Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Tue 4 Mar 2025· 4 advisory changes
2025-03-04published 2025-03-03Advisory fix version movedGHSA-h8h6-7752-g28cCVE-2025-27408
npmmanifest
moderate
stated at publication 4.9.1, now states 4.9.2Days to revision 1
2025-03-04published 2025-03-03Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 1
2025-03-04published 2025-03-03same kind of change as the line aboveGHSA-gh9q-2xrm-x6qvCVE-2025-27219same package and registry as the line abovemoderatesame change as the line aboveDays to revision 1
2025-03-04published 2025-03-03same kind of change as the line aboveGHSA-mhwm-jh88-3gjfCVE-2025-27220same package and registry as the line abovemoderatesame change as the line aboveDays to revision 1
2025-03-04published 2025-03-03Advisory severity changedGHSA-22h5-pq3x-2gf2CVE-2025-27221whole advisorylowstated at publication HIGH, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 1
Mon 3 Mar 2025· 2 advisory changes
2025-03-03published 2025-02-10Advisory withdrawnwhole advisory2 bandswithdrawn 2025-03-03Days to revision 21
2025-03-03published 2025-02-10same kind of change as the line aboveGHSA-qv5f-57gw-vx3hsame package and registry as the line abovehighwithdrawn 2025-03-03Days to revision 21
2025-03-03published 2025-02-10same kind of change as the line aboveGHSA-7wwr-h8cm-9jf7same package and registry as the line abovemoderatewithdrawn 2025-03-03Days to revision 21
Wed 26 Feb 2025· 1 advisory change
2025-02-26published 2025-02-24Package added to advisoryGHSA-c6gw-w398-hv78CVE-2025-27144moderatenot named as affected when the advisory was published, now names github.com/go-jose/go-jose/v3Days to revision 2
Fri 21 Feb 2025· 1 advisory change
2025-02-21published 2024-09-19Advisory withdrawnGHSA-5hc5-fxr9-5frcwhole advisoryhighwithdrawn 2025-02-21Days to revision 156
Thu 20 Feb 2025· 1 advisory change
2025-02-20published 2023-10-10Advisory severity changedGHSA-rr4x-crhf-8886CVE-2025-27097whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 499
Wed 19 Feb 2025· 2 advisory changes
2025-02-19published 2025-01-21Package added to advisoryGHSA-69cg-w8vm-h229CVE-2024-10761moderatenot named as affected when the advisory was published, now names umbraco.cms.web.commonDays to revision 29
2025-02-19published 2024-11-04Advisory withdrawnGHSA-4gmq-m9vp-jrwgwhole advisorylowwithdrawn 2025-02-19Days to revision 108
Tue 18 Feb 2025· 1 advisory change
2025-02-18published 2024-08-21Package added to advisoryGHSA-7r32-vfj5-c2jvCVE-2024-43407moderatenot named as affected when the advisory was published, now names ckeditor/ckeditorDays to revision 181
Fri 14 Feb 2025· 1 advisory change
2025-02-14published 2025-02-12Advisory withdrawnGHSA-xg2h-7cxj-3gvhCVE-2024-57000whole advisorycriticalwithdrawn 2025-02-14Days to revision 3
Thu 13 Feb 2025· 8 advisory changes
2025-02-13published 2023-10-10Package added to advisoryGHSA-jm7m-8jh6-29hpCVE-2023-42794moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 492
2025-02-13published 2025-01-28Package added to advisoryGHSA-58fx-7v9q-3g56CVE-2024-13484highnot named as affected when the advisory was published, now names github.com/redhat-developer/gitops-operatorDays to revision 16
2025-02-13published 2023-12-15 to 2023-12-21Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 420 to 426
2025-02-13published 2023-12-21same kind of change as the line aboveGHSA-f23h-52hj-99p6CVE-2023-51656same package and registry as the line abovecriticalsame change as the line aboveDays to revision 420
2025-02-13published 2023-12-15same kind of change as the line aboveGHSA-6x49-w35h-wqrjCVE-2023-29234same package and registry as the line abovecriticalsame change as the line aboveDays to revision 426
2025-02-13published 2023-11-23Advisory severity changedGHSA-85p4-q357-72h9CVE-2023-43123whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 448
2025-02-13published 2024-02-09Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 370
2025-02-13published 2024-02-09same kind of change as the line aboveGHSA-3hwc-rqwp-v36qCVE-2023-50291same package and registry as the line abovehighsame change as the line aboveDays to revision 370
2025-02-13published 2024-02-09same kind of change as the line aboveGHSA-37vr-vmg4-jwpwCVE-2023-50386same package and registry as the line abovehighsame change as the line aboveDays to revision 370
2025-02-13published 2025-01-22Advisory withdrawnGHSA-572q-86rr-5vgqCVE-2024-55488whole advisorymoderatewithdrawn 2025-02-13Days to revision 22
Tue 11 Feb 2025· 7 advisory changes
2025-02-11published 2025-01-23Package added to advisoryGHSA-pmf4-v838-29hgCVE-2025-24353moderatenot named as affected when the advisory was published, now names @directus/appDays to revision 19
2025-02-11published 2025-02-11Advisory severity changedGHSA-vv2h-2w3q-3fx7CVE-2024-12366whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 0
2025-02-11published 2025-02-04Advisory severity changedGHSA-wmcc-9vch-jmx4CVE-2025-23015whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 7
2025-02-11published 2025-01-21 to 2025-02-06Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 5 to 21
2025-02-11published 2025-01-21same kind of change as the line aboveGHSA-fh5r-crhr-qrrqCVE-2025-23184same package and registry as the line abovehighsame change as the line aboveDays to revision 21
2025-02-11published 2025-02-06same kind of change as the line aboveGHSA-57m2-h3fw-rxhwCVE-2024-45626same package and registry as the line abovehighsame change as the line aboveDays to revision 5
2025-02-11published 2024-12-23Advisory severity changedGHSA-vq94-9pfv-ccqrCVE-2024-45387whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 50
2025-02-11published 2024-05-08Advisory severity changedGHSA-fgh3-pwmp-3qw3CVE-2024-26579whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 279
Mon 10 Feb 2025· 38 advisory changes
2025-02-10published 2019-11-20 to 2022-05-24Package added to advisory4 bandsnot named as affected when the advisory was published, now names magento/project-community-editionDays to revision 993
2025-02-10published 2022-05-24same kind of change as the line aboveGHSA-cc3w-r3w8-hfh7CVE-2021-28567same package registry as the line abovemoderatesame change as the line aboveDays to revision 993
2025-02-10published 2022-05-24same kind of change as the line aboveGHSA-39ch-rg26-gmq5CVE-2021-28556same package registry as the line abovemoderatesame change as the line aboveDays to revision 993
2025-02-10published 2022-05-24same kind of change as the line aboveGHSA-7gh6-f4jh-3crqCVE-2021-28583same package registry as the line abovehighsame change as the line aboveDays to revision 993
2025-02-10published 2022-05-24same kind of change as the line aboveGHSA-7gpv-xrjr-f5h4CVE-2021-28584same package registry as the line abovemoderatesame change as the line aboveDays to revision 993
2025-02-10published 2022-05-24same kind of change as the line aboveGHSA-c38m-9668-6j2wCVE-2021-28585same package registry as the line abovemoderatesame change as the line aboveDays to revision 993
2025-02-10published 2022-05-24same kind of change as the line aboveGHSA-4h3p-63x6-vwg2CVE-2021-21031same package registry as the line abovemoderatesame change as the line aboveDays to revision 993
2025-02-10published 2022-05-24same kind of change as the line aboveGHSA-4jfq-f8hc-775qCVE-2021-21032same package registry as the line abovemoderatesame change as the line aboveDays to revision 993
2025-02-10published 2022-05-24same kind of change as the line aboveGHSA-6988-g89m-27vfCVE-2021-21030same package registry as the line abovehighsame change as the line aboveDays to revision 993
30 more rows in this change are not listed here. Open all 38 rows
Fri 7 Feb 2025· 1 advisory change
2025-02-07published 2025-02-06Advisory withdrawnGHSA-2hjh-495w-hmxcCVE-2024-57610whole advisorymoderatewithdrawn 2025-02-07Days to revision 1
Thu 6 Feb 2025· 2 advisory changes
2025-02-06published 2024-10-11Advisory fix version movedGHSA-pppg-cpfq-h7wrCVE-2024-21534
npmjsonpath-plus
critical
stated at publication 10.0.0, now states 10.2.0Days to revision 32
2025-02-06published 2025-01-29Advisory withdrawnGHSA-29qp-crvh-w22mwhole advisorymoderatewithdrawn 2025-02-06Days to revision 8
Wed 5 Feb 2025· 2 advisory changes
2025-02-05published 2025-01-29Advisory fix version movedGHSA-hcr5-wv4p-h2g2CVE-2025-24884
gogithub.com/richardoc/kube-audit-rest
moderate
stated at publication 0.0.0-20250129191722-db1aa5b86725, now states 0.0.0-20250205113217-9df8886b4819Days to revision 7
2025-02-05published 2024-12-18Advisory withdrawnGHSA-6mpx-pmgp-ww49whole advisorymoderatewithdrawn 2025-02-05Days to revision 50
Tue 4 Feb 2025· 4 advisory changes
2025-02-04published 2025-02-03Advisory severity changedGHSA-qwp8-x4ff-5h87CVE-2025-24959whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 1
2025-02-04published 2024-12-13 to 2024-12-20Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 47 to 54
2025-02-04published 2024-12-20same kind of change as the line aboveGHSA-c9f5-29f6-c35wCVE-2024-21549same package and registry as the line abovemoderatesame change as the line aboveDays to revision 47
2025-02-04published 2024-12-13same kind of change as the line aboveGHSA-g2r4-phv7-5fgvCVE-2024-21544same package and registry as the line abovemoderatesame change as the line aboveDays to revision 54
2025-02-04published 2023-04-26Advisory withdrawnGHSA-939c-3g97-vpvvCVE-2023-26735whole advisoryhighwithdrawn 2025-02-04Days to revision 651
Fri 31 Jan 2025· 6 advisory changes
2025-01-31published 2020-04-29Package added to advisorymoderatenot named as affected when the advisory was published, now names components/jquerynot dated
2025-01-31published 2020-04-29same kind of change as the line aboveGHSA-jpcq-cgw6-v4j6CVE-2020-11023same package registry as the line abovemoderatesame change as the line abovenot dated
2025-01-31published 2020-04-29same kind of change as the line aboveGHSA-gxr4-xjj5-5px2CVE-2020-11022same package registry as the line abovemoderatesame change as the line abovenot dated
2025-01-31published 2018-10-17Package added to advisorycriticalnot named as affected when the advisory was published, now names org.springframework:spring-messagingnot dated
2025-01-31published 2018-10-17same kind of change as the line aboveGHSA-3rmv-2pg5-xvqjCVE-2018-1275same package registry as the line abovecriticalsame change as the line abovenot dated
2025-01-31published 2018-10-17same kind of change as the line aboveGHSA-p5hg-3xm3-gcjgCVE-2018-1270same package registry as the line abovecriticalsame change as the line abovenot dated
2025-01-31published 2024-07-11Package added to advisoryGHSA-9mvj-f7w8-pvh2CVE-2024-6484moderatenot named as affected when the advisory was published, now names bootstrap-sassDays to revision 204
2025-01-31published 2025-01-30Advisory withdrawnGHSA-fcrw-mphx-7cxfwhole advisorymoderatewithdrawn 2025-01-31Days to revision 1
Thu 30 Jan 2025· 1 advisory change
2025-01-30published 2020-04-29Package added to advisoryGHSA-gxr4-xjj5-5px2CVE-2020-11022moderatenot named as affected when the advisory was published, now names athlon1600/youtube-downloadernot dated
Wed 29 Jan 2025· 1 advisory change
2025-01-29published 2021-11-19Advisory severity changedGHSA-3pqh-p72c-fj85CVE-2021-3978whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.not dated
Fri 24 Jan 2025· 2 advisory changes
2025-01-24published 2024-12-05Advisory severity changedGHSA-rhx6-c78j-4q9wCVE-2024-52798whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 50
2025-01-24published 2024-02-19Advisory severity changedGHSA-4g9r-vxhx-9pgxCVE-2024-25710whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 340
Thu 23 Jan 2025· 3 advisory changes
2025-01-23published 2024-12-18Advisory severity changedGHSA-j2v2-3784-vr44whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 36
2025-01-23published 2024-02-19Advisory severity changedGHSA-7pjp-fm93-p6pjCVE-2024-25982whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 339
2025-01-23published 2024-02-19Advisory severity changedGHSA-9r26-5w88-qhp9CVE-2024-25983whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 339
Wed 22 Jan 2025· 4 advisory changes
2025-01-22published 2022-11-21Advisory severity changedGHSA-p5v9-g8w8-5q4vCVE-2022-41930whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 793
2025-01-22published 2024-02-24Advisory severity changedwhole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 334
2025-01-22published 2024-02-24same kind of change as the line aboveGHSA-3v79-q7ph-j75hCVE-2024-27133same package and registry as the line abovecriticalsame change as the line aboveDays to revision 334
2025-01-22published 2024-02-24same kind of change as the line aboveGHSA-6749-m5cp-6cg7CVE-2024-27132same package and registry as the line abovecriticalsame change as the line aboveDays to revision 334
2025-01-22published 2022-10-07Advisory severity changedGHSA-93m7-c69f-5cfjCVE-2020-25614whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
Tue 21 Jan 2025· 13 advisory changes
2025-01-21published 2024-07-17Package added to advisory2 bandsnot named as affected when the advisory was published, now names streampipesDays to revision 188
2025-01-21published 2024-07-17same kind of change as the line aboveGHSA-6523-jf4r-c962CVE-2024-31411same package registry as the line abovehighsame change as the line aboveDays to revision 188
2025-01-21published 2024-07-17same kind of change as the line aboveGHSA-2qph-v9p2-q2gvCVE-2024-30471same package registry as the line abovemoderatesame change as the line aboveDays to revision 188
2025-01-21published 2024-07-17same kind of change as the line aboveGHSA-9gr7-gh74-qg9xCVE-2024-31979same package registry as the line abovemoderatesame change as the line aboveDays to revision 188
2025-01-21published 2024-08-01 to 2024-09-25Advisory severity changedwhole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 119 to 173
2025-01-21published 2024-09-25same kind of change as the line aboveGHSA-q7qr-22qw-pqgxCVE-2024-8291same package and registry as the line abovemoderatesame change as the line aboveDays to revision 119
2025-01-21published 2024-08-12same kind of change as the line aboveGHSA-q5wx-m95r-4cgcCVE-2024-4350same package and registry as the line abovemoderatesame change as the line aboveDays to revision 162
2025-01-21published 2024-08-01same kind of change as the line aboveGHSA-3cpf-jmmc-8jm3CVE-2024-4353same package and registry as the line abovemoderatesame change as the line aboveDays to revision 173
2025-01-21published 2024-09-25same kind of change as the line aboveGHSA-x8h2-255q-jg4xCVE-2024-7398same package and registry as the line abovemoderatesame change as the line aboveDays to revision 119
2025-01-21published 2024-08-08same kind of change as the line aboveGHSA-w6j6-w6jx-vf2rCVE-2024-7394same package and registry as the line abovemoderatesame change as the line aboveDays to revision 166
2025-01-21published 2024-03-06Advisory severity changedwhole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 321
2025-01-21published 2024-03-06same kind of change as the line aboveGHSA-9pp4-mx6x-xh36CVE-2024-28153same package and registry as the line abovemoderatesame change as the line aboveDays to revision 321
2025-01-21published 2024-03-06same kind of change as the line aboveGHSA-5j5r-6mv9-m255CVE-2024-28156same package and registry as the line abovemoderatesame change as the line aboveDays to revision 321
2025-01-21published 2024-03-12Advisory severity changedGHSA-jg2g-4rjg-cmqhCVE-2024-27317whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 315
2025-01-21published 2024-03-07Advisory severity changedwhole advisoryhighstated at publication CRITICAL, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 321
2025-01-21published 2024-03-07same kind of change as the line aboveGHSA-qqv2-35q8-p2g2CVE-2024-0815same package and registry as the line abovehighsame change as the line aboveDays to revision 321
2025-01-21published 2024-03-07same kind of change as the line aboveGHSA-fh54-3vhg-mpc2CVE-2024-0817same package and registry as the line abovehighsame change as the line aboveDays to revision 321
Mon 20 Jan 2025· 2 advisory changes
2025-01-20published 2021-11-10Package added to advisoryGHSA-r28h-x6hv-2fq3CVE-2021-43570criticalnot named as affected when the advisory was published, now names com.starkbank.ellipticcurve:starkbank-ecdsanot dated
2025-01-20published 2024-02-05Advisory severity changedGHSA-9xfw-jjq2-7v8hCVE-2024-24768whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 350
Fri 17 Jan 2025· 6 advisory changes
2025-01-17published 2024-05-20Package added to advisoryGHSA-qxqf-2mfx-x8jwhighnot named as affected when the advisory was published, now names org.verapdf:verapdf-library and 2 moreDays to revision 242
2025-01-17published 2024-05-20same kind of change as the line aboveGHSA-qxqf-2mfx-x8jwCVE-2024-28109same package registry as the line abovehighnot named as affected when the advisory was published, now names org.verapdf:verapdf-libraryDays to revision 242
2025-01-17published 2024-05-20same kind of change as the line aboveGHSA-qxqf-2mfx-x8jwCVE-2024-28109same package registry as the line abovehighnot named as affected when the advisory was published, now names org.verapdf:verapdf-library-arlingtonDays to revision 242
2025-01-17published 2024-05-20same kind of change as the line aboveGHSA-qxqf-2mfx-x8jwCVE-2024-28109same package registry as the line abovehighnot named as affected when the advisory was published, now names org.verapdf:verapdf-library-jakartaDays to revision 242
2025-01-17published 2022-02-10Package added to advisoryGHSA-6566-9526-52v6CVE-2020-10591highnot named as affected when the advisory was published, now names com.walmartlabs.concord:concord-commonnot dated
2025-01-17published 2022-05-24Package added to advisoryGHSA-jffq-528j-mp6cCVE-2020-10991criticalnot named as affected when the advisory was published, now names org.mule.modules:mule-apikit-modulenot dated
2025-01-17published 2024-01-05Advisory severity changedGHSA-733r-8xcp-w9mrCVE-2024-21641whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 378
Thu 16 Jan 2025· 5 advisory changes
2025-01-16published 2023-01-24Package added to advisorymoderatenot named as affected when the advisory was published, now names org.opensearch.plugin:opensearch-securityDays to revision 723
2025-01-16published 2023-01-24same kind of change as the line aboveGHSA-v3cg-7r9h-r2g6CVE-2023-23613same package registry as the line abovemoderatesame change as the line aboveDays to revision 723
2025-01-16published 2023-01-24same kind of change as the line aboveGHSA-864v-6qj7-62qjCVE-2023-23612same package registry as the line abovemoderatesame change as the line aboveDays to revision 723
2025-01-16published 2024-12-02 to 2025-01-14Advisory withdrawnwhole advisory2 bandswithdrawn 2025-01-16Days to revision 2 to 45
2025-01-16published 2024-12-12same kind of change as the line aboveGHSA-22c5-cpvr-cfvqCVE-2024-4109same package and registry as the line abovehighwithdrawn 2025-01-16Days to revision 36
2025-01-16published 2025-01-14same kind of change as the line aboveGHSA-5wjw-h8x5-v65msame package and registry as the line abovemoderatewithdrawn 2025-01-16Days to revision 2
2025-01-16published 2024-12-02same kind of change as the line aboveGHSA-q4h9-7rxj-7gx2same package and registry as the line abovemoderatewithdrawn 2025-01-16Days to revision 45
Wed 15 Jan 2025· 7 advisory changes
2025-01-15published 2023-02-18Package added to advisoryGHSA-jrmh-v64j-mjm9moderatenot named as affected when the advisory was published, now names org.jboss.resteasy:resteasy-core and 1 moreDays to revision 698
2025-01-15published 2023-02-18same kind of change as the line aboveGHSA-jrmh-v64j-mjm9same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.jboss.resteasy:resteasy-coreDays to revision 698
2025-01-15published 2023-02-18same kind of change as the line aboveGHSA-jrmh-v64j-mjm9same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.jboss.resteasy:resteasy-multipart-providerDays to revision 698
2025-01-15published 2024-07-09Package added to advisoryGHSA-vfwh-gvf6-mff8CVE-2024-39031moderatenot named as affected when the advisory was published, now names org.silverpeas.core:silverpeas-core-webDays to revision 190
2025-01-15published 2024-05-22Package added to advisoryGHSA-9rrw-82r2-623pCVE-2024-29392moderatenot named as affected when the advisory was published, now names org.silverpeas.core:silverpeas-coreDays to revision 238
2025-01-15published 2022-05-13Package added to advisoryGHSA-57q5-x8jf-g7h8CVE-2017-7561highnot named as affected when the advisory was published, now names org.jboss.resteasy:resteasy-jaxrsnot dated
2025-01-15published 2020-12-21Advisory severity changedGHSA-4cch-wxpw-8p28CVE-2020-26258whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.not dated
2025-01-15published 2023-02-18Advisory withdrawnGHSA-jrmh-v64j-mjm9whole advisorymoderatewithdrawn 2025-01-15Days to revision 698
Tue 14 Jan 2025· 2 advisory changes
2025-01-14published 2019-02-18Advisory severity changedGHSA-9gqh-q4cx-f2h9CVE-2016-10594whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.not dated
2025-01-14published 2025-01-14Advisory severity changedGHSA-vgf2-gvx8-xwc3CVE-2025-21607whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 0
Fri 10 Jan 2025· 1 advisory change
2025-01-10published 2024-12-02Package added to advisoryGHSA-q3v6-hm2v-pw99CVE-2024-38827moderatenot named as affected when the advisory was published, now names org.springframework.security:spring-security-coreDays to revision 39
Thu 9 Jan 2025· 2 advisory changes
2025-01-09published 2024-03-18Advisory severity changedGHSA-x32m-mvfj-52xvCVE-2024-21652whole advisorycriticalstated at publication MODERATE, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 297
2025-01-09published 2023-08-23Advisory severity changedGHSA-cr5q-6q9f-rq6qCVE-2023-38037whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 505
Wed 8 Jan 2025· 2 advisory changes
2025-01-08published 2024-12-20Package added to advisoryGHSA-27hp-xhwr-wr2mhighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core and 1 moreDays to revision 19
2025-01-08published 2024-12-20same kind of change as the line aboveGHSA-27hp-xhwr-wr2mCVE-2024-56337same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDays to revision 19
2025-01-08published 2024-12-20same kind of change as the line aboveGHSA-27hp-xhwr-wr2mCVE-2024-56337same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-embed-coreDays to revision 19
Mon 6 Jan 2025· 2 advisory changes
2025-01-06published 2025-01-06Advisory severity changedGHSA-237r-r8m4-4q88CVE-2025-21617whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 0
2025-01-06published 2025-01-06Advisory severity changedGHSA-v725-9546-7q7mCVE-2025-21613whole advisorycriticalstated at publication LOW, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 0
Fri 3 Jan 2025· 1 advisory change
2025-01-03published 2023-06-14Advisory severity changedGHSA-w2rr-wvh9-m2m7CVE-2023-34615whole advisoryhighstated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 13
Thu 2 Jan 2025· 1 advisory change
2025-01-02published 2024-12-24Advisory severity changedGHSA-f697-gm3h-xrf9CVE-2024-43441whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 9
Tue 31 Dec 2024· 1 advisory change
2024-12-31published 2024-06-26Advisory severity changedGHSA-gw84-84pc-xp82CVE-2024-21520whole advisorylowstated at publication MODERATE, now states LOWA CVSS version was added; the existing vectors stayed the same.Days to revision 188
Mon 30 Dec 2024· 1 advisory change
2024-12-30published 2024-12-27Advisory severity changedGHSA-w95c-7994-ghprCVE-2024-56522whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 4
Fri 27 Dec 2024· 1 advisory change
2024-12-27published 2024-10-25Advisory fix version movedGHSA-q34m-jh98-gwm2CVE-2024-49767
pypiquart
moderate
stated at publication 0.19.7, now states 0.20.0Days to revision 63
Thu 26 Dec 2024· 1 advisory change
2024-12-26published 2024-12-17Package added to advisoryGHSA-5j33-cvvr-w245CVE-2024-50379highnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDays to revision 9
Mon 23 Dec 2024· 8 advisory changes
2024-12-23published 2024-12-16Package added to advisoryGHSA-8wcc-m6j2-qxvmhighnot named as affected when the advisory was published, now names cosmossdk.io/x/txDays to revision 7
2024-12-23published 2024-12-23Advisory severity changedwhole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 0
2024-12-23published 2024-12-23same kind of change as the line aboveGHSA-qf5v-rp47-55ggCVE-2024-55947same package and registry as the line abovehighsame change as the line aboveDays to revision 0
2024-12-23published 2024-12-23same kind of change as the line aboveGHSA-r7j8-5h9c-f6fxCVE-2024-54148same package and registry as the line abovehighsame change as the line aboveDays to revision 0
2024-12-23published 2023-12-19 to 2024-07-04Advisory withdrawnwhole advisory3 bandswithdrawn 2024-12-23Days to revision 172 to 371
2024-12-23published 2024-07-04same kind of change as the line aboveGHSA-p69r-v3h4-rj4fsame package and registry as the line abovecriticalwithdrawn 2024-12-23Days to revision 172
2024-12-23published 2024-07-04same kind of change as the line aboveGHSA-hf29-9hfh-w63jsame package and registry as the line abovecriticalwithdrawn 2024-12-23Days to revision 172
2024-12-23published 2024-07-04same kind of change as the line aboveGHSA-2vgj-3pvg-xh4wsame package and registry as the line abovecriticalwithdrawn 2024-12-23Days to revision 172
2024-12-23published 2024-07-04same kind of change as the line aboveGHSA-8mm6-wmpp-mmm3same package and registry as the line abovehighwithdrawn 2024-12-23Days to revision 172
2024-12-23published 2023-12-19same kind of change as the line aboveGHSA-3p75-q5cc-qmj7same package and registry as the line abovemoderatewithdrawn 2024-12-23Days to revision 371
Fri 20 Dec 2024· 8 advisory changes
2024-12-20published 2024-12-20Advisory severity changedGHSA-2hr5-cvwp-jr5wCVE-2024-55186whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 0
2024-12-20published 2024-12-19Advisory severity changedGHSA-47h8-jmp3-9f28CVE-2024-56327whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 1
2024-12-20published 2022-08-27 to 2024-09-19Advisory withdrawnwhole advisory3 bandswithdrawn 2024-12-20Days to revision 92 to 847
2024-12-20published 2024-09-19same kind of change as the line aboveGHSA-vvf8-2h68-9475same package and registry as the line abovehighwithdrawn 2024-12-20Days to revision 92
2024-12-20published 2024-02-29same kind of change as the line aboveGHSA-3hrr-xwvg-hxvrsame package and registry as the line abovelowwithdrawn 2024-12-20Days to revision 296
2024-12-20published 2024-09-09same kind of change as the line aboveGHSA-j76j-rqwj-jmvvsame package and registry as the line abovehighwithdrawn 2024-12-20Days to revision 102
2024-12-20published 2024-09-09same kind of change as the line aboveGHSA-57rh-gr4v-j5f6same package and registry as the line abovemoderatewithdrawn 2024-12-20Days to revision 102
2024-12-20published 2022-08-27same kind of change as the line aboveGHSA-j9xq-j329-2xvgsame package and registry as the line abovemoderatewithdrawn 2024-12-20Days to revision 847
2024-12-20published 2024-09-19same kind of change as the line aboveGHSA-4xx7-2cx3-x473same package and registry as the line abovemoderatewithdrawn 2024-12-20Days to revision 92
Thu 19 Dec 2024· 1 advisory change
2024-12-19published 2024-12-10Advisory withdrawnGHSA-f626-677r-j5vqCVE-2024-55586whole advisorymoderatewithdrawn 2024-12-19Days to revision 9
Wed 18 Dec 2024· 6 advisory changes
2024-12-18published 2024-12-16Advisory fix version movedGHSA-27vq-hv74-7cqp
crates.io2 packages
low
stated at publication 2.1.3, now states 2.1.4Days to revision 2
2024-12-18published 2024-12-16Advisory fix version movedGHSA-27vq-hv74-7cqpCVE-2024-58356
crates.iosurrealdb
low
same change as the line aboveDays to revision 2
2024-12-18published 2024-12-16Advisory fix version movedGHSA-27vq-hv74-7cqpCVE-2024-58356
crates.iosurrealdb-core
low
same change as the line aboveDays to revision 2
2024-12-18published 2024-03-15Package added to advisoryGHSA-qqc8-rv37-79q5lownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server and 2 moreDays to revision 278
2024-12-18published 2024-03-15same kind of change as the line aboveGHSA-qqc8-rv37-79q5CVE-2024-28053same package registry as the line abovelownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-serverDays to revision 278
2024-12-18published 2024-03-15same kind of change as the line aboveGHSA-qqc8-rv37-79q5CVE-2024-28053same package registry as the line abovelownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v5Days to revision 278
2024-12-18published 2024-03-15same kind of change as the line aboveGHSA-qqc8-rv37-79q5CVE-2024-28053same package registry as the line abovelownot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server/v6Days to revision 278
2024-12-18published 2024-12-18Advisory severity changedGHSA-2p6p-9rc9-62j9CVE-2024-56145whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 0
Fri 13 Dec 2024· 2 advisory changes
2024-12-13published 2024-12-09Advisory severity changedGHSA-mwcw-c2x4-8c55CVE-2024-55565whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 5
2024-12-13published 2024-12-11Advisory severity changedGHSA-v778-237x-gjrcCVE-2024-45337whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 2
Thu 12 Dec 2024· 1 advisory change
2024-12-12published 2024-12-12Advisory severity changedGHSA-9j3m-fr7q-jxfwCVE-2024-55885whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 0
Mon 9 Dec 2024· 1 advisory change
2024-12-09published 2024-12-09Package added to advisoryGHSA-849r-qrwj-8rv4CVE-2024-54151highnot named as affected when the advisory was published, now names @directus/apiDays to revision 0
Thu 5 Dec 2024· 3 advisory changes
2024-12-05published 2022-05-14Package added to advisoryGHSA-92rv-mvmj-47qhCVE-2018-1000186lownot named as affected when the advisory was published, now names org.jenkins-ci.plugins:ghprbDays to revision 937
2024-12-05published 2023-10-18Package added to advisoryGHSA-m6vm-37g8-gqvhCVE-2023-22102highnot named as affected when the advisory was published, now names mysql:mysql-connector-javaDays to revision 415
2024-12-05published 2022-05-14Advisory severity changedGHSA-92rv-mvmj-47qhCVE-2018-1000186whole advisorylowstated at publication MODERATE, now states LOWA CVSS version was added; the existing vectors stayed the same.Days to revision 937
Wed 4 Dec 2024· 2 advisory changes
2024-12-04published 2024-11-12Advisory severity changedGHSA-xq3w-v528-46rvCVE-2024-47535whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 22
2024-12-04published 2024-12-02Advisory withdrawnGHSA-j5g2-q29x-cw3hwhole advisoryhighwithdrawn 2024-12-04Days to revision 2
Tue 3 Dec 2024· 3 advisory changes
2024-12-03published 2024-11-20Advisory severity changedGHSA-wpvf-5mc3-hv6mwhole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Days to revision 13
2024-12-03published 2024-11-29Advisory withdrawnwhole advisory2 bandswithdrawn 2024-12-03Days to revision 4
2024-12-03published 2024-11-29same kind of change as the line aboveGHSA-cg28-v4wq-whv5CVE-2024-36610same package and registry as the line abovehighwithdrawn 2024-12-03Days to revision 4
2024-12-03published 2024-11-29same kind of change as the line aboveGHSA-7q22-x757-cmgcCVE-2024-36611same package and registry as the line abovemoderatewithdrawn 2024-12-03Days to revision 4

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →