Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Mon 9 Jan 2023· 1 advisory change
2023-01-09published 2022-12-25Advisory severity changedGHSA-q6cq-m9gm-6q2fCVE-2022-45197whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 15
Fri 6 Jan 2023· 10 advisory changes
2023-01-06published 2022-04-08Advisory fix version movedGHSA-h6xw-mghq-7523CVE-2022-27819
crates.iosimple-wayland-hotkey-daemon
moderate
stated at publication 1.1.7, now states 1.2.0not dated
2023-01-06published 2022-11-22Package added to advisoryGHSA-g56w-cwg4-hxx9CVE-2022-4116criticalnot named as affected when the advisory was published, now names io.quarkus:quarkus-vertx-http-deploymentDays to revision 45
2023-01-06published 2022-02-15Package added to advisoryGHSA-wqv3-8cm6-h6wgCVE-2020-8558highnot named as affected when the advisory was published, now names k8s.io/kubernetesnot dated
2023-01-06published 2021-12-09Package added to advisoryGHSA-qrmm-w75w-3wpxmoderatenot named as affected when the advisory was published, now names swashbuckle.aspnetcore.swaggeruinot dated
2023-01-06published 2022-12-25 to 2022-12-28Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9 to 11
2023-01-06published 2022-12-26same kind of change as the line aboveGHSA-6xrf-q977-5vgcCVE-2022-4742same package and registry as the line abovecriticalsame change as the line aboveDays to revision 11
2023-01-06published 2022-12-28same kind of change as the line aboveGHSA-3839-6r69-m497same package and registry as the line abovecriticalsame change as the line aboveDays to revision 9
2023-01-06published 2022-12-28same kind of change as the line aboveGHSA-jpgg-cp2x-qrw3same package and registry as the line abovecriticalsame change as the line aboveDays to revision 9
2023-01-06published 2022-12-25same kind of change as the line aboveGHSA-2j2x-2gpw-g8fmCVE-2020-36632same package and registry as the line abovecriticalsame change as the line aboveDays to revision 11
2023-01-06published 2022-12-28Advisory severity changedGHSA-4348-x292-h437whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 9
2023-01-06published 2022-07-18Advisory severity changedGHSA-cj88-88mr-972wCVE-2021-35065whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
Thu 5 Jan 2023· 1 advisory change
2023-01-05published 2022-04-08Advisory fix version movedGHSA-r3r5-jhw6-4634CVE-2022-27818
crates.iosimple-wayland-hotkey-daemon
critical
stated at publication 1.1.7, now states 1.2.0not dated
Tue 3 Jan 2023· 1 advisory change
2023-01-03published 2022-12-19Advisory severity changedGHSA-4whf-rmx5-8frvCVE-2021-4250whole advisoryhighstated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 16
Mon 2 Jan 2023· 5 advisory changes
2023-01-02published 2022-09-17Advisory severity changedGHSA-x27m-9w8j-5vcwCVE-2022-40150whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.not dated
2023-01-02published 2021-03-12Advisory severity changedGHSA-h6q6-9hqw-rwfvCVE-2021-21366whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2023-01-02published 2022-12-22 to 2022-12-23Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 10 to 11
2023-01-02published 2022-12-23same kind of change as the line aboveGHSA-68gw-r2x5-7r5rCVE-2022-4686same package and registry as the line abovecriticalsame change as the line aboveDays to revision 10
2023-01-02published 2022-12-22same kind of change as the line aboveGHSA-wmxm-6wxc-3xqfCVE-2022-45347same package and registry as the line abovecriticalsame change as the line aboveDays to revision 11
2023-01-02published 2022-12-20Advisory severity changedGHSA-33vh-7x8q-mg35CVE-2022-25904whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 13
Thu 29 Dec 2022· 3 advisory changes
2022-12-29published 2022-12-19Advisory severity changedGHSA-97jv-c342-5xhcCVE-2020-36618whole advisorycriticalstated at publication MODERATE, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 10
2022-12-29published 2022-12-21Advisory severity changedGHSA-c2p4-8mvv-rwmvCVE-2022-40145whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
2022-12-29published 2022-12-21Advisory severity changedGHSA-c6rp-wrp9-qr4qCVE-2021-4264whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
Tue 27 Dec 2022· 7 advisory changes
2022-12-27published 2022-05-24Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-27published 2022-05-24same kind of change as the line aboveGHSA-vr6v-wjfw-rxcrCVE-2020-2226same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-27published 2022-05-24same kind of change as the line aboveGHSA-w43x-5f8f-686pCVE-2020-2225same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-27published 2022-05-24same kind of change as the line aboveGHSA-h6qc-455m-7v6vCVE-2020-2224same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-27published 2022-05-24same kind of change as the line aboveGHSA-gfhj-524q-gcrmCVE-2020-2223same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-27published 2022-05-24same kind of change as the line aboveGHSA-864v-5q2g-fr64CVE-2020-2222same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-27published 2022-05-24same kind of change as the line aboveGHSA-g4j6-m3m3-crw8CVE-2020-2221same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-27published 2022-05-24same kind of change as the line aboveGHSA-qgj4-rc8m-44mqCVE-2020-2220same package and registry as the line abovehighsame change as the line abovenot dated
Fri 23 Dec 2022· 1 advisory change
2022-12-23published 2022-12-19Advisory severity changedGHSA-4jv9-3563-23j3CVE-2016-20018whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 5
Thu 22 Dec 2022· 1 advisory change
2022-12-22published 2022-12-16Advisory severity changedGHSA-47vx-fqr5-j2gwCVE-2022-4565whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
Wed 21 Dec 2022· 1 advisory change
2022-12-21published 2019-01-17Advisory severity changedGHSA-jhjh-ghwx-6h7rCVE-2017-1002157whole advisorycriticalstated at publication LOW, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
Tue 20 Dec 2022· 7 advisory changes
2022-12-20published 2022-12-20Package added to advisoryGHSA-54r5-wr8x-x5v3highnot named as affected when the advisory was published, now names io.apiman:apiman-manager-api-rest-implDays to revision 1
2022-12-20published 2022-12-20Advisory severity changedGHSA-54r5-wr8x-x5v3whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 1
2022-12-20published 2022-12-15 to 2022-12-16Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5
2022-12-20published 2022-12-15same kind of change as the line aboveGHSA-p495-jxh2-wrfgCVE-2021-4245same package and registry as the line abovecriticalsame change as the line aboveDays to revision 5
2022-12-20published 2022-12-16same kind of change as the line aboveGHSA-pmg2-rph8-p8r6CVE-2022-45969same package and registry as the line abovecriticalsame change as the line aboveDays to revision 5
2022-12-20published 2022-05-24Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.not dated
2022-12-20published 2022-05-24same kind of change as the line aboveGHSA-9g4m-ffx6-c29gCVE-2020-2230same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-20published 2022-05-24same kind of change as the line aboveGHSA-hvmc-7g2x-r3p9CVE-2020-2229same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-20published 2022-12-15Advisory severity changedGHSA-gxq5-79m2-gvvqCVE-2022-32531whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 5
Mon 19 Dec 2022· 1 advisory change
2022-12-19published 2022-11-10Package added to advisoryGHSA-4vrc-q7m6-vq7wCVE-2022-44244moderatenot named as affected when the advisory was published, now names io.github.talelin:lin-cms-coreDays to revision 39
Fri 16 Dec 2022· 26 advisory changes
2022-12-16published 2022-05-24 to 2022-10-19Package added to advisory8 rows, one per advisory and package3 bandsnot named as affected when the advisory was published, now names org.jenkins-ci.plugins:credentials-binding and 4 moreDays to revision 206
2022-12-16published 2022-05-24same kind of change as the line aboveGHSA-7ff8-qfwx-8gx5CVE-2020-2182same package registry as the line abovelownot named as affected when the advisory was published, now names org.jenkins-ci.plugins:credentials-bindingnot dated
2022-12-16published 2022-05-24same kind of change as the line aboveGHSA-43j2-r4v3-m8jpCVE-2020-2181same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins:credentials-bindingnot dated
2022-12-16published 2022-05-24same kind of change as the line aboveGHSA-xqpp-26pp-2365CVE-2021-21660same package registry as the line abovemoderatenot named as affected when the advisory was published, now names io.jenkins.plugins:markdown-formatterDays to revision 206
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-7qw2-h9gj-hcvhCVE-2022-43406same package registry as the line abovehighnot named as affected when the advisory was published, now names io.jenkins.plugins:pipeline-groovy-libnot dated
