advisory was published, now names jquery-railsnot dated
2023-05-30published 2023-05-22Advisory severity changedGHSA-xp5g-jhg3-3rg2CVE-2023-33252whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2023-05-30published 2023-05-26Advisory severity changedGHSA-qpgm-gjgf-8c2xCVE-2023-33195whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 4
2023-05-30published 2023-01-03Advisory severity changedGHSA-rq2w-37h9-vg94CVE-2022-45143whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 146
Fri 26 May 2023· 13 advisory changes
2023-05-26published 2017-10-24 to 2022-04-22Package added to advisorymoderatenot named as affected when the advisory was published, now names actionpacknot dated
2023-05-26published 2022-04-22same kind of change as the line aboveGHSA-q58j-fmvf-9rq6CVE-2011-1497same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24same kind of change as the line aboveGHSA-xxr8-833v-c7wcCVE-2011-4319same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24same kind of change as the line aboveGHSA-24fg-p96v-hxh8CVE-2011-0447same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24same kind of change as the line aboveGHSA-fg9w-g6m4-557jCVE-2009-3086same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24same kind of change as the line aboveGHSA-8fqx-7pv4-3jwmCVE-2008-7248same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24same kind of change as the line aboveGHSA-75w6-p6mg-vh8jCVE-2011-0446same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24Package added to advisoryGHSA-fg9w-g6m4-557jCVE-2009-3086moderatenot named as affected when the advisory was published, now names activesupportnot dated
2023-05-26published 2017-10-24Package added to advisory2 bandsnot named as affected when the advisory was published, now names activerecordnot dated
2023-05-26published 2017-10-24same kind of change as the line aboveGHSA-gjxw-5w2q-7grfCVE-2010-3933same package registry as the line abovemoderatesame change as the line abovenot dated
2023-05-26published 2017-10-24same kind of change as the line aboveGHSA-xf96-32q2-9rw2CVE-2008-4094same package registry as the line abovehighsame change as the line abovenot dated
2023-05-26published 2023-05-26Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 0
2023-05-26published 2023-05-26same kind of change as the line aboveGHSA-6qjx-787v-6pxrCVE-2023-33197same package and registry as the line abovemoderatesame change as the line aboveDays to revision 0
2023-05-26published 2023-05-26same kind of change as the line aboveGHSA-cjmm-x9x9-m2w5CVE-2023-33196same package and registry as the line abovemoderatesame change as the line aboveDays to revision 0
2023-05-26published 2023-05-15Advisory severity changedGHSA-4xqq-73wg-5mjpCVE-2023-32758whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 12
2023-05-26published 2023-05-25Advisory severity changedGHSA-hj3f-6gcp-jg8jCVE-2023-28370whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 1
Thu 25 May 2023· 3 advisory changes
2023-05-25published 2023-05-17Advisory severity changedGHSA-25fx-3c2q-cq46CVE-2023-2756whole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 8
2023-05-25published 2023-05-17Advisory severity changedGHSA-92wq-q9pq-gw47CVE-2023-31135whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 8
2023-05-25published 2023-05-16Advisory severity changedGHSA-p6m6-9j36-vfjxCVE-2023-31890whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9
Wed 24 May 2023· 5 advisory changes
2023-05-24published 2022-01-13Package added to advisoryGHSA-vqwg-4v6f-h6x5CVE-2022-20615moderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins:matrix-projectnot dated
2023-05-24published 2023-05-17Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 7
2023-05-24published 2023-05-17same kind of change as the line aboveGHSA-j657-pjgc-c4h6CVE-2023-2752same package and registry as the line abovemoderatesame change as the line aboveDays to revision 7
2023-05-24published 2023-05-17same kind of change as the line aboveGHSA-vppq-6ff8-2m8wCVE-2023-2753same package and registry as the line abovemoderatesame change as the line aboveDays to revision 7
2023-05-24published 2022-01-21Advisory severity changedGHSA-fpj7-9xm6-8hgrCVE-2022-23106whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2023-05-24published 2022-04-23Advisory withdrawnGHSA-xm99-6pv5-q363CVE-2022-29583whole advisoryhighwithdrawn 2023-05-24Days to revision 397
Tue 23 May 2023· 2 advisory changes
2023-05-23published 2023-05-12Advisory severity changedGHSA-7g2v-2frm-rg94CVE-2023-2515whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 12
2023-05-23published 2023-03-10Advisory severity changedGHSA-frgr-c5f2-8qhhCVE-2023-27900whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 74
Mon 22 May 2023· 7 advisory changes
2023-05-22published 2022-05-13Package added to advisoryGHSA-3wqf-4x89-9g79CVE-2018-14040moderatenot named as affected when the advisory was published, now names bootstrapnot dated
2023-05-22published 2023-05-11 to 2023-05-12Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10 to 12
2023-05-22published 2023-05-11same kind of change as the line aboveGHSA-wc6j-5g83-xfm6CVE-2023-30172same package and registry as the line abovehighsame change as the line aboveDays to revision 12
2023-05-22published 2023-05-12same kind of change as the line aboveGHSA-fjx5-xm7q-whvjCVE-2023-30130same package and registry as the line abovehighsame change as the line aboveDays to revision 10
2023-05-22published 2023-05-12same kind of change as the line aboveGHSA-v9rm-7rv9-r3fwCVE-2023-29032same package and registry as the line abovehighsame change as the line aboveDays to revision 11
2023-05-22published 2023-05-12same kind of change as the line aboveGHSA-mg5h-f3q8-c96gCVE-2023-29246same package and registry as the line abovehighsame change as the line aboveDays to revision 11
2023-05-22published 2023-05-12Advisory severity changedGHSA-6vcf-cfjp-qxcwCVE-2023-27238whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 10
2023-05-22published 2022-12-14Advisory severity changedGHSA-2c7v-qcjp-4mg2CVE-2022-41089whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 159
Fri 19 May 2023· 1 advisory change
2023-05-19published 2023-03-10Advisory severity changedGHSA-j664-qhh4-hpf8CVE-2023-27898whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 70
Wed 17 May 2023· 3 advisory changes
2023-05-17published 2023-05-10Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-05-17published 2023-05-10same kind of change as the line aboveGHSA-97cp-mr4m-9mcfCVE-2023-27563same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-05-17published 2023-05-10same kind of change as the line aboveGHSA-r9xw-p7wj-w792CVE-2023-27564same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-05-17published 2023-05-11Advisory severity changedGHSA-mq3x-qgwx-3rfwCVE-2023-2629whole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 6
Tue 16 May 2023· 1 advisory change
2023-05-16published 2021-02-08Advisory severity changedGHSA-fwcm-636p-68r5CVE-2021-21288whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.not dated
Mon 15 May 2023· 2 advisory changes
2023-05-15published 2023-05-15Advisory severity changedGHSA-jh85-wwv9-24hvCVE-2023-32309whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 0
2023-05-15published 2023-05-07Advisory severity changedGHSA-r3xc-prgr-mg9pCVE-2023-31047whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9
Fri 12 May 2023· 1 advisory change
2023-05-12published 2023-05-09Advisory severity changedGHSA-qmqw-r4x6-3w2qCVE-2023-2590whole advisorylowstated at publication HIGH, now states LOWCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 3
Thu 11 May 2023· 3 advisory changes
2023-05-11published 2023-05-05Advisory severity changedGHSA-4m7v-wr6v-2mw5CVE-2023-2531whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-05-11published 2023-05-05Advisory severity changedGHSA-wf7x-fh6w-34r6CVE-2023-32235whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-05-11published 2023-05-04Advisory severity changedGHSA-jj45-24rw-v6jwCVE-2023-30094whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7
Wed 10 May 2023· 3 advisory changes
2023-05-10published 2023-05-04Advisory severity changedGHSA-m69h-4frq-vwq7CVE-2023-30331whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-05-10published 2023-04-26Advisory severity changedGHSA-g36h-4jr6-qmm9CVE-2022-25273whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 13
2023-05-10published 2023-05-02Advisory severity changedGHSA-f8hp-grmr-pp7jCVE-2023-29918whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7
Tue 9 May 2023· 8 advisory changes
2023-05-09published 2023-04-26 to 2023-05-05Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 4 to 14
2023-05-09published 2023-04-26same kind of change as the line aboveGHSA-939c-3g97-vpvvCVE-2023-26735same package and registry as the line abovehighsame change as the line aboveDays to revision 14
2023-05-09published 2023-05-05same kind of change as the line aboveGHSA-mgv8-gggw-mrg6CVE-2023-30837same package and registry as the line abovehighsame change as the line aboveDays to revision 4
2023-05-09published 2023-05-03same kind of change as the line aboveGHSA-2h5h-59f5-c5x9CVE-2023-30551same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-05-09published 2023-05-01 to 2023-05-03Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 6 to 8
2023-05-09published 2023-05-01same kind of change as the line aboveGHSA-pjfj-qvqw-3f6vCVE-2022-45801same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-05-09published 2023-05-02same kind of change as the line aboveGHSA-g2mc-fqqc-hxg3CVE-2023-30855same package and registry as the line abovemoderatesame change as the line aboveDays to revision 7
2023-05-09published 2023-05-03same kind of change as the line aboveGHSA-q9mw-68c2-j6m5CVE-2023-31125same package and registry as the line abovemoderatesame change as the line aboveDays to revision 6
2023-05-09published 2023-04-27Advisory severity changedGHSA-8qhm-ch8h-xgjrCVE-2023-30349whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 12
2023-05-09published 2022-08-06Advisory severity changedGHSA-xh3v-6f9j-wxw3CVE-2022-25275whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
Fri 5 May 2023· 6 advisory changes
2023-05-05published 2023-04-28Advisory severity changedGHSA-vcpr-hm2m-gjjjCVE-2023-28475whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7
2023-05-05published 2023-04-27Advisory severity changedGHSA-2hp9-3xfr-r9w2CVE-2023-31287whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2023-05-05published 2023-04-25Advisory severity changedGHSA-xgh5-gwq5-rpx8CVE-2023-22665whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
2023-05-05published 2023-04-26 to 2023-04-28Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7 to 9
2023-05-05published 2023-04-28same kind of change as the line aboveGHSA-pj76-75cm-3552CVE-2023-28473same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-05-05published 2023-04-26same kind of change as the line aboveGHSA-2x3r-7jgm-gh8xCVE-2020-36070same package and registry as the line abovecriticalsame change as the line aboveDays to revision 9
2023-05-05published 2023-04-26same kind of change as the line aboveGHSA-f737-3fh6-jf6wCVE-2023-30363same package and registry as the line abovecriticalsame change as the line aboveDays to revision 9
Thu 4 May 2023· 6 advisory changes
2023-05-04published 2020-02-20Package added to advisoryGHSA-cmcx-xhr8-3w9pCVE-2020-5243moderatenot named as affected when the advisory was published, now names user_agent_parsernot dated
2023-05-04published 2020-04-29Package added to advisoryGHSA-jpcq-cgw6-v4j6CVE-2020-11023moderatenot named as affected when the advisory was published, now names jquery-railsnot dated
2023-05-04published 2023-04-27Advisory severity changedGHSA-fq95-rx4q-qgg2CVE-2023-2341whole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 7
2023-05-04published 2020-02-20Advisory severity changedGHSA-cmcx-xhr8-3w9pCVE-2020-5243whole advisorymoderatestated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-05-04published 2020-11-13 to 2020-12-08Advisory severity changedwhole advisoryhighstated at publication LOW, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-05-04published 2020-12-08same kind of change as the line aboveGHSA-49r3-2549-3633CVE-2020-26254same package and registry as the line abovehighsame change as the line abovenot dated
2023-05-04published 2020-11-13same kind of change as the line aboveGHSA-23f7-99jx-m54rCVE-2020-26222same package and registry as the line abovehighsame change as the line abovenot dated
Wed 3 May 2023· 3 advisory changes
2023-05-03published 2023-04-24Advisory severity changedGHSA-f9xv-q969-pqx4CVE-2023-2251whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2023-05-03published 2023-04-21Advisory severity changedGHSA-67mg-gm8m-ph5rCVE-2023-2227whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 12
2023-05-03published 2023-04-28Advisory withdrawnGHSA-gh24-c683-79r2CVE-2023-26812whole advisorycriticalwithdrawn 2023-05-03Days to revision 5
Tue 2 May 2023· 4 advisory changes
2023-05-02published 2022-07-19Package added to advisoryGHSA-4x9r-j582-cgr8CVE-2022-33891highnot named as affected when the advisory was published, now names org.apache.spark:spark-parent_2.12not dated
2023-05-02published 2023-04-24Advisory severity changedGHSA-3862-c622-v4fpCVE-2023-31045whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 9
2023-05-02published 2023-04-24Advisory severity changedGHSA-4r6h-8v6p-xvw6CVE-2023-30533whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2023-05-02published 2023-04-20Advisory severity changedGHSA-g5h3-w546-pj7fCVE-2023-20873whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 12
Mon 1 May 2023· 3 advisory changes
2023-05-01published 2022-01-06Package added to advisoryGHSA-29mw-wpgm-hmr9moderatenot named as affected when the advisory was published, now names lodash.trim and 1 morenot dated
2023-05-01published 2022-01-06same kind of change as the line aboveGHSA-29mw-wpgm-hmr9CVE-2020-28500same package registry as the line abovemoderatenot named as affected when the advisory was published, now names lodash.trimnot dated
2023-05-01published 2022-01-06same kind of change as the line aboveGHSA-29mw-wpgm-hmr9CVE-2020-28500same package registry as the line abovemoderatenot named as affected when the advisory was published, now names lodash.trimendnot dated
2023-05-01published 2023-04-21Advisory severity changedGHSA-h3r8-h5qw-4r35CVE-2023-1892whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 11

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →