Every change, newest first
What a record said when it was published, what it says now, and the commit that changed it.
5,026 advisory changes · newest first · grouped by day
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Kind | Advisory, Which advisory was edited, by its GHSA id. | Package, The package the advisory names, and the registry it comes from. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|---|
| Thu 24 Jul 2025· 1 change | |||||
| 2025-07-24published 2025-07-23 | Advisory withdrawn | GHSA-rm8p-cx58-hcvxCVE-2025-54371 | whole advisoryhigh | withdrawn 2025-07-24 | Time to revision 1 days |
| Wed 23 Jul 2025· 1 change | |||||
| 2025-07-23published 2025-07-21 | Advisory severity changed | GHSA-2gxp-6r36-m97rCVE-2025-53528 | whole advisoryhigh | stated at publication LOW, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored. | Time to revision 2 days |
| Tue 22 Jul 2025· 3 changes | |||||
| 2025-07-22published 2023-11-06 | Package added to advisory | GHSA-r67m-mf7v-qp7jCVE-2023-5968 | moderate | not named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v5 | Time to revision 624 days |
| 2025-07-22published 2025-07-19 | Package added to advisory | GHSA-f29h-pxvx-f335CVE-2025-54313 | high | not named as affected when the advisory was published, now names got-fetch | Time to revision 3 days |
| 2025-07-22published 2025-07-21 | Package added to advisory | GHSA-96c2-h667-9fxpCVE-2025-54082 | critical | not named as affected when the advisory was published, now names manogi/nova-tiptap | Time to revision 1 days |
| Mon 21 Jul 2025· 1 change | |||||
| 2025-07-21published 2025-07-18 | Package added to advisory | GHSA-fm79-3f68-h2fcCVE-2025-53901 | low | not named as affected when the advisory was published, now names wasmtime | Time to revision 3 days |
| Fri 18 Jul 2025· 10 changes | |||||
| 2025-07-18published 2022-11-17 | Advisory fix version moved | GHSA-83w4-x5w9-hf4hCVE-2022-43183 | mavencom.xuxueli:xxl-job-core high | stated at publication 2.3.1, now states 2.4.0 | Time to revision 974 days |
| 2025-07-18published 2022-11-25 | Package added to advisory | 2 bands | not named as affected when the advisory was published, now names org.jeecgframework.boot:jeecg-module-system | Time to revision 966 days | |
| 2025-07-18published 2022-11-25 | same kind of change as the line above | GHSA-g5cj-5h58-j93wCVE-2022-45206 | same package registry as the line abovecritical | same change as the line above | Time to revision 966 days |
| 2025-07-18published 2022-11-25 | same kind of change as the line above | GHSA-v87q-rpwp-qr7qCVE-2022-45210 | same package registry as the line abovemoderate | same change as the line above | Time to revision 966 days |
| 2025-07-18published 2022-11-25 | same kind of change as the line above | GHSA-4j2x-v3mr-467mCVE-2022-45207 | same package registry as the line abovecritical | same change as the line above | Time to revision 966 days |
| 2025-07-18published 2022-11-25 | same kind of change as the line above | GHSA-25gv-mvm7-5h3hCVE-2022-45208 | same package registry as the line abovemoderate | same change as the line above | Time to revision 966 days |
| 2025-07-18published 2022-02-01 | Package added to advisory | GHSA-2m53-83f3-562jCVE-2021-23460 | high | not named as affected when the advisory was published, now names org.webjars.npm:min-dash | Duration unknown |
| 2025-07-18published 2022-05-17 | Package added to advisory | GHSA-cm99-x97g-9qx8CVE-2017-12648 | moderate | not named as affected when the advisory was published, now names com.liferay:com.liferay.frontend.taglib | Time to revision 1,159 days |
| 2025-07-18published 2020-09-04 to 2022-05-14 | Advisory withdrawn | whole advisory2 bands | withdrawn 2025-07-18 | Time to revision 1,162 to 1,778 days | |
| 2025-07-18published 2022-01-27 | same kind of change as the line above | GHSA-fm93-fhh2-cg2c | same package and registry as the line abovehigh | withdrawn 2025-07-18 | Time to revision 1,268 days |
| 2025-07-18published 2020-09-04 | same kind of change as the line above | GHSA-4r97-78gf-q24v | same package and registry as the line abovehigh | withdrawn 2025-07-18 | Time to revision 1,778 days |
| 2025-07-18published 2022-05-14 | same kind of change as the line above | GHSA-x6rc-54xp-ccxxCVE-2015-3208 | same package and registry as the line abovecritical | withdrawn 2025-07-18 | Time to revision 1,162 days |
| Wed 16 Jul 2025· 1 change | |||||
| 2025-07-16published 2023-04-02 | Advisory fix version moved | GHSA-h4c9-rr5m-32fmCVE-2023-27025 | mavencom.ruoyi:ruoyi high | stated at publication 4.7.6, now states 4.7.7 | Time to revision 837 days |
| Fri 11 Jul 2025· 1 change | |||||
| 2025-07-11published 2025-07-10 | Package added to advisory | GHSA-275g-g844-73jhCVE-2025-53549 | moderate | not named as affected when the advisory was published, now names matrix-sdk-sqlite | Time to revision 1 days |
| Thu 10 Jul 2025· 1 change | |||||
| 2025-07-10published 2020-09-02 | Package added to advisory | GHSA-7p6w-x2gr-rrf8 | high | not named as affected when the advisory was published, now names ag-grid | Duration unknown |
| Wed 9 Jul 2025· 2 changes | |||||
| 2025-07-09published 2025-06-16 | Package added to advisory | GHSA-vv7r-c36w-3prjCVE-2025-48976 | high | not named as affected when the advisory was published, now names commons-fileupload:commons-fileupload | Time to revision 23 days |
| 2025-07-09published 2025-03-03 | Package added to advisory | GHSA-vm7w-2724-5m23CVE-2024-24778 | moderate | not named as affected when the advisory was published, now names streampipes | Time to revision 128 days |
| Wed 2 Jul 2025· 9 changes | |||||
| 2025-07-02published 2024-12-18 | Package added to advisory | GHSA-p7c9-8xx8-h74f | low | not named as affected when the advisory was published, now names org.apache.kafka:kafka_2.10 and 3 more | Time to revision 196 to 196 days |
| 2025-07-02published 2024-12-18 | same kind of change as the line above | GHSA-p7c9-8xx8-h74fCVE-2024-56128 | same package registry as the line abovelow | not named as affected when the advisory was published, now names org.apache.kafka:kafka_2.10 | Time to revision 196 days |
| 2025-07-02published 2024-12-18 | same kind of change as the line above | GHSA-p7c9-8xx8-h74fCVE-2024-56128 | same package registry as the line abovelow | not named as affected when the advisory was published, now names org.apache.kafka:kafka_2.11 | Time to revision 196 days |
| 2025-07-02published 2024-12-18 | same kind of change as the line above | GHSA-p7c9-8xx8-h74fCVE-2024-56128 | same package registry as the line abovelow | not named as affected when the advisory was published, now names org.apache.kafka:kafka_2.12 | Time to revision 196 days |
| 2025-07-02published 2024-12-18 | same kind of change as the line above | GHSA-p7c9-8xx8-h74fCVE-2024-56128 | same package registry as the line abovelow | not named as affected when the advisory was published, now names org.apache.kafka:kafka_2.13 | Time to revision 196 days |
| 2025-07-02published 2025-05-14 | Package added to advisory | 2 bands | not named as affected when the advisory was published, now names apache-iotdb | Time to revision 49 days | |
| 2025-07-02published 2025-05-14 | same kind of change as the line above | GHSA-5fc3-pqf2-57cxCVE-2025-26864 | same package registry as the line abovemoderate | same change as the line above | Time to revision 49 days |
| 2025-07-02published 2025-05-14 | same kind of change as the line above | GHSA-f4rq-f4j9-f6rmCVE-2024-24780 | same package registry as the line abovecritical | same change as the line above | Time to revision 49 days |
| 2025-07-02published 2022-05-01 | Advisory severity changed | GHSA-pmfx-p95x-cg4pCVE-2006-2571 | whole advisorylow | stated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 1,158 days |
| 2025-07-02published 2022-05-24 to 2023-08-11 | Advisory withdrawn | whole advisory2 bands | withdrawn 2025-07-02 | Time to revision 691 to 1,135 days | |
| 2025-07-02published 2022-05-24 | same kind of change as the line above | GHSA-jffq-528j-mp6cCVE-2020-10991 | same package and registry as the line abovecritical | withdrawn 2025-07-02 | Time to revision 1,135 days |
| 2025-07-02published 2023-08-11 | same kind of change as the line above | GHSA-7rvp-xqj7-rxf2CVE-2020-24950 | same package and registry as the line abovehigh | withdrawn 2025-07-02 | Time to revision 691 days |
| Tue 1 Jul 2025· 6 changes | |||||
| 2025-07-01published 2021-10-06 | Package added to advisory | GHSA-v6w3-2prq-h95f | moderate | not named as affected when the advisory was published, now names org.glassfish:jakarta.el and 1 more | Duration unknown |
| 2025-07-01published 2021-10-06 | same kind of change as the line above | GHSA-v6w3-2prq-h95fCVE-2021-28170 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.glassfish:jakarta.el | Duration unknown |
| 2025-07-01published 2021-10-06 | same kind of change as the line above | GHSA-v6w3-2prq-h95fCVE-2021-28170 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.glassfish:javax.el | Duration unknown |
| 2025-07-01published 2021-11-18 to 2022-05-24 | Advisory withdrawn | whole advisory2 bands | withdrawn 2025-07-01 | Time to revision 1,134 to 1,321 days | |
| 2025-07-01published 2022-05-24 | same kind of change as the line above | GHSA-5h6x-m52p-23phCVE-2019-0223 | same package and registry as the line abovehigh | withdrawn 2025-07-01 | Time to revision 1,134 days |
| 2025-07-01published 2021-11-18 | same kind of change as the line above | GHSA-gpqc-4pp7-5954 | same package and registry as the line abovecritical | withdrawn 2025-07-01 | Time to revision 1,321 days |
| 2025-07-01published 2021-11-18 | same kind of change as the line above | GHSA-6mqr-q86q-6gwr | same package and registry as the line abovecritical | withdrawn 2025-07-01 | Time to revision 1,321 days |
| 2025-07-01published 2021-11-18 | same kind of change as the line above | GHSA-8xfw-5q82-3652 | same package and registry as the line abovecritical | withdrawn 2025-07-01 | Time to revision 1,321 days |
| Mon 30 Jun 2025· 1 change | |||||
| 2025-06-30published 2025-06-17 | Package added to advisory | GHSA-rvqx-wpfh-mfx7CVE-2025-3248 | critical | not named as affected when the advisory was published, now names langflow-base | Time to revision 13 days |
| Tue 24 Jun 2025· 2 changes | |||||
| 2025-06-24published 2024-05-03 | Package added to advisory | GHSA-4h8f-2wvx-gg5w | moderate | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-lts8on and 1 more | Time to revision 417 days |
| 2025-06-24published 2024-05-03 | same kind of change as the line above | GHSA-4h8f-2wvx-gg5wCVE-2024-34447 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-lts8on | Time to revision 417 days |
| 2025-06-24published 2024-05-03 | same kind of change as the line above | GHSA-4h8f-2wvx-gg5wCVE-2024-34447 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.bouncycastle:bctls-fips | Time to revision 417 days |
| Fri 20 Jun 2025· 6 changes | |||||
| 2025-06-20published 2024-09-13 | Package added to advisory | GHSA-v6x6-4v4x-2fx9CVE-2024-6862 | moderate | not named as affected when the advisory was published, now names @lunary/backend | Time to revision 280 days |
| 2025-06-20published 2024-06-06 to 2025-05-22 | Advisory withdrawn | whole advisory2 bands | withdrawn 2025-06-20 | Time to revision 29 to 379 days | |
| 2025-06-20published 2024-09-13 | same kind of change as the line above | GHSA-v6x6-4v4x-2fx9CVE-2024-6862 | same package and registry as the line abovemoderate | withdrawn 2025-06-20 | Time to revision 280 days |
| 2025-06-20published 2024-09-13 | same kind of change as the line above | GHSA-6p2q-8qfq-wq7xCVE-2024-6087 | same package and registry as the line abovehigh | withdrawn 2025-06-20 | Time to revision 280 days |
| 2025-06-20published 2024-09-13 | same kind of change as the line above | GHSA-9jmp-j63g-8x6mCVE-2024-6867 | same package and registry as the line abovemoderate | withdrawn 2025-06-20 | Time to revision 280 days |
| 2025-06-20published 2024-06-06 | same kind of change as the line above | GHSA-rpx8-fg6w-rm6xCVE-2024-5478 | same package and registry as the line abovehigh | withdrawn 2025-06-20 | Time to revision 379 days |
| 2025-06-20published 2025-05-22 | same kind of change as the line above | GHSA-3qmp-g57h-rxf2 | same package and registry as the line abovehigh | withdrawn 2025-06-20 | Time to revision 29 days |
| Thu 19 Jun 2025· 1 change | |||||
| 2025-06-19published 2024-03-03 | Advisory withdrawn | GHSA-jw44-4f3j-q396CVE-2019-25210 | whole advisorymoderate | withdrawn 2025-06-19 | Time to revision 473 days |
| Wed 18 Jun 2025· 4 changes | |||||
| 2025-06-18published 2025-06-17 | Advisory severity changed | whole advisorylow | stated at publication HIGH, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 1 days | |
| 2025-06-18published 2025-06-17 | same kind of change as the line above | GHSA-64x7-m7rh-9m83CVE-2025-45525 | same package and registry as the line abovelow | same change as the line above | Time to revision 1 days |
| 2025-06-18published 2025-06-17 | same kind of change as the line above | GHSA-wgc6-9f6w-h8hxCVE-2025-45526 | same package and registry as the line abovelow | same change as the line above | Time to revision 1 days |
| 2025-06-18published 2025-06-17 | Advisory withdrawn | whole advisorylow | withdrawn 2025-06-18 | Time to revision 1 to 1 days | |
| 2025-06-18published 2025-06-17 | same kind of change as the line above | GHSA-64x7-m7rh-9m83CVE-2025-45525 | same package and registry as the line abovelow | withdrawn 2025-06-18 | Time to revision 1 days |
| 2025-06-18published 2025-06-17 | same kind of change as the line above | GHSA-wgc6-9f6w-h8hxCVE-2025-45526 | same package and registry as the line abovelow | withdrawn 2025-06-18 | Time to revision 1 days |
| Tue 17 Jun 2025· 1 change | |||||
| 2025-06-17published 2025-04-07 | Advisory withdrawn | GHSA-c995-4fw3-j39m | whole advisorycritical | withdrawn 2025-06-17 | Time to revision 71 days |
| Mon 16 Jun 2025· 2 changes | |||||
| 2025-06-16published 2022-05-14 | Advisory fix version moved | GHSA-g434-3q2j-hj4rCVE-2018-12071 | packagistcodeigniter/framework critical | stated at publication 3.1.9, now states 3.1.10 | Time to revision 1,130 days |
| 2025-06-16published 2023-01-11 | Advisory withdrawn | GHSA-798h-g4j5-5537 | whole advisoryhigh | withdrawn 2025-06-16 | Time to revision 887 days |
| Tue 10 Jun 2025· 1 change | |||||
| 2025-06-10published 2025-06-06 | Advisory severity changed | GHSA-62gc-8jr5-x9pmCVE-2025-27531 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 4 days |
| Mon 9 Jun 2025· 2 changes | |||||
| 2025-06-09published 2025-03-26 | Package added to advisory | GHSA-56p6-qw3c-fq2g | low | not named as affected when the advisory was published, now names @directus/api and 1 more | Time to revision 75 days |
| 2025-06-09published 2025-03-26 | same kind of change as the line above | GHSA-56p6-qw3c-fq2gCVE-2025-30351 | same package registry as the line abovelow | not named as affected when the advisory was published, now names @directus/api | Time to revision 75 days |
| 2025-06-09published 2025-03-26 | same kind of change as the line above | GHSA-56p6-qw3c-fq2gCVE-2025-30351 | same package registry as the line abovelow | not named as affected when the advisory was published, now names @directus/types | Time to revision 75 days |
| Fri 6 Jun 2025· 1 change | |||||
| 2025-06-06published 2025-06-05 | Advisory severity changed | GHSA-m65q-v92h-cm7qCVE-2025-5791 | whole advisoryhigh | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | Time to revision 2 days |
| Wed 4 Jun 2025· 1 change | |||||
| 2025-06-04published 2024-03-07 | Advisory severity changed | GHSA-75jp-vq8x-h4cqCVE-2024-28123 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version. | Time to revision 453 days |
| Mon 2 Jun 2025· 1 change | |||||
| 2025-06-02published 2022-05-17 | Package added to advisory | GHSA-2pcj-76hj-xqhmCVE-2016-10131 | critical | not named as affected when the advisory was published, now names bcit-ci/codeigniter | Time to revision 1,113 days |
| Fri 30 May 2025· 2 changes | |||||
| 2025-05-30published 2024-02-27 | Package added to advisory | GHSA-xh6m-7cr7-xx66CVE-2023-45859 | high | not named as affected when the advisory was published, now names com.hazelcast:hazelcast-all | Time to revision 458 days |
| 2025-05-30published 2023-10-05 | Advisory withdrawn | GHSA-56pw-mpj4-fxww | whole advisoryhigh | withdrawn 2025-05-30 | Time to revision 604 days |
| Thu 29 May 2025· 1 change | |||||
| 2025-05-29published 2018-10-19 | Package added to advisory | GHSA-jc7r-v6fg-2gpfCVE-2018-8039 | high | not named as affected when the advisory was published, now names org.apache.cxf:cxf-rt-transports-http | Duration unknown |
| Wed 28 May 2025· 1 change | |||||
| 2025-05-28published 2025-05-28 | Advisory severity changed | GHSA-6vx9-9r2g-8373CVE-2025-5256 | whole advisorymoderate | stated at publication LOW, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored. | Time to revision 0 days |
| Tue 27 May 2025· 5 changes | |||||
| 2025-05-27published 2024-10-18 | Package added to advisory | GHSA-4gc7-5j7h-4qphCVE-2024-38820 | moderate | not named as affected when the advisory was published, now names org.springframework:spring-web | Time to revision 222 days |
| 2025-05-27published 2025-04-01 | Package added to advisory | GHSA-6jwp-4wvj-6597 | critical | not named as affected when the advisory was published, now names org.apache.pinot:pinot-broker and 2 more | Time to revision 56 days |
| 2025-05-27published 2025-04-01 | same kind of change as the line above | GHSA-6jwp-4wvj-6597CVE-2024-56325 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.apache.pinot:pinot-broker | Time to revision 56 days |
| 2025-05-27published 2025-04-01 | same kind of change as the line above | GHSA-6jwp-4wvj-6597CVE-2024-56325 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.apache.pinot:pinot-common | Time to revision 56 days |
| 2025-05-27published 2025-04-01 | same kind of change as the line above | GHSA-6jwp-4wvj-6597CVE-2024-56325 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.apache.pinot:pinot-controller | Time to revision 56 days |
| 2025-05-27published 2021-12-20 | Advisory severity changed | GHSA-627p-rr78-99rjCVE-2020-5415 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same. | Duration unknown |
| Fri 23 May 2025· 2 changes | |||||
| 2025-05-23published 2024-03-18 to 2024-09-23 | Advisory withdrawn | whole advisory2 bands | withdrawn 2025-05-23 | Time to revision 242 to 431 days | |
| 2025-05-23published 2024-03-18 | same kind of change as the line above | GHSA-vcc3-rw6f-jv97 | same package and registry as the line abovemoderate | withdrawn 2025-05-23 | Time to revision 431 days |
| 2025-05-23published 2024-09-23 | same kind of change as the line above | GHSA-3hp8-6j24-m5gm | same package and registry as the line abovehigh | withdrawn 2025-05-23 | Time to revision 242 days |
| Wed 14 May 2025· 3 changes | |||||
| 2025-05-14published 2025-04-28 | Package added to advisory | 2 bands | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | Time to revision 16 days | |
| 2025-05-14published 2025-04-28 | same kind of change as the line above | GHSA-ff77-26x5-69crCVE-2025-31651 | same package registry as the line abovelow | same change as the line above | Time to revision 16 days |
| 2025-05-14published 2025-04-28 | same kind of change as the line above | GHSA-3p2h-wqq4-wf4hCVE-2025-31650 | same package registry as the line abovemoderate | same change as the line above | Time to revision 16 days |
| 2025-05-14published 2025-05-13 | Advisory severity changed | GHSA-h4j7-5rxr-p4wcCVE-2025-26646 | whole advisoryhigh | stated at publication LOW, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored. | Time to revision 1 days |
| Mon 12 May 2025· 4 changes | |||||
| 2025-05-12published 2025-04-08 | Advisory fix version moved | 4 rows, one per advisory and package | packagist2 packages 2 bands | stated at publication 6.5.8.17, now states 6.5.8.18 | Time to revision 27 days |
| 2025-05-12published 2025-04-08 | Advisory fix version moved | GHSA-hh7j-6x3q-f52hCVE-2025-30150 | packagistshopware/core moderate | same change as the line above | Time to revision 27 days |
| 2025-05-12published 2025-04-08 | Advisory fix version moved | GHSA-hh7j-6x3q-f52hCVE-2025-30150 | packagistshopware/platform moderate | same change as the line above | Time to revision 27 days |
| 2025-05-12published 2025-04-08 | Advisory fix version moved | GHSA-8g35-7rmw-7f59CVE-2025-27892 | packagistshopware/core high | same change as the line above | Time to revision 27 days |
| 2025-05-12published 2025-04-08 | Advisory fix version moved | GHSA-8g35-7rmw-7f59CVE-2025-27892 | packagistshopware/platform high | same change as the line above | Time to revision 27 days |
| Wed 7 May 2025· 5 changes | |||||
| 2025-05-07published 2021-12-10 to 2022-01-04 | Package added to advisory | 3 bands | not named as affected when the advisory was published, now names org.ops4j.pax.logging:pax-logging-log4j2 | Duration unknown | |
| 2025-05-07published 2022-01-04 | same kind of change as the line above | GHSA-8489-44mv-ggj8CVE-2021-44832 | same package registry as the line abovemoderate | same change as the line above | Duration unknown |
| 2025-05-07published 2021-12-18 | same kind of change as the line above | GHSA-p6xc-xr62-6r2gCVE-2021-45105 | same package registry as the line abovehigh | same change as the line above | Duration unknown |
| 2025-05-07published 2021-12-14 | same kind of change as the line above | GHSA-7rjr-3q55-vv33CVE-2021-45046 | same package registry as the line abovecritical | same change as the line above | Duration unknown |
| 2025-05-07published 2021-12-10 | same kind of change as the line above | GHSA-jfh8-c2jp-5v3qCVE-2021-44228 | same package registry as the line abovecritical | same change as the line above | Duration unknown |
| 2025-05-07published 2025-05-06 | Advisory severity changed | GHSA-8gqj-226h-gm8rCVE-2025-46573 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 1 days |
| Tue 6 May 2025· 1 change | |||||
| 2025-05-06published 2018-10-16 | Advisory severity changed | GHSA-7378-6268-4278CVE-2018-1002205 | whole advisorymoderate | stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version. | Duration unknown |
| Tue 29 Apr 2025· 9 changes | |||||
| 2025-04-29published 2025-04-01 | Advisory severity changed | whole advisoryhigh | stated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 29 days | |
| 2025-04-29published 2025-04-01 | same kind of change as the line above | GHSA-4f8q-mwgc-3mwcCVE-2025-31691 | same package and registry as the line abovehigh | same change as the line above | Time to revision 29 days |
| 2025-04-29published 2025-04-01 | same kind of change as the line above | GHSA-hf6c-fgp3-jfchCVE-2025-31694 | same package and registry as the line abovehigh | same change as the line above | Time to revision 29 days |
| 2025-04-29published 2025-04-01 | same kind of change as the line above | GHSA-m9w8-wxvp-c9gvCVE-2025-31686 | same package and registry as the line abovehigh | same change as the line above | Time to revision 29 days |
| 2025-04-29published 2025-04-01 | Advisory severity changed | whole advisorymoderate | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 29 days | |
| 2025-04-29published 2025-04-01 | same kind of change as the line above | GHSA-ccc9-jgj7-hxc7CVE-2025-31690 | same package and registry as the line abovemoderate | same change as the line above | Time to revision 29 days |
| 2025-04-29published 2025-04-01 | same kind of change as the line above | GHSA-jv6r-mj9p-9xffCVE-2025-31689 | same package and registry as the line abovemoderate | same change as the line above | Time to revision 29 days |
| 2025-04-29published 2025-04-01 | same kind of change as the line above | GHSA-gf72-h4cp-wcm4CVE-2025-31685 | same package and registry as the line abovemoderate | same change as the line above | Time to revision 29 days |
| 2025-04-29published 2025-04-01 | same kind of change as the line above | GHSA-9w85-x5hg-fr66CVE-2025-31677 | same package and registry as the line abovemoderate | same change as the line above | Time to revision 29 days |
| 2025-04-29published 2025-04-01 | same kind of change as the line above | GHSA-c8q6-wp7v-46r9CVE-2025-31678 | same package and registry as the line abovemoderate | same change as the line above | Time to revision 29 days |
| 2025-04-29published 2025-04-01 | Advisory severity changed | GHSA-jwpx-6c4p-q4jqCVE-2025-31681 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 29 days |
| Tue 22 Apr 2025· 2 changes | |||||
| 2025-04-22published 2025-04-22 | Advisory severity changed | GHSA-x27v-f838-jh93CVE-2025-32951 | whole advisorymoderate | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 0 days |
| 2025-04-22published 2024-10-02 | Advisory withdrawn | GHSA-mrw8-5368-phm3CVE-2024-45965 | whole advisorylow | withdrawn 2025-04-22 | Time to revision 202 days |
| Fri 18 Apr 2025· 1 change | |||||
| 2025-04-18published 2025-04-18 | Advisory fix version moved | GHSA-mg2h-6x62-wpwcCVE-2025-32442 | npmfastify high | stated at publication 5.3.1, now states 5.3.2 | Time to revision 0 days |
| Thu 17 Apr 2025· 1 change | |||||
| 2025-04-17published 2024-04-25 | Advisory withdrawn | GHSA-x5m7-63c6-fx79CVE-2024-1139 | whole advisoryhigh | withdrawn 2025-04-17 | Time to revision 357 days |
| Wed 16 Apr 2025· 1 change | |||||
| 2025-04-16published 2021-03-03 | Advisory severity changed | GHSA-p493-635q-r6grCVE-2021-21353 | whole advisorymoderate | stated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same. | Duration unknown |
| Tue 15 Apr 2025· 1 change | |||||
| 2025-04-15published 2025-03-20 | Advisory withdrawn | GHSA-gjxm-x497-4h6hCVE-2025-0655 | whole advisorycritical | withdrawn 2025-04-15 | Time to revision 26 days |
| Mon 14 Apr 2025· 5 changes | |||||
| 2025-04-14published 2022-05-14 | Package added to advisory | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina | Duration unknown | |
| 2025-04-14published 2022-05-14 | same kind of change as the line above | GHSA-prc3-7f44-w48jCVE-2014-0119 | same package registry as the line abovemoderate | same change as the line above | Duration unknown |
| 2025-04-14published 2022-05-14 | same kind of change as the line above | GHSA-qprx-q2r7-3rx6CVE-2014-0096 | same package registry as the line abovemoderate | same change as the line above | Duration unknown |
| 2025-04-14published 2022-05-14 | Package added to advisory | GHSA-prc3-7f44-w48jCVE-2014-0119 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-jasper | Duration unknown |
| 2025-04-14published 2022-05-14 | Package added to advisory | GHSA-xh5x-j8jf-pcpxCVE-2014-0099 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-util | Duration unknown |
| 2025-04-14published 2022-05-14 | Package added to advisory | GHSA-475f-74wp-pqv5CVE-2014-0075 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Duration unknown |
| Sun 13 Apr 2025· 1 change | |||||
| 2025-04-13published 2025-04-02 | Advisory severity changed | GHSA-49v8-p6mm-3pfjCVE-2025-29085 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 10 days |
| Thu 10 Apr 2025· 2 changes | |||||
| 2025-04-10published 2025-03-24 | Advisory fix version moved | GHSA-5pq3-h73f-66hr | npmaws-cdk-lib low | stated at publication 2.184.0, now states 2.189.0 | Time to revision 16 days |
| 2025-04-10published 2023-09-22 | Advisory withdrawn | GHSA-cc8j-6phr-jv9xCVE-2023-42261 | whole advisoryhigh | withdrawn 2025-04-10 | Time to revision 567 days |
| Wed 9 Apr 2025· 1 change | |||||
| 2025-04-09published 2025-04-09 | Advisory severity changed | GHSA-q62r-8ppj-xvf4CVE-2025-32017 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 0 days |
| Fri 4 Apr 2025· 2 changes | |||||
| 2025-04-04published 2025-01-31 | Advisory severity changed | GHSA-88m4-h43f-wx84CVE-2025-23215 | whole advisorycritical | stated at publication LOW, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 63 days |
| 2025-04-04published 2024-11-12 | Advisory severity changed | GHSA-6x36-qxmj-rv4pCVE-2024-43499 | whole advisoryhigh | stated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 143 days |
| Thu 3 Apr 2025· 1 change | |||||
| 2025-04-03published 2025-03-20 | Package added to advisory | GHSA-x48g-hm9c-ww42CVE-2024-12909 | critical | not named as affected when the advisory was published, now names llama-index-packs-finchat | Time to revision 14 days |
| Wed 2 Apr 2025· 1 change | |||||
| 2025-04-02published 2025-03-20 | Advisory withdrawn | GHSA-4vmg-rw8f-92f9CVE-2024-7804 | whole advisorycritical | withdrawn 2025-04-02 | Time to revision 13 days |
| Tue 1 Apr 2025· 1 change | |||||
| 2025-04-01published 2025-03-28 | Advisory withdrawn | GHSA-799q-f2px-wx8c | whole advisoryhigh | withdrawn 2025-04-01 | Time to revision 4 days |
| Fri 28 Mar 2025· 1 change | |||||
| 2025-03-28published 2025-03-20 | Advisory withdrawn | GHSA-xqgj-r6xv-9cw4CVE-2024-10096 | whole advisorycritical | withdrawn 2025-03-28 | Time to revision 8 days |
| Wed 26 Mar 2025· 1 change | |||||
| 2025-03-26published 2022-03-07 | Advisory severity changed | GHSA-ph3v-2hq5-5qfqCVE-2021-46703 | whole advisorycritical | stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version. | Duration unknown |
| Tue 25 Mar 2025· 1 change | |||||
| 2025-03-25published 2024-12-09 | Advisory withdrawn | GHSA-4v5x-9m47-cqr2 | whole advisorymoderate | withdrawn 2025-03-25 | Time to revision 106 days |
| Sat 22 Mar 2025· 1 change | |||||
| 2025-03-22published 2024-08-15 | Advisory withdrawn | GHSA-qf6h-p3mr-vmh5 | whole advisorymoderate | withdrawn 2025-03-22 | Time to revision 219 days |
| Fri 21 Mar 2025· 2 changes | |||||
| 2025-03-21published 2025-03-19 | Advisory severity changed | GHSA-2x3g-rr4w-4qrpCVE-2025-30197 | whole advisorylow | stated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 2 days |
| 2025-03-21published 2024-05-03 | Advisory severity changed | GHSA-4h8f-2wvx-gg5wCVE-2024-34447 | whole advisorymoderate | stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version. | Time to revision 322 days |
| Thu 20 Mar 2025· 5 changes | |||||
| 2025-03-20published 2025-03-20 | Package added to advisory | GHSA-h7xg-cmpp-48hfCVE-2024-10553 | critical | not named as affected when the advisory was published, now names ai.h2o:h2o-core | Time to revision 0 days |
| 2025-03-20published 2025-03-20 | Package added to advisory | GHSA-2r4x-667f-mpfhCVE-2024-47552 | low | not named as affected when the advisory was published, now names org.apache.seata:seata-config-core | Time to revision 0 days |
| 2025-03-20published 2025-03-12 | Advisory severity changed | whole advisorycritical | stated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 8 days | |
| 2025-03-20published 2025-03-12 | same kind of change as the line above | GHSA-754f-8gm6-c4r2CVE-2025-25292 | same package and registry as the line abovecritical | same change as the line above | Time to revision 8 days |
| 2025-03-20published 2025-03-12 | same kind of change as the line above | GHSA-4vc4-m8qh-g8jmCVE-2025-25291 | same package and registry as the line abovecritical | same change as the line above | Time to revision 8 days |
| 2025-03-20published 2024-08-15 | Advisory withdrawn | GHSA-q83v-hq3j-4pq3 | whole advisorymoderate | withdrawn 2025-03-20 | Time to revision 218 days |
| Wed 19 Mar 2025· 1 change | |||||
| 2025-03-19published 2025-03-10 | Advisory severity changed | GHSA-83qj-6fr2-vhqgCVE-2025-24813 | whole advisorycritical | stated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 9 days |
| Mon 17 Mar 2025· 3 changes | |||||
| 2025-03-17published 2022-02-10 | Package added to advisory | GHSA-3c7p-vv5r-cmr5 | critical | not named as affected when the advisory was published, now names org.apache.solr:solr-core and 1 more | Duration unknown |
| 2025-03-17published 2022-02-10 | same kind of change as the line above | GHSA-3c7p-vv5r-cmr5CVE-2020-13957 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.apache.solr:solr-core | Duration unknown |
| 2025-03-17published 2022-02-10 | same kind of change as the line above | GHSA-3c7p-vv5r-cmr5CVE-2020-13957 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.apache.solr:solr-solrj | Duration unknown |
| 2025-03-17published 2025-03-10 | Package added to advisory | GHSA-83qj-6fr2-vhqgCVE-2025-24813 | critical | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | Time to revision 7 days |
| Fri 14 Mar 2025· 2 changes | |||||
| 2025-03-14published 2025-03-11 | Package added to advisory | GHSA-44f7-5fj5-h4pxCVE-2025-27403 | high | not named as affected when the advisory was published, now names github.com/deislabs/ratify | Time to revision 3 days |
| 2025-03-14published 2023-09-15 | Package added to advisory | GHSA-hvpq-7vcc-5hj5CVE-2023-41592 | moderate | not named as affected when the advisory was published, now names froala-editor | Time to revision 547 days |
| Wed 12 Mar 2025· 3 changes | |||||
| 2025-03-12published 2025-03-12 | Advisory fix version moved | GHSA-q92j-grw3-h492CVE-2025-27407 | rubygemsgraphql critical | stated at publication 1.11.8, now states 1.11.11 | Time to revision 0 days |
| 2025-03-12published 2025-03-12 | Advisory fix version moved | GHSA-q92j-grw3-h492CVE-2025-27407 | rubygemsgraphql critical | stated at publication 2.1.14, now states 2.1.15 | Time to revision 0 days |
| 2025-03-12published 2025-03-12 | Advisory severity changed | GHSA-92rq-c8cf-prrqCVE-2025-25293 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 0 days |
| Tue 11 Mar 2025· 6 changes | |||||
| 2025-03-11published 2025-02-12 | Package added to advisory | GHSA-6fgm-x6ff-w78f | moderate | not named as affected when the advisory was published, now names github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v4 and 2 more | Time to revision 27 days |
| 2025-03-11published 2025-02-12 | same kind of change as the line above | GHSA-6fgm-x6ff-w78f | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v4 | Time to revision 27 days |
| 2025-03-11published 2025-02-12 | same kind of change as the line above | GHSA-6fgm-x6ff-w78f | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v5 | Time to revision 27 days |
| 2025-03-11published 2025-02-12 | same kind of change as the line above | GHSA-6fgm-x6ff-w78f | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v6 | Time to revision 27 days |
| 2025-03-11published 2025-01-23 | Advisory severity changed | GHSA-9cxr-76pm-j3wfCVE-2024-53299 | whole advisorymoderate | stated at publication CRITICAL, now states MODERATENo CVSS vector was stated in the first observed version. | Time to revision 47 days |
| 2025-03-11published 2023-06-21 to 2025-03-11 | Advisory withdrawn | whole advisoryhigh | withdrawn 2025-03-11 | Time to revision 0 to 629 days | |
| 2025-03-11published 2023-06-21 | same kind of change as the line above | GHSA-fqhp-rhm6-8rrjCVE-2023-33289 | same package and registry as the line abovehigh | withdrawn 2025-03-11 | Time to revision 629 days |
| 2025-03-11published 2025-03-11 | same kind of change as the line above | GHSA-5478-v2w6-c6q7 | same package and registry as the line abovehigh | withdrawn 2025-03-11 | Time to revision 0 days |
| Mon 10 Mar 2025· 3 changes | |||||
| 2025-03-10published 2025-01-22 to 2025-02-19 | Advisory withdrawn | whole advisory2 bands | withdrawn 2025-03-10 | Time to revision 19 to 47 days | |
| 2025-03-10published 2025-02-19 | same kind of change as the line above | GHSA-5mwf-688x-mr7x | same package and registry as the line abovelow | withdrawn 2025-03-10 | Time to revision 19 days |
| 2025-03-10published 2025-02-17 | same kind of change as the line above | GHSA-rq4w-cjrr-h8w8 | same package and registry as the line abovemoderate | withdrawn 2025-03-10 | Time to revision 21 days |
| 2025-03-10published 2025-01-22 | same kind of change as the line above | GHSA-m3hp-8546-5qmr | same package and registry as the line abovemoderate | withdrawn 2025-03-10 | Time to revision 47 days |
| Thu 6 Mar 2025· 23 changes | |||||
| 2025-03-06published 2019-11-20 to 2025-02-03 | Package added to advisory | 2 bands | not named as affected when the advisory was published, now names phpoffice/phpexcel | Time to revision 31 to 189 days | |
| 2025-03-06published 2025-02-03 | same kind of change as the line above | GHSA-r57h-547h-w24fCVE-2025-23210 | same package registry as the line abovemoderate | same change as the line above | Time to revision 31 days |
| 2025-03-06published 2025-01-03 | same kind of change as the line above | GHSA-jmpx-686v-c3wxCVE-2024-56365 | same package registry as the line abovehigh | same change as the line above | Time to revision 62 days |
| 2025-03-06published 2024-11-18 | same kind of change as the line above | GHSA-7cc9-j4mv-vcjpCVE-2024-48917 | same package registry as the line abovehigh | same change as the line above | Time to revision 108 days |
| 2025-03-06published 2025-01-03 | same kind of change as the line above | GHSA-q9jv-mm3r-j47rCVE-2024-56412 | same package registry as the line abovemoderate | same change as the line above | Time to revision 62 days |
| 2025-03-06published 2025-01-03 | same kind of change as the line above | GHSA-hwcp-2h35-p66wCVE-2024-56411 | same package registry as the line abovemoderate | same change as the line above | Time to revision 62 days |
| 2025-03-06published 2025-01-03 | same kind of change as the line above | GHSA-wv23-996v-q229CVE-2024-56410 | same package registry as the line abovemoderate | same change as the line above | Time to revision 62 days |
| 2025-03-06published 2025-01-03 | same kind of change as the line above | GHSA-j2xg-cjcx-4677CVE-2024-56409 | same package registry as the line abovehigh | same change as the line above | Time to revision 62 days |
| 2025-03-06published 2025-01-03 | same kind of change as the line above | GHSA-c6fv-7vh8-2rhrCVE-2024-56366 | same package registry as the line abovehigh | same change as the line above | Time to revision 62 days |
| 13 more rows in this change are not listed here. Open all 21 rows → | |||||
| 2025-03-06published 2023-03-03 | Advisory severity changed | GHSA-hm7p-r324-hhf3CVE-2023-27560 | whole advisoryhigh | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | Time to revision 735 days |
| 2025-03-06published 2023-03-06 | Advisory severity changed | GHSA-2563-fp9c-mgm8CVE-2021-36394 | whole advisorycritical | stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version. | Time to revision 731 days |
| Wed 5 Mar 2025· 2 changes | |||||
| 2025-03-05published 2021-11-08 | Package added to advisory | GHSA-282f-qqgm-c34qCVE-2021-23807 | moderate | not named as affected when the advisory was published, now names org.webjars.npm:json-pointer | Duration unknown |
| 2025-03-05published 2021-05-10 | Package added to advisory | GHSA-7mg4-w3w5-x5pcCVE-2020-7709 | moderate | not named as affected when the advisory was published, now names org.webjars.npm:json-pointer | Duration unknown |
Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.
What this page cannot see
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →
Paste your closed CVE tickets and see which of these changes hit them →