Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Fri 31 Oct 2025· 1 change
2025-10-31published 2025-09-24Advisory severity changedGHSA-6xv4-9cqp-92rhCVE-2025-57353whole advisorymoderatestated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Time to revision 37 days
Thu 30 Oct 2025· 1 change
2025-10-30published 2025-10-21Package added to advisoryGHSA-qqj3-g7mx-5p4wCVE-2025-54470highnot named as affected when the advisory was published, now names github.com/neuvector/neuvectorTime to revision 9 days
Wed 29 Oct 2025· 1 change
2025-10-29published 2025-08-20Package added to advisoryGHSA-p72g-pv48-7w9xCVE-2025-54988criticalnot named as affected when the advisory was published, now names org.apache.tika:tika-parsersTime to revision 70 days
Mon 27 Oct 2025· 1 change
2025-10-27published 2025-09-24Advisory fix version movedGHSA-4xh5-x5gv-qwphCVE-2025-8869
pypipip
moderate
stated at publication 25.2, now states 25.3Time to revision 6 days
Fri 24 Oct 2025· 2 changes
2025-10-24published 2025-10-14Advisory severity changedGHSA-7mvr-c777-76hpCVE-2025-59288whole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Time to revision 10 days
2025-10-24published 2025-10-22Advisory severity changedGHSA-gr7h-xw4f-wh86CVE-2025-62710whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 2 days
Wed 22 Oct 2025· 4 changes
2025-10-22published 2022-05-17Advisory severity changedGHSA-mrfm-jxgf-2h6vCVE-2014-3120whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 1,255 days
2025-10-22published 2022-05-04 to 2022-05-13Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Time to revision 1,268 days
2025-10-22published 2022-05-13same kind of change as the line aboveGHSA-47qp-8v9g-39hpCVE-2013-2251same package and registry as the line abovecriticalsame change as the line aboveDuration unknown
2025-10-22published 2022-05-04same kind of change as the line aboveGHSA-4wrr-9h5r-m92wCVE-2012-0391same package and registry as the line abovecriticalsame change as the line aboveTime to revision 1,268 days
2025-10-22published 2017-10-24Advisory severity changedGHSA-6x85-j5j2-27jxCVE-2014-0130whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Duration unknown
Tue 21 Oct 2025· 1 change
2025-10-21published 2025-10-14Advisory severity changedGHSA-mq77-rv97-285mCVE-2025-62172whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 7 days
Mon 20 Oct 2025· 4 changes
2025-10-20published 2021-04-13Package added to advisoryGHSA-r96p-v3cr-gfv8CVE-2020-28470highnot named as affected when the advisory was published, now names @scullyio/ng-libDuration unknown
2025-10-20published 2025-10-10Advisory severity changedGHSA-gj5f-73vh-wpf7CVE-2025-11569whole advisorylowstated at publication HIGH, now states LOWCVSS versions were removed or replaced; no shared version's vector was rescored.Time to revision 11 days
2025-10-20published 2025-09-24 to 2025-10-10Advisory withdrawnwhole advisorylowwithdrawn 2025-10-20Time to revision 11 to 26 days
2025-10-20published 2025-10-10same kind of change as the line aboveGHSA-gj5f-73vh-wpf7CVE-2025-11569same package and registry as the line abovelowwithdrawn 2025-10-20Time to revision 11 days
2025-10-20published 2025-09-24same kind of change as the line aboveGHSA-m929-rg27-gj99same package and registry as the line abovelowwithdrawn 2025-10-20Time to revision 26 days
Fri 17 Oct 2025· 1 change
2025-10-17published 2024-07-01Advisory withdrawnGHSA-9v2f-6vcg-3hgvCVE-2024-39236whole advisorycriticalwithdrawn 2025-10-17Time to revision 473 days
Wed 15 Oct 2025· 1 change
2025-10-15published 2025-05-21Package added to advisoryGHSA-9pp5-9c7g-4r83CVE-2025-41232criticalnot named as affected when the advisory was published, now names org.springframework.security:spring-security-coreTime to revision 147 days
Tue 14 Oct 2025· 1 change
2025-10-14published 2021-12-16Advisory withdrawnGHSA-q6gq-997w-f55gCVE-2020-16845whole advisoryhighwithdrawn 2025-10-14Time to revision 1,398 days
Mon 13 Oct 2025· 7 changes
2025-10-13published 2025-10-03Advisory fix version movedGHSA-964p-j4gg-mhwcCVE-2025-50538
npmflowise
critical
stated at publication 2.2.7-patch.1, now states 3.0.8Time to revision 10 days
2025-10-13published 2025-10-13Package added to advisoryGHSA-3cm9-jrf5-h2cxCVE-2025-62242moderatenot named as affected when the advisory was published, now names com.liferay:com.liferay.change.tracking.webTime to revision 0 days
2025-10-13published 2023-06-14Package added to advisoryGHSA-4g42-gqrg-4633CVE-2023-34396highnot named as affected when the advisory was published, now names org.apache.struts:struts-coreTime to revision 852 days
2025-10-13published 2022-05-13 to 2023-06-14Package added to advisoryhighnot named as affected when the advisory was published, now names struts:strutsTime to revision 852 days
2025-10-13published 2023-06-14same kind of change as the line aboveGHSA-4g42-gqrg-4633CVE-2023-34396same package registry as the line abovehighsame change as the line aboveTime to revision 852 days
2025-10-13published 2022-05-13same kind of change as the line aboveGHSA-7jw3-5q4w-89qgCVE-2016-1181same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-10-13published 2022-05-13same kind of change as the line aboveGHSA-5ggr-mpgw-3mgxCVE-2016-1182same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-10-13published 2022-05-14same kind of change as the line aboveGHSA-cvvx-r33m-v7pqCVE-2015-0899same package registry as the line abovehighsame change as the line aboveDuration unknown
Fri 10 Oct 2025· 1 change
2025-10-10published 2023-08-08Package added to advisoryGHSA-rg2c-cfxv-qp6fCVE-2023-3894highnot named as affected when the advisory was published, now names com.fasterxml.jackson.dataformat:jackson-dataformat-tomlTime to revision 794 days
Thu 9 Oct 2025· 1 change
2025-10-09published 2024-07-11Advisory withdrawnGHSA-vc8w-jr9v-vj7fCVE-2024-6531whole advisorymoderatewithdrawn 2025-10-09Time to revision 455 days
Wed 8 Oct 2025· 2 changes
2025-10-08published 2022-04-17 to 2025-08-21Advisory withdrawnwhole advisorymoderatewithdrawn 2025-10-08Time to revision 48 to 1,271 days
2025-10-08published 2025-08-21same kind of change as the line aboveGHSA-w2wj-hw98-233hsame package and registry as the line abovemoderatewithdrawn 2025-10-08Time to revision 48 days
2025-10-08published 2022-04-17same kind of change as the line aboveGHSA-7gc6-qh9x-w6h8CVE-2022-1365same package and registry as the line abovemoderatewithdrawn 2025-10-08Time to revision 1,271 days
Mon 6 Oct 2025· 7 changes
2025-10-06published 2025-07-11 to 2025-08-08Package added to advisory2 bandsnot named as affected when the advisory was published, now names org.pytorch:executorch-androidTime to revision 60 to 87 days
2025-10-06published 2025-07-11same kind of change as the line aboveGHSA-h952-963h-rv99CVE-2025-30402same package registry as the line abovehighsame change as the line aboveTime to revision 87 days
2025-10-06published 2025-08-08same kind of change as the line aboveGHSA-84m3-f99p-cqx5CVE-2025-30405same package registry as the line abovecriticalsame change as the line aboveTime to revision 60 days
2025-10-06published 2025-08-08same kind of change as the line aboveGHSA-hj95-mhgf-jxc4CVE-2025-30404same package registry as the line abovecriticalsame change as the line aboveTime to revision 60 days
2025-10-06published 2025-08-08same kind of change as the line aboveGHSA-xc7w-r669-48pfCVE-2025-54951same package registry as the line abovecriticalsame change as the line aboveTime to revision 60 days
2025-10-06published 2025-08-08same kind of change as the line aboveGHSA-9m39-3mf3-xwchCVE-2025-54949same package registry as the line abovecriticalsame change as the line aboveTime to revision 60 days
2025-10-06published 2025-08-08same kind of change as the line aboveGHSA-f9hx-c6jf-3qxmCVE-2025-54950same package registry as the line abovecriticalsame change as the line aboveTime to revision 60 days
2025-10-06published 2025-08-14Advisory withdrawnGHSA-xqrq-4mgf-ff32CVE-2025-50817whole advisoryhighwithdrawn 2025-10-06Time to revision 53 days
Fri 3 Oct 2025· 2 changes
2025-10-03published 2025-09-30Package added to advisoryGHSA-27w5-gj5q-82fvCVE-2025-11149highnot named as affected when the advisory was published, now names @nubosoftware/node-staticTime to revision 3 days
2025-10-03published 2025-08-14Advisory withdrawnGHSA-q4xx-mc3q-23x8whole advisorycriticalwithdrawn 2025-10-03Time to revision 50 days
Tue 30 Sep 2025· 37 changes
2025-09-30published 2022-05-17 to 2023-11-22Package added to advisory36 rows, one per advisory and package3 bandsnot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.7.7 and 35 moreTime to revision 679 to 1,233 days
2025-09-30published 2022-05-17same kind of change as the line aboveGHSA-jf9v-fxfq-wm76CVE-2013-3300same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.7.7Time to revision 1,233 days
2025-09-30published 2022-05-17same kind of change as the line aboveGHSA-jf9v-fxfq-wm76CVE-2013-3300same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.8.0Time to revision 1,233 days
2025-09-30published 2022-05-17same kind of change as the line aboveGHSA-jf9v-fxfq-wm76CVE-2013-3300same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.8.1Time to revision 1,233 days
2025-09-30published 2022-05-17same kind of change as the line aboveGHSA-jf9v-fxfq-wm76CVE-2013-3300same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.8.2Time to revision 1,233 days
2025-09-30published 2022-05-17same kind of change as the line aboveGHSA-jf9v-fxfq-wm76CVE-2013-3300same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.9.0Time to revision 1,233 days
2025-09-30published 2022-05-17same kind of change as the line aboveGHSA-jf9v-fxfq-wm76CVE-2013-3300same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.9.0-1Time to revision 1,233 days
2025-09-30published 2022-05-17same kind of change as the line aboveGHSA-jf9v-fxfq-wm76CVE-2013-3300same package registry as the line abovemoderatenot named as affected when the advisory was published, now names net.liftweb:lift-webkit_2.9.1Time to revision 1,233 days
2025-09-30published 2022-06-28same kind of change as the line aboveGHSA-ww3v-6xjf-jv28CVE-2018-18855same package registry as the line abovemoderatenot named as affected when the advisory was published, now names io.spray:spray-json_2.10Duration unknown
28 more rows in this change are not listed here. Open all 36 rows
2025-09-30published 2020-09-03Package added to advisoryGHSA-g64q-3vg8-8f93highnot named as affected when the advisory was published, now names pezDuration unknown
Mon 29 Sep 2025· 2 changes
2025-09-29published 2020-09-03Package added to advisoryGHSA-5854-jvxx-2cg9highnot named as affected when the advisory was published, now names contentDuration unknown
2025-09-29published 2025-08-13Package added to advisoryGHSA-prj3-ccx8-p6x4CVE-2025-55163highnot named as affected when the advisory was published, now names io.grpc:grpc-netty-shadedTime to revision 47 days
Sat 27 Sep 2025· 1 change
2025-09-27published 2025-09-24Advisory severity changedGHSA-776q-jw43-fhjxCVE-2025-48459whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 3 days
Fri 26 Sep 2025· 15 changes
2025-09-26published 2025-09-24Advisory fix version movedGHSA-vj76-c3g6-qr5vCVE-2025-59343
npmtar-fs
high
stated at publication 1.16.5, now states 1.16.6Time to revision 2 days
2025-09-26published 2025-09-24Advisory fix version movedGHSA-vj76-c3g6-qr5vCVE-2025-59343
npmtar-fs
high
stated at publication 2.1.3, now states 2.1.4Time to revision 2 days
2025-09-26published 2020-09-03Package added to advisoryGHSA-g9cg-h3jm-cwrchighnot named as affected when the advisory was published, now names @hapi/pezDuration unknown
2025-09-26published 2025-09-17Package added to advisory3 bandsnot named as affected when the advisory was published, now names d7y.io/dragonfly/v2Time to revision 9 to 9 days
2025-09-26published 2025-09-17same kind of change as the line aboveGHSA-mcvp-rpgg-9273CVE-2025-59410same package registry as the line abovemoderatesame change as the line aboveTime to revision 9 days
2025-09-26published 2025-09-17same kind of change as the line aboveGHSA-hx2h-vjw2-8r54CVE-2025-59354same package registry as the line abovemoderatesame change as the line aboveTime to revision 9 days
2025-09-26published 2025-09-17same kind of change as the line aboveGHSA-255v-qv84-29p5CVE-2025-59353same package registry as the line abovehighsame change as the line aboveTime to revision 9 days
2025-09-26published 2025-09-17same kind of change as the line aboveGHSA-79hx-3fp8-hj66CVE-2025-59352same package registry as the line abovemoderatesame change as the line aboveTime to revision 9 days
2025-09-26published 2025-09-17same kind of change as the line aboveGHSA-4mhv-8rh3-4ghwCVE-2025-59351same package registry as the line abovemoderatesame change as the line aboveTime to revision 9 days
2025-09-26published 2025-09-17same kind of change as the line aboveGHSA-c2fc-9q9c-5486CVE-2025-59350same package registry as the line abovemoderatesame change as the line aboveTime to revision 9 days
2025-09-26published 2025-09-17same kind of change as the line aboveGHSA-8425-8r2f-mrv6CVE-2025-59349same package registry as the line abovelowsame change as the line aboveTime to revision 9 days
2025-09-26published 2025-09-17same kind of change as the line aboveGHSA-2qgr-gfvj-qpcrCVE-2025-59348same package registry as the line abovemoderatesame change as the line aboveTime to revision 9 days
3 more rows in this change are not listed here. Open all 11 rows
2025-09-26published 2025-09-15Advisory withdrawnGHSA-qhwp-454g-2gv4whole advisorymoderatewithdrawn 2025-09-26Time to revision 12 days
