Skip to content

Every change, newest first

Compare earlier and later source statements, with the dates and evidence behind each measured change.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Wed 2 Sep 2026· 6 changes
2026-09-02published 2026-05-06Advisory fix version movedGHSA-248h-974q-xrc2
mavencom.getaxonflow:axonflow-sdk
moderate
stated at publication 6.0.0, now states 7.0.0Time to revision 119 days
2026-09-02published 2024-10-09 to 2025-03-20Advisory withdrawnwhole advisory3 bandswithdrawn 2026-09-02Time to revision 531 to 693 days
2026-09-02published 2025-03-20same kind of change as the line aboveGHSA-x757-hv69-jr45CVE-2024-7959same package and registry as the line abovehighwithdrawn 2026-09-02Time to revision 531 days
2026-09-02published 2025-03-20same kind of change as the line aboveGHSA-pqwr-phvv-v49fCVE-2024-7039same package and registry as the line abovehighwithdrawn 2026-09-02Time to revision 531 days
2026-09-02published 2025-03-20same kind of change as the line aboveGHSA-crh6-pj8c-xrhcCVE-2024-7034same package and registry as the line abovemoderatewithdrawn 2026-09-02Time to revision 531 days
2026-09-02published 2025-03-20same kind of change as the line aboveGHSA-3p9q-7w63-3f8qCVE-2024-7033same package and registry as the line abovemoderatewithdrawn 2026-09-02Time to revision 531 days
2026-09-02published 2024-10-09same kind of change as the line aboveGHSA-mq92-jr35-ffpcCVE-2024-7038same package and registry as the line abovelowwithdrawn 2026-09-02Time to revision 693 days
Tue 1 Sep 2026· 3 changes
2026-09-01published 2026-06-16Package added to advisoryGHSA-5r4w-85f3-pw66highnot named as affected when the advisory was published, now names github.com/traefik/traefik/v2 and 1 moreTime to revision 77 days
2026-09-01published 2026-06-16same kind of change as the line aboveGHSA-5r4w-85f3-pw66CVE-2026-48491same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/traefik/traefik/v2Time to revision 77 days
2026-09-01published 2026-06-16same kind of change as the line aboveGHSA-5r4w-85f3-pw66CVE-2026-48491same package registry as the line abovehighnot named as affected when the advisory was published, now names github.com/traefik/traefik/v3Time to revision 77 days
2026-09-01published 2025-12-01Advisory severity changedGHSA-569q-mpph-wgwwCVE-2025-71401whole advisoryhighstated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 274 days
Mon 31 Aug 2026· 1 change
2026-08-31published 2026-05-12Package added to advisoryGHSA-r29c-68gh-xp6xCVE-2026-41293criticalnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 111 days
Fri 28 Aug 2026· 2 changes
2026-08-28published 2026-06-12Advisory severity changedGHSA-9r4w-jg96-92mvCVE-2026-12681whole advisoryhighstated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.Time to revision 77 days
2026-08-28published 2026-07-02Advisory severity changedGHSA-77pv-3w4q-vrj5CVE-2026-53834whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 57 days
Wed 26 Aug 2026· 1 change
2026-08-26published 2026-02-25Advisory severity changedGHSA-wfx3-6g53-9fgcCVE-2026-56368whole advisorymoderatestated at publication LOW, now states MODERATEA CVSS version was added; the existing vectors stayed the same.Time to revision 182 days
Tue 25 Aug 2026· 1 change
2026-08-25published 2026-07-02Advisory severity changedGHSA-83w9-h5wv-j9xmCVE-2026-53838whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 54 days
Fri 21 Aug 2026· 2 changes
2026-08-21published 2026-07-24 to 2026-08-20Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 1 to 28 days
2026-08-21published 2026-08-20same kind of change as the line aboveGHSA-fm29-4mq3-phg6same package and registry as the line abovehighsame change as the line aboveTime to revision 1 days
2026-08-21published 2026-07-24same kind of change as the line aboveGHSA-r292-9mhp-454mCVE-2026-73566same package and registry as the line abovehighsame change as the line aboveTime to revision 28 days
Fri 14 Aug 2026· 3 changes
2026-08-14published 2026-04-14Advisory fix version movedGHSA-355h-qmc2-wpwfCVE-2026-2332
mavenorg.eclipse.jetty:jetty-http
high
stated at publication 11.0.28, now states 11.0.29Time to revision 35 days
2026-08-14published 2026-02-19Package added to advisoryGHSA-p6jf-79j3-33f3CVE-2025-13590criticalnot named as affected when the advisory was published, now names org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1Time to revision 176 days
2026-08-14published 2026-04-29Package added to advisoryGHSA-w22p-4x9f-486vCVE-2026-42523criticalnot named as affected when the advisory was published, now names com.coravy.hudson.plugins.github:githubTime to revision 107 days
Thu 13 Aug 2026· 1 change
2026-08-13published 2026-07-29Advisory fix version movedGHSA-2v37-7h3g-55p8CVE-2026-67213
npmnanoid
high
stated at publication 3.3.17, now states 3.3.18Time to revision 15 days
Tue 11 Aug 2026· 1 change
2026-08-11published 2026-06-26Advisory severity changedGHSA-4c3c-r6p8-c863CVE-2026-48813whole advisoryhighstated at publication LOW, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Time to revision 46 days
Thu 6 Aug 2026· 1 change
2026-08-06published 2026-05-22Advisory fix version movedGHSA-7m8f-hgjq-8gc9CVE-2026-70646
pypiaiosend
high
stated at publication 3.0.6, now states 3.0.7Time to revision 76 days
Tue 4 Aug 2026· 3 changes
2026-08-04published 2026-07-28Advisory fix version movedGHSA-6wcc-39rp-hh9pCVE-2026-54658
npm@hypequery/clickhouse
critical
stated at publication 2.0.2, now states 2.5.1Time to revision 7 days
2026-08-04published 2026-06-03Package added to advisoryGHSA-2j2x-hqr9-3h42CVE-2026-40181moderatenot named as affected when the advisory was published, now names @remix-run/routerTime to revision 62 days
2026-08-04published 2026-07-21Package added to advisoryGHSA-w5pg-649r-p6ggCVE-2026-58439highnot named as affected when the advisory was published, now names code.gitea.io/giteaTime to revision 13 days
Fri 31 Jul 2026· 6 changes
2026-07-31published 2026-04-07Advisory fix version movedGHSA-89gg-p5r5-q6r4
pypimonai
high
stated at publication 1.5.2, now states 1.6.0Time to revision 115 days
2026-07-31published 2026-07-21Package added to advisoryGHSA-m4p7-r5rc-7g4jCVE-2026-59884highnot named as affected when the advisory was published, now names pyasn1Time to revision 10 days
2026-07-31published 2026-06-16Advisory severity changedGHSA-8xpq-cjcf-3wh9CVE-2026-49401whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 45 days
2026-07-31published 2023-08-29 to 2026-06-03Advisory withdrawnwhole advisorymoderatewithdrawn 2026-07-31Time to revision 58 to 1,067 days
2026-07-31published 2023-08-29same kind of change as the line aboveGHSA-vmf9-6pcv-xr87CVE-2023-39522same package and registry as the line abovemoderatewithdrawn 2026-07-31Time to revision 1,067 days
2026-07-31published 2026-06-03same kind of change as the line aboveGHSA-v42x-x7jp-845hCVE-2026-6657same package and registry as the line abovemoderatewithdrawn 2026-07-31Time to revision 58 days
2026-07-31published 2026-06-02same kind of change as the line aboveGHSA-gf7q-q4j7-hp7cCVE-2026-5422same package and registry as the line abovemoderatewithdrawn 2026-07-31Time to revision 59 days
Thu 30 Jul 2026· 2 changes
2026-07-30published 2025-05-13Package added to advisoryGHSA-qqcr-9jfc-35c4highnot named as affected when the advisory was published, now names oxid-esales/oxideshop-metapackage-ce and 1 moreTime to revision 443 days
2026-07-30published 2025-05-13same kind of change as the line aboveGHSA-qqcr-9jfc-35c4CVE-2024-56526same package registry as the line abovehighnot named as affected when the advisory was published, now names oxid-esales/oxideshop-metapackage-ceTime to revision 443 days
2026-07-30published 2025-05-13same kind of change as the line aboveGHSA-qqcr-9jfc-35c4CVE-2024-56526same package registry as the line abovehighnot named as affected when the advisory was published, now names oxid-esales/smarty-componentTime to revision 443 days
Tue 28 Jul 2026· 1 change
2026-07-28published 2025-08-27Advisory withdrawnGHSA-cxm3-wv7p-598cCVE-2025-10894whole advisorycriticalwithdrawn 2026-07-28Time to revision 335 days
Fri 24 Jul 2026· 1 change
2026-07-24published 2026-05-06Package added to advisoryGHSA-rwm7-x88c-3g2pCVE-2026-42577highnot named as affected when the advisory was published, now names io.netty:netty-transport-classes-epollTime to revision 79 days
Tue 21 Jul 2026· 7 changes
2026-07-21published 2026-05-07Package added to advisoryGHSA-g924-cjx7-2rjwCVE-2026-42597moderatenot named as affected when the advisory was published, now names github.com/gotenberg/gotenberg/v7Time to revision 76 days
2026-07-21published 2026-04-14Package added to advisoryGHSA-2hx3-vp6r-mg3fhighnot named as affected when the advisory was published, now names microsoft.openapi.kiota and 1 moreTime to revision 98 days
2026-07-21published 2026-04-14same kind of change as the line aboveGHSA-2hx3-vp6r-mg3fCVE-2026-41134same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.openapi.kiotaTime to revision 98 days
2026-07-21published 2026-04-14same kind of change as the line aboveGHSA-2hx3-vp6r-mg3fCVE-2026-41134same package registry as the line abovehighnot named as affected when the advisory was published, now names microsoft.openapi.kiota.builderTime to revision 98 days
2026-07-21published 2025-08-26Advisory severity changedwhole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 329 to 329 days
2026-07-21published 2025-08-26same kind of change as the line aboveGHSA-xp4f-hrf8-rxw7CVE-2025-71344same package and registry as the line abovehighsame change as the line aboveTime to revision 329 days
2026-07-21published 2025-08-26same kind of change as the line aboveGHSA-3vg9-h568-4w9mCVE-2025-71354same package and registry as the line abovehighsame change as the line aboveTime to revision 329 days
2026-07-21published 2026-06-23Advisory severity changedGHSA-vcm5-gvmp-78mpCVE-2026-52807whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Time to revision 28 days
2026-07-21published 2026-06-22Advisory severity changedGHSA-c4v7-xg93-qf8gCVE-2026-47267whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 29 days
Mon 20 Jul 2026· 2 changes
2026-07-20published 2025-08-26Advisory severity changedGHSA-8r4j-24qv-fmq9CVE-2025-71361whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 328 days
2026-07-20published 2026-06-05Advisory severity changedGHSA-jr54-jwhj-55gpCVE-2026-47380whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Time to revision 45 days
Sat 18 Jul 2026· 1 change
2026-07-18published 2025-08-26Advisory severity changedGHSA-6w4w-5w54-rjvrCVE-2025-71358whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 326 days
Thu 16 Jul 2026· 1 change
2026-07-16published 2024-05-30Package added to advisoryGHSA-22q7-cg4r-p9mxmoderatenot named as affected when the advisory was published, now names typo3/cms-fluidTime to revision 777 days
Wed 15 Jul 2026· 2 changes
2026-07-15published 2025-12-01Package added to advisoryGHSA-rcmh-qjqh-p98vCVE-2025-14874highnot named as affected when the advisory was published, now names org.webjars.npm:nodemailerTime to revision 226 days
2026-07-15published 2026-06-12Advisory severity changedGHSA-4px2-pw77-vc85CVE-2026-28898whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 33 days
Tue 7 Jul 2026· 2 changes
2026-07-07published 2026-05-08Package added to advisoryGHSA-mx76-r943-rf8gCVE-2026-8149moderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-lts8onTime to revision 61 days
2026-07-07published 2026-06-19Advisory severity changedGHSA-qrpv-q767-xqq2CVE-2026-55255whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 18 days
Mon 6 Jul 2026· 38 changes
2026-07-06published 2026-06-18Package added to advisoryGHSA-jc38-x7x8-2xc8highnot named as affected when the advisory was published, now names web-token/jwt-bundle and 1 moreTime to revision 18 days
2026-07-06published 2026-06-18same kind of change as the line aboveGHSA-jc38-x7x8-2xc8same package registry as the line abovehighnot named as affected when the advisory was published, now names web-token/jwt-bundleTime to revision 18 days
2026-07-06published 2026-06-18same kind of change as the line aboveGHSA-jc38-x7x8-2xc8same package registry as the line abovehighnot named as affected when the advisory was published, now names web-token/jwt-experimentalTime to revision 18 days
2026-07-06published 2026-03-19 to 2026-06-26Package added to advisory3 bandsnot named as affected when the advisory was published, now names scriban.signedTime to revision 10 to 109 days
2026-07-06published 2026-06-26same kind of change as the line aboveGHSA-6q7j-xr26-3h2csame package registry as the line abovemoderatesame change as the line aboveTime to revision 10 days
2026-07-06published 2026-03-24same kind of change as the line aboveGHSA-xw6w-9jjh-p9crsame package registry as the line abovemoderatesame change as the line aboveTime to revision 104 days
2026-07-06published 2026-03-24same kind of change as the line aboveGHSA-m2p3-hwv5-xpqwsame package registry as the line abovemoderatesame change as the line aboveTime to revision 104 days
2026-07-06published 2026-03-24same kind of change as the line aboveGHSA-xcx6-vp38-8hr5same package registry as the line abovehighsame change as the line aboveTime to revision 104 days
2026-07-06published 2026-03-24same kind of change as the line aboveGHSA-v66j-x4hw-fv9gsame package registry as the line abovehighsame change as the line aboveTime to revision 104 days
2026-07-06published 2026-03-24same kind of change as the line aboveGHSA-5wr9-m6jw-xx44same package registry as the line abovecriticalsame change as the line aboveTime to revision 104 days
2026-07-06published 2026-03-24same kind of change as the line aboveGHSA-x6m9-38vm-2xhfsame package registry as the line abovehighsame change as the line aboveTime to revision 104 days
2026-07-06published 2026-03-24same kind of change as the line aboveGHSA-p6q4-fgr8-vx4psame package registry as the line abovehighsame change as the line aboveTime to revision 104 days
5 more rows in this change are not listed here. Open all 13 rows
2026-07-06published 2026-04-22Advisory withdrawnwhole advisory3 bandswithdrawn 2026-07-06Time to revision 75 to 75 days
2026-07-06published 2026-04-22same kind of change as the line aboveGHSA-532v-xp3f-837csame package and registry as the line abovelowwithdrawn 2026-07-06Time to revision 75 days
2026-07-06published 2026-04-22same kind of change as the line aboveGHSA-79rc-qpw3-jv92same package and registry as the line abovelowwithdrawn 2026-07-06Time to revision 75 days
2026-07-06published 2026-04-22same kind of change as the line aboveGHSA-w8m4-4v35-v6x3same package and registry as the line abovehighwithdrawn 2026-07-06Time to revision 75 days
2026-07-06published 2026-04-22same kind of change as the line aboveGHSA-7259-cwhx-3xx3same package and registry as the line abovemoderatewithdrawn 2026-07-06Time to revision 75 days
2026-07-06published 2026-04-22same kind of change as the line aboveGHSA-ggc5-46rg-mr4vsame package and registry as the line abovelowwithdrawn 2026-07-06Time to revision 75 days
2026-07-06published 2026-04-22same kind of change as the line aboveGHSA-66fx-fqv6-5wwxsame package and registry as the line abovemoderatewithdrawn 2026-07-06Time to revision 75 days
2026-07-06published 2026-04-22same kind of change as the line aboveGHSA-67hp-f6hq-2h6gsame package and registry as the line abovemoderatewithdrawn 2026-07-06Time to revision 75 days
2026-07-06published 2026-04-22same kind of change as the line aboveGHSA-vchc-9ggh-3236same package and registry as the line abovemoderatewithdrawn 2026-07-06Time to revision 75 days
15 more rows in this change are not listed here. Open all 23 rows
Thu 2 Jul 2026· 4 changes
2026-07-02published 2026-06-19Advisory fix version movedGHSA-h3m5-97jq-qjrfCVE-2026-57168
mavenio.openremote:openremote-manager
critical
stated at publication 1.24.2, now states 1.25.0Time to revision 13 days
2026-07-02published 2026-04-29Advisory severity changedGHSA-5843-p793-ghmmCVE-2026-22740whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 64 days
2026-07-02published 2026-05-27Advisory severity changedGHSA-6439-2f28-8p8qCVE-2026-45075whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 36 days
2026-07-02published 2026-03-18Advisory withdrawnGHSA-wmxr-6j5f-838pwhole advisoryhighwithdrawn 2026-07-02Time to revision 107 days
Wed 1 Jul 2026· 5 changes
2026-07-01published 2024-11-07 to 2025-08-13Package added to advisory2 bandsnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreTime to revision 322 to 601 days
2026-07-01published 2024-11-07same kind of change as the line aboveGHSA-7jqf-v358-p8g7CVE-2024-38286same package registry as the line abovehighsame change as the line aboveTime to revision 601 days
2026-07-01published 2025-08-13same kind of change as the line aboveGHSA-23hv-mwm6-g8jfCVE-2025-55668same package registry as the line abovemoderatesame change as the line aboveTime to revision 322 days
2026-07-01published 2025-07-10same kind of change as the line aboveGHSA-4j3c-42xv-3f84CVE-2025-52434same package registry as the line abovemoderatesame change as the line aboveTime to revision 356 days
2026-07-01published 2024-11-07 to 2025-07-10Package added to advisory2 bandsnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 356 to 601 days
2026-07-01published 2024-11-07same kind of change as the line aboveGHSA-7jqf-v358-p8g7CVE-2024-38286same package registry as the line abovehighsame change as the line aboveTime to revision 601 days
2026-07-01published 2025-07-10same kind of change as the line aboveGHSA-4j3c-42xv-3f84CVE-2025-52434same package registry as the line abovemoderatesame change as the line aboveTime to revision 356 days
Tue 30 Jun 2026· 2 changes
2026-06-30published 2024-01-12Advisory severity changedGHSA-8qw9-gf7w-42x5whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Time to revision 900 days
2026-06-30published 2026-05-26Advisory withdrawnGHSA-76v6-f83q-pxvhwhole advisoryhighwithdrawn 2026-06-30Time to revision 35 days
Mon 29 Jun 2026· 3 changes
2026-06-29published 2026-02-17Package added to advisoryGHSA-qq5r-98hh-rxc9CVE-2026-24733lownot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 132 days
2026-06-29published 2026-05-19Package added to advisoryGHSA-24c8-4792-22hxhighnot named as affected when the advisory was published, now names scriban.signedTime to revision 41 days
2026-06-29published 2019-10-11Package added to advisoryGHSA-p979-4mfw-53vgCVE-2019-16869highnot named as affected when the advisory was published, now names io.netty:nettyDuration unknown
Fri 26 Jun 2026· 2 changes
2026-06-26published 2026-05-29Package added to advisoryGHSA-6x26-5727-rrm9CVE-2026-47268moderatenot named as affected when the advisory was published, now names github.com/naiba/nezhaTime to revision 28 days
2026-06-26published 2026-06-10Package added to advisoryGHSA-8h84-fhqq-q58vCVE-2026-48025moderatenot named as affected when the advisory was published, now names github.com/forgekeep/nebula-meshTime to revision 16 days
Thu 18 Jun 2026· 8 changes
2026-06-18published 2024-01-19Package added to advisoryGHSA-f4qf-m5gf-8jm8CVE-2024-21733moderatenot named as affected when the advisory was published, now names org.apache.tomcat.experimental:tomcat-embed-programmaticTime to revision 881 days
2026-06-18published 2026-04-09Package added to advisoryGHSA-x4m4-345f-5h5gCVE-2026-34487highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-tribesTime to revision 70 days
2026-06-18published 2024-11-18Package added to advisoryGHSA-f632-9449-3j4wCVE-2024-52318moderatenot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-jasperTime to revision 577 days
2026-06-18published 2019-05-30 to 2024-11-18Package added to advisorymoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcatTime to revision 577 days
2026-06-18published 2024-11-18same kind of change as the line aboveGHSA-f632-9449-3j4wCVE-2024-52318same package registry as the line abovemoderatesame change as the line aboveTime to revision 577 days
2026-06-18published 2019-05-30same kind of change as the line aboveGHSA-jjpq-gp5q-8q6wCVE-2019-0221same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2026-06-18published 2019-05-30 to 2023-02-20Package added to advisory2 bandsnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaTime to revision 1,214 days
2026-06-18published 2023-02-20same kind of change as the line aboveGHSA-hfrx-6qgj-fp6cCVE-2023-24998same package registry as the line abovehighsame change as the line aboveTime to revision 1,214 days
2026-06-18published 2019-05-30same kind of change as the line aboveGHSA-jjpq-gp5q-8q6wCVE-2019-0221same package registry as the line abovemoderatesame change as the line aboveDuration unknown
2026-06-18published 2022-02-10Advisory severity changedGHSA-xp4x-j9vh-c3wfCVE-2019-15609whole advisorycriticalstated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same.Duration unknown
Wed 17 Jun 2026· 1 change
2026-06-17published 2026-06-12Advisory withdrawnGHSA-gv7w-rqvm-qjhrwhole advisoryhighwithdrawn 2026-06-17Time to revision 5 days
Fri 12 Jun 2026· 4 changes
2026-06-12published 2023-10-10 to 2026-02-17Package added to advisorymoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 115 to 976 days
2026-06-12published 2023-10-10same kind of change as the line aboveGHSA-r6j3-px5g-cq3xCVE-2023-45648same package registry as the line abovemoderatesame change as the line aboveTime to revision 976 days
2026-06-12published 2026-02-17same kind of change as the line aboveGHSA-fpj8-gq4v-p354CVE-2025-66614same package registry as the line abovemoderatesame change as the line aboveTime to revision 115 days
2026-06-12published 2023-10-10Package added to advisoryGHSA-g8pj-r55q-5c2vmoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina and 1 moreTime to revision 976 days
2026-06-12published 2023-10-10same kind of change as the line aboveGHSA-g8pj-r55q-5c2vCVE-2023-42795same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaTime to revision 976 days
2026-06-12published 2023-10-10same kind of change as the line aboveGHSA-g8pj-r55q-5c2vCVE-2023-42795same package registry as the line abovemoderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-utilTime to revision 976 days
Thu 11 Jun 2026· 6 changes
2026-06-11published 2026-05-07Package added to advisoryGHSA-2mh5-3cw6-hrrqCVE-2026-40981highnot named as affected when the advisory was published, now names org.springframework.cloud:spring-cloud-config-serverTime to revision 35 days
2026-06-11published 2022-02-08Package added to advisoryGHSA-m7jv-hq7h-mq7chighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocket and 1 moreDuration unknown
2026-06-11published 2022-02-08same kind of change as the line aboveGHSA-m7jv-hq7h-mq7cCVE-2020-13935same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocketDuration unknown
2026-06-11published 2022-02-08same kind of change as the line aboveGHSA-m7jv-hq7h-mq7cCVE-2020-13935same package registry as the line abovehighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-websocketDuration unknown
2026-06-11published 2022-02-09Package added to advisoryGHSA-53hp-jpwq-2jgqCVE-2020-11996highnot named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-coreDuration unknown
2026-06-11published 2023-05-30Advisory severity changedGHSA-mj6p-3pc9-wf5mCVE-2023-2968whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 1,108 days
2026-06-11published 2024-04-18Advisory severity changedGHSA-jjff-q3q4-5hh8CVE-2024-30564whole advisorycriticalstated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.Time to revision 784 days
Tue 9 Jun 2026· 15 changes
2026-06-09published 2021-08-25 to 2022-01-06Advisory fix version moved
crates.ioactix-web
2 bands
stated at publication 0.7.15, now states 0.7.19Duration unknown
2026-06-09published 2022-01-06same kind of change as the line aboveGHSA-9qj6-4rfq-vm84CVE-2018-25024same package and registry as the line abovecriticalsame change as the line aboveDuration unknown
2026-06-09published 2022-01-06same kind of change as the line aboveGHSA-7x36-h62w-vw65CVE-2018-25026same package and registry as the line abovecriticalsame change as the line aboveDuration unknown
2026-06-09published 2022-01-06same kind of change as the line aboveGHSA-fgfm-hqjw-3265CVE-2018-25025same package and registry as the line abovecriticalsame change as the line aboveDuration unknown
2026-06-09published 2021-08-25same kind of change as the line aboveGHSA-w65j-g6c7-g3m4same package and registry as the line abovemoderatesame change as the line aboveDuration unknown
2026-06-09published 2026-06-01Package added to advisoryGHSA-q53q-5r4j-5729CVE-2026-47425moderatenot named as affected when the advisory was published, now names py-rattlerTime to revision 8 days
2026-06-09published 2026-05-29Advisory severity changedGHSA-j6fm-9rfm-j5hxCVE-2026-41237whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 11 days
2026-06-09published 2022-05-24Advisory severity changedGHSA-4hm9-844j-jmxpCVE-2019-13117whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Time to revision 1,477 days
2026-06-09published 2026-05-12Advisory severity changedGHSA-3636-h3vx-6465CVE-2026-44593whole advisoryhighstated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version.Time to revision 27 days
2026-06-09published 2026-05-15Advisory severity changedGHSA-rmqr-h98c-qg2mwhole advisoryhighstated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Time to revision 24 days
2026-06-09published 2026-02-18 to 2026-05-15Advisory withdrawnwhole advisory2 bandswithdrawn 2026-06-09Time to revision 24 to 112 days
2026-06-09published 2026-02-18same kind of change as the line aboveGHSA-wgm6-9rvv-3438CVE-2026-26957same package and registry as the line abovemoderatewithdrawn 2026-06-09Time to revision 112 days
2026-06-09published 2026-05-15same kind of change as the line aboveGHSA-5h62-f8fg-4w7qsame package and registry as the line abovemoderatewithdrawn 2026-06-09Time to revision 24 days
2026-06-09published 2026-05-15same kind of change as the line aboveGHSA-wj3q-vw2v-3rj3same package and registry as the line abovemoderatewithdrawn 2026-06-09Time to revision 24 days
2026-06-09published 2026-05-15same kind of change as the line aboveGHSA-9r8r-x3vg-6xh4same package and registry as the line abovemoderatewithdrawn 2026-06-09Time to revision 24 days
2026-06-09published 2026-05-15same kind of change as the line aboveGHSA-rmqr-h98c-qg2msame package and registry as the line abovehighwithdrawn 2026-06-09Time to revision 24 days
2026-06-09published 2026-05-15same kind of change as the line aboveGHSA-h36g-93qx-rxgrsame package and registry as the line abovemoderatewithdrawn 2026-06-09Time to revision 24 days
Mon 8 Jun 2026· 8 changes
2026-06-08published 2026-05-15Package added to advisoryGHSA-w42g-jj8w-fj77highnot named as affected when the advisory was published, now names thorsten/phpmyfaqTime to revision 24 days
2026-06-08published 2021-04-13Package added to advisoryGHSA-3pcr-4982-548mmoderatenot named as affected when the advisory was published, now names shopware/shopwareDuration unknown
2026-06-08published 2025-10-15Package added to advisoryGHSA-6p6v-m64v-jx8qCVE-2025-55039lownot named as affected when the advisory was published, now names pysparkTime to revision 236 days
2026-06-08published 2026-03-25Package added to advisoryGHSA-7h8w-hj9j-8rjwCVE-2026-33718highnot named as affected when the advisory was published, now names openhands-aiTime to revision 75 days
2026-06-08published 2022-05-02Advisory severity changedGHSA-f7w7-6pjc-wwm6CVE-2009-3555whole advisorycriticalstated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.Time to revision 1,499 days
2026-06-08published 2026-03-03Advisory severity changedGHSA-p4wh-cr8m-gm6cCVE-2026-22217whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 97 days
2026-06-08published 2025-10-15Advisory severity changedGHSA-6p6v-m64v-jx8qCVE-2025-55039whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 236 days
2026-06-08published 2026-05-15Advisory withdrawnGHSA-w42g-jj8w-fj77whole advisoryhighwithdrawn 2026-06-08Time to revision 24 days
Sat 6 Jun 2026· 1 change
2026-06-06published 2026-03-18Advisory fix version movedGHSA-rf6x-r45m-xv3wCVE-2026-33053
pypilangflow
high
stated at publication 1.7.2, now states 1.9.0Time to revision 80 days
Fri 5 Jun 2026· 4 changes
2026-06-05published 2023-08-25Package added to advisoryGHSA-q3mw-pvr8-9ggcCVE-2023-41080moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalinaTime to revision 1,015 days
2026-06-05published 2021-06-16Package added to advisoryGHSA-j39c-c8hj-x4j3CVE-2021-25122highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDuration unknown
2026-06-05published 2026-04-18Package added to advisoryGHSA-w9r4-94fj-xp69CVE-2026-32690lownot named as affected when the advisory was published, now names apache-airflowTime to revision 48 days
2026-06-05published 2025-09-24Package added to advisoryGHSA-776q-jw43-fhjxCVE-2025-48459criticalnot named as affected when the advisory was published, now names apache-iotdbTime to revision 254 days
Mon 1 Jun 2026· 2 changes
2026-06-01published 2026-05-18Package added to advisoryGHSA-v549-xx3c-6pc8moderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost-server and 1 moreTime to revision 14 days
2026-06-01published 2026-05-18same kind of change as the line aboveGHSA-v549-xx3c-6pc8CVE-2026-3637same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost-serverTime to revision 14 days
2026-06-01published 2026-05-18same kind of change as the line aboveGHSA-v549-xx3c-6pc8CVE-2026-3637same package registry as the line abovemoderatenot named as affected when the advisory was published, now names github.com/mattermost/mattermost/server/v8Time to revision 14 days
Fri 29 May 2026· 1 change
2026-05-29published 2026-04-22Package added to advisoryGHSA-ffq5-qpvf-xq7xCVE-2026-42086moderatenot named as affected when the advisory was published, now names openc3Time to revision 37 days
Thu 28 May 2026· 1 change
2026-05-28published 2026-04-27Advisory withdrawnGHSA-c8g3-x47w-8q7pwhole advisoryhighwithdrawn 2026-05-28Time to revision 31 days
Wed 20 May 2026· 10 changes
2026-05-20published 2024-10-09Advisory fix version movedGHSA-pfr9-2p92-qrhqmoderatestated at publication 0.22.0, now states 0.22.1Time to revision 587 days
2026-05-20published 2023-06-14Package added to advisoryGHSA-5wfc-hjrc-gq87CVE-2023-34620highnot named as affected when the advisory was published, now names github.com/hjson/hjson-go/v4Time to revision 1,071 days
2026-05-20published 2023-06-14Package added to advisoryGHSA-5wfc-hjrc-gq87CVE-2023-34620highnot named as affected when the advisory was published, now names laktak/hjsonTime to revision 1,071 days
2026-05-20published 2020-06-15 to 2026-04-09Package added to advisoryhighnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteTime to revision 41 days
2026-05-20published 2026-04-09same kind of change as the line aboveGHSA-69cc-cv78-qc8gCVE-2026-29129same package registry as the line abovehighsame change as the line aboveTime to revision 41 days
2026-05-20published 2020-06-15same kind of change as the line aboveGHSA-qcxh-w3j9-58qrCVE-2019-0199same package registry as the line abovehighsame change as the line aboveDuration unknown
2026-05-20published 2026-04-09Package added to advisory2 bandsnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote-ffmTime to revision 40 to 41 days
2026-05-20published 2026-04-09same kind of change as the line aboveGHSA-95jq-rwvf-vjx4CVE-2026-29145same package registry as the line abovecriticalsame change as the line aboveTime to revision 41 days
2026-05-20published 2026-04-09same kind of change as the line aboveGHSA-24j9-x2wg-9qv6CVE-2026-34500same package registry as the line abovemoderatesame change as the line aboveTime to revision 40 days
2026-05-20published 2024-12-17Package added to advisoryGHSA-653p-vg55-5652CVE-2024-54677moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcatTime to revision 519 days
2026-05-20published 2026-03-31Package added to advisoryGHSA-rvhj-8chj-8v3cCVE-2026-0596criticalnot named as affected when the advisory was published, now names mlflowTime to revision 49 days
2026-05-20published 2026-04-16Advisory severity changedGHSA-v92g-xgxw-vvmmCVE-2026-41205whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 33 days

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Use arrow keys to move between days, Home or End to reach either end, and Enter to open a day.
4,561 record edits in the 52 weeks to 2026-09-07. Scroll for earlier dates.fewermore

What this page cannot see

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Paste your closed CVE tickets and see which of these changes hit them →