Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Fri 28 Apr 2023· 10 advisory changes
2023-04-28published 2023-04-20Advisory severity changedwhole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2023-04-28published 2023-04-20same kind of change as the line aboveGHSA-mjw9-3f9f-jq2wCVE-2023-29522same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-04-28published 2023-04-20same kind of change as the line aboveGHSA-px54-3w5j-qjg9CVE-2023-29518same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-04-28published 2023-04-20same kind of change as the line aboveGHSA-3hjg-cghv-22wwCVE-2023-29519same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-04-28published 2023-04-20same kind of change as the line aboveGHSA-p67q-h88v-5jgrCVE-2023-29521same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-04-28published 2023-02-16Advisory severity changedGHSA-r3vq-92c6-3mqfwhole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 71
2023-04-28published 2023-04-20Advisory severity changedGHSA-9mh9-44q3-v79xCVE-2023-29926whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-04-28published 2023-04-22Advisory severity changedGHSA-h83h-77x2-6w6gCVE-2023-2239whole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 6
2023-04-28published 2023-04-17 to 2023-04-21Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7 to 11
2023-04-28published 2023-04-21same kind of change as the line aboveGHSA-c6mx-3fj9-9j7qCVE-2023-29924same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-04-28published 2023-04-17same kind of change as the line aboveGHSA-pvjv-386f-c8whCVE-2023-24831same package and registry as the line abovecriticalsame change as the line aboveDays to revision 11
2023-04-28published 2023-04-20Advisory severity changedGHSA-44h9-xxvx-pg6xCVE-2023-29515whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
Thu 27 Apr 2023· 5 advisory changes
2023-04-27published 2023-04-17Advisory severity changedGHSA-7jhg-8m74-6f6gCVE-2023-27525whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 10
2023-04-27published 2023-04-17Advisory severity changedGHSA-329j-jfvr-rhr6CVE-2023-22946whole advisorycriticalstated at publication MODERATE, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 10
2023-04-27published 2023-04-20Advisory severity changedGHSA-93hq-5wgc-jc82CVE-2023-30542whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 7
2023-04-27published 2023-04-05Advisory severity changedGHSA-776f-qx25-q3ccCVE-2023-0842whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 22
2023-04-27published 2023-04-25Advisory withdrawnGHSA-wj6r-53f5-q789whole advisorycriticalwithdrawn 2023-04-27Days to revision 2
Tue 25 Apr 2023· 3 advisory changes
2023-04-25published 2023-04-12 to 2023-04-24Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 1 to 13
2023-04-25published 2023-04-24same kind of change as the line aboveGHSA-w9g2-3w7p-72g9CVE-2023-30629same package and registry as the line abovehighsame change as the line aboveDays to revision 1
2023-04-25published 2023-04-12same kind of change as the line aboveGHSA-cwf6-xj49-wp83CVE-2023-29018same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-04-25published 2023-04-24Advisory severity changedGHSA-rg3q-prf8-qxmpCVE-2023-30623whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 1
Fri 21 Apr 2023· 2 advisory changes
2023-04-21published 2021-10-12Package added to advisoryGHSA-q799-q27x-vp7wCVE-2019-5064highnot named as affected when the advisory was published, now names opencv-contrib-python-headlessnot dated
2023-04-21published 2023-04-11Advisory severity changedGHSA-j97g-77fj-9c4pCVE-2023-1976whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
Thu 20 Apr 2023· 1 advisory change
2023-04-20published 2023-04-12Advisory severity changedGHSA-9337-8c6c-c2xgCVE-2023-30512whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 8
Wed 19 Apr 2023· 3 advisory changes
2023-04-19published 2023-04-11Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 8
2023-04-19published 2023-04-11same kind of change as the line aboveGHSA-65v8-6pvw-jwvqCVE-2023-1975same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-04-19published 2023-04-11same kind of change as the line aboveGHSA-8jg3-rx43-3fv4CVE-2023-1974same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-04-19published 2023-04-11Advisory severity changedGHSA-79xf-67r4-q2jjCVE-2023-26122whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
Tue 18 Apr 2023· 2 advisory changes
2023-04-18published 2023-04-17Advisory severity changedGHSA-mx2q-35m2-x2rhCVE-2023-30541whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 1
2023-04-18published 2023-04-13Advisory severity changedGHSA-mg46-f9h5-g27xCVE-2022-45064whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 5
Mon 17 Apr 2023· 1 advisory change
2023-04-17published 2023-04-05Advisory severity changedGHSA-fprp-p869-w6q2CVE-2023-29374whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 13
Fri 14 Apr 2023· 17 advisory changes
2023-04-14published 2022-12-30Package added to advisoryGHSA-w9rv-xmf7-x3ghCVE-2022-44621criticalnot named as affected when the advisory was published, now names org.apache.kylin:kylin-server-baseDays to revision 105
2023-04-14published 2022-11-22Package added to advisoryGHSA-cm43-f2pv-6v68CVE-2022-41131highnot named as affected when the advisory was published, now names apache-airflow-providers-apache-hiveDays to revision 143
2023-04-14published 2021-05-21Package added to advisoryGHSA-hfg5-xpvw-c9x4highnot named as affected when the advisory was published, now names org.apache.camel:camel and 2 morenot dated
2023-04-14published 2021-05-21same kind of change as the line aboveGHSA-hfg5-xpvw-c9x4CVE-2020-11971same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.camel:camelnot dated
2023-04-14published 2021-05-21same kind of change as the line aboveGHSA-hfg5-xpvw-c9x4CVE-2020-11971same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.camel:camel-corenot dated
2023-04-14published 2021-05-21same kind of change as the line aboveGHSA-hfg5-xpvw-c9x4CVE-2020-11971same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.camel:camel-managementnot dated
2023-04-14published 2022-12-13Package added to advisoryGHSA-3vqj-43w4-2q58CVE-2022-45688highnot named as affected when the advisory was published, now names org.json:jsonDays to revision 122
2023-04-14published 2022-01-06Package added to advisoryGHSA-gc67-crq6-hgh5CVE-2021-41561highnot named as affected when the advisory was published, now names org.apache.parquet:parquetnot dated
2023-04-14published 2023-04-07 to 2023-04-11Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 4 to 7
2023-04-14published 2023-04-11same kind of change as the line aboveGHSA-hcg3-56jf-x4vhCVE-2023-26121same package and registry as the line abovecriticalsame change as the line aboveDays to revision 4
2023-04-14published 2023-04-07same kind of change as the line aboveGHSA-5cvg-9pp5-mxcjCVE-2023-28706same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-04-14published 2023-04-10same kind of change as the line aboveGHSA-qm2h-m799-86rcCVE-2023-29215same package and registry as the line abovecriticalsame change as the line aboveDays to revision 5
2023-04-14published 2023-04-10same kind of change as the line aboveGHSA-rrhf-32rq-f28hCVE-2023-29216same package and registry as the line abovecriticalsame change as the line aboveDays to revision 5
2023-04-14published 2023-04-05Advisory severity changedGHSA-32qq-m9fh-f74wCVE-2023-25330whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 9
2023-04-14published 2022-11-22Advisory severity changedGHSA-7wqf-h36w-47mcCVE-2022-38649whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-04-14published 2023-04-10Advisory severity changedGHSA-w6q2-48ch-fj26CVE-2023-25392whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 4
2023-04-14published 2023-04-07Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-04-14published 2023-04-07same kind of change as the line aboveGHSA-85pf-r4c7-3j9rCVE-2023-28707same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-04-14published 2023-04-07same kind of change as the line aboveGHSA-ffj9-4crc-q7wfCVE-2023-28710same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-04-14published 2022-05-17Advisory withdrawnGHSA-4pmp-38hf-rmwjCVE-2014-3555whole advisorymoderatewithdrawn 2023-04-14Days to revision 333
Thu 13 Apr 2023· 2 advisory changes
2023-04-13published 2023-01-18Package added to advisoryGHSA-5pm2-9mr2-3frqCVE-2023-21893highnot named as affected when the advisory was published, now names oracle.manageddataaccess.coreDays to revision 86
2023-04-13published 2022-03-25Advisory severity changedGHSA-q7rv-6hp3-vh96CVE-2022-24775whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
Wed 12 Apr 2023· 3 advisory changes
2023-04-12published 2023-04-03Advisory severity changedGHSA-38h6-gmr2-j4wxCVE-2023-28851whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 9
2023-04-12published 2022-07-20Advisory severity changedGHSA-9339-86wc-4qgfCVE-2022-34169whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2023-04-12published 2023-04-11Advisory severity changedGHSA-f8vr-r385-rh5rCVE-2023-26964whole advisorymoderatestated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 1
Mon 10 Apr 2023· 2 advisory changes
2023-04-10published 2022-11-21Package added to advisoryGHSA-h6q3-vv32-2cq5CVE-2022-41894highnot named as affected when the advisory was published, now names tensorflowDays to revision 140
2023-04-10published 2023-04-03Advisory severity changedGHSA-w7r6-v4j7-h94wCVE-2023-26269whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
Fri 7 Apr 2023· 3 advisory changes
2023-04-07published 2023-04-02Advisory severity changedGHSA-j9h4-p6p7-8652CVE-2023-28672whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 5
2023-04-07published 2023-03-31Advisory severity changedGHSA-wg4w-5m5r-w3p8CVE-2023-27162whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-04-07published 2023-04-04Advisory severity changedGHSA-hx8p-9m48-g76rCVE-2020-20913whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 3
Thu 6 Apr 2023· 3 advisory changes
2023-04-06published 2023-03-30 to 2023-03-31Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7 to 8
2023-04-06published 2023-03-31same kind of change as the line aboveGHSA-6cpg-gqgq-2rrrCVE-2023-1761same package and registry as the line abovemoderatesame change as the line aboveDays to revision 7
2023-04-06published 2023-03-30same kind of change as the line aboveGHSA-v3hp-mcj5-pg39CVE-2023-0620same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-04-06published 2023-03-30Advisory severity changedGHSA-w7qg-j435-78qwCVE-2023-1712whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
Tue 4 Apr 2023· 3 advisory changes
2023-04-04published 2021-06-23Package added to advisoryGHSA-gq5r-cc4w-g8xfhighnot named as affected when the advisory was published, now names github.com/russellhaering/goxmldsignot dated
2023-04-04published 2023-03-24Advisory severity changedGHSA-6wfh-89q8-44jqCVE-2023-25676whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2023-04-04published 2023-03-29Advisory withdrawnGHSA-3r5c-h7g6-cqw7whole advisorymoderatewithdrawn 2023-04-04Days to revision 6
Mon 3 Apr 2023· 4 advisory changes
2023-04-03published 2023-03-31Advisory fix version movedGHSA-6cpg-gqgq-2rrrCVE-2023-1761
packagistthorsten/phpmyfaq
moderate
stated at publication 1.3.12, now states 3.1.12Days to revision 4
2023-04-03published 2023-03-24Advisory severity changedGHSA-7x4v-9gxg-9hwjCVE-2023-25675whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2023-04-03published 2023-03-27Advisory severity changedGHSA-p4qx-6w5p-4rj2CVE-2023-28867whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8
2023-04-03published 2023-02-25Advisory withdrawnGHSA-xr9w-x6gw-c9mjwhole advisoryhighwithdrawn 2023-04-03Days to revision 38
Fri 31 Mar 2023· 8 advisory changes
2023-03-31published 2023-03-23Advisory severity changedGHSA-q2x3-2f9g-h559CVE-2023-28333whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-03-31published 2023-03-24Advisory severity changedGHSA-j5w9-hmfh-4cr6CVE-2023-25671whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-03-31published 2022-11-28Advisory severity changedGHSA-w573-4hg7-7wgqCVE-2022-38900whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 123
2023-03-31published 2019-02-18Advisory severity changedGHSA-9c2p-jw8p-f84vCVE-2016-10556whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-03-31published 2018-08-09Advisory severity changedGHSA-9cp3-fh5x-xfcjCVE-2017-16098whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-03-31published 2023-03-29Advisory withdrawnwhole advisorymoderatewithdrawn 2023-03-31Days to revision 2
2023-03-31published 2023-03-29same kind of change as the line aboveGHSA-6mmf-qm37-pmggsame package and registry as the line abovemoderatewithdrawn 2023-03-31Days to revision 2
2023-03-31published 2023-03-29same kind of change as the line aboveGHSA-69fc-v223-6rjwsame package and registry as the line abovemoderatewithdrawn 2023-03-31Days to revision 2
2023-03-31published 2023-03-29same kind of change as the line aboveGHSA-rp78-4562-gx3csame package and registry as the line abovemoderatewithdrawn 2023-03-31Days to revision 2
Thu 30 Mar 2023· 12 advisory changes
2023-03-30published 2021-09-20Package added to advisoryGHSA-mc22-5q92-8v85CVE-2021-39228moderatenot named as affected when the advisory was published, now names tremor-scriptnot dated
2023-03-30published 2021-05-07Advisory severity changedGHSA-v8w9-2789-6hhrCVE-2020-7610whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-03-30published 2021-09-02Advisory severity changedGHSA-p92x-r36w-9395CVE-2021-23438whole advisorymoderatestated at publication CRITICAL, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-03-30published 2023-03-22 to 2023-03-24Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6 to 8
2023-03-30published 2023-03-24same kind of change as the line aboveGHSA-5w96-866f-6rm8CVE-2023-27579same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-03-30published 2023-03-24same kind of change as the line aboveGHSA-gf97-q72m-7579CVE-2023-25674same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-03-30published 2023-03-24same kind of change as the line aboveGHSA-49rq-hwc3-x77wCVE-2023-25670same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-03-30published 2023-03-24same kind of change as the line aboveGHSA-rcf8-g8jv-vg6pCVE-2023-25669same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-03-30published 2023-03-24same kind of change as the line aboveGHSA-647v-r7qq-24fhCVE-2023-25673same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-03-30published 2023-03-24same kind of change as the line aboveGHSA-94mm-g2mv-8p7rCVE-2023-25672same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-03-30published 2023-03-22same kind of change as the line aboveGHSA-q6g2-g7f3-rr83CVE-2023-1436same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-03-30published 2023-03-22Advisory severity changedGHSA-jxr6-7qg5-8wv6CVE-2023-0870whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7
2023-03-30published 2023-03-07Advisory withdrawnGHSA-8wg7-88cg-7p9jCVE-2023-1247whole advisorymoderatewithdrawn 2023-03-30Days to revision 23
Wed 29 Mar 2023· 1 advisory change
2023-03-29published 2021-09-20Package added to advisoryGHSA-468q-v4jj-485hCVE-2021-3804highnot named as affected when the advisory was published, now names @tarojs/helpernot dated
Tue 28 Mar 2023· 6 advisory changes
2023-03-28published 2023-03-22 to 2023-03-23Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 5
2023-03-28published 2023-03-23same kind of change as the line aboveGHSA-wxmq-v9gx-75pgCVE-2023-28335same package and registry as the line abovehighsame change as the line aboveDays to revision 5
2023-03-28published 2023-03-22same kind of change as the line aboveGHSA-8gg8-wr4j-v2wrCVE-2022-45003same package and registry as the line abovehighsame change as the line aboveDays to revision 5
2023-03-28published 2023-03-23Advisory severity changedGHSA-564r-hj7v-mcr5CVE-2023-20861whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 5
2023-03-28published 2023-03-23Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5
2023-03-28published 2023-03-23same kind of change as the line aboveGHSA-h4cc-fxpp-pgw9CVE-2023-25654same package and registry as the line abovecriticalsame change as the line aboveDays to revision 5
2023-03-28published 2023-03-23same kind of change as the line aboveGHSA-mfvg-qwcw-qvc8CVE-2023-25655same package and registry as the line abovecriticalsame change as the line aboveDays to revision 5
2023-03-28published 2023-03-27Advisory withdrawnGHSA-2w9p-xf5h-qwj3whole advisoryhighwithdrawn 2023-03-28Days to revision 2
Mon 27 Mar 2023· 18 advisory changes
2023-03-27published 2018-11-09Package added to advisorymoderatenot named as affected when the advisory was published, now names mapbox-railsnot dated
2023-03-27published 2018-11-09same kind of change as the line aboveGHSA-qr28-7j6p-9hmvCVE-2017-1000042same package registry as the line abovemoderatesame change as the line abovenot dated
2023-03-27published 2018-11-09same kind of change as the line aboveGHSA-q69p-5h74-w36fCVE-2017-1000043same package registry as the line abovemoderatesame change as the line abovenot dated
2023-03-27published 2017-10-24Package added to advisoryGHSA-34r7-q49f-h37cCVE-2015-8857criticalnot named as affected when the advisory was published, now names uglifiernot dated
2023-03-27published 2021-12-16Package added to advisoryGHSA-gv87-q66h-4277CVE-2021-43113criticalnot named as affected when the advisory was published, now names com.itextpdf:itextpdfnot dated
2023-03-27published 2022-09-25Package added to advisoryGHSA-m7w4-q5vg-5xfpCVE-2022-3257moderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v6not dated
2023-03-27published 2023-03-23Advisory severity changedGHSA-frjg-g767-7363CVE-2023-26114whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5
2023-03-27published 2023-03-16 to 2023-03-24Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 3 to 7
2023-03-27published 2023-03-16same kind of change as the line aboveGHSA-cp96-jpmq-xrr2CVE-2023-26484same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-03-27published 2023-03-24same kind of change as the line aboveGHSA-558h-mq8x-7q9gCVE-2023-25665same package and registry as the line abovehighsame change as the line aboveDays to revision 3
2023-03-27published 2023-03-24same kind of change as the line aboveGHSA-f637-vh3r-vfh2CVE-2023-25666same package and registry as the line abovehighsame change as the line aboveDays to revision 3
2023-03-27published 2023-03-24same kind of change as the line aboveGHSA-64jg-wjww-7c5wCVE-2023-25663same package and registry as the line abovehighsame change as the line aboveDays to revision 3
2023-03-27published 2023-03-24same kind of change as the line aboveGHSA-6hg6-5c2q-7rcrCVE-2023-25664same package and registry as the line abovehighsame change as the line aboveDays to revision 3
2023-03-27published 2023-03-24same kind of change as the line aboveGHSA-7jvm-xxmr-v5cwCVE-2023-25662same package and registry as the line abovehighsame change as the line aboveDays to revision 3
2023-03-27published 2023-03-24same kind of change as the line aboveGHSA-93vr-9q9m-pj8pCVE-2023-25659same package and registry as the line abovehighsame change as the line aboveDays to revision 3
2023-03-27published 2023-03-24same kind of change as the line aboveGHSA-68v3-g9cm-rmm6CVE-2023-25658same package and registry as the line abovehighsame change as the line aboveDays to revision 3
1 more row in this change is not listed here. Open all 9 rows
2023-03-27published 2023-03-21Advisory severity changedGHSA-h2wg-83fc-xvm9CVE-2023-1541whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 7
2023-03-27published 2023-03-24Advisory severity changedGHSA-gw97-ff7c-9v96CVE-2023-25668whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 3
2023-03-27published 2023-03-24Advisory severity changedGHSA-qjqc-vqcf-5qvjCVE-2023-25660whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 3
Fri 24 Mar 2023· 3 advisory changes
2023-03-24published 2023-03-21Advisory severity changedGHSA-jhjm-5xjg-mpqpCVE-2023-27087whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 3
2023-03-24published 2023-03-21Advisory severity changedGHSA-h384-ph77-3699CVE-2018-25082whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 3
2023-03-24published 2023-03-21Advisory severity changedGHSA-r95w-7cpx-h5mxCVE-2023-1542whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 3
Thu 23 Mar 2023· 6 advisory changes
2023-03-23published 2023-03-19 to 2023-03-21Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 3
2023-03-23published 2023-03-19same kind of change as the line aboveGHSA-3x8x-79m2-3w2wCVE-2021-46877same package and registry as the line abovehighsame change as the line abovenot dated
2023-03-23published 2023-03-21same kind of change as the line aboveGHSA-79hx-g43v-xfmrCVE-2023-1543same package and registry as the line abovehighsame change as the line aboveDays to revision 3
2023-03-23published 2023-03-18 to 2023-03-21Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 3 to 5
2023-03-23published 2023-03-21same kind of change as the line aboveGHSA-hwj7-frgj-7829CVE-2023-1537same package and registry as the line abovecriticalsame change as the line aboveDays to revision 3
2023-03-23published 2023-03-18same kind of change as the line aboveGHSA-pmhg-cmjc-3875CVE-2023-28609same package and registry as the line abovecriticalsame change as the line aboveDays to revision 5
2023-03-23published 2023-03-17Advisory severity changedGHSA-86jq-pwgx-6vrqCVE-2023-1463whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 6
2023-03-23published 2023-03-20Advisory withdrawnGHSA-xrqq-wqh4-5hg2CVE-2023-28426whole advisorymoderatewithdrawn 2023-03-23Days to revision 3
Wed 22 Mar 2023· 3 advisory changes
2023-03-22published 2021-05-10Advisory fix version movedGHSA-x5r6-x823-9848CVE-2020-7766
npmjson-ptr
high
stated at publication 2.0.0, now states 2.1.0not dated
2023-03-22published 2020-02-21Package added to advisoryGHSA-cqqj-4p63-rrmmCVE-2019-20444criticalnot named as affected when the advisory was published, now names io.netty:netty-codec-httpnot dated
2023-03-22published 2023-03-15Advisory severity changedGHSA-4grc-q4fj-45p8CVE-2023-0100whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
Mon 20 Mar 2023· 3 advisory changes
2023-03-20published 2021-05-04Advisory severity changedGHSA-h4j5-c7cj-74xgCVE-2020-28502whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-03-20published 2022-12-27Advisory severity changedGHSA-c5hg-mr8r-f6jpCVE-2022-36437whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 83
2023-03-20published 2023-03-15Advisory severity changedGHSA-2rq5-699j-x7p6CVE-2023-25345whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 5
Fri 17 Mar 2023· 2 advisory changes
2023-03-17published 2023-03-08Advisory fix version movedGHSA-933g-v89r-x8pfCVE-2023-23638
mavenorg.apache.dubbo:dubbo
critical
stated at publication 2.7.21, now states 2.7.22Days to revision 9
2023-03-17published 2023-03-15Advisory severity changedGHSA-h6g5-wqqr-3mw3CVE-2023-25695whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 2
Thu 16 Mar 2023· 5 advisory changes
2023-03-16published 2022-02-15Package added to advisoryGHSA-pf59-j7c2-rh6xCVE-2020-13597moderatenot named as affected when the advisory was published, now names github.com/projectcalico/caliconot dated
2023-03-16published 2022-01-06Package added to advisoryGHSA-w428-f65r-h4q2CVE-2021-45687criticalnot named as affected when the advisory was published, now names raw-cpuidnot dated
2023-03-16published 2022-05-24Package added to advisoryGHSA-4rjr-3gj2-5crqCVE-2021-20332moderatenot named as affected when the advisory was published, now names mongodbnot dated
2023-03-16published 2023-03-12Advisory severity changedGHSA-66m4-gc8h-hpjxCVE-2022-48366whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 5
2023-03-16published 2023-03-12Advisory severity changedGHSA-89p3-9j8c-fqh4whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 5
Wed 15 Mar 2023· 8 advisory changes
2023-03-15published 2023-03-09 to 2023-03-10Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5 to 7
2023-03-15published 2023-03-10same kind of change as the line aboveGHSA-795w-7426-m94jCVE-2021-33360same package and registry as the line abovecriticalsame change as the line aboveDays to revision 5
2023-03-15published 2023-03-10same kind of change as the line aboveGHSA-j83x-r9qq-9g4vCVE-2023-1307same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-03-15published 2023-03-09same kind of change as the line aboveGHSA-9jh3-4pc9-hq29CVE-2023-26109same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-03-15published 2023-03-09same kind of change as the line aboveGHSA-cxx3-36qc-m6qmCVE-2023-26110same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-03-15published 2023-03-01 to 2023-03-10Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 5 to 14
2023-03-15published 2023-03-10same kind of change as the line aboveGHSA-6x8f-x6qw-qwx3CVE-2023-1313same package and registry as the line abovehighsame change as the line aboveDays to revision 5
2023-03-15published 2023-03-01same kind of change as the line aboveGHSA-f6hc-9g49-xmx7CVE-2023-24533same package and registry as the line abovehighsame change as the line aboveDays to revision 14
2023-03-15published 2023-03-10same kind of change as the line aboveGHSA-vp98-w2p3-mv35CVE-2023-26464same package and registry as the line abovehighsame change as the line aboveDays to revision 5
2023-03-15published 2023-03-10Advisory severity changedGHSA-jx2x-fg9p-7gc7CVE-2023-24774whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →