Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Thu 9 Feb 2023· 16 advisory changes
2023-02-09published 2021-12-20 to 2022-12-28Package added to advisorymoderatenot named as affected when the advisory was published, now names github.com/go-yaml/yamlDays to revision 44
2023-02-09published 2022-12-28same kind of change as the line aboveGHSA-r88r-gmrh-7j83CVE-2021-4235same package registry as the line abovemoderatesame change as the line aboveDays to revision 44
2023-02-09published 2021-12-20same kind of change as the line aboveGHSA-wxc4-f4m6-wwqvCVE-2019-11254same package registry as the line abovemoderatesame change as the line abovenot dated
2023-02-09published 2022-08-30Package added to advisoryGHSA-grvv-h2f9-7v9cCVE-2022-36009moderatenot named as affected when the advisory was published, now names github.com/matrix-org/gomatrixserverlibnot dated
2023-02-09published 2021-06-29Package added to advisoryGHSA-mr6h-chqp-p9g2CVE-2014-8681moderatenot named as affected when the advisory was published, now names github.com/gogits/gogsnot dated
2023-02-09published 2021-06-29Package added to advisoryGHSA-jm5c-rv3w-w83mCVE-2020-26242moderatenot named as affected when the advisory was published, now names github.com/holiman/uint256not dated
2023-02-09published 2019-07-05Package added to advisoryGHSA-x64g-wjmw-w328CVE-2015-5306criticalnot named as affected when the advisory was published, now names python-ironic-inspector-clientnot dated
2023-02-09published 2021-08-25Package added to advisory2 bandsnot named as affected when the advisory was published, now names tensorflownot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-cfpj-3q4c-jhvrCVE-2021-37680same package registry as the line abovemoderatesame change as the line abovenot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-7xwj-5r4v-429pCVE-2021-37681same package registry as the line abovehighsame change as the line abovenot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-rhrq-64mq-hf9hCVE-2021-37683same package registry as the line abovemoderatesame change as the line abovenot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-c545-c4f9-rf6vCVE-2021-37685same package registry as the line abovemoderatesame change as the line abovenot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-jwf9-w5xm-f437CVE-2021-37687same package registry as the line abovemoderatesame change as the line abovenot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-vcjj-9vg7-vf68CVE-2021-37688same package registry as the line abovehighsame change as the line abovenot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-wf5p-c75w-w3whCVE-2021-37689same package registry as the line abovehighsame change as the line abovenot dated
2023-02-09published 2021-08-25same kind of change as the line aboveGHSA-4c4g-crqm-xrxwCVE-2021-37682same package registry as the line abovemoderatesame change as the line abovenot dated
2023-02-09published 2022-04-30Package added to advisoryGHSA-66vw-v2x9-hw75CVE-2022-1227highnot named as affected when the advisory was published, now names github.com/containers/psgonot dated
2023-02-09published 2023-02-06Advisory withdrawnGHSA-6pm2-j2v8-h3cjCVE-2023-0669whole advisoryhighwithdrawn 2023-02-09Days to revision 3
Wed 8 Feb 2023· 4 advisory changes
2023-02-08published 2023-02-01Advisory severity changedGHSA-22j4-qc48-j8f8CVE-2023-24997whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-02-08published 2023-02-01Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-02-08published 2023-02-01same kind of change as the line aboveGHSA-q2jf-h9jm-m7p4CVE-2023-23969same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-02-08published 2023-02-01same kind of change as the line aboveGHSA-q9p5-w2v9-6wxfCVE-2023-24977same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-02-08published 2022-03-24Advisory severity changedGHSA-vvff-6wrr-4g7qCVE-2021-3589whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 13
Tue 7 Feb 2023· 13 advisory changes
2023-02-07published 2022-12-14Package added to advisoryGHSA-53mm-hx32-6475CVE-2022-47406criticalnot named as affected when the advisory was published, now names derhansen/fe_change_pwdDays to revision 55
2023-02-07published 2022-12-28Package added to advisoryGHSA-vp56-r7qv-783vCVE-2020-36559highnot named as affected when the advisory was published, now names aahframe.workDays to revision 42
2023-02-07published 2022-12-22 to 2022-12-25Package added to advisory2 bandsnot named as affected when the advisory was published, now names code.sajari.com/docconvDays to revision 44 to 48
2023-02-07published 2022-12-25same kind of change as the line aboveGHSA-qvx2-59g8-8hphCVE-2022-4741same package registry as the line abovemoderatesame change as the line aboveDays to revision 44
2023-02-07published 2022-12-22same kind of change as the line aboveGHSA-6m4h-hfpp-x8cxCVE-2022-4643same package registry as the line abovecriticalsame change as the line aboveDays to revision 48
2023-02-07published 2023-01-30Advisory severity changedGHSA-rw83-v3pw-m362whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 9
2023-02-07published 2023-01-29 to 2023-01-31Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7 to 10
2023-02-07published 2023-01-29same kind of change as the line aboveGHSA-9mq4-9556-6qxqCVE-2021-4315same package and registry as the line abovehighsame change as the line aboveDays to revision 10
2023-02-07published 2023-01-31same kind of change as the line aboveGHSA-rc47-6667-2j5jCVE-2022-25881same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-02-07published 2023-01-30same kind of change as the line aboveGHSA-pp4w-9x82-6r47CVE-2023-24830same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-02-07published 2021-05-10Advisory severity changedGHSA-7qw8-847f-pggmCVE-2021-20291whole advisorymoderatestated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-02-07published 2021-06-23Advisory severity changedGHSA-4hq8-gmxx-h6w9CVE-2020-27846whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-02-07published 2023-01-31Advisory severity changedGHSA-c6rx-gxqv-vr5jCVE-2022-21129whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-02-07published 2021-05-18Advisory severity changedGHSA-rmh2-65xw-9m6qCVE-2020-10675whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-02-07published 2023-01-29Advisory severity changedGHSA-g7gf-2rqw-5rwxCVE-2023-0569whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 9
Mon 6 Feb 2023· 7 advisory changes
2023-02-06published 2022-09-16Advisory fix version movedGHSA-3pgj-pg6c-r5p7CVE-2022-36087
pypioauthlib
moderate
stated at publication 3.2.1, now states 3.2.2not dated
2023-02-06published 2023-01-29Advisory severity changedGHSA-pm72-27mg-fc28CVE-2023-0564whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2023-02-06published 2023-01-26Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 11
2023-02-06published 2023-01-26same kind of change as the line aboveGHSA-x9q4-qwfh-9gjqCVE-2023-24427same package and registry as the line abovecriticalsame change as the line aboveDays to revision 11
2023-02-06published 2023-01-26same kind of change as the line aboveGHSA-h8p8-6378-649pCVE-2023-24430same package and registry as the line abovecriticalsame change as the line aboveDays to revision 11
2023-02-06published 2023-01-26Advisory severity changedGHSA-3g2g-rcm6-rrq2CVE-2023-24440whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
2023-02-06published 2023-01-26Advisory severity changedGHSA-pcc2-w6m8-x5w4CVE-2023-24429whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 11
2023-02-06published 2023-01-26Advisory severity changedGHSA-g29v-5pwh-wxx4CVE-2023-24439whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
Fri 3 Feb 2023· 16 advisory changes
2023-02-03published 2019-07-16Advisory severity changedGHSA-2mp5-m968-gwr2CVE-2019-5447whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-02-03published 2018-09-17Advisory severity changedGHSA-c9j3-wqph-5xx9CVE-2018-3786whole advisorycriticalstated at publication LOW, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-02-03published 2018-08-21Advisory severity changedGHSA-h3c2-x77c-7pvrCVE-2018-3785whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-02-03published 2022-02-15Advisory severity changedGHSA-xx8c-m748-xr4jCVE-2016-1905whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-02-03published 2022-02-09Advisory severity changedGHSA-h39q-95q5-9jfpCVE-2020-1734whole advisoryhighstated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.not dated
2023-02-03published 2023-01-26Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-4x65-4fjx-r7m6CVE-2023-24442same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-98qc-v8vg-mcx4CVE-2023-24454same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-96jv-c7m6-q43gCVE-2023-24446same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-wj79-9fxj-j86pCVE-2023-24447same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-px2f-cqrf-f2qgCVE-2023-24452same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-5xhh-6xfv-7q42CVE-2023-24458same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-g5mj-c26g-vmpmCVE-2023-24443same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-9963-gmh8-vvm6CVE-2023-24456same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-54jw-jqr9-6cj9CVE-2022-25962same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-9w5j-4mwv-2wj8CVE-2022-25860same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
2023-02-03published 2023-01-26same kind of change as the line aboveGHSA-j8wr-fwf2-vvr9CVE-2022-25908same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
Thu 2 Feb 2023· 4 advisory changes
2023-02-02published 2021-01-06Package added to advisoryGHSA-w7jx-j77m-wp65CVE-2024-21911moderatenot named as affected when the advisory was published, now names tinymcenot dated
2023-02-02published 2021-01-06Package added to advisoryGHSA-w7jx-j77m-wp65CVE-2024-21911moderatenot named as affected when the advisory was published, now names tinymce/tinymcenot dated
2023-02-02published 2023-01-26Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2023-02-02published 2023-01-26same kind of change as the line aboveGHSA-69f2-4375-qv9hCVE-2022-21810same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-02-02published 2023-01-26same kind of change as the line aboveGHSA-g5qr-xgg7-8q2wCVE-2022-25350same package and registry as the line abovehighsame change as the line aboveDays to revision 7
Wed 1 Feb 2023· 4 advisory changes
2023-02-01published 2023-01-27Advisory severity changedGHSA-jgh8-vchw-q3g7CVE-2023-24622whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 6
2023-02-01published 2023-01-23Advisory severity changedGHSA-6jmx-pv77-wm5wCVE-2023-0435whole advisorycriticalstated at publication MODERATE, now states CRITICALCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 9
2023-02-01published 2019-07-31Advisory severity changedGHSA-7j93-2h6r-hm49CVE-2019-5458whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-02-01published 2023-01-21Advisory severity changedGHSA-c732-xvv8-g94cCVE-2023-22884whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 11
Tue 31 Jan 2023· 7 advisory changes
2023-01-31published 2018-07-18Advisory severity changedGHSA-h24f-9mm4-w336CVE-2018-3726whole advisorymoderatestated at publication CRITICAL, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-01-31published 2018-07-26 to 2018-08-08Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-01-31published 2018-08-08same kind of change as the line aboveGHSA-8f64-q7jc-ccgpCVE-2018-3773same package and registry as the line abovemoderatesame change as the line abovenot dated
2023-01-31published 2018-07-26same kind of change as the line aboveGHSA-jrhj-2j3q-xf3vCVE-2018-3716same package and registry as the line abovemoderatesame change as the line abovenot dated
2023-01-31published 2018-07-26same kind of change as the line aboveGHSA-2x4q-6jfv-8h9hCVE-2018-3715same package and registry as the line abovemoderatesame change as the line abovenot dated
2023-01-31published 2018-07-18Advisory severity changedGHSA-qmm9-x5gr-4gfmCVE-2018-3743whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-01-31published 2018-06-07 to 2018-09-18Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-01-31published 2018-09-18same kind of change as the line aboveGHSA-fm87-46vv-jqrrCVE-2018-3744same package and registry as the line abovecriticalsame change as the line abovenot dated
2023-01-31published 2018-06-07same kind of change as the line aboveGHSA-3pxp-6963-46r9CVE-2018-3746same package and registry as the line abovecriticalsame change as the line abovenot dated
Mon 30 Jan 2023· 1 advisory change
2023-01-30published 2020-02-19Package added to advisoryGHSA-mxhp-79qh-mcx6CVE-2019-10790highnot named as affected when the advisory was published, now names taffydbnot dated
Fri 27 Jan 2023· 5 advisory changes
2023-01-27published 2023-01-14 to 2023-01-20Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7 to 13
2023-01-27published 2023-01-20same kind of change as the line aboveGHSA-hj4g-4w36-x8hpCVE-2022-47747same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-01-27published 2023-01-14same kind of change as the line aboveGHSA-7cxr-h8wm-fg4cCVE-2023-22602same package and registry as the line abovehighsame change as the line aboveDays to revision 13
2023-01-27published 2022-02-15Advisory severity changedGHSA-qhm4-jxv7-j9pqCVE-2020-8551whole advisorymoderatestated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-01-27published 2021-04-20Advisory severity changedGHSA-2xpj-f5g2-8p7mCVE-2020-17446whole advisorycriticalstated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.not dated
2023-01-27published 2022-12-22Advisory withdrawnGHSA-27h2-hvpr-p74qCVE-2022-23529whole advisoryhighwithdrawn 2023-01-27Days to revision 37
Thu 26 Jan 2023· 3 advisory changes
2023-01-26published 2021-05-06Package added to advisoryGHSA-3c6g-pvg8-gqw2CVE-2020-7712highnot named as affected when the advisory was published, now names org.webjars.npm:jsonnot dated
2023-01-26published 2017-10-24Package added to advisoryGHSA-hpcf-8vf9-q4gjCVE-2016-7103moderatenot named as affected when the advisory was published, now names jquery-ui-railsnot dated
2023-01-26published 2023-01-19Advisory severity changedGHSA-6w89-c65w-jx2cCVE-2022-47105whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 7
Wed 25 Jan 2023· 4 advisory changes
2023-01-25published 2023-01-20Package added to advisoryGHSA-6g8q-qfpv-57wpCVE-2023-22727criticalnot named as affected when the advisory was published, now names cakephp/databaseDays to revision 5
2023-01-25published 2021-05-24Advisory severity changedGHSA-3892-2r52-p65mCVE-2020-7671whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-01-25published 2023-01-13Advisory severity changedGHSA-jmj6-p2j9-68cpCVE-2022-3143whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 13
2023-01-25published 2022-12-13Advisory severity changedGHSA-g8q8-fggx-9r3qCVE-2022-3782whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 43
Tue 24 Jan 2023· 7 advisory changes
2023-01-24published 2023-01-09 to 2023-01-14Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 11 to 15
2023-01-24published 2023-01-09same kind of change as the line aboveGHSA-pfpr-3463-c6jhCVE-2022-46648same package and registry as the line abovehighsame change as the line aboveDays to revision 15
2023-01-24published 2023-01-14same kind of change as the line aboveGHSA-fxg5-wq6x-vr4wCVE-2022-41721same package and registry as the line abovehighsame change as the line aboveDays to revision 11
2023-01-24published 2023-01-16Advisory severity changedGHSA-85gf-wr67-f83wCVE-2015-10053whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8
2023-01-24published 2023-01-16Advisory severity changedGHSA-7222-r37x-8q3mCVE-2022-43719whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 8
2023-01-24published 2023-01-16Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 8
2023-01-24published 2023-01-16same kind of change as the line aboveGHSA-cxvp-3frm-3876CVE-2022-41703same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-01-24published 2023-01-16same kind of change as the line aboveGHSA-fpmr-qmgh-42x2CVE-2022-43720same package and registry as the line abovemoderatesame change as the line aboveDays to revision 8
2023-01-24published 2023-01-23Advisory severity changedGHSA-q764-g6fm-555vCVE-2023-23608whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 1
Mon 23 Jan 2023· 10 advisory changes
2023-01-23published 2017-10-24Advisory severity changedGHSA-5vx5-9q73-wgp4CVE-2017-7540whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-01-23published 2018-01-22Advisory severity changedGHSA-5jcf-c5rg-rmm8CVE-2017-0889whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2023-01-23published 2021-05-24Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-01-23published 2021-05-24same kind of change as the line aboveGHSA-x3v4-pxvm-63j8CVE-2020-7659same package and registry as the line abovehighsame change as the line abovenot dated
2023-01-23published 2021-05-24same kind of change as the line aboveGHSA-4f68-49qq-h392CVE-2020-13163same package and registry as the line abovehighsame change as the line abovenot dated
2023-01-23published 2019-09-11Advisory severity changedGHSA-fcjw-8rhj-gwwcCVE-2019-16109whole advisorymoderatestated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
2023-01-23published 2023-01-14Advisory severity changedGHSA-q3rm-f527-ghxjCVE-2023-0299whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9
2023-01-23published 2023-01-13 to 2023-01-16Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 8 to 10
2023-01-23published 2023-01-16same kind of change as the line aboveGHSA-g92r-9rxw-cmgxCVE-2023-0311same package and registry as the line abovecriticalsame change as the line aboveDays to revision 8
2023-01-23published 2023-01-13same kind of change as the line aboveGHSA-m589-mv4q-p7rjCVE-2022-45299same package and registry as the line abovecriticalsame change as the line aboveDays to revision 10
2023-01-23published 2023-01-12Advisory severity changedGHSA-v436-q368-hvggCVE-2023-0091whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
2023-01-23published 2022-10-27Advisory withdrawnGHSA-9chr-4fjh-5rgwCVE-2022-3704whole advisorylowwithdrawn 2023-01-23Days to revision 88
Fri 20 Jan 2023· 3 advisory changes
2023-01-20published 2019-11-05Advisory severity changedGHSA-c3gv-9cxf-6f57CVE-2019-15587whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-01-20published 2023-01-13Advisory severity changedGHSA-vvj3-85vf-fgmwCVE-2022-21191whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2023-01-20published 2023-01-12Advisory severity changedGHSA-rv9x-wmw4-44qjCVE-2023-0227whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 9
Thu 19 Jan 2023· 2 advisory changes
2023-01-19published 2023-01-11Advisory severity changedwhole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 8
2023-01-19published 2023-01-11same kind of change as the line aboveGHSA-798h-g4j5-5537same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-01-19published 2023-01-11same kind of change as the line aboveGHSA-qv66-f876-vjvrCVE-2018-25074same package and registry as the line abovehighsame change as the line aboveDays to revision 8
Tue 17 Jan 2023· 1 advisory change
2023-01-17published 2022-12-12Advisory severity changedGHSA-j8x2-2m5w-j939CVE-2022-23511whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 36
Fri 13 Jan 2023· 4 advisory changes
2023-01-13published 2023-01-10Advisory severity changedGHSA-4r2f-6fm9-2qghwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 4
2023-01-13published 2023-01-10Advisory severity changedGHSA-96jv-r488-c2rjCVE-2023-22895whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 4
2023-01-13published 2023-01-09Advisory severity changedGHSA-9vvw-cc9w-f27hCVE-2017-20165whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-01-13published 2023-01-09Advisory severity changedGHSA-xj9v-6q2f-vqhxCVE-2022-25890whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 4
Thu 12 Jan 2023· 2 advisory changes
2023-01-12published 2023-01-07Advisory severity changedGHSA-wvr2-q86m-6whpCVE-2021-4307whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5
2023-01-12published 2023-01-06Advisory severity changedGHSA-f259-h6m8-hm8mCVE-2022-25923whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6
Wed 11 Jan 2023· 6 advisory changes
2023-01-11published 2023-01-05Advisory severity changedGHSA-wg99-5vrx-j2ggCVE-2020-36640whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6
2023-01-11published 2023-01-05Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6 to 7
2023-01-11published 2023-01-05same kind of change as the line aboveGHSA-6g33-8w2q-4hxvCVE-2021-4305same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2023-01-11published 2023-01-05same kind of change as the line aboveGHSA-vf99-xw26-86g5CVE-2023-22626same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-01-11published 2023-01-05Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7
2023-01-11published 2023-01-05same kind of change as the line aboveGHSA-h8r9-467r-vjjfCVE-2023-0057same package and registry as the line abovemoderatesame change as the line aboveDays to revision 7
2023-01-11published 2023-01-05same kind of change as the line aboveGHSA-m3g7-wrrq-v5c8CVE-2023-0055same package and registry as the line abovemoderatesame change as the line aboveDays to revision 7
2023-01-11published 2023-01-10Advisory severity changedGHSA-8f7f-vqg5-jrv9CVE-2023-21538whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 0
Tue 10 Jan 2023· 45 advisory changes
2023-01-10published 2022-12-28Package added to advisoryGHSA-967g-cjx4-h7j6highnot named as affected when the advisory was published, now names github.com/ipld/go-codec-dagpbDays to revision 14
2023-01-10published 2022-12-12Advisory severity changedGHSA-hh82-3pmq-7frpCVE-2022-41915whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 29
2023-01-10published 2023-01-04Advisory severity changedGHSA-3xh5-8hvq-rc8xCVE-2022-45875whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6
2023-01-10published 2023-01-02 to 2023-01-04Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7 to 8
2023-01-10published 2023-01-04same kind of change as the line aboveGHSA-vp62-m958-qj8cCVE-2022-38723same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2023-01-10published 2023-01-02same kind of change as the line aboveGHSA-pfrm-4rjw-g9q5CVE-2021-4299same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2023-01-10published 2022-12-27Advisory severity changedwhole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 14 to 15
2023-01-10published 2022-12-27same kind of change as the line aboveGHSA-p27h-4cpf-fw48CVE-2018-25049same package and registry as the line abovehighsame change as the line aboveDays to revision 15
2023-01-10published 2022-12-27same kind of change as the line aboveGHSA-j5p7-jf4q-742qCVE-2015-10005same package and registry as the line abovehighsame change as the line aboveDays to revision 14
2023-01-10published 2022-12-28 to 2022-12-30Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11 to 14
2023-01-10published 2022-12-30same kind of change as the line aboveGHSA-6whj-8g9g-5jvxCVE-2022-4863same package and registry as the line abovemoderatesame change as the line aboveDays to revision 11
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-r88r-gmrh-7j83CVE-2021-4235same package and registry as the line abovemoderatesame change as the line aboveDays to revision 14
2023-01-10published 2022-12-29same kind of change as the line aboveGHSA-vh43-cc6x-prprCVE-2022-4848same package and registry as the line abovemoderatesame change as the line aboveDays to revision 12
2023-01-10published 2022-12-29same kind of change as the line aboveGHSA-42q2-m54f-jh95CVE-2022-4851same package and registry as the line abovemoderatesame change as the line aboveDays to revision 12
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-qrrf-xvcf-p64qCVE-2022-4797same package and registry as the line abovemoderatesame change as the line aboveDays to revision 13
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-6fx9-29x2-fmfjCVE-2022-4814same package and registry as the line abovemoderatesame change as the line aboveDays to revision 13
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-7qpw-2j9m-rw8cCVE-2022-4813same package and registry as the line abovemoderatesame change as the line aboveDays to revision 13
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-hc5q-26h8-r9wfCVE-2022-4811same package and registry as the line abovemoderatesame change as the line aboveDays to revision 13
4 more rows in this change are not listed here. Open all 12 rows
2023-01-10published 2022-02-11 to 2022-12-30Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
2023-01-10published 2022-12-30same kind of change as the line aboveGHSA-cwh7-28vg-jmprCVE-2018-25059same package and registry as the line abovemoderatesame change as the line aboveDays to revision 11
2023-01-10published 2022-02-11same kind of change as the line aboveGHSA-q9x4-q76f-5h5jCVE-2019-19030same package and registry as the line abovemoderatesame change as the line abovenot dated
2023-01-10published 2022-12-27 to 2022-12-30Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 11 to 13
2023-01-10published 2022-12-30same kind of change as the line aboveGHSA-w9rv-xmf7-x3ghCVE-2022-44621same package and registry as the line abovecriticalsame change as the line aboveDays to revision 11
2023-01-10published 2022-12-27same kind of change as the line aboveGHSA-m8r9-qxx8-mrxpCVE-2022-4724same package and registry as the line abovecriticalsame change as the line aboveDays to revision 13
2023-01-10published 2022-12-27 to 2022-12-31Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 10 to 14
2023-01-10published 2022-12-31same kind of change as the line aboveGHSA-gvfj-fxx3-j323CVE-2022-48195same package and registry as the line abovecriticalsame change as the line aboveDays to revision 11
2023-01-10published 2022-12-31same kind of change as the line aboveGHSA-8w5q-5fpq-v4pmCVE-2022-4865same package and registry as the line abovecriticalsame change as the line aboveDays to revision 10
2023-01-10published 2022-12-31same kind of change as the line aboveGHSA-x9p9-v3x6-68mqCVE-2022-4866same package and registry as the line abovecriticalsame change as the line aboveDays to revision 10
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-32qh-8vg6-9g43CVE-2018-25046same package and registry as the line abovecriticalsame change as the line aboveDays to revision 14
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-jcr6-mmjj-pchwCVE-2017-20146same package and registry as the line abovecriticalsame change as the line aboveDays to revision 14
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-f5c5-hmw9-v8hxCVE-2020-36561same package and registry as the line abovecriticalsame change as the line aboveDays to revision 14
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-rmj9-q58g-9qggCVE-2020-36560same package and registry as the line abovecriticalsame change as the line aboveDays to revision 14
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-jpf8-h7h7-3ppmCVE-2020-36566same package and registry as the line abovecriticalsame change as the line aboveDays to revision 14
2 more rows in this change are not listed here. Open all 10 rows
2023-01-10published 2022-07-15 to 2022-12-31Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10 to 14
2023-01-10published 2022-12-31same kind of change as the line aboveGHSA-7599-fqgm-v84pCVE-2018-25061same package and registry as the line abovehighsame change as the line aboveDays to revision 10
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-5vw4-v588-pgv8CVE-2015-10004same package and registry as the line abovehighsame change as the line aboveDays to revision 14
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-fjgq-224f-fq37CVE-2019-25073same package and registry as the line abovehighsame change as the line aboveDays to revision 14
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-q9qr-jwpw-3qvvCVE-2016-15005same package and registry as the line abovehighsame change as the line aboveDays to revision 14
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-vp56-r7qv-783vCVE-2020-36559same package and registry as the line abovehighsame change as the line aboveDays to revision 14
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-6q6q-88xp-6f2rCVE-2022-3064same package and registry as the line abovehighsame change as the line aboveDays to revision 14
2023-01-10published 2022-12-28same kind of change as the line aboveGHSA-5x84-q523-vvwrCVE-2020-36564same package and registry as the line abovehighsame change as the line aboveDays to revision 14
2023-01-10published 2022-07-15same kind of change as the line aboveGHSA-697v-pxg3-j262CVE-2020-28191same package and registry as the line abovehighsame change as the line abovenot dated
2 more rows in this change are not listed here. Open all 10 rows
2023-01-10published 2022-12-27Advisory severity changedGHSA-8h43-xg5g-9cj7CVE-2022-4732whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 13
2023-01-10published 2022-04-05Advisory severity changedGHSA-g27j-74fp-xfprCVE-2022-26969whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
Mon 9 Jan 2023· 1 advisory change
2023-01-09published 2022-02-15Advisory severity changedGHSA-6hv3-7c34-4hx8CVE-2019-14802whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →