Every change, newest first
Compare earlier and later source statements, with the dates and evidence behind each measured change.
5,026 advisory changes · newest first · grouped by day
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Kind | Advisory, Which advisory was edited, by its GHSA id. | Package, The package the advisory names, and the registry it comes from. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|---|
| Wed 2 Sep 2026· 6 changes | |||||
| 2026-09-02published 2026-05-06 | Advisory fix version moved | GHSA-248h-974q-xrc2 | mavencom.getaxonflow:axonflow-sdk moderate | stated at publication 6.0.0, now states 7.0.0 | Time to revision 119 days |
| 2026-09-02published 2024-10-09 to 2025-03-20 | Advisory withdrawn | whole advisory3 bands | withdrawn 2026-09-02 | Time to revision 531 to 693 days | |
| 2026-09-02published 2025-03-20 | same kind of change as the line above | GHSA-x757-hv69-jr45CVE-2024-7959 | same package and registry as the line abovehigh | withdrawn 2026-09-02 | Time to revision 531 days |
| 2026-09-02published 2025-03-20 | same kind of change as the line above | GHSA-pqwr-phvv-v49fCVE-2024-7039 | same package and registry as the line abovehigh | withdrawn 2026-09-02 | Time to revision 531 days |
| 2026-09-02published 2025-03-20 | same kind of change as the line above | GHSA-crh6-pj8c-xrhcCVE-2024-7034 | same package and registry as the line abovemoderate | withdrawn 2026-09-02 | Time to revision 531 days |
| 2026-09-02published 2025-03-20 | same kind of change as the line above | GHSA-3p9q-7w63-3f8qCVE-2024-7033 | same package and registry as the line abovemoderate | withdrawn 2026-09-02 | Time to revision 531 days |
| 2026-09-02published 2024-10-09 | same kind of change as the line above | GHSA-mq92-jr35-ffpcCVE-2024-7038 | same package and registry as the line abovelow | withdrawn 2026-09-02 | Time to revision 693 days |
| Tue 1 Sep 2026· 3 changes | |||||
| 2026-09-01published 2026-06-16 | Package added to advisory | GHSA-5r4w-85f3-pw66 | high | not named as affected when the advisory was published, now names github.com/traefik/traefik/v2 and 1 more | Time to revision 77 days |
| 2026-09-01published 2026-06-16 | same kind of change as the line above | GHSA-5r4w-85f3-pw66CVE-2026-48491 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/traefik/traefik/v2 | Time to revision 77 days |
| 2026-09-01published 2026-06-16 | same kind of change as the line above | GHSA-5r4w-85f3-pw66CVE-2026-48491 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names github.com/traefik/traefik/v3 | Time to revision 77 days |
| 2026-09-01published 2025-12-01 | Advisory severity changed | GHSA-569q-mpph-wgwwCVE-2025-71401 | whole advisoryhigh | stated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 274 days |
| Mon 31 Aug 2026· 1 change | |||||
| 2026-08-31published 2026-05-12 | Package added to advisory | GHSA-r29c-68gh-xp6xCVE-2026-41293 | critical | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 111 days |
| Fri 28 Aug 2026· 2 changes | |||||
| 2026-08-28published 2026-06-12 | Advisory severity changed | GHSA-9r4w-jg96-92mvCVE-2026-12681 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same. | Time to revision 77 days |
| 2026-08-28published 2026-07-02 | Advisory severity changed | GHSA-77pv-3w4q-vrj5CVE-2026-53834 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 57 days |
| Wed 26 Aug 2026· 1 change | |||||
| 2026-08-26published 2026-02-25 | Advisory severity changed | GHSA-wfx3-6g53-9fgcCVE-2026-56368 | whole advisorymoderate | stated at publication LOW, now states MODERATEA CVSS version was added; the existing vectors stayed the same. | Time to revision 182 days |
| Tue 25 Aug 2026· 1 change | |||||
| 2026-08-25published 2026-07-02 | Advisory severity changed | GHSA-83w9-h5wv-j9xmCVE-2026-53838 | whole advisorymoderate | stated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 54 days |
| Fri 21 Aug 2026· 2 changes | |||||
| 2026-08-21published 2026-07-24 to 2026-08-20 | Advisory severity changed | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 1 to 28 days | |
| 2026-08-21published 2026-08-20 | same kind of change as the line above | GHSA-fm29-4mq3-phg6 | same package and registry as the line abovehigh | same change as the line above | Time to revision 1 days |
| 2026-08-21published 2026-07-24 | same kind of change as the line above | GHSA-r292-9mhp-454mCVE-2026-73566 | same package and registry as the line abovehigh | same change as the line above | Time to revision 28 days |
| Fri 14 Aug 2026· 3 changes | |||||
| 2026-08-14published 2026-04-14 | Advisory fix version moved | GHSA-355h-qmc2-wpwfCVE-2026-2332 | mavenorg.eclipse.jetty:jetty-http high | stated at publication 11.0.28, now states 11.0.29 | Time to revision 35 days |
| 2026-08-14published 2026-02-19 | Package added to advisory | GHSA-p6jf-79j3-33f3CVE-2025-13590 | critical | not named as affected when the advisory was published, now names org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1 | Time to revision 176 days |
| 2026-08-14published 2026-04-29 | Package added to advisory | GHSA-w22p-4x9f-486vCVE-2026-42523 | critical | not named as affected when the advisory was published, now names com.coravy.hudson.plugins.github:github | Time to revision 107 days |
| Thu 13 Aug 2026· 1 change | |||||
| 2026-08-13published 2026-07-29 | Advisory fix version moved | GHSA-2v37-7h3g-55p8CVE-2026-67213 | npmnanoid high | stated at publication 3.3.17, now states 3.3.18 | Time to revision 15 days |
| Tue 11 Aug 2026· 1 change | |||||
| 2026-08-11published 2026-06-26 | Advisory severity changed | GHSA-4c3c-r6p8-c863CVE-2026-48813 | whole advisoryhigh | stated at publication LOW, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored. | Time to revision 46 days |
| Thu 6 Aug 2026· 1 change | |||||
| 2026-08-06published 2026-05-22 | Advisory fix version moved | GHSA-7m8f-hgjq-8gc9CVE-2026-70646 | pypiaiosend high | stated at publication 3.0.6, now states 3.0.7 | Time to revision 76 days |
| Tue 4 Aug 2026· 3 changes | |||||
| 2026-08-04published 2026-07-28 | Advisory fix version moved | GHSA-6wcc-39rp-hh9pCVE-2026-54658 | npm@hypequery/clickhouse critical | stated at publication 2.0.2, now states 2.5.1 | Time to revision 7 days |
| 2026-08-04published 2026-06-03 | Package added to advisory | GHSA-2j2x-hqr9-3h42CVE-2026-40181 | moderate | not named as affected when the advisory was published, now names @remix-run/router | Time to revision 62 days |
| 2026-08-04published 2026-07-21 | Package added to advisory | GHSA-w5pg-649r-p6ggCVE-2026-58439 | high | not named as affected when the advisory was published, now names code.gitea.io/gitea | Time to revision 13 days |
| Fri 31 Jul 2026· 6 changes | |||||
| 2026-07-31published 2026-04-07 | Advisory fix version moved | GHSA-89gg-p5r5-q6r4 | pypimonai high | stated at publication 1.5.2, now states 1.6.0 | Time to revision 115 days |
| 2026-07-31published 2026-07-21 | Package added to advisory | GHSA-m4p7-r5rc-7g4jCVE-2026-59884 | high | not named as affected when the advisory was published, now names pyasn1 | Time to revision 10 days |
| 2026-07-31published 2026-06-16 | Advisory severity changed | GHSA-8xpq-cjcf-3wh9CVE-2026-49401 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 45 days |
| 2026-07-31published 2023-08-29 to 2026-06-03 | Advisory withdrawn | whole advisorymoderate | withdrawn 2026-07-31 | Time to revision 58 to 1,067 days | |
| 2026-07-31published 2023-08-29 | same kind of change as the line above | GHSA-vmf9-6pcv-xr87CVE-2023-39522 | same package and registry as the line abovemoderate | withdrawn 2026-07-31 | Time to revision 1,067 days |
| 2026-07-31published 2026-06-03 | same kind of change as the line above | GHSA-v42x-x7jp-845hCVE-2026-6657 | same package and registry as the line abovemoderate | withdrawn 2026-07-31 | Time to revision 58 days |
| 2026-07-31published 2026-06-02 | same kind of change as the line above | GHSA-gf7q-q4j7-hp7cCVE-2026-5422 | same package and registry as the line abovemoderate | withdrawn 2026-07-31 | Time to revision 59 days |
| Thu 30 Jul 2026· 2 changes | |||||
| 2026-07-30published 2025-05-13 | Package added to advisory | GHSA-qqcr-9jfc-35c4 | high | not named as affected when the advisory was published, now names oxid-esales/oxideshop-metapackage-ce and 1 more | Time to revision 443 days |
| 2026-07-30published 2025-05-13 | same kind of change as the line above | GHSA-qqcr-9jfc-35c4CVE-2024-56526 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names oxid-esales/oxideshop-metapackage-ce | Time to revision 443 days |
| 2026-07-30published 2025-05-13 | same kind of change as the line above | GHSA-qqcr-9jfc-35c4CVE-2024-56526 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names oxid-esales/smarty-component | Time to revision 443 days |
| Tue 28 Jul 2026· 1 change | |||||
| 2026-07-28published 2025-08-27 | Advisory withdrawn | GHSA-cxm3-wv7p-598cCVE-2025-10894 | whole advisorycritical | withdrawn 2026-07-28 | Time to revision 335 days |
| Fri 24 Jul 2026· 1 change | |||||
| 2026-07-24published 2026-05-06 | Package added to advisory | GHSA-rwm7-x88c-3g2pCVE-2026-42577 | high | not named as affected when the advisory was published, now names io.netty:netty-transport-classes-epoll | Time to revision 79 days |
| Tue 21 Jul 2026· 7 changes | |||||
| 2026-07-21published 2026-05-07 | Package added to advisory | GHSA-g924-cjx7-2rjwCVE-2026-42597 | moderate | not named as affected when the advisory was published, now names github.com/gotenberg/gotenberg/v7 | Time to revision 76 days |
| 2026-07-21published 2026-04-14 | Package added to advisory | GHSA-2hx3-vp6r-mg3f | high | not named as affected when the advisory was published, now names microsoft.openapi.kiota and 1 more | Time to revision 98 days |
| 2026-07-21published 2026-04-14 | same kind of change as the line above | GHSA-2hx3-vp6r-mg3fCVE-2026-41134 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.openapi.kiota | Time to revision 98 days |
| 2026-07-21published 2026-04-14 | same kind of change as the line above | GHSA-2hx3-vp6r-mg3fCVE-2026-41134 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names microsoft.openapi.kiota.builder | Time to revision 98 days |
| 2026-07-21published 2025-08-26 | Advisory severity changed | whole advisoryhigh | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | Time to revision 329 to 329 days | |
| 2026-07-21published 2025-08-26 | same kind of change as the line above | GHSA-xp4f-hrf8-rxw7CVE-2025-71344 | same package and registry as the line abovehigh | same change as the line above | Time to revision 329 days |
| 2026-07-21published 2025-08-26 | same kind of change as the line above | GHSA-3vg9-h568-4w9mCVE-2025-71354 | same package and registry as the line abovehigh | same change as the line above | Time to revision 329 days |
| 2026-07-21published 2026-06-23 | Advisory severity changed | GHSA-vcm5-gvmp-78mpCVE-2026-52807 | whole advisorymoderate | stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version. | Time to revision 28 days |
| 2026-07-21published 2026-06-22 | Advisory severity changed | GHSA-c4v7-xg93-qf8gCVE-2026-47267 | whole advisoryhigh | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | Time to revision 29 days |
| Mon 20 Jul 2026· 2 changes | |||||
| 2026-07-20published 2025-08-26 | Advisory severity changed | GHSA-8r4j-24qv-fmq9CVE-2025-71361 | whole advisoryhigh | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | Time to revision 328 days |
| 2026-07-20published 2026-06-05 | Advisory severity changed | GHSA-jr54-jwhj-55gpCVE-2026-47380 | whole advisorymoderate | stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version. | Time to revision 45 days |
| Sat 18 Jul 2026· 1 change | |||||
| 2026-07-18published 2025-08-26 | Advisory severity changed | GHSA-6w4w-5w54-rjvrCVE-2025-71358 | whole advisoryhigh | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | Time to revision 326 days |
| Thu 16 Jul 2026· 1 change | |||||
| 2026-07-16published 2024-05-30 | Package added to advisory | GHSA-22q7-cg4r-p9mx | moderate | not named as affected when the advisory was published, now names typo3/cms-fluid | Time to revision 777 days |
| Wed 15 Jul 2026· 2 changes | |||||
| 2026-07-15published 2025-12-01 | Package added to advisory | GHSA-rcmh-qjqh-p98vCVE-2025-14874 | high | not named as affected when the advisory was published, now names org.webjars.npm:nodemailer | Time to revision 226 days |
| 2026-07-15published 2026-06-12 | Advisory severity changed | GHSA-4px2-pw77-vc85CVE-2026-28898 | whole advisorymoderate | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 33 days |
| Tue 7 Jul 2026· 2 changes | |||||
| 2026-07-07published 2026-05-08 | Package added to advisory | GHSA-mx76-r943-rf8gCVE-2026-8149 | moderate | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-lts8on | Time to revision 61 days |
| 2026-07-07published 2026-06-19 | Advisory severity changed | GHSA-qrpv-q767-xqq2CVE-2026-55255 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 18 days |
| Mon 6 Jul 2026· 38 changes | |||||
| 2026-07-06published 2026-06-18 | Package added to advisory | GHSA-jc38-x7x8-2xc8 | high | not named as affected when the advisory was published, now names web-token/jwt-bundle and 1 more | Time to revision 18 days |
| 2026-07-06published 2026-06-18 | same kind of change as the line above | GHSA-jc38-x7x8-2xc8 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names web-token/jwt-bundle | Time to revision 18 days |