Thu 25 Sep 2025· 4 changes
2025-09-25published 2020-09-03Package added to advisoryGHSA-3wqh-h42r-x8fqhighnot named as affected when the advisory was published, now names @hapi/contentDuration unknown
2025-09-25published 2025-09-15 to 2025-09-17Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 8 to 10 days
2025-09-25published 2025-09-17same kind of change as the line aboveGHSA-9pw5-wx67-q964CVE-2025-10619same package and registry as the line abovemoderatesame change as the line aboveTime to revision 8 days
2025-09-25published 2025-09-15same kind of change as the line aboveGHSA-hjm5-xgj8-vwj6CVE-2025-59376same package and registry as the line abovemoderatesame change as the line aboveTime to revision 10 days
2025-09-25published 2025-09-15Advisory severity changedGHSA-4hqq-7q79-932pCVE-2025-59377whole advisorycriticalstated at publication LOW, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 10 days
Wed 24 Sep 2025· 4 changes
2025-09-24published 2022-09-23 to 2022-10-25Package added to advisory2 bandsnot named as affected when the advisory was published, now names org.apache.xmlgraphics:batik-bridgeDuration unknown
2025-09-24published 2022-10-25same kind of change as the line aboveGHSA-rwqr-m72q-v6cmCVE-2022-42890same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-09-24published 2022-09-23same kind of change as the line aboveGHSA-53jm-3hc9-fqqcCVE-2022-38648same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-09-24published 2022-09-23same kind of change as the line aboveGHSA-c5xv-qc8p-mh2vCVE-2022-38398same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-09-24published 2025-08-11Advisory severity changedGHSA-qpjq-c5hr-7925CVE-2025-54478whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 44 days
Tue 23 Sep 2025· 6 changes
2025-09-23published 2023-03-28Package added to advisoryGHSA-7phw-cxx7-q9vqCVE-2023-20860criticalnot named as affected when the advisory was published, now names org.springframework:spring-webmvcTime to revision 911 days
2025-09-23published 2025-09-18Advisory severity changedGHSA-vv9c-xxg7-wmv7CVE-2025-6237whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 6 days
2025-09-23published 2025-09-22Advisory severity changedGHSA-j2xj-h7w5-r7vpCVE-2025-59526whole advisorymoderatestated at publication LOW, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Time to revision 1 days
2025-09-23published 2025-08-18 to 2025-09-10Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 13 to 37 days
2025-09-23published 2025-08-18same kind of change as the line aboveGHSA-xfp8-x3j6-h67vCVE-2025-9096same package and registry as the line abovemoderatesame change as the line aboveTime to revision 37 days
2025-09-23published 2025-08-18same kind of change as the line aboveGHSA-q4rg-7cjj-5r86CVE-2025-9095same package and registry as the line abovemoderatesame change as the line aboveTime to revision 37 days
2025-09-23published 2025-09-10same kind of change as the line aboveGHSA-xp8g-32qh-mv28CVE-2025-57520same package and registry as the line abovemoderatesame change as the line aboveTime to revision 13 days
Mon 22 Sep 2025· 2 changes
2025-09-22published 2025-09-11 to 2025-09-16Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 6 to 12 days
2025-09-22published 2025-09-16same kind of change as the line aboveGHSA-mp7c-m3rh-r56vCVE-2025-59160same package and registry as the line abovemoderatesame change as the line aboveTime to revision 6 days
2025-09-22published 2025-09-11same kind of change as the line aboveGHSA-33vc-wfww-vjfvCVE-2025-9910same package and registry as the line abovemoderatesame change as the line aboveTime to revision 12 days
Thu 18 Sep 2025· 3 changes
2025-09-18published 2025-09-10Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.Time to revision 8 to 8 days
2025-09-18published 2025-09-10same kind of change as the line aboveGHSA-jgw4-cr84-mqxgCVE-2025-10155same package and registry as the line abovecriticalsame change as the line aboveTime to revision 8 days
2025-09-18published 2025-09-10same kind of change as the line aboveGHSA-mjqp-26hc-grxgCVE-2025-10156same package and registry as the line abovecriticalsame change as the line aboveTime to revision 8 days
2025-09-18published 2025-09-10same kind of change as the line aboveGHSA-f7qq-56ww-84crCVE-2025-10157same package and registry as the line abovecriticalsame change as the line aboveTime to revision 8 days
Wed 17 Sep 2025· 1 change
2025-09-17published 2025-08-06Advisory withdrawnGHSA-qj5r-2r5p-phc7whole advisorymoderatewithdrawn 2025-09-17Time to revision 42 days
Tue 16 Sep 2025· 1 change
2025-09-16published 2021-07-27Package added to advisoryGHSA-2363-cqg2-863cCVE-2021-33813highnot named as affected when the advisory was published, now names org.jdom:jdom2Duration unknown
Mon 15 Sep 2025· 1 change
2025-09-15published 2025-09-12Advisory fix version movedGHSA-wgpv-6j63-x5phCVE-2025-58434
npmflowise
critical
stated at publication 3.0.5, now states 3.0.6Time to revision 3 days
Fri 12 Sep 2025· 15 changes
2025-09-12published 2020-01-08 to 2025-06-03Package added to advisorymoderatenot named as affected when the advisory was published, now names org.hibernate:hibernate-validatorTime to revision 101 to 309 days
2025-09-12published 2025-06-03same kind of change as the line aboveGHSA-7v6m-28jr-rg84CVE-2025-35036same package registry as the line abovemoderatesame change as the line aboveTime to revision 101 days
2025-09-12published 2021-06-04same kind of change as the line aboveGHSA-rmrm-75hp-phr2CVE-2020-10693same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-09-12published 2020-01-08same kind of change as the line aboveGHSA-m8p2-495h-ccmhCVE-2019-10219same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-09-12published 2024-11-07same kind of change as the line aboveGHSA-x83m-pf6f-pf9gCVE-2023-1932same package registry as the line abovemoderatesame change as the line aboveTime to revision 309 days
2025-09-12published 2018-10-16 to 2018-10-18Package added to advisory3 bandsnot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onDuration unknown
2025-09-12published 2018-10-17same kind of change as the line aboveGHSA-4mv7-cq75-3qjmCVE-2015-7940same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-09-12published 2018-10-17same kind of change as the line aboveGHSA-r97x-3g8f-gx3mCVE-2016-1000340same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-09-12published 2018-10-17same kind of change as the line aboveGHSA-4vhj-98r6-424hCVE-2016-1000338same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-09-12published 2018-10-16same kind of change as the line aboveGHSA-xqj7-j8j5-f2xrCVE-2018-1000180same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-09-12published 2018-10-17same kind of change as the line aboveGHSA-w285-wf9q-5w69CVE-2016-1000352same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-09-12published 2018-10-18same kind of change as the line aboveGHSA-9gp4-qrff-c648CVE-2016-1000345same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-09-12published 2018-10-17same kind of change as the line aboveGHSA-fjqm-246c-mwqgCVE-2016-1000346same package registry as the line abovelowsame change as the line aboveDuration unknown
2025-09-12published 2018-10-18same kind of change as the line aboveGHSA-2j2x-hx4g-2gf4CVE-2016-1000344same package registry as the line abovehighsame change as the line aboveDuration unknown
3 more rows in this change are not listed here. Open all 11 rows
Thu 11 Sep 2025· 1 change
2025-09-11published 2024-07-11Advisory withdrawnGHSA-9mvj-f7w8-pvh2CVE-2024-6484whole advisorymoderatewithdrawn 2025-09-11Time to revision 427 days
Tue 9 Sep 2025· 1 change
2025-09-09published 2025-09-09Advisory fix version movedGHSA-w62p-hx95-gf2cCVE-2025-59037
npm@duckdb/duckdb-wasm
high
stated at publication 1.29.3, now states 1.30.0Time to revision 0 days
Mon 8 Sep 2025· 1 change
2025-09-08published 2025-07-09Package added to advisoryGHSA-q92v-3f4w-5xg8CVE-2025-53742moderatenot named as affected when the advisory was published, now names org.jenkins-ci.plugins:applitools-eyesTime to revision 61 days
Fri 5 Sep 2025· 1 change
2025-09-05published 2025-09-04Advisory severity changedGHSA-fghv-69vj-qj49CVE-2025-58056whole advisorylowstated at publication HIGH, now states LOWCVSS versions were removed or replaced; no shared version's vector was rescored.Time to revision 1 days
Tue 2 Sep 2025· 7 changes
2025-09-02published 2022-05-14Package added to advisoryGHSA-xjgh-84hx-56c5highnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core and 1 moreDuration unknown
2025-09-02published 2022-05-14same kind of change as the line aboveGHSA-xjgh-84hx-56c5CVE-2017-12617same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDuration unknown
2025-09-02published 2022-05-14same kind of change as the line aboveGHSA-xjgh-84hx-56c5CVE-2017-12617same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaDuration unknown
2025-09-02published 2022-05-14Package added to advisoryGHSA-w3j5-q8f2-3cqqCVE-2016-8745highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-utilDuration unknown
2025-09-02published 2023-03-10Package added to advisoryGHSA-vp98-w2p3-mv35CVE-2023-26464highnot named as affected when the advisory was published, now names log4j:log4jTime to revision 907 days
2025-09-02published 2022-05-17Package added to advisoryGHSA-rpjm-422r-95mhCVE-2022-30126moderatenot named as affected when the advisory was published, now names org.apache.tika:tika-coreDuration unknown
2025-09-02published 2022-03-12Package added to advisoryGHSA-cr3q-pqgq-m8c2CVE-2018-25031moderatenot named as affected when the advisory was published, now names org.webjars:swagger-uiDuration unknown
2025-09-02published 2018-10-17Package added to advisoryGHSA-qcj7-g2j5-g7r3CVE-2016-1000342highnot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onDuration unknown
Fri 29 Aug 2025· 5 changes
2025-08-29published 2025-08-28Advisory fix version movedGHSA-jc7w-c686-c4v9CVE-2025-58058
gogithub.com/ulikunitz/xz
moderate
stated at publication 0.5.14, now states 0.5.15Time to revision 1 days
2025-08-29published 2025-08-20Package added to advisoryGHSA-mpww-r37c-vxjwCVE-2025-43746moderatenot named as affected when the advisory was published, now names ccom.liferay:com.liferay.dynamic.data.mapping.webTime to revision 9 days
2025-08-29published 2022-05-14 to 2025-08-20Advisory withdrawnwhole advisory2 bandswithdrawn 2025-08-29Time to revision 10 to 1,204 days
2025-08-29published 2022-05-14same kind of change as the line aboveGHSA-7mj4-2984-955fCVE-2018-18307same package and registry as the line abovemoderatewithdrawn 2025-08-29Time to revision 1,204 days
2025-08-29published 2025-08-20same kind of change as the line aboveGHSA-xh9h-692f-mmg4CVE-2025-54364same package and registry as the line abovelowwithdrawn 2025-08-29Time to revision 10 days
2025-08-29published 2025-08-20same kind of change as the line aboveGHSA-6fxp-p9mg-q64wCVE-2025-54363same package and registry as the line abovelowwithdrawn 2025-08-29Time to revision 10 days
Wed 27 Aug 2025· 1 change
2025-08-27published 2022-05-20Advisory fix version movedGHSA-hp87-p4gw-j4gqCVE-2022-28948
gogopkg.in/yaml.v3
high
stated at publication 3.0.0, now states 3.0.1Time to revision 13 days
Tue 26 Aug 2025· 1 change
2025-08-26published 2025-08-21Advisory severity changedGHSA-xr97-25v7-hc2qCVE-2025-55742whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 5 days
Mon 25 Aug 2025· 1 change
2025-08-25published 2022-01-27Advisory withdrawnGHSA-77rm-9x9h-xj3gCVE-2021-22570whole advisoryhighwithdrawn 2025-08-25Time to revision 1,307 days
Fri 22 Aug 2025· 2 changes
2025-08-22published 2025-08-13Package added to advisoryGHSA-gqp3-2cvr-x8m3CVE-2025-48989highnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreTime to revision 9 days
2025-08-22published 2025-08-22Advisory severity changedGHSA-74rg-6f92-g6wxCVE-2025-55745whole advisorylowstated at publication HIGH, now states LOWNo CVSS vector was stated in the first observed version.Time to revision 0 days
Thu 21 Aug 2025· 2 changes
2025-08-21published 2025-08-14Advisory severity changedGHSA-r4mg-4433-c7g3CVE-2025-24293whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 8 days
2025-08-21published 2025-08-21Advisory severity changedGHSA-8hmm-4crw-vm2cCVE-2025-57755whole advisoryhighstated at publication LOW, now states HIGHA CVSS version was added; the existing vectors stayed the same.Time to revision 0 days
Wed 20 Aug 2025· 1 change
2025-08-20published 2025-07-14Advisory severity changedGHSA-6qjf-g333-pv38CVE-2025-53623whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 37 days
Thu 14 Aug 2025· 5 changes
2025-08-14published 2021-03-18Advisory fix version moved
pypipillow
high
stated at publication 8.1.1, now states 8.1.2Duration unknown
2025-08-14published 2021-03-18same kind of change as the line aboveGHSA-95q3-8gr9-gm8wCVE-2021-27923same package and registry as the line abovehighsame change as the line aboveDuration unknown
2025-08-14published 2021-03-18same kind of change as the line aboveGHSA-3wvg-mj6g-m9cvCVE-2021-27922same package and registry as the line abovehighsame change as the line aboveDuration unknown
2025-08-14published 2021-03-18same kind of change as the line aboveGHSA-f4w8-cv6p-x6r5CVE-2021-27921same package and registry as the line abovehighsame change as the line aboveDuration unknown
2025-08-14published 2022-05-24Package added to advisoryGHSA-j2h2-cvwh-cr64CVE-2020-14457moderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v5Time to revision 1,178 days
2025-08-14published 2025-08-12Package added to advisoryGHSA-m5c7-5gv3-hcpfCVE-2025-43734moderatenot named as affected when the advisory was published, now names com.liferay:com.liferay.frontend.taglib.clayTime to revision 2 days
Wed 13 Aug 2025· 1 change
2025-08-13published 2025-07-20Advisory withdrawnGHSA-mqcp-p2hv-vw6xCVE-2025-54314whole advisoryhighwithdrawn 2025-08-13Time to revision 25 days
Tue 12 Aug 2025· 2 changes
2025-08-12published 2025-07-25Advisory severity changedGHSA-75jv-vfxf-3865CVE-2025-55013whole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 18 days
2025-08-12published 2025-08-11Advisory withdrawnGHSA-pwq7-2gvj-vg9vwhole advisoryhighwithdrawn 2025-08-12Time to revision 1 days
Mon 11 Aug 2025· 7 changes
2025-08-11published 2018-07-26 to 2022-01-06Package added to advisory3 bandsnot named as affected when the advisory was published, now names lodash-railsDuration unknown
2025-08-11published 2019-07-19same kind of change as the line aboveGHSA-x5rq-j2xg-h7qmCVE-2019-1010266same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-08-11published 2019-07-10same kind of change as the line aboveGHSA-jf85-cpcp-j695CVE-2019-10744same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2025-08-11published 2019-02-07same kind of change as the line aboveGHSA-4xc9-xhrj-v574CVE-2018-16487same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-08-11published 2018-07-26same kind of change as the line aboveGHSA-fvqr-27wr-82fmCVE-2018-3721same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-08-11published 2020-07-15same kind of change as the line aboveGHSA-p6mc-m468-83gwCVE-2020-8203same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-08-11published 2021-05-06same kind of change as the line aboveGHSA-35jh-r3h4-6jhmCVE-2021-23337same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-08-11published 2022-01-06same kind of change as the line aboveGHSA-29mw-wpgm-hmr9CVE-2020-28500same package registry as the line abovemoderatesame change as the line aboveDuration unknown
Fri 8 Aug 2025· 2 changes
2025-08-08published 2025-07-28Package added to advisoryGHSA-4mxg-3p6v-xgq3criticalnot named as affected when the advisory was published, now names @node-saml/passport-saml and 1 moreTime to revision 11 days
2025-08-08published 2025-07-28same kind of change as the line aboveGHSA-4mxg-3p6v-xgq3CVE-2025-54419same package registry as the line abovecriticalnot named as affected when the advisory was published, now names @node-saml/passport-samlTime to revision 11 days
2025-08-08published 2025-07-28same kind of change as the line aboveGHSA-4mxg-3p6v-xgq3CVE-2025-54419same package registry as the line abovecriticalnot named as affected when the advisory was published, now names passport-samlTime to revision 11 days
Thu 7 Aug 2025· 2 changes
2025-08-07published 2025-07-27Advisory severity changedGHSA-6v92-r5mx-h5fxCVE-2025-5120whole advisorycriticalstated at publication HIGH, now states CRITICALCVSS versions were removed or replaced; no shared version's vector was rescored.Time to revision 11 days
2025-08-07published 2025-03-17Advisory withdrawnGHSA-3rw8-4xrq-3f7pwhole advisorymoderatewithdrawn 2025-08-07Time to revision 143 days
Tue 5 Aug 2025· 1 change
2025-08-05published 2025-07-20Advisory severity changedGHSA-mqcp-p2hv-vw6xCVE-2025-54314whole advisoryhighstated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 17 days
Mon 4 Aug 2025· 4 changes
2025-08-04published 2024-09-26 to 2024-10-31Package added to advisoryhighnot named as affected when the advisory was published, now names github.com/openbao/openbaoTime to revision 277 to 312 days
2025-08-04published 2024-10-10same kind of change as the line aboveGHSA-rr8j-7w34-xp5jCVE-2024-9180same package registry as the line abovehighsame change as the line aboveTime to revision 298 days
2025-08-04published 2024-10-31same kind of change as the line aboveGHSA-g233-2p4r-3q7vCVE-2024-8185same package registry as the line abovehighsame change as the line aboveTime to revision 277 days
2025-08-04published 2024-09-26same kind of change as the line aboveGHSA-jg74-mwgw-v6x3CVE-2024-7594same package registry as the line abovehighsame change as the line aboveTime to revision 312 days
2025-08-04published 2025-07-25Advisory withdrawnGHSA-cmm8-gw4m-26cwCVE-2025-43712whole advisorylowwithdrawn 2025-08-04Time to revision 10 days
Fri 1 Aug 2025· 2 changes
2025-08-01published 2022-10-16 to 2025-07-05Advisory withdrawnwhole advisory2 bandswithdrawn 2025-08-01Time to revision 28 to 1,020 days
2025-08-01published 2022-10-16same kind of change as the line aboveGHSA-w596-4wvx-j9j6CVE-2022-42969same package and registry as the line abovehighwithdrawn 2025-08-01Time to revision 1,020 days
2025-08-01published 2025-07-05same kind of change as the line aboveGHSA-rxf6-323f-44fcsame package and registry as the line abovemoderatewithdrawn 2025-08-01Time to revision 28 days
Wed 30 Jul 2025· 3 changes
2025-07-30published 2025-07-30Advisory severity changedGHSA-rrqh-93c8-j966CVE-2025-54572whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 0 days
2025-07-30published 2025-07-10 to 2025-07-18Advisory withdrawnwhole advisorymoderatewithdrawn 2025-07-30Time to revision 12 to 20 days
2025-07-30published 2025-07-18same kind of change as the line aboveGHSA-83j7-mhw9-388wsame package and registry as the line abovemoderatewithdrawn 2025-07-30Time to revision 12 days
2025-07-30published 2025-07-10same kind of change as the line aboveGHSA-gj52-35xm-gxjhsame package and registry as the line abovemoderatewithdrawn 2025-07-30Time to revision 20 days
Tue 29 Jul 2025· 3 changes
2025-07-29published 2025-06-26Package added to advisoryGHSA-xh32-cx6c-cp4vCVE-2025-47943moderatenot named as affected when the advisory was published, now names gogs.io/gogsTime to revision 33 days
2025-07-29published 2025-07-25Advisory withdrawnwhole advisory2 bandswithdrawn 2025-07-29Time to revision 4 to 5 days
2025-07-29published 2025-07-25same kind of change as the line aboveGHSA-mvw6-62qv-vmqfsame package and registry as the line abovelowwithdrawn 2025-07-29Time to revision 5 days
2025-07-29published 2025-07-25same kind of change as the line aboveGHSA-49jm-g4m8-x53pCVE-2025-45406same package and registry as the line abovemoderatewithdrawn 2025-07-29Time to revision 4 days
Mon 28 Jul 2025· 8 changes
2025-07-28published 2025-07-18Advisory fix version movedGHSA-xffm-g5w8-qvg7
npm@eslint/plugin-kit
low
stated at publication 0.3.3, now states 0.3.4Time to revision 10 days
2025-07-28published 2025-05-30Package added to advisoryGHSA-6j2q-c73v-97c5CVE-2025-41235highnot named as affected when the advisory was published, now names org.springframework.cloud:spring-cloud-gateway-server-mvcTime to revision 60 days
2025-07-28published 2025-07-18 to 2025-07-25Advisory severity changedwhole advisorylowstated at publication HIGH, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 3 to 10 days
2025-07-28published 2025-07-25same kind of change as the line aboveGHSA-cmm8-gw4m-26cwCVE-2025-43712same package and registry as the line abovelowsame change as the line aboveTime to revision 3 days
2025-07-28published 2025-07-18same kind of change as the line aboveGHSA-xffm-g5w8-qvg7same package and registry as the line abovelowsame change as the line aboveTime to revision 10 days
2025-07-28published 2024-01-22Advisory severity changedGHSA-r7qv-8r2h-pg27CVE-2024-58266whole advisorylowstated at publication HIGH, now states LOWNo CVSS vector was stated in the first observed version.Time to revision 553 days
2025-07-28published 2024-04-05Advisory severity changedGHSA-5gmm-6m36-r7jhCVE-2023-53156whole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 479 days
2025-07-28published 2024-01-24Advisory severity changedGHSA-7g9j-g5jg-3vv3CVE-2024-58265whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Time to revision 551 days
2025-07-28published 2023-12-21Advisory severity changedGHSA-6ggr-cwv4-g7qgCVE-2023-53157whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 585 days
Fri 25 Jul 2025· 3 changes
2025-07-25published 2024-08-01Package added to advisoryGHSA-vvpg-55p7-5h8wlownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server and 2 moreTime to revision 358 days
2025-07-25published 2024-08-01same kind of change as the line aboveGHSA-vvpg-55p7-5h8wCVE-2024-39837same package registry as the line abovelownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-serverTime to revision 358 days
2025-07-25published 2024-08-01same kind of change as the line aboveGHSA-vvpg-55p7-5h8wCVE-2024-39837same package registry as the line abovelownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v5Time to revision 358 days
2025-07-25published 2024-08-01same kind of change as the line aboveGHSA-vvpg-55p7-5h8wCVE-2024-39837same package registry as the line abovelownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v6Time to revision 358 days

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

What this page cannot see

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Paste your closed CVE tickets and see which of these changes hit them →