⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

Create Draft to queue a suggestion for refinement.

Dismiss to remove a suggestion from the queue.

CVE-2024-8373
4.8 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 3 months ago
AngularJS improper sanitization in '<source>' element

Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

angular
==>=0.0.0

pkgs.angular-language-server

LSP for angular completions, AOT diagnostic, quick info and go to definitions

pkgs.vimPlugins.nvim-treesitter-parsers.angular

  • nixos-25.05 ???
    • nixpkgs-25.05-darwin
    • nixos-25.05-small
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable
Package maintainers: 1
CVE-2025-5278
4.4 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): NONE
  • Availability impact (A): LOW
created 3 months ago
Coreutils: heap buffer under-read in gnu coreutils sort via key specification

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

rhcos
coreutils

pkgs.coreutils

GNU Core Utilities

pkgs.coreutils-full

GNU Core Utilities

pkgs.policycoreutils

SELinux policy core utilities

pkgs.coreutils-prefixed

GNU Core Utilities
Package maintainers: 4
CVE-2025-48798
7.3 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 3 months ago
Gimp: multiple use after free in xcf parser

A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.

gimp
*
<3.0.0
gimp:2.8
*
gimp:2.8/gimp

pkgs.zigimports

Automatically remove unused imports and globals from Zig files

pkgs.gimpPlugins.bimp

Batch Image Manipulation Plugin for GIMP

pkgs.gimpPlugins.gmic

GIMP plugin for the G'MIC image processing framework

pkgs.gimp3Plugins.gmic

GIMP plugin for the G'MIC image processing framework

pkgs.gimpPlugins.lightning

  • nixos-25.05 ???
    • nixpkgs-25.05-darwin
    • nixos-25.05-small
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.gimp3Plugins.lightning

  • nixos-25.05 ???
    • nixpkgs-25.05-darwin
    • nixos-25.05-small
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable
Package maintainers: 3
CVE-2025-48796
7.3 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 3 months ago
Gimp: stack-based buffer overflows in file-ico

A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrary code execution.

gimp
<2.99.16
gimp:2.8/gimp

pkgs.zigimports

Automatically remove unused imports and globals from Zig files

pkgs.gimpPlugins.bimp

Batch Image Manipulation Plugin for GIMP

pkgs.gimpPlugins.gmic

GIMP plugin for the G'MIC image processing framework

pkgs.gimp3Plugins.gmic

GIMP plugin for the G'MIC image processing framework

pkgs.gimpPlugins.lightning

  • nixos-25.05 ???
    • nixpkgs-25.05-darwin
    • nixos-25.05-small
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.gimp3Plugins.lightning

  • nixos-25.05 ???
    • nixpkgs-25.05-darwin
    • nixos-25.05-small
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable
Package maintainers: 3
CVE-2025-48797
7.3 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 3 months ago
Gimp: multiple heap buffer overflows in tga parser

A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.

gimp
*
<3.0.0
gimp:2.8
*
gimp:2.8/gimp

pkgs.zigimports

Automatically remove unused imports and globals from Zig files

pkgs.gimpPlugins.bimp

Batch Image Manipulation Plugin for GIMP

pkgs.gimpPlugins.gmic

GIMP plugin for the G'MIC image processing framework

pkgs.gimp3Plugins.gmic

GIMP plugin for the G'MIC image processing framework

pkgs.gimpPlugins.lightning

  • nixos-25.05 ???
    • nixpkgs-25.05-darwin
    • nixos-25.05-small
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.gimp3Plugins.lightning

  • nixos-25.05 ???
    • nixpkgs-25.05-darwin
    • nixos-25.05-small
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable
Package maintainers: 3
CVE-2025-23394
9.8 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 3 months ago
daily-backup.sh script in cyrus-imapd allows escalation from cyrus to root

A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed cyrus-imapd before 3.8.4-2.1.

cyrus-imapd
<3.8.4-2.1
Package maintainers: 2
CVE-2025-32286
8.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 3 months ago
WordPress Butcher <= 2.40 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Butcher allows PHP Local File Inclusion. This issue affects Butcher: from n/a through 2.40.

butcher
=<2.40

pkgs.haskellPackages.butcher.x86_64-linux

Chops a command or program invocation into digestable pieces

pkgs.haskellPackages.butcher.aarch64-linux

Chops a command or program invocation into digestable pieces

pkgs.haskellPackages.butcher.x86_64-darwin

Chops a command or program invocation into digestable pieces

pkgs.haskellPackages.butcher.aarch64-darwin

Chops a command or program invocation into digestable pieces
CVE-2025-46448
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 3 months ago
WordPress Document Management System <= 1.24 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reifsnyderb Document Management System allows Reflected XSS. This issue affects Document Management System: from n/a through 1.24.

dms
=<1.24

pkgs.dms

UPnP DLNA Digital Media Server with basic video transcoding

pkgs.haskellPackages.amazonka-dms

Amazon Database Migration Service SDK

pkgs.python311Packages.types-aiobotocore-dms

Type annotations for aiobotocore dms

pkgs.python313Packages.types-aiobotocore-dms

Type annotations for aiobotocore dms

pkgs.python312Packages.ndms2-client.x86_64-linux

Keenetic NDMS 2.x and 3.x client

pkgs.python312Packages.ndms2-client.aarch64-linux

Keenetic NDMS 2.x and 3.x client

pkgs.python312Packages.ndms2-client.x86_64-darwin

Keenetic NDMS 2.x and 3.x client

pkgs.python312Packages.mypy-boto3-dms.x86_64-linux

Type annotations for boto3 dms

pkgs.python312Packages.ndms2-client.aarch64-darwin

Keenetic NDMS 2.x and 3.x client

pkgs.python312Packages.mypy-boto3-dms.aarch64-linux

Type annotations for boto3 dms

pkgs.python312Packages.mypy-boto3-dms.x86_64-darwin

Type annotations for boto3 dms

pkgs.python312Packages.mypy-boto3-dms.aarch64-darwin

Type annotations for boto3 dms

pkgs.python312Packages.types-aiobotocore-dms.x86_64-linux

Type annotations for aiobotocore dms

pkgs.python312Packages.types-aiobotocore-dms.aarch64-linux

Type annotations for aiobotocore dms

pkgs.python312Packages.types-aiobotocore-dms.x86_64-darwin

Type annotations for aiobotocore dms

pkgs.python312Packages.types-aiobotocore-dms.aarch64-darwin

Type annotations for aiobotocore dms
Package maintainers: 9
CVE-2025-32293
8.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 3 months ago
WordPress Finance Consultant <= 2.8 - PHP Object Injection Vulnerability

Deserialization of Untrusted Data vulnerability in designthemes Finance Consultant allows Object Injection. This issue affects Finance Consultant: from n/a through 2.8.

finance
=<2.8

pkgs.python311Packages.yfinance

Module to doiwnload Yahoo! Finance market data

pkgs.python313Packages.yfinance

Module to doiwnload Yahoo! Finance market data

pkgs.python311Packages.mplfinance

Matplotlib utilities for the visualization, and visual analysis, of financial data

pkgs.python313Packages.mplfinance

Matplotlib utilities for the visualization, and visual analysis, of financial data

pkgs.python311Packages.finvizfinance

Finviz Finance information downloader

pkgs.python312Packages.finvizfinance

Finviz Finance information downloader

pkgs.python313Packages.finvizfinance

Finviz Finance information downloader

pkgs.python312Packages.yfinance.x86_64-linux

Module to doiwnload Yahoo! Finance market data

pkgs.python312Packages.yfinance.aarch64-linux

Module to doiwnload Yahoo! Finance market data

pkgs.python312Packages.yfinance.x86_64-darwin

Module to doiwnload Yahoo! Finance market data

pkgs.python312Packages.mplfinance.x86_64-linux

Matplotlib utilities for the visualization, and visual analysis, of financial data

pkgs.python312Packages.yfinance.aarch64-darwin

Module to doiwnload Yahoo! Finance market data

pkgs.python312Packages.mplfinance.aarch64-linux

Matplotlib utilities for the visualization, and visual analysis, of financial data

pkgs.python312Packages.mplfinance.x86_64-darwin

Matplotlib utilities for the visualization, and visual analysis, of financial data

pkgs.python312Packages.mplfinance.aarch64-darwin

Matplotlib utilities for the visualization, and visual analysis, of financial data

pkgs.python312Packages.finvizfinance.x86_64-linux

Finviz Finance information downloader

pkgs.python312Packages.finvizfinance.aarch64-linux

Finviz Finance information downloader

pkgs.python312Packages.finvizfinance.x86_64-darwin

Finviz Finance information downloader

pkgs.python312Packages.finvizfinance.aarch64-darwin

Finviz Finance information downloader
Package maintainers: 2
CVE-2024-22309
8.7 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 3 months ago
WordPress ChatBot Plugin <= 5.1.0 is vulnerable to PHP Object Injection

Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from n/a through 5.1.0.

chatbot
=<5.1.0

pkgs.gnomeExtensions.penguin-ai-chatbot

A GNOME Shell extension that provides a chatbot interface using various LLM providers, including Anthropic, OpenAI, Gemini, and OpenRouter. Features include multiple provider support, customizable models, chat history, customizable appearance, a keyboard shortcut, and copy-to-clipboard functionality.
  • nixos-25.05 22
    • nixpkgs-25.05-darwin 22
    • nixos-25.05-small 22
  • nixos-unstable 11
    • nixos-unstable-small 11
    • nixpkgs-unstable 11
Package maintainers: 1