| 2026-07-06published 2026-06-18 | same kind of change as the line above | GHSA-jc38-x7x8-2xc8 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names web-token/jwt-experimental | Time to revision 18 days |
| 2026-07-06published 2026-03-19 to 2026-06-26 | Package added to advisory | 3 bands | not named as affected when the advisory was published, now names scriban.signed | Time to revision 10 to 109 days | |
| 2026-07-06published 2026-06-26 | same kind of change as the line above | GHSA-6q7j-xr26-3h2c | same package registry as the line abovemoderate | same change as the line above | Time to revision 10 days |
| 2026-07-06published 2026-03-24 | same kind of change as the line above | GHSA-xw6w-9jjh-p9cr | same package registry as the line abovemoderate | same change as the line above | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | same kind of change as the line above | GHSA-m2p3-hwv5-xpqw | same package registry as the line abovemoderate | same change as the line above | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | same kind of change as the line above | GHSA-xcx6-vp38-8hr5 | same package registry as the line abovehigh | same change as the line above | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | same kind of change as the line above | GHSA-v66j-x4hw-fv9g | same package registry as the line abovehigh | same change as the line above | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | same kind of change as the line above | GHSA-5wr9-m6jw-xx44 | same package registry as the line abovecritical | same change as the line above | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | same kind of change as the line above | GHSA-x6m9-38vm-2xhf | same package registry as the line abovehigh | same change as the line above | Time to revision 104 days |
| 2026-07-06published 2026-03-24 | same kind of change as the line above | GHSA-p6q4-fgr8-vx4p | same package registry as the line abovehigh | same change as the line above | Time to revision 104 days |
| 5 more rows in this change are not listed here. Open all 13 rows → | |||||
| 2026-07-06published 2026-04-22 | Advisory withdrawn | whole advisory3 bands | withdrawn 2026-07-06 | Time to revision 75 to 75 days | |
| 2026-07-06published 2026-04-22 | same kind of change as the line above | GHSA-532v-xp3f-837c | same package and registry as the line abovelow | withdrawn 2026-07-06 | Time to revision 75 days |
| 2026-07-06published 2026-04-22 | same kind of change as the line above | GHSA-79rc-qpw3-jv92 | same package and registry as the line abovelow | withdrawn 2026-07-06 | Time to revision 75 days |
| 2026-07-06published 2026-04-22 | same kind of change as the line above | GHSA-w8m4-4v35-v6x3 | same package and registry as the line abovehigh | withdrawn 2026-07-06 | Time to revision 75 days |
| 2026-07-06published 2026-04-22 | same kind of change as the line above | GHSA-7259-cwhx-3xx3 | same package and registry as the line abovemoderate | withdrawn 2026-07-06 | Time to revision 75 days |
| 2026-07-06published 2026-04-22 | same kind of change as the line above | GHSA-ggc5-46rg-mr4v | same package and registry as the line abovelow | withdrawn 2026-07-06 | Time to revision 75 days |
| 2026-07-06published 2026-04-22 | same kind of change as the line above | GHSA-66fx-fqv6-5wwx | same package and registry as the line abovemoderate | withdrawn 2026-07-06 | Time to revision 75 days |
| 2026-07-06published 2026-04-22 | same kind of change as the line above | GHSA-67hp-f6hq-2h6g | same package and registry as the line abovemoderate | withdrawn 2026-07-06 | Time to revision 75 days |
| 2026-07-06published 2026-04-22 | same kind of change as the line above | GHSA-vchc-9ggh-3236 | same package and registry as the line abovemoderate | withdrawn 2026-07-06 | Time to revision 75 days |
| 15 more rows in this change are not listed here. Open all 23 rows → | |||||
| Thu 2 Jul 2026· 4 changes | |||||
| 2026-07-02published 2026-06-19 | Advisory fix version moved | GHSA-h3m5-97jq-qjrfCVE-2026-57168 | mavenio.openremote:openremote-manager critical | stated at publication 1.24.2, now states 1.25.0 | Time to revision 13 days |
| 2026-07-02published 2026-04-29 | Advisory severity changed | GHSA-5843-p793-ghmmCVE-2026-22740 | whole advisorymoderate | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 64 days |
| 2026-07-02published 2026-05-27 | Advisory severity changed | GHSA-6439-2f28-8p8qCVE-2026-45075 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 36 days |
| 2026-07-02published 2026-03-18 | Advisory withdrawn | GHSA-wmxr-6j5f-838p | whole advisoryhigh | withdrawn 2026-07-02 | Time to revision 107 days |
| Wed 1 Jul 2026· 5 changes | |||||
| 2026-07-01published 2024-11-07 to 2025-08-13 | Package added to advisory | 2 bands | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | Time to revision 322 to 601 days | |
| 2026-07-01published 2024-11-07 | same kind of change as the line above | GHSA-7jqf-v358-p8g7CVE-2024-38286 | same package registry as the line abovehigh | same change as the line above | Time to revision 601 days |
| 2026-07-01published 2025-08-13 | same kind of change as the line above | GHSA-23hv-mwm6-g8jfCVE-2025-55668 | same package registry as the line abovemoderate | same change as the line above | Time to revision 322 days |
| 2026-07-01published 2025-07-10 | same kind of change as the line above | GHSA-4j3c-42xv-3f84CVE-2025-52434 | same package registry as the line abovemoderate | same change as the line above | Time to revision 356 days |
| 2026-07-01published 2024-11-07 to 2025-07-10 | Package added to advisory | 2 bands | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 356 to 601 days | |
| 2026-07-01published 2024-11-07 | same kind of change as the line above | GHSA-7jqf-v358-p8g7CVE-2024-38286 | same package registry as the line abovehigh | same change as the line above | Time to revision 601 days |
| 2026-07-01published 2025-07-10 | same kind of change as the line above | GHSA-4j3c-42xv-3f84CVE-2025-52434 | same package registry as the line abovemoderate | same change as the line above | Time to revision 356 days |
| Tue 30 Jun 2026· 2 changes | |||||
| 2026-06-30published 2024-01-12 | Advisory severity changed | GHSA-8qw9-gf7w-42x5 | whole advisorymoderate | stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version. | Time to revision 900 days |
| 2026-06-30published 2026-05-26 | Advisory withdrawn | GHSA-76v6-f83q-pxvh | whole advisoryhigh | withdrawn 2026-06-30 | Time to revision 35 days |
| Mon 29 Jun 2026· 3 changes | |||||
| 2026-06-29published 2026-02-17 | Package added to advisory | GHSA-qq5r-98hh-rxc9CVE-2026-24733 | low | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 132 days |
| 2026-06-29published 2026-05-19 | Package added to advisory | GHSA-24c8-4792-22hx | high | not named as affected when the advisory was published, now names scriban.signed | Time to revision 41 days |
| 2026-06-29published 2019-10-11 | Package added to advisory | GHSA-p979-4mfw-53vgCVE-2019-16869 | high | not named as affected when the advisory was published, now names io.netty:netty | Duration unknown |
| Fri 26 Jun 2026· 2 changes | |||||
| 2026-06-26published 2026-05-29 | Package added to advisory | GHSA-6x26-5727-rrm9CVE-2026-47268 | moderate | not named as affected when the advisory was published, now names github.com/naiba/nezha | Time to revision 28 days |
| 2026-06-26published 2026-06-10 | Package added to advisory | GHSA-8h84-fhqq-q58vCVE-2026-48025 | moderate | not named as affected when the advisory was published, now names github.com/forgekeep/nebula-mesh | Time to revision 16 days |
| Thu 18 Jun 2026· 8 changes | |||||
| 2026-06-18published 2024-01-19 | Package added to advisory | GHSA-f4qf-m5gf-8jm8CVE-2024-21733 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat.experimental:tomcat-embed-programmatic | Time to revision 881 days |
| 2026-06-18published 2026-04-09 | Package added to advisory | GHSA-x4m4-345f-5h5gCVE-2026-34487 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-tribes | Time to revision 70 days |
| 2026-06-18published 2024-11-18 | Package added to advisory | GHSA-f632-9449-3j4wCVE-2024-52318 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-jasper | Time to revision 577 days |
| 2026-06-18published 2019-05-30 to 2024-11-18 | Package added to advisory | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat | Time to revision 577 days | |
| 2026-06-18published 2024-11-18 | same kind of change as the line above | GHSA-f632-9449-3j4wCVE-2024-52318 | same package registry as the line abovemoderate | same change as the line above | Time to revision 577 days |
| 2026-06-18published 2019-05-30 | same kind of change as the line above | GHSA-jjpq-gp5q-8q6wCVE-2019-0221 | same package registry as the line abovemoderate | same change as the line above | Duration unknown |
| 2026-06-18published 2019-05-30 to 2023-02-20 | Package added to advisory | 2 bands | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina | Time to revision 1,214 days | |
| 2026-06-18published 2023-02-20 | same kind of change as the line above | GHSA-hfrx-6qgj-fp6cCVE-2023-24998 | same package registry as the line abovehigh | same change as the line above | Time to revision 1,214 days |
| 2026-06-18published 2019-05-30 | same kind of change as the line above | GHSA-jjpq-gp5q-8q6wCVE-2019-0221 | same package registry as the line abovemoderate | same change as the line above | Duration unknown |
| 2026-06-18published 2022-02-10 | Advisory severity changed | GHSA-xp4x-j9vh-c3wfCVE-2019-15609 | whole advisorycritical | stated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same. | Duration unknown |
| Wed 17 Jun 2026· 1 change | |||||
| 2026-06-17published 2026-06-12 | Advisory withdrawn | GHSA-gv7w-rqvm-qjhr | whole advisoryhigh | withdrawn 2026-06-17 | Time to revision 5 days |
| Fri 12 Jun 2026· 4 changes | |||||
| 2026-06-12published 2023-10-10 to 2026-02-17 | Package added to advisory | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 115 to 976 days | |
| 2026-06-12published 2023-10-10 | same kind of change as the line above | GHSA-r6j3-px5g-cq3xCVE-2023-45648 | same package registry as the line abovemoderate | same change as the line above | Time to revision 976 days |
| 2026-06-12published 2026-02-17 | same kind of change as the line above | GHSA-fpj8-gq4v-p354CVE-2025-66614 | same package registry as the line abovemoderate | same change as the line above | Time to revision 115 days |
| 2026-06-12published 2023-10-10 | Package added to advisory | GHSA-g8pj-r55q-5c2v | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina and 1 more | Time to revision 976 days |
| 2026-06-12published 2023-10-10 | same kind of change as the line above | GHSA-g8pj-r55q-5c2vCVE-2023-42795 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina | Time to revision 976 days |
| 2026-06-12published 2023-10-10 | same kind of change as the line above | GHSA-g8pj-r55q-5c2vCVE-2023-42795 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-util | Time to revision 976 days |
| Thu 11 Jun 2026· 6 changes | |||||
| 2026-06-11published 2026-05-07 | Package added to advisory | GHSA-2mh5-3cw6-hrrqCVE-2026-40981 | high | not named as affected when the advisory was published, now names org.springframework.cloud:spring-cloud-config-server | Time to revision 35 days |
| 2026-06-11published 2022-02-08 | Package added to advisory | GHSA-m7jv-hq7h-mq7c | high | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocket and 1 more | Duration unknown |
| 2026-06-11published 2022-02-08 | same kind of change as the line above | GHSA-m7jv-hq7h-mq7cCVE-2020-13935 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocket | Duration unknown |
| 2026-06-11published 2022-02-08 | same kind of change as the line above | GHSA-m7jv-hq7h-mq7cCVE-2020-13935 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-websocket | Duration unknown |
| 2026-06-11published 2022-02-09 | Package added to advisory | GHSA-53hp-jpwq-2jgqCVE-2020-11996 | high | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | Duration unknown |
| 2026-06-11published 2023-05-30 | Advisory severity changed | GHSA-mj6p-3pc9-wf5mCVE-2023-2968 | whole advisoryhigh | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | Time to revision 1,108 days |
| 2026-06-11published 2024-04-18 | Advisory severity changed | GHSA-jjff-q3q4-5hh8CVE-2024-30564 | whole advisorycritical | stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version. | Time to revision 784 days |
| Tue 9 Jun 2026· 15 changes | |||||
| 2026-06-09published 2021-08-25 to 2022-01-06 | Advisory fix version moved | crates.ioactix-web 2 bands | stated at publication 0.7.15, now states 0.7.19 | Duration unknown | |
| 2026-06-09published 2022-01-06 | same kind of change as the line above | GHSA-9qj6-4rfq-vm84CVE-2018-25024 | same package and registry as the line abovecritical | same change as the line above | Duration unknown |
| 2026-06-09published 2022-01-06 | same kind of change as the line above | GHSA-7x36-h62w-vw65CVE-2018-25026 | same package and registry as the line abovecritical | same change as the line above | Duration unknown |
| 2026-06-09published 2022-01-06 | same kind of change as the line above | GHSA-fgfm-hqjw-3265CVE-2018-25025 | same package and registry as the line abovecritical | same change as the line above | Duration unknown |
| 2026-06-09published 2021-08-25 | same kind of change as the line above | GHSA-w65j-g6c7-g3m4 | same package and registry as the line abovemoderate | same change as the line above | Duration unknown |
| 2026-06-09published 2026-06-01 | Package added to advisory | GHSA-q53q-5r4j-5729CVE-2026-47425 | moderate | not named as affected when the advisory was published, now names py-rattler | Time to revision 8 days |
| 2026-06-09published 2026-05-29 | Advisory severity changed | GHSA-j6fm-9rfm-j5hxCVE-2026-41237 | whole advisoryhigh | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | Time to revision 11 days |
| 2026-06-09published 2022-05-24 | Advisory severity changed | GHSA-4hm9-844j-jmxpCVE-2019-13117 | whole advisorymoderate | stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version. | Time to revision 1,477 days |
| 2026-06-09published 2026-05-12 | Advisory severity changed | GHSA-3636-h3vx-6465CVE-2026-44593 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version. | Time to revision 27 days |
| 2026-06-09published 2026-05-15 | Advisory severity changed | GHSA-rmqr-h98c-qg2m | whole advisoryhigh | stated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored. | Time to revision 24 days |
| 2026-06-09published 2026-02-18 to 2026-05-15 | Advisory withdrawn | whole advisory2 bands | withdrawn 2026-06-09 | Time to revision 24 to 112 days | |
| 2026-06-09published 2026-02-18 | same kind of change as the line above | GHSA-wgm6-9rvv-3438CVE-2026-26957 | same package and registry as the line abovemoderate | withdrawn 2026-06-09 | Time to revision 112 days |
| 2026-06-09published 2026-05-15 | same kind of change as the line above | GHSA-5h62-f8fg-4w7q | same package and registry as the line abovemoderate | withdrawn 2026-06-09 | Time to revision 24 days |
| 2026-06-09published 2026-05-15 | same kind of change as the line above | GHSA-wj3q-vw2v-3rj3 | same package and registry as the line abovemoderate | withdrawn 2026-06-09 | Time to revision 24 days |
| 2026-06-09published 2026-05-15 | same kind of change as the line above | GHSA-9r8r-x3vg-6xh4 | same package and registry as the line abovemoderate | withdrawn 2026-06-09 | Time to revision 24 days |
| 2026-06-09published 2026-05-15 | same kind of change as the line above | GHSA-rmqr-h98c-qg2m | same package and registry as the line abovehigh | withdrawn 2026-06-09 | Time to revision 24 days |
| 2026-06-09published 2026-05-15 | same kind of change as the line above | GHSA-h36g-93qx-rxgr | same package and registry as the line abovemoderate | withdrawn 2026-06-09 | Time to revision 24 days |
| Mon 8 Jun 2026· 8 changes | |||||
| 2026-06-08published 2026-05-15 | Package added to advisory | GHSA-w42g-jj8w-fj77 | high | not named as affected when the advisory was published, now names thorsten/phpmyfaq | Time to revision 24 days |
| 2026-06-08published 2021-04-13 | Package added to advisory | GHSA-3pcr-4982-548m | moderate | not named as affected when the advisory was published, now names shopware/shopware | Duration unknown |
| 2026-06-08published 2025-10-15 | Package added to advisory | GHSA-6p6v-m64v-jx8qCVE-2025-55039 | low | not named as affected when the advisory was published, now names pyspark | Time to revision 236 days |
| 2026-06-08published 2026-03-25 | Package added to advisory | GHSA-7h8w-hj9j-8rjwCVE-2026-33718 | high | not named as affected when the advisory was published, now names openhands-ai | Time to revision 75 days |
| 2026-06-08published 2022-05-02 | Advisory severity changed | GHSA-f7w7-6pjc-wwm6CVE-2009-3555 | whole advisorycritical | stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version. | Time to revision 1,499 days |
| 2026-06-08published 2026-03-03 | Advisory severity changed | GHSA-p4wh-cr8m-gm6cCVE-2026-22217 | whole advisorymoderate | stated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 97 days |
| 2026-06-08published 2025-10-15 | Advisory severity changed | GHSA-6p6v-m64v-jx8qCVE-2025-55039 | whole advisorylow | stated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 236 days |
| 2026-06-08published 2026-05-15 | Advisory withdrawn | GHSA-w42g-jj8w-fj77 | whole advisoryhigh | withdrawn 2026-06-08 | Time to revision 24 days |
| Sat 6 Jun 2026· 1 change | |||||
| 2026-06-06published 2026-03-18 | Advisory fix version moved | GHSA-rf6x-r45m-xv3wCVE-2026-33053 | pypilangflow high | stated at publication 1.7.2, now states 1.9.0 | Time to revision 80 days |
| Fri 5 Jun 2026· 4 changes | |||||
| 2026-06-05published 2023-08-25 | Package added to advisory | GHSA-q3mw-pvr8-9ggcCVE-2023-41080 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-catalina | Time to revision 1,015 days |
| 2026-06-05published 2021-06-16 | Package added to advisory | GHSA-j39c-c8hj-x4j3CVE-2021-25122 | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Duration unknown |
| 2026-06-05published 2026-04-18 | Package added to advisory | GHSA-w9r4-94fj-xp69CVE-2026-32690 | low | not named as affected when the advisory was published, now names apache-airflow | Time to revision 48 days |
| 2026-06-05published 2025-09-24 | Package added to advisory | GHSA-776q-jw43-fhjxCVE-2025-48459 | critical | not named as affected when the advisory was published, now names apache-iotdb | Time to revision 254 days |
| Mon 1 Jun 2026· 2 changes | |||||
| 2026-06-01published 2026-05-18 | Package added to advisory | GHSA-v549-xx3c-6pc8 | moderate | not named as affected when the advisory was published, now names github.com/mattermost/mattermost-server and 1 more | Time to revision 14 days |
| 2026-06-01published 2026-05-18 | same kind of change as the line above | GHSA-v549-xx3c-6pc8CVE-2026-3637 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names github.com/mattermost/mattermost-server | Time to revision 14 days |
| 2026-06-01published 2026-05-18 | same kind of change as the line above | GHSA-v549-xx3c-6pc8CVE-2026-3637 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names github.com/mattermost/mattermost/server/v8 | Time to revision 14 days |
| Fri 29 May 2026· 1 change | |||||
| 2026-05-29published 2026-04-22 | Package added to advisory | GHSA-ffq5-qpvf-xq7xCVE-2026-42086 | moderate | not named as affected when the advisory was published, now names openc3 | Time to revision 37 days |
| Thu 28 May 2026· 1 change | |||||
| 2026-05-28published 2026-04-27 | Advisory withdrawn | GHSA-c8g3-x47w-8q7p | whole advisoryhigh | withdrawn 2026-05-28 | Time to revision 31 days |
| Wed 20 May 2026· 10 changes | |||||
| 2026-05-20published 2024-10-09 | Advisory fix version moved | GHSA-pfr9-2p92-qrhq | crates.iodbn moderate | stated at publication 0.22.0, now states 0.22.1 | Time to revision 587 days |
| 2026-05-20published 2023-06-14 | Package added to advisory | GHSA-5wfc-hjrc-gq87CVE-2023-34620 | high | not named as affected when the advisory was published, now names github.com/hjson/hjson-go/v4 | Time to revision 1,071 days |
| 2026-05-20published 2023-06-14 | Package added to advisory | GHSA-5wfc-hjrc-gq87CVE-2023-34620 | high | not named as affected when the advisory was published, now names laktak/hjson | Time to revision 1,071 days |
| 2026-05-20published 2020-06-15 to 2026-04-09 | Package added to advisory | high | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | Time to revision 41 days | |
| 2026-05-20published 2026-04-09 | same kind of change as the line above | GHSA-69cc-cv78-qc8gCVE-2026-29129 | same package registry as the line abovehigh | same change as the line above | Time to revision 41 days |
| 2026-05-20published 2020-06-15 | same kind of change as the line above | GHSA-qcxh-w3j9-58qrCVE-2019-0199 | same package registry as the line abovehigh | same change as the line above | Duration unknown |
| 2026-05-20published 2026-04-09 | Package added to advisory | 2 bands | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote-ffm | Time to revision 40 to 41 days | |
| 2026-05-20published 2026-04-09 | same kind of change as the line above | GHSA-95jq-rwvf-vjx4CVE-2026-29145 | same package registry as the line abovecritical | same change as the line above | Time to revision 41 days |
| 2026-05-20published 2026-04-09 | same kind of change as the line above | GHSA-24j9-x2wg-9qv6CVE-2026-34500 | same package registry as the line abovemoderate | same change as the line above | Time to revision 40 days |
| 2026-05-20published 2024-12-17 | Package added to advisory | GHSA-653p-vg55-5652CVE-2024-54677 | moderate | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat | Time to revision 519 days |
| 2026-05-20published 2026-03-31 | Package added to advisory | GHSA-rvhj-8chj-8v3cCVE-2026-0596 | critical | not named as affected when the advisory was published, now names mlflow | Time to revision 49 days |
| 2026-05-20published 2026-04-16 | Advisory severity changed | GHSA-v92g-xgxw-vvmmCVE-2026-41205 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 33 days |
Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.
What this page cannot see
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →
Paste your closed CVE tickets and see which of these changes hit them →