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-4hjj-9gp7-4frgCVE-2022-43405same package registry as the line abovehighnot named as affected when the advisory was published, now names io.jenkins.plugins:pipeline-groovy-libnot dated
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-4hjj-9gp7-4frgCVE-2022-43405same package registry as the line abovehighnot named as affected when the advisory was published, now names org.jenkins-ci.plugins.workflow:workflow-cps-global-libnot dated
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-27rf-8mjp-r363CVE-2022-43404same package registry as the line abovehighnot named as affected when the advisory was published, now names org.jenkins-ci.plugins.workflow:workflow-cpsnot dated
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-7vr5-72w7-q6jcCVE-2022-43401same package registry as the line abovehighnot named as affected when the advisory was published, now names org.jenkins-ci.plugins.workflow:workflow-cpsnot dated
2022-12-16published 2022-05-24Advisory severity changedGHSA-7ff8-qfwx-8gx5CVE-2020-2182whole advisorylowstated at publication MODERATE, now states LOWCVSS versions were removed or replaced; no shared version's vector was rescored.not dated
2022-12-16published 2022-05-24Advisory severity changedGHSA-c5r9-rx53-q3gfCVE-2021-21696whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-16published 2022-05-24Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-16published 2022-05-24same kind of change as the line aboveGHSA-cvvm-4cr9-r436CVE-2021-21695same package and registry as the line abovecriticalsame change as the line abovenot dated
2022-12-16published 2022-05-24same kind of change as the line aboveGHSA-m9hr-259f-2v23CVE-2021-21688same package and registry as the line abovecriticalsame change as the line abovenot dated
2022-12-16published 2022-05-24same kind of change as the line aboveGHSA-4g38-hrm4-rg94CVE-2021-21686same package and registry as the line abovecriticalsame change as the line abovenot dated
2022-12-16published 2022-10-19Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-7rrj-hqv6-fvppCVE-2022-43435same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-wmfh-h3vm-rcxmCVE-2022-43434same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-cvxj-4745-843xCVE-2022-43433same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-px4x-hjm5-w8x3CVE-2022-43432same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-xp3r-9wx8-q2mmCVE-2022-43428same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-vf5v-6wjm-vr7vCVE-2022-43425same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-hvcr-927w-qcvqCVE-2022-43420same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-64r9-x74q-wxmhCVE-2022-43409same package and registry as the line abovehighsame change as the line abovenot dated
2 more rows in this change are not listed here. Open all 10 rows
2022-12-16published 2022-10-19Advisory severity changedwhole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.not dated
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-mf4p-wjrm-cmjpCVE-2022-43426same package and registry as the line abovelowsame change as the line abovenot dated
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-2jxx-2x93-2q2fCVE-2022-43412same package and registry as the line abovelowsame change as the line abovenot dated
2022-12-16published 2022-10-19same kind of change as the line aboveGHSA-f9f9-4r63-4qccCVE-2022-43411same package and registry as the line abovelowsame change as the line abovenot dated
Thu 15 Dec 2022· 13 advisory changes
2022-12-15published 2022-12-12Advisory severity changedGHSA-vc9x-gmmr-p7jjCVE-2021-4243whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 3
2022-12-15published 2022-12-13Advisory severity changedGHSA-x3x3-qwjq-8gj4CVE-2022-46364whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 2
2022-12-15published 2022-11-16Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 29
2022-12-15published 2022-11-16same kind of change as the line aboveGHSA-chcg-gh9p-96c5CVE-2022-45401same package and registry as the line abovehighsame change as the line aboveDays to revision 29
2022-12-15published 2022-11-16same kind of change as the line aboveGHSA-j923-26c2-qq9pCVE-2022-45387same package and registry as the line abovehighsame change as the line aboveDays to revision 29
2022-12-15published 2022-11-16same kind of change as the line aboveGHSA-298r-5c48-7q2rCVE-2022-45380same package and registry as the line abovehighsame change as the line aboveDays to revision 29
2022-12-15published 2022-11-16Advisory severity changedwhole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 29
2022-12-15published 2022-11-16same kind of change as the line aboveGHSA-8538-25v4-25pgCVE-2022-45400same package and registry as the line abovehighsame change as the line aboveDays to revision 29
2022-12-15published 2022-11-16same kind of change as the line aboveGHSA-3g9q-cmgv-g4p6CVE-2022-45381same package and registry as the line abovehighsame change as the line aboveDays to revision 29
2022-12-15published 2022-11-16Advisory severity changedwhole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 29
2022-12-15published 2022-11-16same kind of change as the line aboveGHSA-8847-xvjw-9g43CVE-2022-45397same package and registry as the line abovemoderatesame change as the line aboveDays to revision 29
2022-12-15published 2022-11-16same kind of change as the line aboveGHSA-h4wx-78p9-fwxwCVE-2022-45396same package and registry as the line abovemoderatesame change as the line aboveDays to revision 29
2022-12-15published 2022-11-16Advisory severity changedGHSA-hw4f-g7wh-xp52CVE-2022-45393whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 29
2022-12-15published 2022-11-16Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 29
2022-12-15published 2022-11-16same kind of change as the line aboveGHSA-vj5r-mmp4-3hrxCVE-2022-38666same package and registry as the line abovemoderatesame change as the line aboveDays to revision 29
2022-12-15published 2022-11-16same kind of change as the line aboveGHSA-3vwm-fc87-mq6hCVE-2022-45391same package and registry as the line abovemoderatesame change as the line aboveDays to revision 29
2022-12-15published 2022-11-16same kind of change as the line aboveGHSA-v535-pc6r-77qhCVE-2022-45385same package and registry as the line abovemoderatesame change as the line aboveDays to revision 29
Wed 14 Dec 2022· 3 advisory changes
2022-12-14published 2022-12-12Advisory severity changedGHSA-4gjr-vgfx-9qvwCVE-2022-45968whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 2
2022-12-14published 2022-12-12Advisory severity changedGHSA-957m-g6rf-4c2mCVE-2022-45970whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 2
2022-12-14published 2021-10-12Advisory severity changedGHSA-fj58-h2fr-3pp2CVE-2019-18413whole advisorycriticalstated at publication MODERATE, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.not dated
Tue 13 Dec 2022· 8 advisory changes
2022-12-13published 2022-12-13Package added to advisory2 bandsnot named as affected when the advisory was published, now names typo3/cmsDays to revision 0
2022-12-13published 2022-12-13same kind of change as the line aboveGHSA-8w3p-qh3x-6gjrCVE-2022-23504same package registry as the line abovemoderatesame change as the line aboveDays to revision 0
2022-12-13published 2022-12-13same kind of change as the line aboveGHSA-c5wx-6c2c-f7rmCVE-2022-23503same package registry as the line abovehighsame change as the line aboveDays to revision 0
2022-12-13published 2022-12-13same kind of change as the line aboveGHSA-mgj2-q8wp-29rrCVE-2022-23502same package registry as the line abovemoderatesame change as the line aboveDays to revision 0
2022-12-13published 2022-12-13same kind of change as the line aboveGHSA-jfp7-79g7-89rfCVE-2022-23501same package registry as the line abovemoderatesame change as the line aboveDays to revision 0
2022-12-13published 2022-12-13same kind of change as the line aboveGHSA-8c28-5mp7-v24hCVE-2022-23500same package registry as the line abovemoderatesame change as the line aboveDays to revision 0
2022-12-13published 2022-12-13same kind of change as the line aboveGHSA-hvwx-qh2h-xcfjCVE-2022-23499same package registry as the line abovemoderatesame change as the line aboveDays to revision 0
2022-12-13published 2022-12-11Advisory severity changedGHSA-wpgc-5cr5-h9ggCVE-2022-4409whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 2
2022-12-13published 2022-07-28Advisory severity changedGHSA-m485-79jq-cxx7CVE-2022-36916whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
Mon 12 Dec 2022· 11 advisory changes
2022-12-12published 2022-12-07 to 2022-12-08Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 4 to 5
2022-12-12published 2022-12-08same kind of change as the line aboveGHSA-468w-8x39-gj5vCVE-2022-46153same package and registry as the line abovemoderatesame change as the line aboveDays to revision 4
2022-12-12published 2022-12-07same kind of change as the line aboveGHSA-j453-hm5x-c46wCVE-2020-36565same package and registry as the line abovemoderatesame change as the line aboveDays to revision 5
2022-12-12published 2022-12-09Advisory severity changedGHSA-hc5g-xf64-j49jCVE-2022-4375whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 4
2022-12-12published 2022-12-08Advisory severity changedGHSA-rprg-4v7q-87v7CVE-2022-4123whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 4
2022-12-12published 2022-07-28Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-12published 2022-07-28same kind of change as the line aboveGHSA-8xwj-2wgh-gprhCVE-2022-36882same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-12published 2022-07-28same kind of change as the line aboveGHSA-cm7j-p8hc-97vjCVE-2022-36881same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-12published 2022-07-28Advisory severity changedGHSA-mxcc-7h5m-x57rCVE-2022-36885whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-12published 2022-07-01Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-12published 2022-07-01same kind of change as the line aboveGHSA-7rrx-375m-j6crCVE-2022-34795same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-12published 2022-07-01same kind of change as the line aboveGHSA-j33r-cgm6-pv48CVE-2022-34794same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-12published 2022-07-01same kind of change as the line aboveGHSA-hqmp-vxj7-5wpqCVE-2022-34791same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-12published 2022-07-01same kind of change as the line aboveGHSA-2v6r-jf2g-j5q5CVE-2022-34786same package and registry as the line abovehighsame change as the line abovenot dated
Fri 9 Dec 2022· 24 advisory changes
2022-12-09published 2022-07-28 to 2022-09-22Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-09published 2022-07-28same kind of change as the line aboveGHSA-v878-67xw-grw2CVE-2022-36883same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-09published 2022-07-28same kind of change as the line aboveGHSA-j5qq-6rpm-qjghCVE-2022-36889same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-09published 2022-09-22same kind of change as the line aboveGHSA-6cvr-rvpm-9wx4CVE-2022-41249same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-09published 2022-07-28same kind of change as the line aboveGHSA-57f2-52wj-7vj6CVE-2022-36899same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-09published 2022-07-01 to 2022-07-28Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-09published 2022-07-01same kind of change as the line aboveGHSA-f655-xhvm-cwp4CVE-2022-34777same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-09published 2022-07-28same kind of change as the line aboveGHSA-6xf5-c3cx-67pvCVE-2022-36894same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-09published 2022-07-01same kind of change as the line aboveGHSA-8hv7-4vfc-w8pgCVE-2022-34778same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-09published 2022-07-01same kind of change as the line aboveGHSA-hpf7-mmqw-g6vqCVE-2022-34783same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-09published 2022-07-01same kind of change as the line aboveGHSA-j2gv-q44j-xm42CVE-2022-34784same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-09published 2022-07-01same kind of change as the line aboveGHSA-w257-f7qj-4vrqCVE-2022-34790same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-09published 2022-07-01 to 2022-09-22Advisory severity changedwhole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-09published 2022-09-22same kind of change as the line aboveGHSA-cpm5-cqr9-7p79CVE-2022-41248same package and registry as the line abovelowsame change as the line abovenot dated
2022-12-09published 2022-07-28same kind of change as the line aboveGHSA-2qh6-hhvv-m2wwCVE-2022-36901same package and registry as the line abovelowsame change as the line abovenot dated
2022-12-09published 2022-09-22same kind of change as the line aboveGHSA-j7xv-fc46-hgpgCVE-2022-41247same package and registry as the line abovelowsame change as the line abovenot dated
2022-12-09published 2022-07-01same kind of change as the line aboveGHSA-56hc-wf49-2h96CVE-2022-34799same package and registry as the line abovelowsame change as the line abovenot dated
2022-12-09published 2022-07-01same kind of change as the line aboveGHSA-v3r8-6vfj-pppfCVE-2022-34800same package and registry as the line abovelowsame change as the line abovenot dated
2022-12-09published 2022-07-01same kind of change as the line aboveGHSA-7298-w54j-q7wmCVE-2022-34801same package and registry as the line abovelowsame change as the line abovenot dated
2022-12-09published 2022-07-01same kind of change as the line aboveGHSA-pgp9-x83g-v8x8CVE-2022-34802same package and registry as the line abovelowsame change as the line abovenot dated
2022-12-09published 2022-07-01same kind of change as the line aboveGHSA-gvmr-mp5q-9wvwCVE-2022-34805same package and registry as the line abovelowsame change as the line abovenot dated
3 more rows in this change are not listed here. Open all 11 rows
2022-12-09published 2022-12-06Advisory severity changedGHSA-m8xw-9x5x-6vh3CVE-2022-44900whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 3
2022-12-09published 2022-12-08Advisory severity changedGHSA-x39j-h85h-3f46CVE-2022-23495whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 1
2022-12-09published 2022-12-08Advisory severity changedGHSA-h2ph-vhm7-g4hpCVE-2022-23469whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 1
Thu 8 Dec 2022· 3 advisory changes
2022-12-08published 2022-12-06Advisory severity changedGHSA-59fh-rjq3-xq7jCVE-2022-44289whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 2
2022-12-08published 2022-09-22Advisory severity changedGHSA-qgv4-7jhx-c72qCVE-2022-41234whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-08published 2022-07-12Advisory severity changedGHSA-3hhc-qp5v-9p2jCVE-2022-32224whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
Wed 7 Dec 2022· 2 advisory changes
2022-12-07published 2022-05-27Advisory severity changedGHSA-wq4h-7r42-5hrrCVE-2022-30123whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.not dated
2022-12-07published 2022-05-27Advisory severity changedGHSA-hxqx-xwvh-44m2CVE-2022-30122whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
Tue 6 Dec 2022· 12 advisory changes
2022-12-06published 2022-12-06Advisory severity changedGHSA-7vx2-5349-qj99CVE-2022-46464whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 1
2022-12-06published 2022-12-05Advisory severity changedGHSA-q5j9-f95w-f4prCVE-2022-43484whole advisoryhighstated at publication CRITICAL, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 2
2022-12-06published 2022-09-22Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-06published 2022-09-22same kind of change as the line aboveGHSA-pxp5-g66h-wpv2CVE-2022-41244same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-06published 2022-09-22same kind of change as the line aboveGHSA-7jwg-hq85-c6m6CVE-2022-41243same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-06published 2022-09-22Advisory severity changedGHSA-j8xr-2279-88qjCVE-2022-41241whole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-06published 2022-12-05Advisory severity changedGHSA-w66j-xc7r-m2jvCVE-2022-45046whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 1
2022-12-06published 2022-12-03Advisory severity changedGHSA-cgp8-4m63-fhh5CVE-2021-37533whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 3
2022-12-06published 2022-09-22Advisory severity changedGHSA-fq2h-r2h9-pj8rCVE-2022-41229whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-06published 2022-09-17Advisory withdrawnwhole advisory2 bandswithdrawn 2022-12-06Days to revision 81
2022-12-06published 2022-09-17same kind of change as the line aboveGHSA-5hc5-c3m9-8vcjCVE-2022-40155same package and registry as the line abovelowwithdrawn 2022-12-06Days to revision 81
2022-12-06published 2022-09-17same kind of change as the line aboveGHSA-9fwf-46g9-45rxCVE-2022-40154same package and registry as the line abovelowwithdrawn 2022-12-06Days to revision 81
2022-12-06published 2022-09-17same kind of change as the line aboveGHSA-fv22-xp26-mm9wCVE-2022-40153same package and registry as the line abovehighwithdrawn 2022-12-06Days to revision 81
2022-12-06published 2022-09-17same kind of change as the line aboveGHSA-4rv7-wj6m-6c6rCVE-2022-40156same package and registry as the line abovelowwithdrawn 2022-12-06Days to revision 81
Mon 5 Dec 2022· 29 advisory changes
2022-12-05published 2022-06-24 to 2022-09-22Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-05published 2022-06-24same kind of change as the line aboveGHSA-64mj-3p92-589vCVE-2022-34176same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-05published 2022-06-24same kind of change as the line aboveGHSA-39r3-h8q6-2phqCVE-2022-34178same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-05published 2022-06-24same kind of change as the line aboveGHSA-h642-5h74-3x9cCVE-2022-34182same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-05published 2022-06-24same kind of change as the line aboveGHSA-65r6-w7vr-c75rCVE-2022-34183same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-05published 2022-06-24same kind of change as the line aboveGHSA-hc44-p2qq-cfm9CVE-2022-34184same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-05published 2022-06-24same kind of change as the line aboveGHSA-5hh2-f4h9-446gCVE-2022-34185same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-05published 2022-06-24same kind of change as the line aboveGHSA-7558-6q45-6x7mCVE-2022-34186same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-05published 2022-06-24same kind of change as the line aboveGHSA-x95w-qf3m-pqpxCVE-2022-34187same package and registry as the line abovehighsame change as the line abovenot dated
12 more rows in this change are not listed here. Open all 20 rows
2022-12-05published 2022-06-24 to 2022-09-22Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-05published 2022-06-24same kind of change as the line aboveGHSA-93mx-2vf9-28c4CVE-2022-34179same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-05published 2022-06-24same kind of change as the line aboveGHSA-xxhf-xq6v-c8mjCVE-2022-34180same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-05published 2022-09-22same kind of change as the line aboveGHSA-j2mj-g8jp-gjfmCVE-2022-41228same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-05published 2022-09-22same kind of change as the line aboveGHSA-jjch-7g85-4m72CVE-2022-41227same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-05published 2022-06-24same kind of change as the line aboveGHSA-g67p-jvvc-qf54CVE-2022-34203same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-05published 2022-06-24Advisory severity changedGHSA-298j-9q4w-6rm4CVE-2022-34181whole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-05published 2022-09-22Advisory severity changedGHSA-g43x-pcc9-f472CVE-2022-41226whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-05published 2022-06-24Advisory severity changedwhole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-05published 2022-06-24same kind of change as the line aboveGHSA-xcp5-j5fj-3xp6CVE-2022-34202same package and registry as the line abovelowsame change as the line abovenot dated
2022-12-05published 2022-06-24same kind of change as the line aboveGHSA-9h79-5m2f-mqj2CVE-2022-34213same package and registry as the line abovelowsame change as the line abovenot dated
Sat 3 Dec 2022· 2 advisory changes
2022-12-03published 2019-07-31Advisory severity changedGHSA-j657-59rv-qwm6CVE-2019-5457whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2022-12-03published 2021-04-13Advisory severity changedGHSA-67mq-h2r9-rh2mCVE-2020-28460whole advisorymoderatestated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.not dated
Fri 2 Dec 2022· 16 advisory changes
2022-12-02published 2022-05-18Advisory severity changedGHSA-5786-3qjg-mr88CVE-2022-30948whole advisorylowstated at publication HIGH, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-02published 2022-05-18Advisory severity changedGHSA-8vfc-fcr2-47pjCVE-2022-30949whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-02published 2022-02-16 to 2022-05-18Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-02published 2022-05-18same kind of change as the line aboveGHSA-xhw3-wmx2-76wfCVE-2022-30950same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-02published 2022-05-18same kind of change as the line aboveGHSA-p566-wpxx-574mCVE-2022-30951same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-02published 2022-02-16same kind of change as the line aboveGHSA-fhfh-6cjg-57rgCVE-2022-25192same package and registry as the line abovemoderatesame change as the line abovenot dated
2022-12-02published 2022-04-13 to 2022-05-18Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-02published 2022-05-18same kind of change as the line aboveGHSA-4m42-8qfq-h3q9CVE-2022-30956same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-02published 2022-05-18same kind of change as the line aboveGHSA-7h2j-h5xp-h3ghCVE-2022-30959same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-02published 2022-05-18same kind of change as the line aboveGHSA-6wh8-mr6f-6cx2CVE-2022-30960same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-02published 2022-05-18same kind of change as the line aboveGHSA-7rjv-q3pp-wc4pCVE-2022-30962same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-02published 2022-05-18same kind of change as the line aboveGHSA-ppwv-mvqg-q89hCVE-2022-30961same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-02published 2022-05-18same kind of change as the line aboveGHSA-5pmp-7wc9-v7vwCVE-2022-30963same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-02published 2022-05-18same kind of change as the line aboveGHSA-h3v9-46pp-h33wCVE-2022-30964same package and registry as the line abovehighsame change as the line abovenot dated
2022-12-02published 2022-05-18same kind of change as the line aboveGHSA-mw4r-5mfc-m5vcCVE-2022-30967same package and registry as the line abovehighsame change as the line abovenot dated
3 more rows in this change are not listed here. Open all 11 rows
Thu 1 Dec 2022· 5 advisory changes
2022-12-01published 2021-03-29Advisory fix version movedGHSA-mvg9-xffr-p774CVE-2021-25291
pypipillow
high
stated at publication 8.1.1, now states 8.2.0not dated
2022-12-01published 2022-04-13Advisory severity changedGHSA-jmxr-w2jc-qp7wCVE-2022-29049whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-01published 2022-02-16Advisory severity changedGHSA-fm6q-97gw-c4whCVE-2022-25186whole advisorylowstated at publication HIGH, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 9
2022-12-01published 2022-02-16Advisory severity changedGHSA-vwx4-frpr-w27jCVE-2022-25210whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-12-01published 2022-11-26Advisory severity changedGHSA-83g7-8fch-p37mCVE-2022-45908whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6
Wed 30 Nov 2022· 2 advisory changes
2022-11-30published 2022-11-23Advisory severity changedGHSA-22wj-vf5f-wrvjCVE-2022-45868whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2022-11-30published 2022-11-24Advisory severity changedGHSA-gr58-76rp-mmg4CVE-2022-2650whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6
Tue 29 Nov 2022· 2 advisory changes
2022-11-29published 2022-02-10Advisory severity changedGHSA-34wx-x2w9-vqm3CVE-2022-0538whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2022-11-29published 2022-11-22Advisory severity changedGHSA-rmf2-pwfq-h75jCVE-2022-40189whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
Mon 28 Nov 2022· 3 advisory changes
2022-11-28published 2022-11-22Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 6
2022-11-28published 2022-11-22same kind of change as the line aboveGHSA-cm43-f2pv-6v68CVE-2022-41131same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2022-11-28published 2022-11-22same kind of change as the line aboveGHSA-rp7f-fhm8-9hpfCVE-2022-33012same package and registry as the line abovehighsame change as the line aboveDays to revision 6
2022-11-28published 2022-11-21Advisory severity changedGHSA-r7qp-cfhv-p84wCVE-2022-41940whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 7
Sat 26 Nov 2022· 3 advisory changes
2022-11-26published 2022-11-23Advisory severity changedGHSA-wqg7-mx6p-2rw3CVE-2022-45462whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 4
2022-11-26published 2022-11-22Advisory severity changedGHSA-g56w-cwg4-hxx9CVE-2022-4116whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 4
2022-11-26published 2022-11-19Advisory severity changedGHSA-3xg8-cc8f-9wv2CVE-2022-4064whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 7
Fri 25 Nov 2022· 1 advisory change
2022-11-25published 2022-01-19Package added to advisoryGHSA-f7vh-qwp3-x37mCVE-2022-23307criticalnot named as affected when the advisory was published, now names log4j:log4jnot dated
Wed 23 Nov 2022· 3 advisory changes
2022-11-23published 2022-11-21Advisory severity changedGHSA-hf94-8mx5-2vvjCVE-2022-4105whole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 2
2022-11-23published 2022-11-21Advisory severity changedGHSA-4wfh-48v4-3r84CVE-2022-45470whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 2
2022-11-23published 2022-08-27Advisory severity changedGHSA-qpq9-jpv4-6gwrCVE-2021-3632whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →