Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Wed 15 Mar 2023· 1 advisory change
2023-03-15published 2022-03-04Advisory withdrawnGHSA-m6gg-86c6-gfr9CVE-2022-23710whole advisorymoderatewithdrawn 2023-03-15Days to revision 377
Tue 14 Mar 2023· 3 advisory changes
2023-03-14published 2023-03-08Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6
2023-03-14published 2023-03-08same kind of change as the line aboveGHSA-933g-v89r-x8pfCVE-2023-23638same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-03-14published 2023-03-08same kind of change as the line aboveGHSA-347f-rxg8-qgrvCVE-2023-1269same package and registry as the line abovecriticalsame change as the line aboveDays to revision 6
2023-03-14published 2021-08-26Advisory severity changedGHSA-2rqw-v265-jf8cCVE-2021-22942whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
Mon 13 Mar 2023· 7 advisory changes
2023-03-13published 2023-03-07Advisory severity changedGHSA-5gp5-vxj6-4257CVE-2022-4134whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 7
2023-03-13published 2023-03-05Advisory severity changedGHSA-67j4-2mh6-8627CVE-2021-4329whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-03-13published 2023-03-06Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-03-13published 2023-03-06same kind of change as the line aboveGHSA-4rmj-w58m-fvchCVE-2021-36396same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-03-13published 2023-03-06same kind of change as the line aboveGHSA-6722-xvq8-3254CVE-2023-26107same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-03-13published 2023-03-06Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-03-13published 2023-03-06same kind of change as the line aboveGHSA-f46j-r7q3-6cm2CVE-2021-36393same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-03-13published 2023-03-06same kind of change as the line aboveGHSA-qc86-vgf2-6fq6CVE-2021-36392same package and registry as the line abovecriticalsame change as the line aboveDays to revision 7
2023-03-13published 2023-03-06Advisory severity changedGHSA-4jpv-8r57-pv7jCVE-2023-26108whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7
Fri 10 Mar 2023· 3 advisory changes
2023-03-10published 2023-02-28 to 2023-03-03Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7 to 10
2023-03-10published 2023-03-03same kind of change as the line aboveGHSA-vpvm-3wq2-2wvmCVE-2023-27561same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-03-10published 2023-02-28same kind of change as the line aboveGHSA-4w59-c3gc-rrhpCVE-2023-23929same package and registry as the line abovehighsame change as the line aboveDays to revision 10
2023-03-10published 2023-02-17Advisory severity changedGHSA-qgc7-mgm3-q253CVE-2022-41727whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 21
Thu 9 Mar 2023· 5 advisory changes
2023-03-09published 2023-02-28 to 2023-03-05Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 4 to 8
2023-03-09published 2023-03-05same kind of change as the line aboveGHSA-8ccw-f83g-v7g3CVE-2023-0734same package and registry as the line abovemoderatesame change as the line aboveDays to revision 4
2023-03-09published 2023-02-28same kind of change as the line aboveGHSA-36gx-9q6h-g429CVE-2022-39228same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-03-09published 2023-03-01same kind of change as the line aboveGHSA-hjv9-hm2f-rpcjCVE-2023-0507same package and registry as the line abovemoderatesame change as the line aboveDays to revision 7
2023-03-09published 2023-03-01same kind of change as the line aboveGHSA-xw5p-hw8j-xg4qCVE-2023-0594same package and registry as the line abovemoderatesame change as the line aboveDays to revision 7
2023-03-09published 2023-02-17Advisory severity changedGHSA-vvpx-j8f3-3w6hCVE-2022-41723whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 20
Wed 8 Mar 2023· 2 advisory changes
2023-03-08published 2022-01-07Package added to advisoryGHSA-wrxc-mr2w-cjpvCVE-2020-11529moderatenot named as affected when the advisory was published, now names getgrav/gravnot dated
2023-03-08published 2022-01-05Package added to advisoryGHSA-4w23-c97g-fq5vCVE-2021-4130highnot named as affected when the advisory was published, now names snipe/snipe-itnot dated
Tue 7 Mar 2023· 3 advisory changes
2023-03-07published 2023-02-25Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2023-03-07published 2023-02-25same kind of change as the line aboveGHSA-xr9w-x6gw-c9mjsame package and registry as the line abovehighsame change as the line aboveDays to revision 10
2023-03-07published 2023-02-25same kind of change as the line aboveGHSA-p7qq-rrvw-x55xCVE-2023-1033same package and registry as the line abovehighsame change as the line aboveDays to revision 10
2023-03-07published 2023-02-24Advisory severity changedGHSA-j75r-vf64-6rrhCVE-2023-0481whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 10
Mon 6 Mar 2023· 11 advisory changes
2023-03-06published 2022-04-23Advisory severity changedGHSA-6wj9-77wq-jq7pCVE-2012-6685whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-03-06published 2023-02-24Advisory severity changedGHSA-3x49-g6rc-c284CVE-2022-23535whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 10
2023-03-06published 2023-02-08 to 2023-02-24Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 10 to 26
2023-03-06published 2023-02-08same kind of change as the line aboveGHSA-w67w-mw4j-8qrvCVE-2022-4203same package and registry as the line abovecriticalsame change as the line aboveDays to revision 26
2023-03-06published 2023-02-24same kind of change as the line aboveGHSA-j69x-v4wc-3fpfCVE-2023-25693same package and registry as the line abovecriticalsame change as the line aboveDays to revision 10
2023-03-06published 2023-02-24same kind of change as the line aboveGHSA-8g23-2q5p-8866CVE-2023-25691same package and registry as the line abovecriticalsame change as the line aboveDays to revision 10
2023-03-06published 2023-02-24same kind of change as the line aboveGHSA-9mwf-mw74-9cv5CVE-2023-25696same package and registry as the line abovecriticalsame change as the line aboveDays to revision 10
2023-03-06published 2023-02-24Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2023-03-06published 2023-02-24same kind of change as the line aboveGHSA-h8p2-8g72-qpghCVE-2023-25692same package and registry as the line abovehighsame change as the line aboveDays to revision 10
2023-03-06published 2023-02-24same kind of change as the line aboveGHSA-w695-p3j5-hrj9CVE-2023-25956same package and registry as the line abovehighsame change as the line aboveDays to revision 10
2023-03-06published 2022-05-24Advisory severity changedGHSA-vwq9-cmqr-3c8cCVE-2019-10343whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2023-03-06published 2020-02-04Advisory severity changedGHSA-r679-m633-g7wcCVE-2019-12422whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-03-06published 2022-10-06Advisory withdrawnGHSA-wrx5-rp7m-mm49CVE-2022-41852whole advisorycriticalwithdrawn 2023-03-06Days to revision 151
Fri 3 Mar 2023· 3 advisory changes
2023-03-03published 2023-02-24Advisory severity changedGHSA-9fh3-j99m-f4v7CVE-2022-36231whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-03-03published 2021-06-02Advisory severity changedGHSA-h72c-w3q3-55qqCVE-2020-13388whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-03-03published 2022-09-17Advisory withdrawnGHSA-3mq5-fq9h-gj7jwhole advisorylowwithdrawn 2023-03-03Days to revision 168
Thu 2 Mar 2023· 6 advisory changes
2023-03-02published 2021-01-13Package added to advisoryGHSA-jxwx-85vp-gvwmCVE-2021-21252highnot named as affected when the advisory was published, now names jquery.validationnot dated
2023-03-02published 2022-11-21Package added to advisoryGHSA-vqp6-rc3h-83cpCVE-2022-41924criticalnot named as affected when the advisory was published, now names tailscale.comDays to revision 101
2023-03-02published 2023-02-20Advisory severity changedGHSA-337f-xr2x-6fcfCVE-2023-25613whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 10
2023-03-02published 2022-02-15Advisory severity changedGHSA-qrrc-ww9x-r43gCVE-2020-13401whole advisorymoderatestated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-03-02published 2023-02-20Advisory severity changedGHSA-4jx2-hvqw-93j9CVE-2016-15026whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2023-03-02published 2023-03-01Advisory severity changedGHSA-6q8m-42qq-64r7CVE-2021-4326whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 1
Wed 1 Mar 2023· 11 advisory changes
2023-03-01published 2023-02-08Advisory severity changedGHSA-x4qr-2fvf-3mr5CVE-2023-0286whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 13
2023-03-01published 2018-07-26Advisory severity changedwhole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-03-01published 2018-07-26same kind of change as the line aboveGHSA-xcvv-84j5-jw9hCVE-2018-3720same package and registry as the line abovehighsame change as the line abovenot dated
2023-03-01published 2018-07-26same kind of change as the line aboveGHSA-3mpr-hq3p-49h9CVE-2018-3719same package and registry as the line abovehighsame change as the line abovenot dated
2023-03-01published 2018-09-06Advisory severity changedGHSA-gpvj-q7fp-jcchCVE-2018-3787whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-03-01published 2023-02-17Advisory severity changedGHSA-5vx9-j5cw-47vqCVE-2021-32163whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 11
2023-03-01published 2018-07-26 to 2018-07-27Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-03-01published 2018-07-27same kind of change as the line aboveGHSA-p7c9-jqhq-vr3vCVE-2018-3770same package and registry as the line abovemoderatesame change as the line abovenot dated
2023-03-01published 2018-07-26same kind of change as the line aboveGHSA-52r9-g5g6-2hjpCVE-2018-3714same package and registry as the line abovemoderatesame change as the line abovenot dated
2023-03-01published 2018-07-26same kind of change as the line aboveGHSA-4rvg-955w-h68qCVE-2018-3713same package and registry as the line abovemoderatesame change as the line abovenot dated
2023-03-01published 2018-07-26same kind of change as the line aboveGHSA-rch9-xh7r-mqgwCVE-2018-3717same package and registry as the line abovemoderatesame change as the line abovenot dated
2023-03-01published 2018-10-09Advisory severity changedGHSA-8w4h-3cm3-2pm2CVE-2018-3745whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-03-01published 2018-08-03Advisory severity changedGHSA-534w-937m-v7x3CVE-2018-3777whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
Tue 28 Feb 2023· 10 advisory changes
2023-02-28published 2018-10-17Package added to advisoryGHSA-p699-3wgc-7h72CVE-2018-1339moderatenot named as affected when the advisory was published, now names org.apache.tika:tika-parsersnot dated
2023-02-28published 2023-01-23Package added to advisoryGHSA-jqh6-9574-5x22criticalnot named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.convertors and 4 moreDays to revision 36
2023-02-28published 2023-01-23same kind of change as the line aboveGHSA-jqh6-9574-5x22CVE-2023-24057same package registry as the line abovecriticalnot named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.convertorsDays to revision 36
2023-02-28published 2023-01-23same kind of change as the line aboveGHSA-jqh6-9574-5x22CVE-2023-24057same package registry as the line abovecriticalnot named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.r4bDays to revision 36
2023-02-28published 2023-01-23same kind of change as the line aboveGHSA-jqh6-9574-5x22CVE-2023-24057same package registry as the line abovecriticalnot named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.r5Days to revision 36
2023-02-28published 2023-01-23same kind of change as the line aboveGHSA-jqh6-9574-5x22CVE-2023-24057same package registry as the line abovecriticalnot named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.utilitiesDays to revision 36
2023-02-28published 2023-01-23same kind of change as the line aboveGHSA-jqh6-9574-5x22CVE-2023-24057same package registry as the line abovecriticalnot named as affected when the advisory was published, now names ca.uhn.hapi.fhir:org.hl7.fhir.validationDays to revision 36
2023-02-28published 2022-02-16Advisory severity changedGHSA-vg27-hr3v-3cqvCVE-2022-0637whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-02-28published 2023-02-17Advisory severity changedGHSA-f9c6-4j9h-6c5rCVE-2023-0880whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 12
2023-02-28published 2023-02-17Advisory severity changedGHSA-vp4r-h765-5mwpCVE-2023-0877whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 12
2023-02-28published 2023-02-17Advisory severity changedGHSA-w479-w22g-cffhCVE-2023-0821whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
Fri 24 Feb 2023· 8 advisory changes
2023-02-24published 2022-10-07Package added to advisoryGHSA-mqqv-chpx-vq25CVE-2020-7711highnot named as affected when the advisory was published, now names github.com/russellhaering/gosaml2not dated
2023-02-24published 2022-12-13Advisory severity changedGHSA-3vqj-43w4-2q58CVE-2022-45688whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 73
2023-02-24published 2023-02-12 to 2023-02-16Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8 to 12
2023-02-24published 2023-02-16same kind of change as the line aboveGHSA-q9ww-gjpw-p9g6CVE-2023-0860same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-02-24published 2023-02-15same kind of change as the line aboveGHSA-rr93-7c6x-8v4vCVE-2023-25767same package and registry as the line abovehighsame change as the line aboveDays to revision 9
2023-02-24published 2023-02-12same kind of change as the line aboveGHSA-gpvj-gp8c-c7p2CVE-2019-25103same package and registry as the line abovehighsame change as the line aboveDays to revision 12
2023-02-24published 2023-02-12Advisory severity changedwhole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 12
2023-02-24published 2023-02-12same kind of change as the line aboveGHSA-6vv4-qq3r-9rv8CVE-2023-0790same package and registry as the line abovehighsame change as the line aboveDays to revision 12
2023-02-24published 2023-02-12same kind of change as the line aboveGHSA-fxrq-xhj9-rf5jCVE-2023-0793same package and registry as the line abovehighsame change as the line aboveDays to revision 12
2023-02-24published 2023-02-16Advisory withdrawnGHSA-8mwq-mj73-qv68whole advisorycriticalwithdrawn 2023-02-24Days to revision 8
Thu 23 Feb 2023· 9 advisory changes
2023-02-23published 2023-02-12 to 2023-02-16Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8 to 11
2023-02-23published 2023-02-12same kind of change as the line aboveGHSA-6vp5-vv9p-7q62CVE-2023-0789same package and registry as the line abovecriticalsame change as the line aboveDays to revision 11
2023-02-23published 2023-02-12same kind of change as the line aboveGHSA-r6cw-356h-mvwgCVE-2023-0788same package and registry as the line abovecriticalsame change as the line aboveDays to revision 11
2023-02-23published 2023-02-13same kind of change as the line aboveGHSA-6fcj-9vfw-jq2mCVE-2023-24188same package and registry as the line abovecriticalsame change as the line aboveDays to revision 10
2023-02-23published 2023-02-16same kind of change as the line aboveGHSA-r58m-v5pr-jhhqCVE-2020-19825same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
2023-02-23published 2023-02-13Advisory severity changedGHSA-r2vq-p658-p274CVE-2023-25240whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2023-02-23published 2023-02-15Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 8
2023-02-23published 2023-02-15same kind of change as the line aboveGHSA-h97r-fchm-m23xCVE-2023-25763same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-02-23published 2023-02-15same kind of change as the line aboveGHSA-p2fr-mq9m-6w6pCVE-2023-25764same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-02-23published 2023-02-15Advisory severity changedGHSA-c9c2-wcxh-3w5jCVE-2023-25765whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-02-23published 2023-02-15Advisory severity changedGHSA-2hrw-hx67-34x6CVE-2023-24580whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
Wed 22 Feb 2023· 8 advisory changes
2023-02-22published 2019-02-22Package added to advisoryGHSA-9v3m-8fp8-mj99moderatenot named as affected when the advisory was published, now names bootstrap and 1 morenot dated
2023-02-22published 2019-02-22same kind of change as the line aboveGHSA-9v3m-8fp8-mj99CVE-2019-8331same package registry as the line abovemoderatenot named as affected when the advisory was published, now names bootstrapnot dated
2023-02-22published 2019-02-22same kind of change as the line aboveGHSA-9v3m-8fp8-mj99CVE-2019-8331same package registry as the line abovemoderatenot named as affected when the advisory was published, now names bootstrap-sassnot dated
2023-02-22published 2019-02-22Package added to advisoryGHSA-9v3m-8fp8-mj99moderatenot named as affected when the advisory was published, now names bootstrap and 2 morenot dated
2023-02-22published 2019-02-22same kind of change as the line aboveGHSA-9v3m-8fp8-mj99CVE-2019-8331same package registry as the line abovemoderatenot named as affected when the advisory was published, now names bootstrapnot dated
2023-02-22published 2019-02-22same kind of change as the line aboveGHSA-9v3m-8fp8-mj99CVE-2019-8331same package registry as the line abovemoderatenot named as affected when the advisory was published, now names bootstrap.lessnot dated
2023-02-22published 2019-02-22same kind of change as the line aboveGHSA-9v3m-8fp8-mj99CVE-2019-8331same package registry as the line abovemoderatenot named as affected when the advisory was published, now names bootstrap.sassnot dated
2023-02-22published 2021-05-18Advisory severity changedGHSA-5rcv-m4m3-hfh7CVE-2020-14040whole advisorymoderatestated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-02-22published 2023-02-12Advisory severity changedGHSA-j533-2g8v-pmpgCVE-2019-25102whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2023-02-22published 2022-12-12Advisory withdrawnGHSA-vc9x-gmmr-p7jjCVE-2021-4243whole advisorymoderatewithdrawn 2023-02-22Days to revision 71
Tue 21 Feb 2023· 6 advisory changes
2023-02-21published 2023-02-08Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 13
2023-02-21published 2023-02-08same kind of change as the line aboveGHSA-r7jw-wp68-3xchCVE-2023-0215same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-02-21published 2023-02-08same kind of change as the line aboveGHSA-29xx-hcv2-c4cpCVE-2023-0216same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-02-21published 2023-02-08same kind of change as the line aboveGHSA-v5w6-wcm8-jm4qCVE-2022-4450same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-02-21published 2023-02-08same kind of change as the line aboveGHSA-vxrh-cpg7-8vjrCVE-2023-0217same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-02-21published 2023-02-08same kind of change as the line aboveGHSA-vrh7-x64v-7vxqCVE-2023-0401same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-02-21published 2021-08-04Advisory severity changedGHSA-cmhx-cq75-c4mjCVE-2019-0820whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
Fri 17 Feb 2023· 7 advisory changes
2023-02-17published 2022-02-15Package added to advisoryGHSA-jp32-vmm6-3vf5CVE-2015-5305moderatenot named as affected when the advisory was published, now names k8s.io/kubernetesnot dated
2023-02-17published 2021-06-23Package added to advisoryGHSA-cjjc-xp8v-855wCVE-2020-7919highnot named as affected when the advisory was published, now names golang.org/x/cryptonot dated
2023-02-17published 2022-02-11Advisory severity changedGHSA-4w5x-x539-ppf5CVE-2020-26892whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2023-02-17published 2022-02-11Advisory severity changedGHSA-h2fg-54x9-5qhqCVE-2020-26521whole advisoryhighstated at publication LOW, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-02-17published 2023-02-10Advisory severity changedGHSA-rfhw-fm4m-52j6CVE-2023-0777whole advisorycriticalstated at publication HIGH, now states CRITICALCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 7
2023-02-17published 2022-08-24Advisory severity changedGHSA-wwch-cmqr-hhrmCVE-2021-3701whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2023-02-17published 2023-02-10Advisory severity changedGHSA-4gj3-6r43-3wfcCVE-2023-23631whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
Thu 16 Feb 2023· 11 advisory changes
2023-02-16published 2020-06-10Package added to advisoryGHSA-qr95-4mq5-r3fhCVE-2020-4043highnot named as affected when the advisory was published, now names maikuolan/phpmusselnot dated
2023-02-16published 2021-06-23Package added to advisoryGHSA-86r9-39j9-99wpCVE-2016-9121criticalnot named as affected when the advisory was published, now names github.com/square/go-josenot dated
2023-02-16published 2021-12-20Package added to advisoryGHSA-m9hp-7r99-94h5CVE-2020-26290criticalnot named as affected when the advisory was published, now names github.com/russellhaering/goxmldsignot dated
2023-02-16published 2023-01-18Advisory severity changedGHSA-579w-22j4-4749CVE-2022-44566whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 29
2023-02-16published 2023-02-08Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9
2023-02-16published 2023-02-08same kind of change as the line aboveGHSA-hjmr-xm25-36mhCVE-2023-0743same package and registry as the line abovecriticalsame change as the line aboveDays to revision 9
2023-02-16published 2023-02-08same kind of change as the line aboveGHSA-p7wj-c85f-xq9hCVE-2023-0741same package and registry as the line abovecriticalsame change as the line aboveDays to revision 9
2023-02-16published 2023-02-08Advisory severity changedGHSA-qx34-47fc-vv79CVE-2023-0739whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 9
2023-02-16published 2023-02-07 to 2023-02-09Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7 to 9
2023-02-16published 2023-02-07same kind of change as the line aboveGHSA-26f8-x7cc-wqpcCVE-2023-25194same package and registry as the line abovehighsame change as the line aboveDays to revision 9
2023-02-16published 2023-02-09same kind of change as the line aboveGHSA-86rf-38v8-9c4xCVE-2023-0759same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-02-16published 2021-05-18Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-02-16published 2021-05-18same kind of change as the line aboveGHSA-wjm3-fq3r-5x46CVE-2020-36066same package and registry as the line abovehighsame change as the line abovenot dated
2023-02-16published 2021-05-18same kind of change as the line aboveGHSA-ffhg-7mh4-33c4CVE-2020-9283same package and registry as the line abovehighsame change as the line abovenot dated
Wed 15 Feb 2023· 11 advisory changes
2023-02-15published 2021-07-26Advisory fix version movedGHSA-xcf7-q56x-78ghCVE-2021-23409
gogithub.com/pires/go-proxyproto
high
stated at publication 0.6.0, now states 0.6.1not dated
2023-02-15published 2022-05-24Advisory severity changedGHSA-7c2m-vwxw-5qwwCVE-2019-17560whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-02-15published 2023-02-08Advisory severity changedGHSA-65px-4cpf-697rCVE-2023-0740whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-02-15published 2023-02-08Advisory severity changedGHSA-rmw8-7823-wp7fCVE-2023-0742whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-02-15published 2023-01-25 to 2023-02-15Advisory severity changedwhole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 0 to 21
2023-02-15published 2023-01-25same kind of change as the line aboveGHSA-cq4p-vp5q-4522CVE-2022-43757same package and registry as the line abovehighsame change as the line aboveDays to revision 21
2023-02-15published 2023-02-15same kind of change as the line aboveGHSA-7j9h-3jxf-3vrfCVE-2023-25171same package and registry as the line abovehighsame change as the line aboveDays to revision 0
2023-02-15published 2023-01-25Advisory severity changedGHSA-34p5-jp77-fcrcCVE-2022-43758whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 21
2023-02-15published 2021-06-16Advisory severity changedGHSA-v528-7hrm-frqpCVE-2021-27568whole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2023-02-15published 2023-02-06Advisory severity changedGHSA-6pm2-j2v8-h3cjCVE-2023-0669whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2023-02-15published 2023-02-01Advisory severity changedGHSA-3gv2-29qc-v67mCVE-2022-24895whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 14
2023-02-15published 2023-02-13Advisory withdrawnGHSA-6p89-3p7c-qrhvCVE-2022-48110whole advisorymoderatewithdrawn 2023-02-15Days to revision 2
Tue 14 Feb 2023· 5 advisory changes
2023-02-14published 2022-08-18Package added to advisoryGHSA-8449-7gc2-pwrpCVE-2022-38149highnot named as affected when the advisory was published, now names github.com/hashicorp/consul-templatenot dated
2023-02-14published 2022-09-29Package added to advisoryGHSA-c9qr-f6c8-rgxfCVE-2022-40082highnot named as affected when the advisory was published, now names github.com/cloudwego/hertznot dated
2023-02-14published 2023-02-06Advisory severity changedGHSA-84mm-prjg-49xmCVE-2015-10073whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-02-14published 2023-02-04Advisory severity changedGHSA-p9w8-2mpq-49h9CVE-2018-25079whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2023-02-14published 2023-02-11Advisory withdrawnGHSA-8x6c-cv3v-vp6gwhole advisoryhighwithdrawn 2023-02-14Days to revision 3
Mon 13 Feb 2023· 2 advisory changes
2023-02-13published 2022-02-22Package added to advisoryGHSA-fgv8-vj5c-2ppqCVE-2019-16884highnot named as affected when the advisory was published, now names github.com/opencontainers/selinuxnot dated
2023-02-13published 2023-02-02Advisory severity changedGHSA-8xv4-jj4h-qww6CVE-2023-23937whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
Fri 10 Feb 2023· 4 advisory changes
2023-02-10published 2023-02-04Advisory severity changedGHSA-9fqc-9cpr-w73qCVE-2023-0671whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-02-10published 2023-02-03Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
2023-02-10published 2023-02-03same kind of change as the line aboveGHSA-fqp6-fw9g-xpxpCVE-2021-37306same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-02-10published 2023-02-03same kind of change as the line aboveGHSA-rwhw-6c6r-2823CVE-2021-37304same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-02-10published 2023-02-03same kind of change as the line aboveGHSA-4f48-qpch-4ppxCVE-2021-37305same package and registry as the line abovehighsame change as the line aboveDays to revision 6
Thu 9 Feb 2023· 4 advisory changes
2023-02-09published 2022-07-15Advisory fix version movedGHSA-qwrj-9hmp-gpxhCVE-2022-31145
gogithub.com/flyteorg/flyteadmin
moderate
stated at publication 1.1.30, now states 1.1.31not dated
2023-02-09published 2021-06-23Advisory fix version movedGHSA-h395-qcrw-5vmqCVE-2020-28483
gogithub.com/gin-gonic/gin
high
stated at publication 1.7.0, now states 1.7.7not dated
2023-02-09published 2022-05-22Advisory fix version movedGHSA-qx32-f6g6-fcfrCVE-2022-31259
gogithub.com/beego/beego
critical
stated at publication 1.12.4, now states 1.12.9not dated
2023-02-09published 2022-04-06Advisory fix version movedGHSA-28r6-jm5h-mrggCVE-2021-30080
gogithub.com/beego/beego/v2
high
stated at publication 2.0.2, now states 2.0.3not dated

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →