Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Thu 24 Jul 2025· 1 change
2025-07-24published 2025-07-23Advisory withdrawnGHSA-rm8p-cx58-hcvxCVE-2025-54371whole advisoryhighwithdrawn 2025-07-24Time to revision 1 days
Wed 23 Jul 2025· 1 change
2025-07-23published 2025-07-21Advisory severity changedGHSA-2gxp-6r36-m97rCVE-2025-53528whole advisoryhighstated at publication LOW, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Time to revision 2 days
Tue 22 Jul 2025· 3 changes
2025-07-22published 2023-11-06Package added to advisoryGHSA-r67m-mf7v-qp7jCVE-2023-5968moderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v5Time to revision 624 days
2025-07-22published 2025-07-19Package added to advisoryGHSA-f29h-pxvx-f335CVE-2025-54313highnot named as affected when the advisory was published, now names got-fetchTime to revision 3 days
2025-07-22published 2025-07-21Package added to advisoryGHSA-96c2-h667-9fxpCVE-2025-54082criticalnot named as affected when the advisory was published, now names manogi/nova-tiptapTime to revision 1 days
Mon 21 Jul 2025· 1 change
2025-07-21published 2025-07-18Package added to advisoryGHSA-fm79-3f68-h2fcCVE-2025-53901lownot named as affected when the advisory was published, now names wasmtimeTime to revision 3 days
Fri 18 Jul 2025· 10 changes
2025-07-18published 2022-11-17Advisory fix version movedGHSA-83w4-x5w9-hf4hCVE-2022-43183
mavencom.xuxueli:xxl-job-core
high
stated at publication 2.3.1, now states 2.4.0Time to revision 974 days
2025-07-18published 2022-11-25Package added to advisory2 bandsnot named as affected when the advisory was published, now names org.jeecgframework.boot:jeecg-module-systemTime to revision 966 days
2025-07-18published 2022-11-25same kind of change as the line aboveGHSA-g5cj-5h58-j93wCVE-2022-45206same package registry as the line abovecriticalsame change as the line aboveTime to revision 966 days
2025-07-18published 2022-11-25same kind of change as the line aboveGHSA-v87q-rpwp-qr7qCVE-2022-45210same package registry as the line abovemoderatesame change as the line aboveTime to revision 966 days
2025-07-18published 2022-11-25same kind of change as the line aboveGHSA-4j2x-v3mr-467mCVE-2022-45207same package registry as the line abovecriticalsame change as the line aboveTime to revision 966 days
2025-07-18published 2022-11-25same kind of change as the line aboveGHSA-25gv-mvm7-5h3hCVE-2022-45208same package registry as the line abovemoderatesame change as the line aboveTime to revision 966 days
2025-07-18published 2022-02-01Package added to advisoryGHSA-2m53-83f3-562jCVE-2021-23460highnot named as affected when the advisory was published, now names org.webjars.npm:min-dashDuration unknown
2025-07-18published 2022-05-17Package added to advisoryGHSA-cm99-x97g-9qx8CVE-2017-12648moderatenot named as affected when the advisory was published, now names com.liferay:com.liferay.frontend.taglibTime to revision 1,159 days
2025-07-18published 2020-09-04 to 2022-05-14Advisory withdrawnwhole advisory2 bandswithdrawn 2025-07-18Time to revision 1,162 to 1,778 days
2025-07-18published 2022-01-27same kind of change as the line aboveGHSA-fm93-fhh2-cg2csame package and registry as the line abovehighwithdrawn 2025-07-18Time to revision 1,268 days
2025-07-18published 2020-09-04same kind of change as the line aboveGHSA-4r97-78gf-q24vsame package and registry as the line abovehighwithdrawn 2025-07-18Time to revision 1,778 days
2025-07-18published 2022-05-14same kind of change as the line aboveGHSA-x6rc-54xp-ccxxCVE-2015-3208same package and registry as the line abovecriticalwithdrawn 2025-07-18Time to revision 1,162 days
Wed 16 Jul 2025· 1 change
2025-07-16published 2023-04-02Advisory fix version movedGHSA-h4c9-rr5m-32fmCVE-2023-27025
mavencom.ruoyi:ruoyi
high
stated at publication 4.7.6, now states 4.7.7Time to revision 837 days
Fri 11 Jul 2025· 1 change
2025-07-11published 2025-07-10Package added to advisoryGHSA-275g-g844-73jhCVE-2025-53549moderatenot named as affected when the advisory was published, now names matrix-sdk-sqliteTime to revision 1 days
Thu 10 Jul 2025· 1 change
2025-07-10published 2020-09-02Package added to advisoryGHSA-7p6w-x2gr-rrf8highnot named as affected when the advisory was published, now names ag-gridDuration unknown
Wed 9 Jul 2025· 2 changes
2025-07-09published 2025-06-16Package added to advisoryGHSA-vv7r-c36w-3prjCVE-2025-48976highnot named as affected when the advisory was published, now names commons-fileupload:commons-fileuploadTime to revision 23 days
2025-07-09published 2025-03-03Package added to advisoryGHSA-vm7w-2724-5m23CVE-2024-24778moderatenot named as affected when the advisory was published, now names streampipesTime to revision 128 days
Wed 2 Jul 2025· 9 changes
2025-07-02published 2024-12-18Package added to advisoryGHSA-p7c9-8xx8-h74flownot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.10 and 3 moreTime to revision 196 to 196 days
2025-07-02published 2024-12-18same kind of change as the line aboveGHSA-p7c9-8xx8-h74fCVE-2024-56128same package registry as the line abovelownot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.10Time to revision 196 days
2025-07-02published 2024-12-18same kind of change as the line aboveGHSA-p7c9-8xx8-h74fCVE-2024-56128same package registry as the line abovelownot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.11Time to revision 196 days
2025-07-02published 2024-12-18same kind of change as the line aboveGHSA-p7c9-8xx8-h74fCVE-2024-56128same package registry as the line abovelownot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.12Time to revision 196 days
2025-07-02published 2024-12-18same kind of change as the line aboveGHSA-p7c9-8xx8-h74fCVE-2024-56128same package registry as the line abovelownot named as affected when the advisory was published, now names org.apache.kafka:kafka_2.13Time to revision 196 days
2025-07-02published 2025-05-14Package added to advisory2 bandsnot named as affected when the advisory was published, now names apache-iotdbTime to revision 49 days
2025-07-02published 2025-05-14same kind of change as the line aboveGHSA-5fc3-pqf2-57cxCVE-2025-26864same package registry as the line abovemoderatesame change as the line aboveTime to revision 49 days
2025-07-02published 2025-05-14same kind of change as the line aboveGHSA-f4rq-f4j9-f6rmCVE-2024-24780same package registry as the line abovecriticalsame change as the line aboveTime to revision 49 days
2025-07-02published 2022-05-01Advisory severity changedGHSA-pmfx-p95x-cg4pCVE-2006-2571whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 1,158 days
2025-07-02published 2022-05-24 to 2023-08-11Advisory withdrawnwhole advisory2 bandswithdrawn 2025-07-02Time to revision 691 to 1,135 days
2025-07-02published 2022-05-24same kind of change as the line aboveGHSA-jffq-528j-mp6cCVE-2020-10991same package and registry as the line abovecriticalwithdrawn 2025-07-02Time to revision 1,135 days
2025-07-02published 2023-08-11same kind of change as the line aboveGHSA-7rvp-xqj7-rxf2CVE-2020-24950same package and registry as the line abovehighwithdrawn 2025-07-02Time to revision 691 days
Tue 1 Jul 2025· 6 changes
2025-07-01published 2021-10-06Package added to advisoryGHSA-v6w3-2prq-h95fmoderatenot named as affected when the advisory was published, now names org.glassfish:jakarta.el and 1 moreDuration unknown
2025-07-01published 2021-10-06same kind of change as the line aboveGHSA-v6w3-2prq-h95fCVE-2021-28170same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.glassfish:jakarta.elDuration unknown
2025-07-01published 2021-10-06same kind of change as the line aboveGHSA-v6w3-2prq-h95fCVE-2021-28170same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.glassfish:javax.elDuration unknown
2025-07-01published 2021-11-18 to 2022-05-24Advisory withdrawnwhole advisory2 bandswithdrawn 2025-07-01Time to revision 1,134 to 1,321 days
2025-07-01published 2022-05-24same kind of change as the line aboveGHSA-5h6x-m52p-23phCVE-2019-0223same package and registry as the line abovehighwithdrawn 2025-07-01Time to revision 1,134 days
2025-07-01published 2021-11-18same kind of change as the line aboveGHSA-gpqc-4pp7-5954same package and registry as the line abovecriticalwithdrawn 2025-07-01Time to revision 1,321 days
2025-07-01published 2021-11-18same kind of change as the line aboveGHSA-6mqr-q86q-6gwrsame package and registry as the line abovecriticalwithdrawn 2025-07-01Time to revision 1,321 days
2025-07-01published 2021-11-18same kind of change as the line aboveGHSA-8xfw-5q82-3652same package and registry as the line abovecriticalwithdrawn 2025-07-01Time to revision 1,321 days
Mon 30 Jun 2025· 1 change
2025-06-30published 2025-06-17Package added to advisoryGHSA-rvqx-wpfh-mfx7CVE-2025-3248criticalnot named as affected when the advisory was published, now names langflow-baseTime to revision 13 days
Tue 24 Jun 2025· 2 changes
2025-06-24published 2024-05-03Package added to advisoryGHSA-4h8f-2wvx-gg5wmoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-lts8on and 1 moreTime to revision 417 days
2025-06-24published 2024-05-03same kind of change as the line aboveGHSA-4h8f-2wvx-gg5wCVE-2024-34447same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-lts8onTime to revision 417 days
2025-06-24published 2024-05-03same kind of change as the line aboveGHSA-4h8f-2wvx-gg5wCVE-2024-34447same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.bouncycastle:bctls-fipsTime to revision 417 days
Fri 20 Jun 2025· 6 changes
2025-06-20published 2024-09-13Package added to advisoryGHSA-v6x6-4v4x-2fx9CVE-2024-6862moderatenot named as affected when the advisory was published, now names @lunary/backendTime to revision 280 days
2025-06-20published 2024-06-06 to 2025-05-22Advisory withdrawnwhole advisory2 bandswithdrawn 2025-06-20Time to revision 29 to 379 days
2025-06-20published 2024-09-13same kind of change as the line aboveGHSA-v6x6-4v4x-2fx9CVE-2024-6862same package and registry as the line abovemoderatewithdrawn 2025-06-20Time to revision 280 days
2025-06-20published 2024-09-13same kind of change as the line aboveGHSA-6p2q-8qfq-wq7xCVE-2024-6087same package and registry as the line abovehighwithdrawn 2025-06-20Time to revision 280 days
2025-06-20published 2024-09-13same kind of change as the line aboveGHSA-9jmp-j63g-8x6mCVE-2024-6867same package and registry as the line abovemoderatewithdrawn 2025-06-20Time to revision 280 days
2025-06-20published 2024-06-06same kind of change as the line aboveGHSA-rpx8-fg6w-rm6xCVE-2024-5478same package and registry as the line abovehighwithdrawn 2025-06-20Time to revision 379 days
2025-06-20published 2025-05-22same kind of change as the line aboveGHSA-3qmp-g57h-rxf2same package and registry as the line abovehighwithdrawn 2025-06-20Time to revision 29 days
Thu 19 Jun 2025· 1 change
2025-06-19published 2024-03-03Advisory withdrawnGHSA-jw44-4f3j-q396CVE-2019-25210whole advisorymoderatewithdrawn 2025-06-19Time to revision 473 days
Wed 18 Jun 2025· 4 changes
2025-06-18published 2025-06-17Advisory severity changedwhole advisorylowstated at publication HIGH, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 1 days
2025-06-18published 2025-06-17same kind of change as the line aboveGHSA-64x7-m7rh-9m83CVE-2025-45525same package and registry as the line abovelowsame change as the line aboveTime to revision 1 days
2025-06-18published 2025-06-17same kind of change as the line aboveGHSA-wgc6-9f6w-h8hxCVE-2025-45526same package and registry as the line abovelowsame change as the line aboveTime to revision 1 days
2025-06-18published 2025-06-17Advisory withdrawnwhole advisorylowwithdrawn 2025-06-18Time to revision 1 to 1 days
2025-06-18published 2025-06-17same kind of change as the line aboveGHSA-64x7-m7rh-9m83CVE-2025-45525same package and registry as the line abovelowwithdrawn 2025-06-18Time to revision 1 days
2025-06-18published 2025-06-17same kind of change as the line aboveGHSA-wgc6-9f6w-h8hxCVE-2025-45526same package and registry as the line abovelowwithdrawn 2025-06-18Time to revision 1 days
Tue 17 Jun 2025· 1 change
2025-06-17published 2025-04-07Advisory withdrawnGHSA-c995-4fw3-j39mwhole advisorycriticalwithdrawn 2025-06-17Time to revision 71 days
Mon 16 Jun 2025· 2 changes
2025-06-16published 2022-05-14Advisory fix version movedGHSA-g434-3q2j-hj4rCVE-2018-12071
packagistcodeigniter/framework
critical
stated at publication 3.1.9, now states 3.1.10Time to revision 1,130 days
2025-06-16published 2023-01-11Advisory withdrawnGHSA-798h-g4j5-5537whole advisoryhighwithdrawn 2025-06-16Time to revision 887 days
Tue 10 Jun 2025· 1 change
2025-06-10published 2025-06-06Advisory severity changedGHSA-62gc-8jr5-x9pmCVE-2025-27531whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 4 days
Mon 9 Jun 2025· 2 changes
2025-06-09published 2025-03-26Package added to advisoryGHSA-56p6-qw3c-fq2glownot named as affected when the advisory was published, now names @directus/api and 1 moreTime to revision 75 days
2025-06-09published 2025-03-26same kind of change as the line aboveGHSA-56p6-qw3c-fq2gCVE-2025-30351same package registry as the line abovelownot named as affected when the advisory was published, now names @directus/apiTime to revision 75 days
2025-06-09published 2025-03-26same kind of change as the line aboveGHSA-56p6-qw3c-fq2gCVE-2025-30351same package registry as the line abovelownot named as affected when the advisory was published, now names @directus/typesTime to revision 75 days
Fri 6 Jun 2025· 1 change
2025-06-06published 2025-06-05Advisory severity changedGHSA-m65q-v92h-cm7qCVE-2025-5791whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 2 days
Wed 4 Jun 2025· 1 change
2025-06-04published 2024-03-07Advisory severity changedGHSA-75jp-vq8x-h4cqCVE-2024-28123whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 453 days
Mon 2 Jun 2025· 1 change
2025-06-02published 2022-05-17Package added to advisoryGHSA-2pcj-76hj-xqhmCVE-2016-10131criticalnot named as affected when the advisory was published, now names bcit-ci/codeigniterTime to revision 1,113 days
Fri 30 May 2025· 2 changes
2025-05-30published 2024-02-27Package added to advisoryGHSA-xh6m-7cr7-xx66CVE-2023-45859highnot named as affected when the advisory was published, now names com.hazelcast:hazelcast-allTime to revision 458 days
2025-05-30published 2023-10-05Advisory withdrawnGHSA-56pw-mpj4-fxwwwhole advisoryhighwithdrawn 2025-05-30Time to revision 604 days
Thu 29 May 2025· 1 change
2025-05-29published 2018-10-19Package added to advisoryGHSA-jc7r-v6fg-2gpfCVE-2018-8039highnot named as affected when the advisory was published, now names org.apache.cxf:cxf-rt-transports-httpDuration unknown
Wed 28 May 2025· 1 change
2025-05-28published 2025-05-28Advisory severity changedGHSA-6vx9-9r2g-8373CVE-2025-5256whole advisorymoderatestated at publication LOW, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored.Time to revision 0 days
Tue 27 May 2025· 5 changes
2025-05-27published 2024-10-18Package added to advisoryGHSA-4gc7-5j7h-4qphCVE-2024-38820moderatenot named as affected when the advisory was published, now names org.springframework:spring-webTime to revision 222 days
2025-05-27published 2025-04-01Package added to advisoryGHSA-6jwp-4wvj-6597criticalnot named as affected when the advisory was published, now names org.apache.pinot:pinot-broker and 2 moreTime to revision 56 days
2025-05-27published 2025-04-01same kind of change as the line aboveGHSA-6jwp-4wvj-6597CVE-2024-56325same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.pinot:pinot-brokerTime to revision 56 days
2025-05-27published 2025-04-01same kind of change as the line aboveGHSA-6jwp-4wvj-6597CVE-2024-56325same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.pinot:pinot-commonTime to revision 56 days
2025-05-27published 2025-04-01same kind of change as the line aboveGHSA-6jwp-4wvj-6597CVE-2024-56325same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.pinot:pinot-controllerTime to revision 56 days
2025-05-27published 2021-12-20Advisory severity changedGHSA-627p-rr78-99rjCVE-2020-5415whole advisoryhighstated at publication CRITICAL, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.Duration unknown
Fri 23 May 2025· 2 changes
2025-05-23published 2024-03-18 to 2024-09-23Advisory withdrawnwhole advisory2 bandswithdrawn 2025-05-23Time to revision 242 to 431 days
2025-05-23published 2024-03-18same kind of change as the line aboveGHSA-vcc3-rw6f-jv97same package and registry as the line abovemoderatewithdrawn 2025-05-23Time to revision 431 days
2025-05-23published 2024-09-23same kind of change as the line aboveGHSA-3hp8-6j24-m5gmsame package and registry as the line abovehighwithdrawn 2025-05-23Time to revision 242 days
Wed 14 May 2025· 3 changes
2025-05-14published 2025-04-28Package added to advisory2 bandsnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreTime to revision 16 days
2025-05-14published 2025-04-28same kind of change as the line aboveGHSA-ff77-26x5-69crCVE-2025-31651same package registry as the line abovelowsame change as the line aboveTime to revision 16 days
2025-05-14published 2025-04-28same kind of change as the line aboveGHSA-3p2h-wqq4-wf4hCVE-2025-31650same package registry as the line abovemoderatesame change as the line aboveTime to revision 16 days
2025-05-14published 2025-05-13Advisory severity changedGHSA-h4j7-5rxr-p4wcCVE-2025-26646whole advisoryhighstated at publication LOW, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Time to revision 1 days
Mon 12 May 2025· 4 changes
2025-05-12published 2025-04-08Advisory fix version moved4 rows, one per advisory and package
packagist2 packages
2 bands
stated at publication 6.5.8.17, now states 6.5.8.18Time to revision 27 days
2025-05-12published 2025-04-08Advisory fix version movedGHSA-hh7j-6x3q-f52hCVE-2025-30150
packagistshopware/core
moderate
same change as the line aboveTime to revision 27 days
2025-05-12published 2025-04-08Advisory fix version movedGHSA-hh7j-6x3q-f52hCVE-2025-30150
packagistshopware/platform
moderate
same change as the line aboveTime to revision 27 days
2025-05-12published 2025-04-08Advisory fix version movedGHSA-8g35-7rmw-7f59CVE-2025-27892
packagistshopware/core
high
same change as the line aboveTime to revision 27 days
2025-05-12published 2025-04-08Advisory fix version movedGHSA-8g35-7rmw-7f59CVE-2025-27892
packagistshopware/platform
high
same change as the line aboveTime to revision 27 days
Wed 7 May 2025· 5 changes
2025-05-07published 2021-12-10 to 2022-01-04Package added to advisory3 bandsnot named as affected when the advisory was published, now names org.ops4j.pax.logging:pax-logging-log4j2Duration unknown
2025-05-07published 2022-01-04same kind of change as the line aboveGHSA-8489-44mv-ggj8CVE-2021-44832same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-05-07published 2021-12-18same kind of change as the line aboveGHSA-p6xc-xr62-6r2gCVE-2021-45105same package registry as the line abovehighsame change as the line aboveDuration unknown
2025-05-07published 2021-12-14same kind of change as the line aboveGHSA-7rjr-3q55-vv33CVE-2021-45046same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2025-05-07published 2021-12-10same kind of change as the line aboveGHSA-jfh8-c2jp-5v3qCVE-2021-44228same package registry as the line abovecriticalsame change as the line aboveDuration unknown
2025-05-07published 2025-05-06Advisory severity changedGHSA-8gqj-226h-gm8rCVE-2025-46573whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 1 days
Tue 6 May 2025· 1 change
2025-05-06published 2018-10-16Advisory severity changedGHSA-7378-6268-4278CVE-2018-1002205whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Duration unknown
Tue 29 Apr 2025· 9 changes
2025-04-29published 2025-04-01Advisory severity changedwhole advisoryhighstated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 29 days
2025-04-29published 2025-04-01same kind of change as the line aboveGHSA-4f8q-mwgc-3mwcCVE-2025-31691same package and registry as the line abovehighsame change as the line aboveTime to revision 29 days
2025-04-29published 2025-04-01same kind of change as the line aboveGHSA-hf6c-fgp3-jfchCVE-2025-31694same package and registry as the line abovehighsame change as the line aboveTime to revision 29 days
2025-04-29published 2025-04-01same kind of change as the line aboveGHSA-m9w8-wxvp-c9gvCVE-2025-31686same package and registry as the line abovehighsame change as the line aboveTime to revision 29 days
2025-04-29published 2025-04-01Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 29 days
2025-04-29published 2025-04-01same kind of change as the line aboveGHSA-ccc9-jgj7-hxc7CVE-2025-31690same package and registry as the line abovemoderatesame change as the line aboveTime to revision 29 days
2025-04-29published 2025-04-01same kind of change as the line aboveGHSA-jv6r-mj9p-9xffCVE-2025-31689same package and registry as the line abovemoderatesame change as the line aboveTime to revision 29 days
2025-04-29published 2025-04-01same kind of change as the line aboveGHSA-gf72-h4cp-wcm4CVE-2025-31685same package and registry as the line abovemoderatesame change as the line aboveTime to revision 29 days
2025-04-29published 2025-04-01same kind of change as the line aboveGHSA-9w85-x5hg-fr66CVE-2025-31677same package and registry as the line abovemoderatesame change as the line aboveTime to revision 29 days
2025-04-29published 2025-04-01same kind of change as the line aboveGHSA-c8q6-wp7v-46r9CVE-2025-31678same package and registry as the line abovemoderatesame change as the line aboveTime to revision 29 days
2025-04-29published 2025-04-01Advisory severity changedGHSA-jwpx-6c4p-q4jqCVE-2025-31681whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 29 days
Tue 22 Apr 2025· 2 changes
2025-04-22published 2025-04-22Advisory severity changedGHSA-x27v-f838-jh93CVE-2025-32951whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 0 days
2025-04-22published 2024-10-02Advisory withdrawnGHSA-mrw8-5368-phm3CVE-2024-45965whole advisorylowwithdrawn 2025-04-22Time to revision 202 days
Fri 18 Apr 2025· 1 change
2025-04-18published 2025-04-18Advisory fix version movedGHSA-mg2h-6x62-wpwcCVE-2025-32442
npmfastify
high
stated at publication 5.3.1, now states 5.3.2Time to revision 0 days
Thu 17 Apr 2025· 1 change
2025-04-17published 2024-04-25Advisory withdrawnGHSA-x5m7-63c6-fx79CVE-2024-1139whole advisoryhighwithdrawn 2025-04-17Time to revision 357 days
Wed 16 Apr 2025· 1 change
2025-04-16published 2021-03-03Advisory severity changedGHSA-p493-635q-r6grCVE-2021-21353whole advisorymoderatestated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same.Duration unknown
Tue 15 Apr 2025· 1 change
2025-04-15published 2025-03-20Advisory withdrawnGHSA-gjxm-x497-4h6hCVE-2025-0655whole advisorycriticalwithdrawn 2025-04-15Time to revision 26 days
Mon 14 Apr 2025· 5 changes
2025-04-14published 2022-05-14Package added to advisorymoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaDuration unknown
2025-04-14published 2022-05-14same kind of change as the line aboveGHSA-prc3-7f44-w48jCVE-2014-0119same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-04-14published 2022-05-14same kind of change as the line aboveGHSA-qprx-q2r7-3rx6CVE-2014-0096same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2025-04-14published 2022-05-14Package added to advisoryGHSA-prc3-7f44-w48jCVE-2014-0119moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-jasperDuration unknown
2025-04-14published 2022-05-14Package added to advisoryGHSA-xh5x-j8jf-pcpxCVE-2014-0099moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-utilDuration unknown
2025-04-14published 2022-05-14Package added to advisoryGHSA-475f-74wp-pqv5CVE-2014-0075moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDuration unknown
Sun 13 Apr 2025· 1 change
2025-04-13published 2025-04-02Advisory severity changedGHSA-49v8-p6mm-3pfjCVE-2025-29085whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 10 days
Thu 10 Apr 2025· 2 changes
2025-04-10published 2025-03-24Advisory fix version movedGHSA-5pq3-h73f-66hr
npmaws-cdk-lib
low
stated at publication 2.184.0, now states 2.189.0Time to revision 16 days
2025-04-10published 2023-09-22Advisory withdrawnGHSA-cc8j-6phr-jv9xCVE-2023-42261whole advisoryhighwithdrawn 2025-04-10Time to revision 567 days
Wed 9 Apr 2025· 1 change
2025-04-09published 2025-04-09Advisory severity changedGHSA-q62r-8ppj-xvf4CVE-2025-32017whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 0 days
Fri 4 Apr 2025· 2 changes
2025-04-04published 2025-01-31Advisory severity changedGHSA-88m4-h43f-wx84CVE-2025-23215whole advisorycriticalstated at publication LOW, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 63 days
2025-04-04published 2024-11-12Advisory severity changedGHSA-6x36-qxmj-rv4pCVE-2024-43499whole advisoryhighstated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 143 days
Thu 3 Apr 2025· 1 change
2025-04-03published 2025-03-20Package added to advisoryGHSA-x48g-hm9c-ww42CVE-2024-12909criticalnot named as affected when the advisory was published, now names llama-index-packs-finchatTime to revision 14 days
Wed 2 Apr 2025· 1 change
2025-04-02published 2025-03-20Advisory withdrawnGHSA-4vmg-rw8f-92f9CVE-2024-7804whole advisorycriticalwithdrawn 2025-04-02Time to revision 13 days
Tue 1 Apr 2025· 1 change
2025-04-01published 2025-03-28Advisory withdrawnGHSA-799q-f2px-wx8cwhole advisoryhighwithdrawn 2025-04-01Time to revision 4 days
Fri 28 Mar 2025· 1 change
2025-03-28published 2025-03-20Advisory withdrawnGHSA-xqgj-r6xv-9cw4CVE-2024-10096whole advisorycriticalwithdrawn 2025-03-28Time to revision 8 days
Wed 26 Mar 2025· 1 change
2025-03-26published 2022-03-07Advisory severity changedGHSA-ph3v-2hq5-5qfqCVE-2021-46703whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Duration unknown
Tue 25 Mar 2025· 1 change
2025-03-25published 2024-12-09Advisory withdrawnGHSA-4v5x-9m47-cqr2whole advisorymoderatewithdrawn 2025-03-25Time to revision 106 days
Sat 22 Mar 2025· 1 change
2025-03-22published 2024-08-15Advisory withdrawnGHSA-qf6h-p3mr-vmh5whole advisorymoderatewithdrawn 2025-03-22Time to revision 219 days
Fri 21 Mar 2025· 2 changes
2025-03-21published 2025-03-19Advisory severity changedGHSA-2x3g-rr4w-4qrpCVE-2025-30197whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 2 days
2025-03-21published 2024-05-03Advisory severity changedGHSA-4h8f-2wvx-gg5wCVE-2024-34447whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Time to revision 322 days
Thu 20 Mar 2025· 5 changes
2025-03-20published 2025-03-20Package added to advisoryGHSA-h7xg-cmpp-48hfCVE-2024-10553criticalnot named as affected when the advisory was published, now names ai.h2o:h2o-coreTime to revision 0 days
2025-03-20published 2025-03-20Package added to advisoryGHSA-2r4x-667f-mpfhCVE-2024-47552lownot named as affected when the advisory was published, now names org.apache.seata:seata-config-coreTime to revision 0 days
2025-03-20published 2025-03-12Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 8 days
2025-03-20published 2025-03-12same kind of change as the line aboveGHSA-754f-8gm6-c4r2CVE-2025-25292same package and registry as the line abovecriticalsame change as the line aboveTime to revision 8 days
2025-03-20published 2025-03-12same kind of change as the line aboveGHSA-4vc4-m8qh-g8jmCVE-2025-25291same package and registry as the line abovecriticalsame change as the line aboveTime to revision 8 days
2025-03-20published 2024-08-15Advisory withdrawnGHSA-q83v-hq3j-4pq3whole advisorymoderatewithdrawn 2025-03-20Time to revision 218 days
Wed 19 Mar 2025· 1 change
2025-03-19published 2025-03-10Advisory severity changedGHSA-83qj-6fr2-vhqgCVE-2025-24813whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 9 days
Mon 17 Mar 2025· 3 changes
2025-03-17published 2022-02-10Package added to advisoryGHSA-3c7p-vv5r-cmr5criticalnot named as affected when the advisory was published, now names org.apache.solr:solr-core and 1 moreDuration unknown
2025-03-17published 2022-02-10same kind of change as the line aboveGHSA-3c7p-vv5r-cmr5CVE-2020-13957same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.solr:solr-coreDuration unknown
2025-03-17published 2022-02-10same kind of change as the line aboveGHSA-3c7p-vv5r-cmr5CVE-2020-13957same package registry as the line abovecriticalnot named as affected when the advisory was published, now names org.apache.solr:solr-solrjDuration unknown
2025-03-17published 2025-03-10Package added to advisoryGHSA-83qj-6fr2-vhqgCVE-2025-24813criticalnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreTime to revision 7 days
Fri 14 Mar 2025· 2 changes
2025-03-14published 2025-03-11Package added to advisoryGHSA-44f7-5fj5-h4pxCVE-2025-27403highnot named as affected when the advisory was published, now names github.com/deislabs/ratifyTime to revision 3 days
2025-03-14published 2023-09-15Package added to advisoryGHSA-hvpq-7vcc-5hj5CVE-2023-41592moderatenot named as affected when the advisory was published, now names froala-editorTime to revision 547 days
Wed 12 Mar 2025· 3 changes
2025-03-12published 2025-03-12Advisory fix version movedGHSA-q92j-grw3-h492CVE-2025-27407
rubygemsgraphql
critical
stated at publication 1.11.8, now states 1.11.11Time to revision 0 days
2025-03-12published 2025-03-12Advisory fix version movedGHSA-q92j-grw3-h492CVE-2025-27407
rubygemsgraphql
critical
stated at publication 2.1.14, now states 2.1.15Time to revision 0 days
2025-03-12published 2025-03-12Advisory severity changedGHSA-92rq-c8cf-prrqCVE-2025-25293whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 0 days
Tue 11 Mar 2025· 6 changes
2025-03-11published 2025-02-12Package added to advisoryGHSA-6fgm-x6ff-w78fmoderatenot named as affected when the advisory was published, now names github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v4 and 2 moreTime to revision 27 days
2025-03-11published 2025-02-12same kind of change as the line aboveGHSA-6fgm-x6ff-w78fsame package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v4Time to revision 27 days
2025-03-11published 2025-02-12same kind of change as the line aboveGHSA-6fgm-x6ff-w78fsame package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v5Time to revision 27 days
2025-03-11published 2025-02-12same kind of change as the line aboveGHSA-6fgm-x6ff-w78fsame package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v6Time to revision 27 days
2025-03-11published 2025-01-23Advisory severity changedGHSA-9cxr-76pm-j3wfCVE-2024-53299whole advisorymoderatestated at publication CRITICAL, now states MODERATENo CVSS vector was stated in the first observed version.Time to revision 47 days
2025-03-11published 2023-06-21 to 2025-03-11Advisory withdrawnwhole advisoryhighwithdrawn 2025-03-11Time to revision 0 to 629 days
2025-03-11published 2023-06-21same kind of change as the line aboveGHSA-fqhp-rhm6-8rrjCVE-2023-33289same package and registry as the line abovehighwithdrawn 2025-03-11Time to revision 629 days
2025-03-11published 2025-03-11same kind of change as the line aboveGHSA-5478-v2w6-c6q7same package and registry as the line abovehighwithdrawn 2025-03-11Time to revision 0 days
Mon 10 Mar 2025· 3 changes
2025-03-10published 2025-01-22 to 2025-02-19Advisory withdrawnwhole advisory2 bandswithdrawn 2025-03-10Time to revision 19 to 47 days
2025-03-10published 2025-02-19same kind of change as the line aboveGHSA-5mwf-688x-mr7xsame package and registry as the line abovelowwithdrawn 2025-03-10Time to revision 19 days
2025-03-10published 2025-02-17same kind of change as the line aboveGHSA-rq4w-cjrr-h8w8same package and registry as the line abovemoderatewithdrawn 2025-03-10Time to revision 21 days
2025-03-10published 2025-01-22same kind of change as the line aboveGHSA-m3hp-8546-5qmrsame package and registry as the line abovemoderatewithdrawn 2025-03-10Time to revision 47 days
Thu 6 Mar 2025· 23 changes
2025-03-06published 2019-11-20 to 2025-02-03Package added to advisory2 bandsnot named as affected when the advisory was published, now names phpoffice/phpexcelTime to revision 31 to 189 days
2025-03-06published 2025-02-03same kind of change as the line aboveGHSA-r57h-547h-w24fCVE-2025-23210same package registry as the line abovemoderatesame change as the line aboveTime to revision 31 days
2025-03-06published 2025-01-03same kind of change as the line aboveGHSA-jmpx-686v-c3wxCVE-2024-56365same package registry as the line abovehighsame change as the line aboveTime to revision 62 days
2025-03-06published 2024-11-18same kind of change as the line aboveGHSA-7cc9-j4mv-vcjpCVE-2024-48917same package registry as the line abovehighsame change as the line aboveTime to revision 108 days
2025-03-06published 2025-01-03same kind of change as the line aboveGHSA-q9jv-mm3r-j47rCVE-2024-56412same package registry as the line abovemoderatesame change as the line aboveTime to revision 62 days
2025-03-06published 2025-01-03same kind of change as the line aboveGHSA-hwcp-2h35-p66wCVE-2024-56411same package registry as the line abovemoderatesame change as the line aboveTime to revision 62 days
2025-03-06published 2025-01-03same kind of change as the line aboveGHSA-wv23-996v-q229CVE-2024-56410same package registry as the line abovemoderatesame change as the line aboveTime to revision 62 days
2025-03-06published 2025-01-03same kind of change as the line aboveGHSA-j2xg-cjcx-4677CVE-2024-56409same package registry as the line abovehighsame change as the line aboveTime to revision 62 days
2025-03-06published 2025-01-03same kind of change as the line aboveGHSA-c6fv-7vh8-2rhrCVE-2024-56366same package registry as the line abovehighsame change as the line aboveTime to revision 62 days
13 more rows in this change are not listed here. Open all 21 rows
2025-03-06published 2023-03-03Advisory severity changedGHSA-hm7p-r324-hhf3CVE-2023-27560whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 735 days
2025-03-06published 2023-03-06Advisory severity changedGHSA-2563-fp9c-mgm8CVE-2021-36394whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Time to revision 731 days
Wed 5 Mar 2025· 2 changes
2025-03-05published 2021-11-08Package added to advisoryGHSA-282f-qqgm-c34qCVE-2021-23807moderatenot named as affected when the advisory was published, now names org.webjars.npm:json-pointerDuration unknown
2025-03-05published 2021-05-10Package added to advisoryGHSA-7mg4-w3w5-x5pcCVE-2020-7709moderatenot named as affected when the advisory was published, now names org.webjars.npm:json-pointerDuration unknown

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

What this page cannot see

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Paste your closed CVE tickets and see which of these changes hit them →