⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

Create Draft to queue a suggestion for refinement.

Dismiss to remove a suggestion from the queue.

CVE-2025-30621
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 3 months, 2 weeks ago
WordPress Translator plugin <= 0.3 - CSRF to Stored XSS vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in kornelly Translator allows Stored XSS. This issue affects Translator: from n/a through 0.3.

translator
=<0.3

pkgs.krunner-translator

Plugin for KRunner which integrates a translator, supports Google Translate, Bing Translator, youdao and Baidu Fanyi

pkgs.gtranslator.x86_64-linux

GNOME translation making program

pkgs.gtranslator.aarch64-linux

GNOME translation making program

pkgs.texlivePackages.translator

Easy translation of strings in LaTeX

pkgs.deep-translator.x86_64-linux

Python tool to translate between different languages by using multiple translators

pkgs.deep-translator.aarch64-linux

Python tool to translate between different languages by using multiple translators

pkgs.deep-translator.x86_64-darwin

Python tool to translate between different languages by using multiple translators

pkgs.deep-translator.aarch64-darwin

Python tool to translate between different languages by using multiple translators

pkgs.krunner-translator.x86_64-linux

A plugin for KRunner which integrates a translator, supports Google Translate, Bing Translator, youdao and Baidu Fanyi

pkgs.krunner-translator.aarch64-linux

A plugin for KRunner which integrates a translator, supports Google Translate, Bing Translator, youdao and Baidu Fanyi

pkgs.python311Packages.deep-translator

Python tool to translate between different languages by using multiple translators

pkgs.python311Packages.aws-sam-translator

Python library to transform SAM templates into AWS CloudFormation templates

pkgs.python312Packages.aws-sam-translator

Python library to transform SAM templates into AWS CloudFormation templates

pkgs.texlivePackages.translator.x86_64-linux

Easy translation of strings in LaTeX

pkgs.python311Packages.deep-translator.x86_64-linux

Python tool to translate between different languages by using multiple translators

pkgs.python312Packages.deep-translator.x86_64-linux

Python tool to translate between different languages by using multiple translators

pkgs.python311Packages.deep-translator.aarch64-linux

Python tool to translate between different languages by using multiple translators

pkgs.python311Packages.deep-translator.x86_64-darwin

Python tool to translate between different languages by using multiple translators

pkgs.python312Packages.deep-translator.aarch64-linux

Python tool to translate between different languages by using multiple translators

pkgs.python312Packages.deep-translator.x86_64-darwin

Python tool to translate between different languages by using multiple translators

pkgs.azure-cli-extensions.cli-translator.x86_64-linux

Translate ARM template to executable Azure CLI scripts

pkgs.python311Packages.deep-translator.aarch64-darwin

Python tool to translate between different languages by using multiple translators

pkgs.python312Packages.deep-translator.aarch64-darwin

Python tool to translate between different languages by using multiple translators

pkgs.azure-cli-extensions.cli-translator.aarch64-linux

Translate ARM template to executable Azure CLI scripts

pkgs.azure-cli-extensions.cli-translator.x86_64-darwin

Translate ARM template to executable Azure CLI scripts

pkgs.python311Packages.aws-sam-translator.x86_64-linux

Python library to transform SAM templates into AWS CloudFormation templates

pkgs.python312Packages.aws-sam-translator.x86_64-linux

Python library to transform SAM templates into AWS CloudFormation templates

pkgs.azure-cli-extensions.cli-translator.aarch64-darwin

Translate ARM template to executable Azure CLI scripts

pkgs.python311Packages.aws-sam-translator.aarch64-linux

Python library to transform SAM templates into AWS CloudFormation templates

pkgs.python311Packages.aws-sam-translator.x86_64-darwin

Python library to transform SAM templates into AWS CloudFormation templates

pkgs.python312Packages.aws-sam-translator.aarch64-linux

Python library to transform SAM templates into AWS CloudFormation templates

pkgs.python312Packages.aws-sam-translator.x86_64-darwin

Python library to transform SAM templates into AWS CloudFormation templates

pkgs.python311Packages.aws-sam-translator.aarch64-darwin

Python library to transform SAM templates into AWS CloudFormation templates

pkgs.python312Packages.aws-sam-translator.aarch64-darwin

Python library to transform SAM templates into AWS CloudFormation templates
Package maintainers: 4
CVE-2024-41937
6.1 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 3 months, 2 weeks ago
Apache Airflow: Stored XSS Vulnerability on provider link

Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web server and the user to click the provider link. Users should upgrade to 2.10.0 or later, which fixes this vulnerability.

apache-airflow
<2.10.0

pkgs.apache-airflow.x86_64-linux

Programmatically author, schedule and monitor data pipelines

pkgs.apache-airflow.aarch64-linux

Programmatically author, schedule and monitor data pipelines

pkgs.apache-airflow.x86_64-darwin

Programmatically author, schedule and monitor data pipelines

pkgs.apache-airflow.aarch64-darwin

Programmatically author, schedule and monitor data pipelines
Package maintainers: 3
CVE-2024-25142
5.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 3 months, 2 weeks ago
Apache Airflow: Cache Control - Storage of Sensitive Data in Browser Cache

Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser. This issue affects Apache Airflow: before 2.9.2. Users are recommended to upgrade to version 2.9.2, which fixes the issue.

apache-airflow
<2.9.2

pkgs.apache-airflow.x86_64-linux

Programmatically author, schedule and monitor data pipelines

pkgs.apache-airflow.aarch64-linux

Programmatically author, schedule and monitor data pipelines

pkgs.apache-airflow.x86_64-darwin

Programmatically author, schedule and monitor data pipelines

pkgs.apache-airflow.aarch64-darwin

Programmatically author, schedule and monitor data pipelines
Package maintainers: 3
CVE-2022-28656
5.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 3 months, 2 weeks ago
is_closing_session() allows users to consume RAM in the Apport process

is_closing_session() allows users to consume RAM in the Apport process

apport
<2.21.0

pkgs.texlivePackages.skrapport

'Simple' class for reports, etc.

pkgs.texlivePackages.skrapport.x86_64-linux

'Simple' class for reports, etc.

pkgs.haskellPackages.apportionment.x86_64-linux

Round a set of numbers while maintaining its sum

pkgs.haskellPackages.apportionment.aarch64-linux

Round a set of numbers while maintaining its sum

pkgs.haskellPackages.apportionment.x86_64-darwin

Round a set of numbers while maintaining its sum

pkgs.haskellPackages.apportionment.aarch64-darwin

Round a set of numbers while maintaining its sum
Package maintainers: 1
CVE-2024-6219
3.8 LOW
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 3 months, 2 weeks ago
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, …

Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.

lxd
<5.21.1

pkgs.lxdvdrip

Command line tool to make a copy from a video DVD for private use

pkgs.lxd-image-server

Creates and manages a simplestreams lxd image server on top of nginx

pkgs.lxd-ui.x86_64-linux

Web user interface for LXD

pkgs.lxd-ui.aarch64-linux

Web user interface for LXD

pkgs.lxdvdrip.x86_64-linux

Command line tool to make a copy from a video DVD for private use

pkgs.lxd-image-server.x86_64-linux

Creates and manages a simplestreams lxd image server on top of nginx

pkgs.lxd-image-server.aarch64-linux

Creates and manages a simplestreams lxd image server on top of nginx

pkgs.python311Packages.pylxd.x86_64-linux

Library for interacting with the LXD REST API

pkgs.python312Packages.pylxd.x86_64-linux

Library for interacting with the LXD REST API

pkgs.python311Packages.pylxd.aarch64-linux

Library for interacting with the LXD REST API

pkgs.python311Packages.pylxd.x86_64-darwin

Library for interacting with the LXD REST API

pkgs.python312Packages.pylxd.aarch64-linux

Library for interacting with the LXD REST API

pkgs.python312Packages.pylxd.x86_64-darwin

Library for interacting with the LXD REST API

pkgs.python311Packages.pylxd.aarch64-darwin

Library for interacting with the LXD REST API

pkgs.python312Packages.pylxd.aarch64-darwin

Library for interacting with the LXD REST API
Package maintainers: 1
CVE-2023-32190
7.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 3 months, 2 weeks ago
mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable

mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.

mlocate
<0.26-37.1

pkgs.mlocate

Merging locate is an utility to index and quickly search for files

pkgs.mlocate.x86_64-linux

Merging locate is an utility to index and quickly search for files

pkgs.mlocate.aarch64-linux

Merging locate is an utility to index and quickly search for files
CVE-2024-11734
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 3 months, 2 weeks ago
Org.keycloak:keycloak-quarkus-server: denial of service in keycloak server via security headers

A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request.

keycloak
<26.0.8
rhbk/keycloak-rhel9
*
rhbk/keycloak-rhel9-operator
*
rhbk/keycloak-operator-bundle
*
org.keycloak/keycloak-quarkus-server

pkgs.keycloak.x86_64-linux

Identity and access management for modern applications and services

pkgs.keycloak.aarch64-linux

Identity and access management for modern applications and services

pkgs.python311Packages.python-keycloak.x86_64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-linux

Provides access to the Keycloak API

pkgs.python311Packages.python-keycloak.aarch64-linux

Provides access to the Keycloak API

pkgs.python311Packages.python-keycloak.x86_64-darwin

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-darwin

Provides access to the Keycloak API

pkgs.python311Packages.python-keycloak.aarch64-darwin

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-darwin

Provides access to the Keycloak API
Package maintainers: 3
CVE-2024-11736
4.9 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): HIGH
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 3 months, 2 weeks ago
Org.keycloak:keycloak-quarkus-server: unrestricted admin use of system and environment variables

A vulnerability was found in Keycloak. Admin users may have to access sensitive server environment variables and system properties through user-configurable URLs. When configuring backchannel logout URLs or admin URLs, admin users can include placeholders like ${env.VARNAME} or ${PROPNAME}. The server replaces these placeholders with the actual values of environment variables or system properties during URL processing.

keycloak
<26.0.8
rhbk/keycloak-rhel9
*
rhbk/keycloak-rhel9-operator
*
rhbk/keycloak-operator-bundle
*
org.keycloak/keycloak-quarkus-server

pkgs.keycloak.x86_64-linux

Identity and access management for modern applications and services

pkgs.keycloak.aarch64-linux

Identity and access management for modern applications and services

pkgs.python311Packages.python-keycloak.x86_64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-linux

Provides access to the Keycloak API

pkgs.python311Packages.python-keycloak.aarch64-linux

Provides access to the Keycloak API

pkgs.python311Packages.python-keycloak.x86_64-darwin

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-darwin

Provides access to the Keycloak API

pkgs.python311Packages.python-keycloak.aarch64-darwin

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-darwin

Provides access to the Keycloak API
Package maintainers: 3
CVE-2025-2487
4.9 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): HIGH
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 3 months, 2 weeks ago
389-ds-base: null pointer dereference leads to denial of service

A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.

389-ds-base
=<2.4.6
=<3.0.6
=<2.5.3
=<2.6.1
*
redhat-ds:12
*
389-ds:1.4/389-ds-base
redhat-ds:11/389-ds-base
redhat-ds:12/389-ds-base

pkgs._389-ds-base.x86_64-linux

Enterprise-class Open Source LDAP server for Linux

pkgs._389-ds-base.aarch64-linux

Enterprise-class Open Source LDAP server for Linux
Package maintainers: 1
CVE-2025-0495 created 3 months, 3 weeks ago
Secrets leakage to telemetry endpoint via cache backend configuration via buildx

Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. When supplied as user input, these secure values may be inadvertently captured in OpenTelemetry traces as part of the arguments and flags for the traced CLI command. OpenTelemetry traces are also saved in BuildKit daemon's history records. This vulnerability does not impact secrets passed to the Github cache backend via environment variables or registry authentication.

buildx
=<0.21.2
Package maintainers: 2