⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

Create Draft to queue a suggestion for refinement.

Dismiss to remove a suggestion from the queue.

CVE-2025-31179
6.2 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 5 months, 1 week ago
Gnuplot: gnuplot segmentation fault on xstrftime

A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.

gnuplot
<6.0

pkgs.gnuplot

Portable command-line driven graphing utility for many platforms

pkgs.gnuplot_qt

Portable command-line driven graphing utility for many platforms

pkgs.feedgnuplot

General purpose pipe-oriented plotting tool

pkgs.gnuplot_aquaterm

Portable command-line driven graphing utility for many platforms

pkgs.haskellPackages.gnuplot

2D and 3D plots using gnuplot

pkgs.haskellPackages.gnuplot.x86_64-linux

2D and 3D plots using gnuplot

pkgs.haskellPackages.gnuplot.aarch64-linux

2D and 3D plots using gnuplot

pkgs.haskellPackages.gnuplot.x86_64-darwin

2D and 3D plots using gnuplot

pkgs.haskellPackages.gnuplot.aarch64-darwin

2D and 3D plots using gnuplot

pkgs.chickenPackages_5.chickenEggs.gnuplot-pipe

A simple interface to Gnuplot

pkgs.vimPlugins.nvim-treesitter-parsers.gnuplot

  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable
Package maintainers: 3
CVE-2022-1242
7.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 5 months, 1 week ago
Apport can be tricked into connecting to arbitrary sockets as …

Apport can be tricked into connecting to arbitrary sockets as the root user

apport
<2.21.0

pkgs.haskellPackages.apportionment

Round a set of numbers while maintaining its sum
Package maintainers: 1
CVE-2025-31178
6.2 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 5 months, 1 week ago
Gnuplot: gnuplot segmentation fault on getannotatestring

A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.

gnuplot
<6.0

pkgs.gnuplot

Portable command-line driven graphing utility for many platforms

pkgs.gnuplot_qt

Portable command-line driven graphing utility for many platforms

pkgs.feedgnuplot

General purpose pipe-oriented plotting tool

pkgs.gnuplot_aquaterm

Portable command-line driven graphing utility for many platforms

pkgs.haskellPackages.gnuplot

2D and 3D plots using gnuplot

pkgs.haskellPackages.gnuplot.x86_64-linux

2D and 3D plots using gnuplot

pkgs.haskellPackages.gnuplot.aarch64-linux

2D and 3D plots using gnuplot

pkgs.haskellPackages.gnuplot.x86_64-darwin

2D and 3D plots using gnuplot

pkgs.haskellPackages.gnuplot.aarch64-darwin

2D and 3D plots using gnuplot

pkgs.chickenPackages_5.chickenEggs.gnuplot-pipe

A simple interface to Gnuplot

pkgs.vimPlugins.nvim-treesitter-parsers.gnuplot

  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable
Package maintainers: 3
CVE-2023-0593
5.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 5 months, 1 week ago
Path traversal in yaffshiv

A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attacker could force yaffshiv to write outside of the extraction directory. This issue affects yaffshiv up to version 0.1 included, which is the most recent at time of publication.

yaffshiv
=<0.1
Package maintainers: 1
CVE-2025-31181
6.2 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 5 months, 1 week ago
Gnuplot: gnuplot segmentation fault on x11_graphics

A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash.

gnuplot
<6.1

pkgs.gnuplot

Portable command-line driven graphing utility for many platforms

pkgs.gnuplot_qt

Portable command-line driven graphing utility for many platforms

pkgs.feedgnuplot

General purpose pipe-oriented plotting tool

pkgs.gnuplot_aquaterm

Portable command-line driven graphing utility for many platforms

pkgs.haskellPackages.gnuplot

2D and 3D plots using gnuplot

pkgs.haskellPackages.gnuplot.x86_64-linux

2D and 3D plots using gnuplot

pkgs.haskellPackages.gnuplot.aarch64-linux

2D and 3D plots using gnuplot

pkgs.haskellPackages.gnuplot.x86_64-darwin

2D and 3D plots using gnuplot

pkgs.haskellPackages.gnuplot.aarch64-darwin

2D and 3D plots using gnuplot

pkgs.chickenPackages_5.chickenEggs.gnuplot-pipe

A simple interface to Gnuplot

pkgs.vimPlugins.nvim-treesitter-parsers.gnuplot

  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable
Package maintainers: 3
CVE-2023-0592
5.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 5 months, 1 week ago
Path traversal in jefferson

A path traversal vulnerability affects jefferson's JFFS2 filesystem extractor. By crafting malicious JFFS2 files, attackers could force jefferson to write outside of the extraction directory.This issue affects jefferson: before 0.4.1.

jefferson
<0.4.1

pkgs.jefferson

JFFS2 filesystem extraction tool
Package maintainers: 2
CVE-2025-28855
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 5 months, 1 week ago
WordPress Teleport plugin <= 1.2.4 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Teleport allows Reflected XSS. This issue affects Teleport: from n/a through 1.2.4.

teleport
=<1.2.4

pkgs.teleport

Certificate authority and access plane for SSH, Kubernetes, web applications, and databases

pkgs.teleport_15

Certificate authority and access plane for SSH, Kubernetes, web applications, and databases

pkgs.teleport_16

Certificate authority and access plane for SSH, Kubernetes, web applications, and databases

pkgs.lomiri.teleports

Ubuntu Touch Telegram client

pkgs.lomiri.teleports.x86_64-linux

Ubuntu Touch Telegram client

pkgs.lomiri.teleports.aarch64-linux

Ubuntu Touch Telegram client

pkgs.obs-studio-plugins.obs-teleport

OBS Studio plugin for an open NDI-like replacement
Package maintainers: 7
CVE-2025-28916
9.8 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 5 months, 1 week ago
WordPress Docpro plugin <= 2.0.1 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Docpro allows PHP Local File Inclusion. This issue affects Docpro: from n/a through 2.0.1.

docpro
=<2.0.1

pkgs.python311Packages.jupyter-docprovider

JupyterLab/Jupyter Notebook 7+ extension integrating collaborative shared models

pkgs.python312Packages.jupyter-docprovider

JupyterLab/Jupyter Notebook 7+ extension integrating collaborative shared models

pkgs.python312Packages.jupyter-docprovider.x86_64-linux

JupyterLab/Jupyter Notebook 7+ extension integrating collaborative shared models

pkgs.python312Packages.jupyter-docprovider.aarch64-linux

JupyterLab/Jupyter Notebook 7+ extension integrating collaborative shared models

pkgs.python312Packages.jupyter-docprovider.x86_64-darwin

JupyterLab/Jupyter Notebook 7+ extension integrating collaborative shared models

pkgs.python312Packages.jupyter-docprovider.aarch64-darwin

JupyterLab/Jupyter Notebook 7+ extension integrating collaborative shared models
Package maintainers: 3
CVE-2025-28873
8.5 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): LOW
created 5 months, 1 week ago
WordPress Shuffle plugin <= 0.5 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Shuffle allows Blind SQL Injection. This issue affects Shuffle: from n/a through 0.5.

shuffle
=<0.5

pkgs.ashuffle

Automatic library-wide shuffle for mpd

pkgs.linuxPackages.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxPackages_lqx.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxPackages_zen.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.haskellPackages.random-shuffle

Random shuffle implementation

pkgs.linuxPackages-libre.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxPackages_latest.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxPackages_xanmod.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxPackages_hardened.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxPackages.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxPackages_6_1_hardened.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxPackages_latest-libre.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxPackages.shufflecake.aarch64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxPackages_6_11_hardened.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxPackages_xanmod_stable.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxKernel.packages.linux_6_1.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxKernel.packages.linux_6_6.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxPackages_lqx.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxPackages_zen.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_6_11.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxKernel.packages.linux_6_12.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxKernel.packages.linux_libre.shufflecake

Plausible deniability (hidden storage) layer for Linux

pkgs.linuxPackages-libre.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxPackages-libre.shufflecake.aarch64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxPackages_latest.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxPackages_xanmod.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxPackages_latest.shufflecake.aarch64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_hardened.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxPackages_hardened.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxPackages_hardened.shufflecake.aarch64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_6_1_hardened.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxKernel.packages.linux_latest_libre.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxPackages_6_1_hardened.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxPackages_latest-libre.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_6_11_hardened.shufflecake

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.linuxPackages_6_11_hardened.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxPackages_6_1_hardened.shufflecake.aarch64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxPackages_latest-libre.shufflecake.aarch64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxPackages_xanmod_stable.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxPackages_6_11_hardened.shufflecake.aarch64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_6_1.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_6_6.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_6_1.shufflecake.aarch64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_6_11.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_6_12.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_6_6.shufflecake.aarch64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_6_11.shufflecake.aarch64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_6_12.shufflecake.aarch64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_hardened.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_hardened.shufflecake.aarch64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_6_1_hardened.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_latest_libre.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_6_11_hardened.shufflecake.x86_64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_6_1_hardened.shufflecake.aarch64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_latest_libre.shufflecake.aarch64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small

pkgs.linuxKernel.packages.linux_6_11_hardened.shufflecake.aarch64-linux

Plausible deniability (hidden storage) layer for Linux
  • nixos-unstable ???
    • nixos-unstable-small
Package maintainers: 2
CVE-2024-47516
9.8 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 5 months, 1 week ago
Pagure: argument injection in pagurerepo.log()

A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure instance.

pagure
==5.14.1

pkgs.haskellPackages.pagure

Pagure REST client library

pkgs.haskellPackages.pagure-cli

Pagure client