Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2025-6384 created 4 weeks, 1 day ago Improper Control of Dynamically-Managed Code Resources in Crafter Studio Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain RCE (Remote Code Execution). This issue affects CrafterCMS: from 4.0.0 through 4.2.2. Studio <4.3.0 pkgs.rstudio Set of integrated tools for the R language nixos-unstable ??? nixpkgs-unstable 2025.05.1+513 pkgs.rstudio-server Set of integrated tools for the R language nixos-unstable ??? nixpkgs-unstable 2025.05.1+513 pkgs.rstudioWrapper nixos-unstable ??? nixpkgs-unstable 2025.05.1+513-wrapper pkgs.rstudioServerWrapper nixos-unstable ??? nixpkgs-unstable 2025.05.1+513-wrapper pkgs.vscode-extensions.visualstudiotoolsforunity.vstuc Integrates Visual Studio Code for Unity nixos-unstable ??? nixpkgs-unstable 1.1.3 pkgs.vscode-extensions.visualstudioexptteam.vscodeintellicode AI-assisted development nixos-unstable ??? nixpkgs-unstable 1.3.2 pkgs.vscode-extensions.visualstudioexptteam.intellicode-api-usage-examples See relevant code examples from GitHub for over 100K different APIs right in your editor nixos-unstable ??? nixpkgs-unstable 0.2.9 Package maintainers: 5 @ciil Simon Lackerbauer <simon@lackerbauer.com> @cfhammill Chris Hammill <cfhammill@gmail.com> @TomaSajt TomaSajt @TheMaxMur Maxim Muravev <muravjev.mak@yandex.ru> @mibmo mib <mib@kanp.ai> CVE-2025-23999 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 4 weeks, 1 day ago WordPress Breeze plugin <= 2.2.13 - Broken Access Control vulnerability Missing Authorization vulnerability in Cloudways Breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through 2.2.13. breeze =<2.2.13 pkgs.kdePackages.breeze Artwork, styles and assets for the Breeze visual style for the Plasma Desktop nixos-unstable ??? nixpkgs-unstable 6.4.5 pkgs.kdePackages.breeze-gtk Breeze widget theme for GTK 2 and 3 nixos-unstable ??? nixpkgs-unstable 6.4.5 pkgs.kdePackages.breeze-grub GRUB theme for the Breeze visual style for the Plasma Desktop nixos-unstable ??? nixpkgs-unstable 6.4.5 pkgs.libsForQt5.breeze-icons nixos-unstable ??? nixpkgs-unstable 5.116.0 pkgs.kdePackages.breeze-icons Breeze icon theme. nixos-unstable ??? nixpkgs-unstable 6.18.0 pkgs.breeze-hacked-cursor-theme Breeze Hacked cursor theme nixos-unstable ??? nixpkgs-unstable 0-unstable-2024-01-28 pkgs.kdePackages.breeze-plymouth Plymouth theme for the Breeze visual style for the Plasma Desktop nixos-unstable ??? nixpkgs-unstable 6.4.5 pkgs.python312Packages.seabreeze Python library to access Ocean Optics spectrometers nixos-unstable ??? nixpkgs-unstable 2.10.1 pkgs.python313Packages.seabreeze Python library to access Ocean Optics spectrometers nixos-unstable ??? nixpkgs-unstable 2.10.1 pkgs.plasma5Packages.breeze-icons nixos-unstable ??? nixpkgs-unstable 5.116.0 pkgs.kdePackages.qqc2-breeze-style Breeze inspired QQC2 Style nixos-unstable ??? nixpkgs-unstable 6.4.5 pkgs.wordpressPackages.plugins.breeze nixos-unstable ??? nixpkgs-unstable 2.2.9 pkgs.kdePackages.sierra-breeze-enhanced OSX-like window decoration for KDE Plasma written in C++ nixos-unstable ??? nixpkgs-unstable 2.1.1 pkgs.qt6Packages.sierra-breeze-enhanced OSX-like window decoration for KDE Plasma written in C++ nixos-unstable ??? nixpkgs-unstable 2.1.1 Package maintainers: 10 @A1ca7raz A1ca7raz <aya@wtm.moe> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> @ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru> @ttuegel Thomas Tuegel <ttuegel@mailbox.org> @NickCao Nick Cao <nickcao@nichi.co> @mjm Matt Moriarity <matt@mattmoriarity.com> @LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev> @K900 Ilya K. <me@0upti.me> @nyanloutre Paul Trehiou <paul@nyanlout.re> @Anomalocaridid Duncan Russell <duncan@anomalocaris.xyz> CVE-2025-49254 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 4 weeks, 1 day ago WordPress Nika <= 1.2.8 - Local File Inclusion Vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Nika allows PHP Local File Inclusion. This issue affects Nika: from n/a through 1.2.8. nika =<1.2.8 pkgs.nika-fonts Persian/Arabic Open Source Font nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.python312Packages.minikanren Relational programming in Python nixos-unstable ??? nixpkgs-unstable 1.0.5 pkgs.python313Packages.minikanren Relational programming in Python nixos-unstable ??? nixpkgs-unstable 1.0.5 Package maintainers: 1 @Etjean Etienne Jean <et.jean@outlook.fr> CVE-2025-49179 6.6 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): HIGH created 4 weeks, 1 day ago Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x record extension A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks. tigervnc * xorg-x11-server * xorg-x11-server-Xwayland * pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0 CVE-2025-49259 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 4 weeks, 1 day ago WordPress Hara <= 1.2.10 - Local File Inclusion Vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Hara allows PHP Local File Inclusion. This issue affects Hara: from n/a through 1.2.10. hara =<1.2.10 pkgs.charasay Future of cowsay - Colorful characters saying something nixos-unstable ??? nixpkgs-unstable 3.3.0 pkgs.gnome-characters Simple utility application to find and insert unusual characters nixos-unstable ??? nixpkgs-unstable 48.0 pkgs.keepass-charactercopy nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.unicode-character-database Unicode Character Database nixos-unstable ??? nixpkgs-unstable 16.0.0 pkgs.haskellPackages.character-ps Pattern synonyms for ASCII characters for Word8, Word16 etc nixos-unstable ??? nixpkgs-unstable 0.1 pkgs.coqPackages.mathcomp-character nixos-unstable ??? nixpkgs-unstable 2.4.0 pkgs.python312Packages.characteristic Python attributes without boilerplate nixos-unstable ??? nixpkgs-unstable 14.3.0 pkgs.python313Packages.characteristic Python attributes without boilerplate nixos-unstable ??? nixpkgs-unstable 14.3.0 pkgs.magnetophonDSP.CharacterCompressor Compressor with character. For jack and lv2 nixos-unstable ??? nixpkgs-unstable 0.3.3 pkgs.python312Packages.character-encoding-utils Some character encoding utils nixos-unstable ??? nixpkgs-unstable 0.0.9 pkgs.python313Packages.character-encoding-utils Some character encoding utils nixos-unstable ??? nixpkgs-unstable 0.0.9 Package maintainers: 11 @hmajid2301 Haseeb Majid <hello@haseebmajid.dev> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @jtojnar Jan Tojnar <jtojnar@gmail.com> @bobby285271 Bobby Rong <rjl931189261@126.com> @h7x4 h7x4 <h7x4@nani.wtf> @TakWolf TakWolf <takwolf@foxmail.com> @vbgl Vincent Laporte <Vincent.Laporte@gmail.com> @jwiegley John Wiegley <johnw@newartisans.com> @CohenCyril Cyril Cohen <cyril.cohen@inria.fr> @magnetophon Bart Brouns <bart@magnetophon.nl> CVE-2025-49175 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 4 weeks, 1 day ago Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: out-of-bounds read in x rendering extension animated cursors A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potential crash. tigervnc * xorg-x11-server * xorg-x11-server-Xwayland * pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0 CVE-2025-49176 6.6 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): HIGH created 4 weeks, 1 day ago Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in big requests extension A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check. tigervnc * xorg-x11-server * xorg-x11-server-Xwayland * pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0 CVE-2025-24761 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 4 weeks, 1 day ago CISA ADP Vulnrichment None dsk =<2.2 pkgs.idsk Manipulating CPC dsk images and files nixos-unstable ??? nixpkgs-unstable 0.20 pkgs.libdsk Library for accessing discs and disc image files nixos-unstable ??? nixpkgs-unstable 1.5.22 pkgs.robotfindskitten Yet another zen simulation; A simple find-the-kitten game nixos-unstable ??? nixpkgs-unstable 2.8284271.702 pkgs.python312Packages.pmdsky-debug-py Autogenerated and statically check-able pmdsky-debug symbol definitions for Python nixos-unstable ??? nixpkgs-unstable 10.0.48 pkgs.python313Packages.pmdsky-debug-py Autogenerated and statically check-able pmdsky-debug symbol definitions for Python nixos-unstable ??? nixpkgs-unstable 10.0.48 Package maintainers: 2 @wegank Weijia Wang <contact@weijia.wang> @marius851000 Marius David <mariusdavid@laposte.net> CVE-2025-31919 9.8 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 4 weeks, 1 day ago WordPress Spare <= 1.7 - PHP Object Injection Vulnerability Deserialization of Untrusted Data vulnerability in themeton Spare allows Object Injection. This issue affects Spare: from n/a through 1.7. spare =<1.7 pkgs.asciiquarium-transparent Aquarium/sea animation in ASCII art (with option of transparent background) nixos-unstable ??? nixpkgs-unstable 1.4 pkgs.materia-theme-transparent Transparent Material Design theme for GNOME/GTK based desktop environments nixos-unstable ??? nixpkgs-unstable 0-unstable-2021-03-22 pkgs.gnomeExtensions.transparent-top-bar Bring back the transparent top bar when free-floating in GNOME Shell 3.32. nixos-unstable ??? nixpkgs-unstable 24 pkgs.gnomeExtensions.transparent-window-moving Makes the window semi-transparent when moving or resizing nixos-unstable ??? nixpkgs-unstable 19 pkgs.sway-contrib.inactive-windows-transparency It makes inactive sway windows transparent nixos-unstable ??? nixpkgs-unstable 0-unstable-2024-03-19 pkgs.gnomeExtensions.transparent-top-bar-adjustable-transparency Fork of: https://github.com/zhanghai/gnome-shell-extension-transparent-top-bar nixos-unstable ??? nixpkgs-unstable 24 Package maintainers: 4 @quantenzitrone quantenzitrone <nix@dev.quantenzitrone.eu> @evils Evils <evils.devils@protonmail.com> @honnip Jung seungwoo <me@honnip.page> @CorbinWunderlich Corbin Wunderlich <corbin@wcopy.net> CVE-2025-49253 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 4 weeks, 1 day ago WordPress Lasa <= 1.1 - Local File Inclusion Vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Lasa allows PHP Local File Inclusion. This issue affects Lasa: from n/a through 1.1. lasa =<1.1 pkgs.typstPackages.lasagna_0_1_0 Add layers, toggle them using tags easily nixos-unstable ??? nixpkgs-unstable 0.1.0 pkgs.typstPackages.lasaveur_0_1_3 Porting vim-latex's math shorthands to Typst. An accommendating vim syntax file is provided in the repo nixos-unstable ??? nixpkgs-unstable 0.1.3 pkgs.typstPackages.lasaveur_0_1_4 Porting vim-latex's math shorthands to Typst. An accommendating vim syntax file is provided in the repo nixos-unstable ??? nixpkgs-unstable 0.1.4 Package maintainers: 1 @cherrypiejam Gongqi Huang
CVE-2025-6384 created 4 weeks, 1 day ago Improper Control of Dynamically-Managed Code Resources in Crafter Studio Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain RCE (Remote Code Execution). This issue affects CrafterCMS: from 4.0.0 through 4.2.2. Studio <4.3.0 pkgs.rstudio Set of integrated tools for the R language nixos-unstable ??? nixpkgs-unstable 2025.05.1+513 pkgs.rstudio-server Set of integrated tools for the R language nixos-unstable ??? nixpkgs-unstable 2025.05.1+513 pkgs.rstudioWrapper nixos-unstable ??? nixpkgs-unstable 2025.05.1+513-wrapper pkgs.rstudioServerWrapper nixos-unstable ??? nixpkgs-unstable 2025.05.1+513-wrapper pkgs.vscode-extensions.visualstudiotoolsforunity.vstuc Integrates Visual Studio Code for Unity nixos-unstable ??? nixpkgs-unstable 1.1.3 pkgs.vscode-extensions.visualstudioexptteam.vscodeintellicode AI-assisted development nixos-unstable ??? nixpkgs-unstable 1.3.2 pkgs.vscode-extensions.visualstudioexptteam.intellicode-api-usage-examples See relevant code examples from GitHub for over 100K different APIs right in your editor nixos-unstable ??? nixpkgs-unstable 0.2.9 Package maintainers: 5 @ciil Simon Lackerbauer <simon@lackerbauer.com> @cfhammill Chris Hammill <cfhammill@gmail.com> @TomaSajt TomaSajt @TheMaxMur Maxim Muravev <muravjev.mak@yandex.ru> @mibmo mib <mib@kanp.ai>
pkgs.rstudio Set of integrated tools for the R language nixos-unstable ??? nixpkgs-unstable 2025.05.1+513
pkgs.rstudio-server Set of integrated tools for the R language nixos-unstable ??? nixpkgs-unstable 2025.05.1+513
pkgs.vscode-extensions.visualstudiotoolsforunity.vstuc Integrates Visual Studio Code for Unity nixos-unstable ??? nixpkgs-unstable 1.1.3
pkgs.vscode-extensions.visualstudioexptteam.vscodeintellicode AI-assisted development nixos-unstable ??? nixpkgs-unstable 1.3.2
pkgs.vscode-extensions.visualstudioexptteam.intellicode-api-usage-examples See relevant code examples from GitHub for over 100K different APIs right in your editor nixos-unstable ??? nixpkgs-unstable 0.2.9
CVE-2025-23999 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 4 weeks, 1 day ago WordPress Breeze plugin <= 2.2.13 - Broken Access Control vulnerability Missing Authorization vulnerability in Cloudways Breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through 2.2.13. breeze =<2.2.13 pkgs.kdePackages.breeze Artwork, styles and assets for the Breeze visual style for the Plasma Desktop nixos-unstable ??? nixpkgs-unstable 6.4.5 pkgs.kdePackages.breeze-gtk Breeze widget theme for GTK 2 and 3 nixos-unstable ??? nixpkgs-unstable 6.4.5 pkgs.kdePackages.breeze-grub GRUB theme for the Breeze visual style for the Plasma Desktop nixos-unstable ??? nixpkgs-unstable 6.4.5 pkgs.libsForQt5.breeze-icons nixos-unstable ??? nixpkgs-unstable 5.116.0 pkgs.kdePackages.breeze-icons Breeze icon theme. nixos-unstable ??? nixpkgs-unstable 6.18.0 pkgs.breeze-hacked-cursor-theme Breeze Hacked cursor theme nixos-unstable ??? nixpkgs-unstable 0-unstable-2024-01-28 pkgs.kdePackages.breeze-plymouth Plymouth theme for the Breeze visual style for the Plasma Desktop nixos-unstable ??? nixpkgs-unstable 6.4.5 pkgs.python312Packages.seabreeze Python library to access Ocean Optics spectrometers nixos-unstable ??? nixpkgs-unstable 2.10.1 pkgs.python313Packages.seabreeze Python library to access Ocean Optics spectrometers nixos-unstable ??? nixpkgs-unstable 2.10.1 pkgs.plasma5Packages.breeze-icons nixos-unstable ??? nixpkgs-unstable 5.116.0 pkgs.kdePackages.qqc2-breeze-style Breeze inspired QQC2 Style nixos-unstable ??? nixpkgs-unstable 6.4.5 pkgs.wordpressPackages.plugins.breeze nixos-unstable ??? nixpkgs-unstable 2.2.9 pkgs.kdePackages.sierra-breeze-enhanced OSX-like window decoration for KDE Plasma written in C++ nixos-unstable ??? nixpkgs-unstable 2.1.1 pkgs.qt6Packages.sierra-breeze-enhanced OSX-like window decoration for KDE Plasma written in C++ nixos-unstable ??? nixpkgs-unstable 2.1.1 Package maintainers: 10 @A1ca7raz A1ca7raz <aya@wtm.moe> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> @ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru> @ttuegel Thomas Tuegel <ttuegel@mailbox.org> @NickCao Nick Cao <nickcao@nichi.co> @mjm Matt Moriarity <matt@mattmoriarity.com> @LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev> @K900 Ilya K. <me@0upti.me> @nyanloutre Paul Trehiou <paul@nyanlout.re> @Anomalocaridid Duncan Russell <duncan@anomalocaris.xyz>
pkgs.kdePackages.breeze Artwork, styles and assets for the Breeze visual style for the Plasma Desktop nixos-unstable ??? nixpkgs-unstable 6.4.5
pkgs.kdePackages.breeze-gtk Breeze widget theme for GTK 2 and 3 nixos-unstable ??? nixpkgs-unstable 6.4.5
pkgs.kdePackages.breeze-grub GRUB theme for the Breeze visual style for the Plasma Desktop nixos-unstable ??? nixpkgs-unstable 6.4.5
pkgs.breeze-hacked-cursor-theme Breeze Hacked cursor theme nixos-unstable ??? nixpkgs-unstable 0-unstable-2024-01-28
pkgs.kdePackages.breeze-plymouth Plymouth theme for the Breeze visual style for the Plasma Desktop nixos-unstable ??? nixpkgs-unstable 6.4.5
pkgs.python312Packages.seabreeze Python library to access Ocean Optics spectrometers nixos-unstable ??? nixpkgs-unstable 2.10.1
pkgs.python313Packages.seabreeze Python library to access Ocean Optics spectrometers nixos-unstable ??? nixpkgs-unstable 2.10.1
pkgs.kdePackages.qqc2-breeze-style Breeze inspired QQC2 Style nixos-unstable ??? nixpkgs-unstable 6.4.5
pkgs.kdePackages.sierra-breeze-enhanced OSX-like window decoration for KDE Plasma written in C++ nixos-unstable ??? nixpkgs-unstable 2.1.1
pkgs.qt6Packages.sierra-breeze-enhanced OSX-like window decoration for KDE Plasma written in C++ nixos-unstable ??? nixpkgs-unstable 2.1.1
CVE-2025-49254 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 4 weeks, 1 day ago WordPress Nika <= 1.2.8 - Local File Inclusion Vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Nika allows PHP Local File Inclusion. This issue affects Nika: from n/a through 1.2.8. nika =<1.2.8 pkgs.nika-fonts Persian/Arabic Open Source Font nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.python312Packages.minikanren Relational programming in Python nixos-unstable ??? nixpkgs-unstable 1.0.5 pkgs.python313Packages.minikanren Relational programming in Python nixos-unstable ??? nixpkgs-unstable 1.0.5 Package maintainers: 1 @Etjean Etienne Jean <et.jean@outlook.fr>
pkgs.python312Packages.minikanren Relational programming in Python nixos-unstable ??? nixpkgs-unstable 1.0.5
pkgs.python313Packages.minikanren Relational programming in Python nixos-unstable ??? nixpkgs-unstable 1.0.5
CVE-2025-49179 6.6 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): HIGH created 4 weeks, 1 day ago Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x record extension A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks. tigervnc * xorg-x11-server * xorg-x11-server-Xwayland * pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0
CVE-2025-49259 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 4 weeks, 1 day ago WordPress Hara <= 1.2.10 - Local File Inclusion Vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Hara allows PHP Local File Inclusion. This issue affects Hara: from n/a through 1.2.10. hara =<1.2.10 pkgs.charasay Future of cowsay - Colorful characters saying something nixos-unstable ??? nixpkgs-unstable 3.3.0 pkgs.gnome-characters Simple utility application to find and insert unusual characters nixos-unstable ??? nixpkgs-unstable 48.0 pkgs.keepass-charactercopy nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.unicode-character-database Unicode Character Database nixos-unstable ??? nixpkgs-unstable 16.0.0 pkgs.haskellPackages.character-ps Pattern synonyms for ASCII characters for Word8, Word16 etc nixos-unstable ??? nixpkgs-unstable 0.1 pkgs.coqPackages.mathcomp-character nixos-unstable ??? nixpkgs-unstable 2.4.0 pkgs.python312Packages.characteristic Python attributes without boilerplate nixos-unstable ??? nixpkgs-unstable 14.3.0 pkgs.python313Packages.characteristic Python attributes without boilerplate nixos-unstable ??? nixpkgs-unstable 14.3.0 pkgs.magnetophonDSP.CharacterCompressor Compressor with character. For jack and lv2 nixos-unstable ??? nixpkgs-unstable 0.3.3 pkgs.python312Packages.character-encoding-utils Some character encoding utils nixos-unstable ??? nixpkgs-unstable 0.0.9 pkgs.python313Packages.character-encoding-utils Some character encoding utils nixos-unstable ??? nixpkgs-unstable 0.0.9 Package maintainers: 11 @hmajid2301 Haseeb Majid <hello@haseebmajid.dev> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @jtojnar Jan Tojnar <jtojnar@gmail.com> @bobby285271 Bobby Rong <rjl931189261@126.com> @h7x4 h7x4 <h7x4@nani.wtf> @TakWolf TakWolf <takwolf@foxmail.com> @vbgl Vincent Laporte <Vincent.Laporte@gmail.com> @jwiegley John Wiegley <johnw@newartisans.com> @CohenCyril Cyril Cohen <cyril.cohen@inria.fr> @magnetophon Bart Brouns <bart@magnetophon.nl>
pkgs.charasay Future of cowsay - Colorful characters saying something nixos-unstable ??? nixpkgs-unstable 3.3.0
pkgs.gnome-characters Simple utility application to find and insert unusual characters nixos-unstable ??? nixpkgs-unstable 48.0
pkgs.unicode-character-database Unicode Character Database nixos-unstable ??? nixpkgs-unstable 16.0.0
pkgs.haskellPackages.character-ps Pattern synonyms for ASCII characters for Word8, Word16 etc nixos-unstable ??? nixpkgs-unstable 0.1
pkgs.python312Packages.characteristic Python attributes without boilerplate nixos-unstable ??? nixpkgs-unstable 14.3.0
pkgs.python313Packages.characteristic Python attributes without boilerplate nixos-unstable ??? nixpkgs-unstable 14.3.0
pkgs.magnetophonDSP.CharacterCompressor Compressor with character. For jack and lv2 nixos-unstable ??? nixpkgs-unstable 0.3.3
pkgs.python312Packages.character-encoding-utils Some character encoding utils nixos-unstable ??? nixpkgs-unstable 0.0.9
pkgs.python313Packages.character-encoding-utils Some character encoding utils nixos-unstable ??? nixpkgs-unstable 0.0.9
CVE-2025-49175 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 4 weeks, 1 day ago Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: out-of-bounds read in x rendering extension animated cursors A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potential crash. tigervnc * xorg-x11-server * xorg-x11-server-Xwayland * pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0
CVE-2025-49176 6.6 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): HIGH created 4 weeks, 1 day ago Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in big requests extension A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check. tigervnc * xorg-x11-server * xorg-x11-server-Xwayland * pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0
CVE-2025-24761 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 4 weeks, 1 day ago CISA ADP Vulnrichment None dsk =<2.2 pkgs.idsk Manipulating CPC dsk images and files nixos-unstable ??? nixpkgs-unstable 0.20 pkgs.libdsk Library for accessing discs and disc image files nixos-unstable ??? nixpkgs-unstable 1.5.22 pkgs.robotfindskitten Yet another zen simulation; A simple find-the-kitten game nixos-unstable ??? nixpkgs-unstable 2.8284271.702 pkgs.python312Packages.pmdsky-debug-py Autogenerated and statically check-able pmdsky-debug symbol definitions for Python nixos-unstable ??? nixpkgs-unstable 10.0.48 pkgs.python313Packages.pmdsky-debug-py Autogenerated and statically check-able pmdsky-debug symbol definitions for Python nixos-unstable ??? nixpkgs-unstable 10.0.48 Package maintainers: 2 @wegank Weijia Wang <contact@weijia.wang> @marius851000 Marius David <mariusdavid@laposte.net>
pkgs.libdsk Library for accessing discs and disc image files nixos-unstable ??? nixpkgs-unstable 1.5.22
pkgs.robotfindskitten Yet another zen simulation; A simple find-the-kitten game nixos-unstable ??? nixpkgs-unstable 2.8284271.702
pkgs.python312Packages.pmdsky-debug-py Autogenerated and statically check-able pmdsky-debug symbol definitions for Python nixos-unstable ??? nixpkgs-unstable 10.0.48
pkgs.python313Packages.pmdsky-debug-py Autogenerated and statically check-able pmdsky-debug symbol definitions for Python nixos-unstable ??? nixpkgs-unstable 10.0.48
CVE-2025-31919 9.8 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 4 weeks, 1 day ago WordPress Spare <= 1.7 - PHP Object Injection Vulnerability Deserialization of Untrusted Data vulnerability in themeton Spare allows Object Injection. This issue affects Spare: from n/a through 1.7. spare =<1.7 pkgs.asciiquarium-transparent Aquarium/sea animation in ASCII art (with option of transparent background) nixos-unstable ??? nixpkgs-unstable 1.4 pkgs.materia-theme-transparent Transparent Material Design theme for GNOME/GTK based desktop environments nixos-unstable ??? nixpkgs-unstable 0-unstable-2021-03-22 pkgs.gnomeExtensions.transparent-top-bar Bring back the transparent top bar when free-floating in GNOME Shell 3.32. nixos-unstable ??? nixpkgs-unstable 24 pkgs.gnomeExtensions.transparent-window-moving Makes the window semi-transparent when moving or resizing nixos-unstable ??? nixpkgs-unstable 19 pkgs.sway-contrib.inactive-windows-transparency It makes inactive sway windows transparent nixos-unstable ??? nixpkgs-unstable 0-unstable-2024-03-19 pkgs.gnomeExtensions.transparent-top-bar-adjustable-transparency Fork of: https://github.com/zhanghai/gnome-shell-extension-transparent-top-bar nixos-unstable ??? nixpkgs-unstable 24 Package maintainers: 4 @quantenzitrone quantenzitrone <nix@dev.quantenzitrone.eu> @evils Evils <evils.devils@protonmail.com> @honnip Jung seungwoo <me@honnip.page> @CorbinWunderlich Corbin Wunderlich <corbin@wcopy.net>
pkgs.asciiquarium-transparent Aquarium/sea animation in ASCII art (with option of transparent background) nixos-unstable ??? nixpkgs-unstable 1.4
pkgs.materia-theme-transparent Transparent Material Design theme for GNOME/GTK based desktop environments nixos-unstable ??? nixpkgs-unstable 0-unstable-2021-03-22
pkgs.gnomeExtensions.transparent-top-bar Bring back the transparent top bar when free-floating in GNOME Shell 3.32. nixos-unstable ??? nixpkgs-unstable 24
pkgs.gnomeExtensions.transparent-window-moving Makes the window semi-transparent when moving or resizing nixos-unstable ??? nixpkgs-unstable 19
pkgs.sway-contrib.inactive-windows-transparency It makes inactive sway windows transparent nixos-unstable ??? nixpkgs-unstable 0-unstable-2024-03-19
pkgs.gnomeExtensions.transparent-top-bar-adjustable-transparency Fork of: https://github.com/zhanghai/gnome-shell-extension-transparent-top-bar nixos-unstable ??? nixpkgs-unstable 24
CVE-2025-49253 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 4 weeks, 1 day ago WordPress Lasa <= 1.1 - Local File Inclusion Vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Lasa allows PHP Local File Inclusion. This issue affects Lasa: from n/a through 1.1. lasa =<1.1 pkgs.typstPackages.lasagna_0_1_0 Add layers, toggle them using tags easily nixos-unstable ??? nixpkgs-unstable 0.1.0 pkgs.typstPackages.lasaveur_0_1_3 Porting vim-latex's math shorthands to Typst. An accommendating vim syntax file is provided in the repo nixos-unstable ??? nixpkgs-unstable 0.1.3 pkgs.typstPackages.lasaveur_0_1_4 Porting vim-latex's math shorthands to Typst. An accommendating vim syntax file is provided in the repo nixos-unstable ??? nixpkgs-unstable 0.1.4 Package maintainers: 1 @cherrypiejam Gongqi Huang
pkgs.typstPackages.lasagna_0_1_0 Add layers, toggle them using tags easily nixos-unstable ??? nixpkgs-unstable 0.1.0
pkgs.typstPackages.lasaveur_0_1_3 Porting vim-latex's math shorthands to Typst. An accommendating vim syntax file is provided in the repo nixos-unstable ??? nixpkgs-unstable 0.1.3
pkgs.typstPackages.lasaveur_0_1_4 Porting vim-latex's math shorthands to Typst. An accommendating vim syntax file is provided in the repo nixos-unstable ??? nixpkgs-unstable 0.1.4