Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Wed 21 Sep 2022· 1 advisory change
2022-09-21published 2022-02-10Advisory severity changedGHSA-hp5x-rqf7-43vfCVE-2020-5403whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 223
Mon 19 Sep 2022· 65 advisory changes
2022-09-19published 2020-09-23Advisory fix version movedGHSA-q3vw-4jx3-rrr2
mavendev.personnummer:personnummer
low
stated at publication 1.0.1, now states 3.3.0Days to revision 726
2022-09-19published 2022-09-16Package added to advisoryGHSA-634p-93h9-92vhCVE-2022-39217moderatenot named as affected when the advisory was published, now names some-natalie/ghas-to-csvDays to revision 3
2022-09-19published 2022-09-15Advisory severity changedGHSA-j9fq-vwqv-2fm2CVE-2022-2900whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 5
2022-09-19published 2022-04-27 to 2022-09-16Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 4 to 145
2022-09-19published 2022-04-27same kind of change as the line aboveGHSA-ch3h-j2vf-95pvCVE-2022-27777same package and registry as the line abovemoderatesame change as the line aboveDays to revision 145
2022-09-19published 2022-09-16same kind of change as the line aboveGHSA-pqw5-jmp5-px4vCVE-2022-3224same package and registry as the line abovemoderatesame change as the line aboveDays to revision 4
2022-09-19published 2022-09-16Advisory severity changedGHSA-7hgc-php5-77qqCVE-2022-36103whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 3
2022-09-19published 2022-09-16Advisory severity changedGHSA-237r-mx84-7x8cCVE-2022-36436whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 3
2022-09-19published 2022-09-12 to 2022-09-15Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 5 to 8
2022-09-19published 2022-09-15same kind of change as the line aboveGHSA-2gg5-7c4v-6xx2same package and registry as the line abovehighsame change as the line aboveDays to revision 5
2022-09-19published 2022-09-12same kind of change as the line aboveGHSA-p2f7-9cv7-jjf6CVE-2022-26049same package and registry as the line abovehighsame change as the line aboveDays to revision 8
2022-09-19published 2022-09-16Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 3
2022-09-19published 2022-09-16same kind of change as the line aboveGHSA-m6vp-8q9j-whx4CVE-2022-35983same package and registry as the line abovemoderatesame change as the line aboveDays to revision 3
2022-09-19published 2022-09-16same kind of change as the line aboveGHSA-p2xf-8hgm-hpw5CVE-2022-35984same package and registry as the line abovemoderatesame change as the line aboveDays to revision 3
2022-09-19published 2022-09-16same kind of change as the line aboveGHSA-9942-r22v-78cpCVE-2022-35985same package and registry as the line abovemoderatesame change as the line aboveDays to revision 3
2022-09-19published 2022-09-16same kind of change as the line aboveGHSA-wr9v-g9vf-c74vCVE-2022-35986same package and registry as the line abovemoderatesame change as the line aboveDays to revision 3
2022-09-19published 2022-09-16same kind of change as the line aboveGHSA-9vqj-64pv-w55cCVE-2022-35988same package and registry as the line abovemoderatesame change as the line aboveDays to revision 3
2022-09-19published 2022-09-16same kind of change as the line aboveGHSA-j43h-pgmg-5hjqCVE-2022-35989same package and registry as the line abovemoderatesame change as the line aboveDays to revision 3
2022-09-19published 2022-09-16same kind of change as the line aboveGHSA-397c-5g2j-qxpvCVE-2022-35982same package and registry as the line abovemoderatesame change as the line aboveDays to revision 3
2022-09-19published 2022-09-16same kind of change as the line aboveGHSA-vxv8-r8q2-63xwCVE-2022-35981same package and registry as the line abovemoderatesame change as the line aboveDays to revision 3
45 more rows in this change are not listed here. Open all 53 rows
2022-09-19published 2022-09-16Advisory severity changedGHSA-pxrw-j2fv-hx3hCVE-2022-35937whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 3
2022-09-19published 2022-09-16Advisory severity changedGHSA-74w3-p89x-ffghwhole advisorylowstated at publication CRITICAL, now states LOWThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 3
2022-09-19published 2022-09-16Advisory withdrawnGHSA-74w3-p89x-ffghwhole advisorylowwithdrawn 2022-09-19Days to revision 3
Fri 16 Sep 2022· 6 advisory changes
2022-09-16published 2022-09-14Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 3
2022-09-16published 2022-09-14same kind of change as the line aboveGHSA-4wjj-jwc9-2x96CVE-2022-2989same package and registry as the line abovehighsame change as the line aboveDays to revision 3
2022-09-16published 2022-09-14same kind of change as the line aboveGHSA-fmq7-gh8v-mjvcCVE-2022-1278same package and registry as the line abovehighsame change as the line aboveDays to revision 3
2022-09-16published 2022-09-14same kind of change as the line aboveGHSA-fjm8-m7m6-2fjpCVE-2022-2990same package and registry as the line abovehighsame change as the line aboveDays to revision 3
2022-09-16published 2022-09-12 to 2022-09-13Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 4 to 5
2022-09-16published 2022-09-13same kind of change as the line aboveGHSA-wxx5-w9jc-48wxCVE-2022-37767same package and registry as the line abovecriticalsame change as the line aboveDays to revision 4
2022-09-16published 2022-09-12same kind of change as the line aboveGHSA-fj2m-w3wv-x9prCVE-2022-39135same package and registry as the line abovecriticalsame change as the line aboveDays to revision 5
2022-09-16published 2022-09-10Advisory severity changedGHSA-9vm3-r8gq-cr6xCVE-2022-38638whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
Thu 15 Sep 2022· 2 advisory changes
2022-09-15published 2022-09-07Package added to advisoryGHSA-jj62-mc3m-j769CVE-2020-21516criticalnot named as affected when the advisory was published, now names feehi/cmsDays to revision 9
2022-09-15published 2022-09-15Advisory severity changedGHSA-m77f-652q-wwp4CVE-2022-3212whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 1
Wed 14 Sep 2022· 1 advisory change
2022-09-14published 2021-01-04Advisory severity changedGHSA-4w2v-q235-vp99CVE-2020-28168whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 618
Sun 11 Sep 2022· 3 advisory changes
2022-09-11published 2021-08-25Package added to advisoryGHSA-69fv-gw6g-8ccgCVE-2018-20998criticalnot named as affected when the advisory was published, now names arrayfireDays to revision 381
2022-09-11published 2022-09-01Advisory severity changedGHSA-qf7j-25g9-r63fCVE-2022-36058whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9
2022-09-11published 2022-08-31Advisory severity changedGHSA-jhjh-776m-4765CVE-2022-31152whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
Fri 9 Sep 2022· 3 advisory changes
2022-09-09published 2021-05-07Advisory fix version movedGHSA-cgc7-mwp4-3ccxCVE-2020-15930
npmjoplin
moderate
stated at publication 1.0.246, now states 1.1.7Days to revision 490
2022-09-09published 2020-09-11Advisory fix version movedGHSA-p82g-2xpp-m5r3CVE-2015-5654
npmdojo
moderate
stated at publication 1.2.0, now states 1.9.1Days to revision 728
2022-09-09published 2021-05-17Package added to advisoryGHSA-jqh7-w5pr-cr56CVE-2020-8176moderatenot named as affected when the advisory was published, now names @shopify/koa-shopify-authDays to revision 480
Thu 8 Sep 2022· 6 advisory changes
2022-09-08published 2022-04-27 to 2022-08-26Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 14 to 134
2022-09-08published 2022-08-26same kind of change as the line aboveGHSA-7527-8855-9cf8CVE-2022-2255same package and registry as the line abovehighsame change as the line aboveDays to revision 14
2022-09-08published 2022-07-15same kind of change as the line aboveGHSA-339q-62wm-c39wCVE-2021-3859same package and registry as the line abovehighsame change as the line aboveDays to revision 55
2022-09-08published 2022-04-27same kind of change as the line aboveGHSA-4pc7-vqv5-5r3vCVE-2021-3827same package and registry as the line abovehighsame change as the line aboveDays to revision 134
2022-09-08published 2022-05-24Advisory severity changedGHSA-rhgr-952r-6p8qCVE-2022-29599whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 108
2022-09-08published 2021-11-08Advisory severity changedGHSA-862g-9h5m-m3qvCVE-2021-3917whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 304
2022-09-08published 2020-12-14Advisory severity changedGHSA-hfvc-g252-rp4gCVE-2020-7791whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 633
Wed 7 Sep 2022· 1 advisory change
2022-09-07published 2021-09-15Package added to advisoryGHSA-5vp3-v4hc-gx76CVE-2021-41264criticalnot named as affected when the advisory was published, now names @openzeppelin/contracts-upgradeableDays to revision 357
Tue 6 Sep 2022· 2 advisory changes
2022-09-06published 2022-05-24Package added to advisoryGHSA-hxrm-9w7p-39ccCVE-2020-1045highnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.win-arm64Days to revision 105
2022-09-06published 2022-03-18Advisory severity changedGHSA-8v3j-jfg3-v3fvCVE-2021-44908whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 173
Fri 2 Sep 2022· 2 advisory changes
2022-09-02published 2022-05-24Advisory fix version movedGHSA-xr8f-59pp-rxxhCVE-2019-1302
nugetmicrosoft.aspnetcore.spaservices
moderate
stated at publication 2.1.2, now states 2.1.13Days to revision 101
2022-09-02published 2022-05-24Advisory fix version movedGHSA-xr8f-59pp-rxxhCVE-2019-1302
nugetmicrosoft.aspnetcore.spaservices
moderate
stated at publication 2.2.1, now states 2.2.7Days to revision 101
Thu 1 Sep 2022· 7 advisory changes
2022-09-01published 2021-11-19 to 2022-06-17Package added to advisory2 bandsnot named as affected when the advisory was published, now names opcfoundation.netstandard.opc.ua.coreDays to revision 76 to 286
2022-09-01published 2022-06-17same kind of change as the line aboveGHSA-r7pq-3x6p-7jcmCVE-2022-29863same package registry as the line abovehighsame change as the line aboveDays to revision 76
2022-09-01published 2022-06-17same kind of change as the line aboveGHSA-vhfw-v69p-crcwCVE-2022-29864same package registry as the line abovehighsame change as the line aboveDays to revision 76
2022-09-01published 2022-06-17same kind of change as the line aboveGHSA-fvxf-r9fw-49pcCVE-2022-29865same package registry as the line abovehighsame change as the line aboveDays to revision 76
2022-09-01published 2022-06-17same kind of change as the line aboveGHSA-6fp8-cxc9-4fr9CVE-2022-29866same package registry as the line abovehighsame change as the line aboveDays to revision 76
2022-09-01published 2021-11-19same kind of change as the line aboveGHSA-mjww-934m-h4jwCVE-2020-29457same package registry as the line abovemoderatesame change as the line aboveDays to revision 286
2022-09-01published 2022-06-17same kind of change as the line aboveGHSA-5q2v-6j86-5h9vCVE-2022-29862same package registry as the line abovehighsame change as the line aboveDays to revision 76
2022-09-01published 2022-08-24Advisory severity changedGHSA-mw9h-hcp7-fgc6CVE-2022-33916whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 9
Fri 26 Aug 2022· 12 advisory changes
2022-08-26published 2022-05-24Package added to advisoryGHSA-hxrm-9w7p-39cchighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app and 10 moreDays to revision 94
2022-08-26published 2022-05-24same kind of change as the line aboveGHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.appDays to revision 94
2022-08-26published 2022-05-24same kind of change as the line aboveGHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-armDays to revision 94
2022-08-26published 2022-05-24same kind of change as the line aboveGHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-arm64Days to revision 94
2022-08-26published 2022-05-24same kind of change as the line aboveGHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-musl-arm64Days to revision 94
2022-08-26published 2022-05-24same kind of change as the line aboveGHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-musl-x64Days to revision 94
2022-08-26published 2022-05-24same kind of change as the line aboveGHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.linux-x64Days to revision 94
2022-08-26published 2022-05-24same kind of change as the line aboveGHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.osx-x64Days to revision 94
2022-08-26published 2022-05-24same kind of change as the line aboveGHSA-hxrm-9w7p-39ccCVE-2020-1045same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.aspnetcore.app.runtime.win-armDays to revision 94
3 more rows in this change are not listed here. Open all 11 rows
2022-08-26published 2022-08-18Advisory severity changedGHSA-mjvm-mhgc-q4gpCVE-2022-36008whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 8
Tue 23 Aug 2022· 1 advisory change
2022-08-23published 2022-08-10Advisory fix version movedGHSA-9jmq-rx5f-8jwqCVE-2021-32862
pypinbconvert
moderate
stated at publication 6.3, now states 6.5.1Days to revision 13
Mon 22 Aug 2022· 6 advisory changes
2022-08-22published 2022-08-10Advisory severity changedGHSA-9jmq-rx5f-8jwqCVE-2021-32862whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 12
2022-08-22published 2021-03-19Advisory severity changedGHSA-jgwr-3qm3-26f3CVE-2021-25329whole advisoryhighstated at publication CRITICAL, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 521
2022-08-22published 2021-01-21Advisory severity changedGHSA-5p3x-r448-pc62CVE-2021-21239whole advisorymoderatestated at publication LOW, now states MODERATEA CVSS version was added; the existing vectors stayed the same.Days to revision 578
2022-08-22published 2022-07-26Advisory severity changedGHSA-fw3v-x4f2-v673CVE-2022-34749whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 16
2022-08-22published 2022-04-09 to 2022-06-08Advisory withdrawnwhole advisorycriticalwithdrawn 2022-08-22Days to revision 76 to 136
2022-08-22published 2022-06-08same kind of change as the line aboveGHSA-vv7q-mfpc-qgm5CVE-2022-31279same package and registry as the line abovecriticalwithdrawn 2022-08-22Days to revision 76
2022-08-22published 2022-04-09same kind of change as the line aboveGHSA-86r3-4gq8-xw8qCVE-2021-43503same package and registry as the line abovecriticalwithdrawn 2022-08-22Days to revision 136
Tue 16 Aug 2022· 1 advisory change
2022-08-16published 2022-07-22Advisory severity changedGHSA-mhxj-85r3-2x55CVE-2022-36313whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 26
Mon 15 Aug 2022· 6 advisory changes
2022-08-15published 2022-08-06 to 2022-08-11Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 4 to 10
2022-08-15published 2022-08-11same kind of change as the line aboveGHSA-33wh-w4m7-c6r8CVE-2022-35956same package and registry as the line abovemoderatesame change as the line aboveDays to revision 4
2022-08-15published 2022-08-06same kind of change as the line aboveGHSA-rqmg-hrg4-fm69CVE-2022-37450same package and registry as the line abovemoderatesame change as the line aboveDays to revision 10
2022-08-15published 2022-08-10Advisory severity changedGHSA-7qqq-gh2f-wq76CVE-2022-25907whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6
2022-08-15published 2021-05-06 to 2021-09-23Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 326 to 466
2022-08-15published 2021-09-23same kind of change as the line aboveGHSA-fpv6-f8jw-rc3rCVE-2021-41088same package and registry as the line abovehighsame change as the line aboveDays to revision 326
2022-08-15published 2021-08-31same kind of change as the line aboveGHSA-2h3h-q99f-3fhcCVE-2021-39134same package and registry as the line abovehighsame change as the line aboveDays to revision 349
2022-08-15published 2021-05-06same kind of change as the line aboveGHSA-46f2-3v63-3xrpCVE-2021-28966same package and registry as the line abovehighsame change as the line aboveDays to revision 466
Fri 12 Aug 2022· 1 advisory change
2022-08-12published 2022-02-09Package added to advisoryGHSA-jh6m-3pqw-242hCVE-2020-14359highnot named as affected when the advisory was published, now names github.com/keycloak/keycloak-gatekeeperDays to revision 185
Thu 11 Aug 2022· 15 advisory changes
2022-08-11published 2022-07-15 to 2022-07-26Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 16 to 27
2022-08-11published 2022-07-15same kind of change as the line aboveGHSA-44vr-rwwj-p88hCVE-2022-31180same package and registry as the line abovecriticalsame change as the line aboveDays to revision 27
2022-08-11published 2022-07-26same kind of change as the line aboveGHSA-ww2v-frv5-pj5xCVE-2022-35131same package and registry as the line abovecriticalsame change as the line aboveDays to revision 16
2022-08-11published 2022-07-15Advisory severity changedGHSA-jjc5-fp7p-6f8wCVE-2022-31179whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 27
2022-08-11published 2022-01-06Advisory severity changedGHSA-pccr-q7v9-5f27CVE-2021-44548whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 217
2022-08-11published 2021-12-16Advisory severity changedGHSA-cxg7-84wp-8pcqCVE-2021-4117whole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 238
2022-08-11published 2021-01-29Advisory severity changedGHSA-hgmg-hhc8-g5wrCVE-2021-21254whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 559
2022-08-11published 2022-07-19 to 2022-07-29Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 13 to 22
2022-08-11published 2022-07-29same kind of change as the line aboveGHSA-2cpx-6pqp-wf35CVE-2022-31183same package and registry as the line abovecriticalsame change as the line aboveDays to revision 13
2022-08-11published 2022-07-19same kind of change as the line aboveGHSA-jxvf-m3x5-mxwqCVE-2020-28471same package and registry as the line abovecriticalsame change as the line aboveDays to revision 22
2022-08-11published 2020-12-21Advisory severity changedGHSA-9f66-54xg-pc2cCVE-2020-26275whole advisorymoderatestated at publication LOW, now states MODERATEA CVSS version was added; the existing vectors stayed the same.Days to revision 598
2022-08-11published 2022-02-15Advisory severity changedGHSA-pf59-j7c2-rh6xCVE-2020-13597whole advisorymoderatestated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 178
2022-08-11published 2021-04-19Advisory severity changedGHSA-wmg4-8cp2-hpg9CVE-2021-29430whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 479
2022-08-11published 2022-07-27Advisory severity changedGHSA-8274-h5jp-97vrCVE-2022-31109whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 14
2022-08-11published 2020-07-07Advisory severity changedGHSA-93f3-23rq-pjfpCVE-2020-15095whole advisorymoderatestated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 764
2022-08-11published 2019-12-13Advisory severity changedwhole advisoryhighstated at publication LOW, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 971
2022-08-11published 2019-12-13same kind of change as the line aboveGHSA-4328-8hgf-7wjrCVE-2019-16777same package and registry as the line abovehighsame change as the line aboveDays to revision 971
2022-08-11published 2019-12-13same kind of change as the line aboveGHSA-x8qc-rrcw-4r46CVE-2019-16776same package and registry as the line abovehighsame change as the line aboveDays to revision 971
Wed 10 Aug 2022· 8 advisory changes
2022-08-10published 2022-07-19Package added to advisoryGHSA-4x9r-j582-cgr8CVE-2022-33891highnot named as affected when the advisory was published, now names pysparkDays to revision 23
2022-08-10published 2022-07-29Advisory severity changedGHSA-32ff-4g79-vgfcCVE-2022-31177whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 12
2022-08-10published 2022-07-23Advisory severity changedGHSA-5469-c5p2-xv5gCVE-2022-34113whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 19
2022-08-10published 2022-07-23Advisory severity changedGHSA-c2pj-rr68-pw94CVE-2022-34112whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 19
2022-08-10published 2021-10-12Advisory severity changedGHSA-qv95-g3gm-x542CVE-2021-41802whole advisorylowstated at publication MODERATE, now states LOWThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 302
2022-08-10published 2021-09-29Advisory severity changedGHSA-x55w-vjjp-222rCVE-2021-3820whole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 315
2022-08-10published 2021-09-13Advisory severity changedGHSA-cqqh-49mx-fq63CVE-2021-3645whole advisorycriticalstated at publication MODERATE, now states CRITICALCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 331
2022-08-10published 2022-07-20Advisory severity changedGHSA-99j7-mhfh-w84pCVE-2022-31162whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 22
Fri 5 Aug 2022· 2 advisory changes
2022-08-05published 2022-05-24Package added to advisoryGHSA-cjw4-2w9r-r8mvCVE-2019-12410highnot named as affected when the advisory was published, now names pyarrowDays to revision 73
2022-08-05published 2022-07-18Advisory severity changedGHSA-4hq8-jgr8-mw9jCVE-2020-7641whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 19
Thu 4 Aug 2022· 1 advisory change
2022-08-04published 2022-02-11Package added to advisoryGHSA-6qq8-5wq3-86rpCVE-2020-15129moderatenot named as affected when the advisory was published, now names github.com/containous/traefik/v2/pkg/apiDays to revision 174
Wed 3 Aug 2022· 1 advisory change
2022-08-03published 2020-08-31Advisory fix version movedGHSA-4mv4-gmmf-q382CVE-2015-6584
npmdatatables
high
stated at publication 1.10.8, now states 1.10.10Days to revision 702
Tue 2 Aug 2022· 2 advisory changes
2022-08-02published 2021-05-18Advisory severity changedGHSA-58pf-pcwv-qg85CVE-2020-7665whole advisoryhighstated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 441
2022-08-02published 2019-12-02Advisory severity changedGHSA-6xc2-mj39-q599CVE-2019-18818whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 974
Fri 29 Jul 2022· 8 advisory changes
2022-07-29published 2022-02-11Package added to advisoryGHSA-6qq8-5wq3-86rpCVE-2020-15129moderatenot named as affected when the advisory was published, now names github.com/containous/traefik/v2Days to revision 168
2022-07-29published 2021-04-20Advisory severity changedGHSA-6757-jp84-gxfxCVE-2020-1747whole advisorycriticalstated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.Days to revision 465
2022-07-29published 2022-07-15Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 14
2022-07-29published 2022-07-15same kind of change as the line aboveGHSA-rpxg-hg79-h8q9CVE-2022-35628same package and registry as the line abovecriticalsame change as the line aboveDays to revision 14
2022-07-29published 2022-07-15same kind of change as the line aboveGHSA-j3h2-8mf8-j5r2CVE-2015-8031same package and registry as the line abovecriticalsame change as the line aboveDays to revision 14
2022-07-29published 2022-07-14Advisory severity changedGHSA-6w2f-6wq3-rjvfCVE-2022-32065whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 16
2022-07-29published 2020-11-24Advisory severity changedGHSA-vfrc-7r7c-w9mxCVE-2020-26237whole advisorymoderatestated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 612
2022-07-29published 2019-10-15Advisory severity changedGHSA-c427-hjc3-wrfwCVE-2019-17495whole advisorycriticalstated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.Days to revision 1,018
2022-07-29published 2022-07-23Advisory severity changedGHSA-m7gr-5w5g-36jfCVE-2022-34037whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
Tue 26 Jul 2022· 1 advisory change
2022-07-26published 2022-05-14Package added to advisoryGHSA-2xjx-v99w-gqf3CVE-2019-0545highnot named as affected when the advisory was published, now names microsoft.netcore.appDays to revision 74
Fri 22 Jul 2022· 3 advisory changes
2022-07-22published 2022-07-14 to 2022-07-16Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7 to 9
2022-07-22published 2022-07-16same kind of change as the line aboveGHSA-4wf5-vphf-c2xcCVE-2022-25858same package and registry as the line abovehighsame change as the line aboveDays to revision 7
2022-07-22published 2022-07-14same kind of change as the line aboveGHSA-227g-7cvv-6ff3CVE-2022-31781same package and registry as the line abovehighsame change as the line aboveDays to revision 9
2022-07-22published 2022-07-17Advisory severity changedGHSA-fr75-x856-q6j8CVE-2021-36711whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 6
Thu 21 Jul 2022· 2 advisory changes
2022-07-21published 2022-04-26Advisory severity changedGHSA-75p6-52g3-rqc8CVE-2022-1245whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 86
2022-07-21published 2022-06-16Advisory withdrawnGHSA-cqpr-pcm7-m3jcwhole advisorymoderatewithdrawn 2022-07-21Days to revision 35
Wed 20 Jul 2022· 3 advisory changes
2022-07-20published 2022-07-09Advisory severity changedGHSA-8rq8-f485-7v8xCVE-2022-35411whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 12
2022-07-20published 2020-12-08Advisory severity changedGHSA-g3h8-cg9x-47qwCVE-2020-26255whole advisorymoderatestated at publication LOW, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.Days to revision 589
2022-07-20published 2022-07-13Advisory severity changedGHSA-7488-6x3r-23w5CVE-2022-31507whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 7
Tue 19 Jul 2022· 2 advisory changes
2022-07-19published 2022-07-15Advisory severity changedGHSA-8mjr-jr5h-q2xrCVE-2022-31153whole advisorymoderatestated at publication CRITICAL, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 4
2022-07-19published 2022-07-09Advisory severity changedGHSA-5jgj-h9wp-53frCVE-2022-32115whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 11
Sat 16 Jul 2022· 4 advisory changes
2022-07-16published 2022-07-06Package added to advisoryGHSA-f2gr-7299-487hmoderatenot named as affected when the advisory was published, now names github.com/ipfs/go-ipfsDays to revision 9
2022-07-16published 2021-08-30Package added to advisoryGHSA-7774-7vr3-cc8jCVE-2021-39155highnot named as affected when the advisory was published, now names istio.io/istioDays to revision 320
2022-07-16published 2022-06-17Package added to advisoryGHSA-75rw-34q6-72crCVE-2022-31053criticalnot named as affected when the advisory was published, now names github.com/biscuit-auth/biscuit-goDays to revision 29
2022-07-16published 2021-09-02Package added to advisoryGHSA-7h6j-2268-fhcmCVE-2020-9321moderatenot named as affected when the advisory was published, now names github.com/traefik/traefikDays to revision 316
Fri 15 Jul 2022· 6 advisory changes
2022-07-15published 2022-07-06 to 2022-07-07Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9 to 10
2022-07-15published 2022-07-07same kind of change as the line aboveGHSA-h975-r69h-4w9pCVE-2022-32533same package and registry as the line abovecriticalsame change as the line aboveDays to revision 9
2022-07-15published 2022-07-06same kind of change as the line aboveGHSA-8r94-4h3c-939fCVE-2022-2321same package and registry as the line abovecriticalsame change as the line aboveDays to revision 10
2022-07-15published 2022-07-06 to 2022-07-07Advisory severity changedwhole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9 to 10
2022-07-15published 2022-07-07same kind of change as the line aboveGHSA-xj57-8qj4-c4m6CVE-2022-33980same package and registry as the line abovecriticalsame change as the line aboveDays to revision 9
2022-07-15published 2022-07-06same kind of change as the line aboveGHSA-95f9-94vc-665hCVE-2022-31836same package and registry as the line abovecriticalsame change as the line aboveDays to revision 10
2022-07-15published 2022-07-05Advisory severity changedGHSA-wpqr-jcpx-745rCVE-2022-31116whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 10
2022-07-15published 2022-07-05Advisory severity changedGHSA-fm67-cv37-96ffCVE-2022-31117whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 10
Thu 14 Jul 2022· 1 advisory change
2022-07-14published 2022-07-05Advisory severity changedGHSA-ffmh-x56j-9rc3CVE-2022-31147whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 9

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →