Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2024-5290 8.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago An issue was discovered in Ubuntu wpa_supplicant that resulted in … An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root). Membership in the netdev group or access to the dbus interface of wpa_supplicant allow an unprivileged user to specify an arbitrary path to a module to be loaded by the wpa_supplicant process; other escalation paths might exist. wpa <2:2.9-1ubuntu4.4 <2.4-0ubuntu6.8+esm1 <2:2.10-21ubuntu0.1 <2:2.10-6ubuntu2.1 <2.1-0ubuntu1.7+esm5 <2:2.6-15ubuntu2.8+esm1 pkgs.wpaperd Minimal wallpaper daemon for Wayland nixos-unstable ??? nixpkgs-unstable 1.2.2 pkgs.cowpatty Offline dictionary attack against WPA/WPA2 networks nixos-unstable ??? nixpkgs-unstable 4.8 pkgs.vowpal-wabbit Machine learning system focused on online reinforcement learning nixos-unstable ??? nixpkgs-unstable 9.10.0 pkgs.wpa_supplicant_gui Qt-based GUI for wpa_supplicant nixos-unstable ??? nixpkgs-unstable 2.11 pkgs.wpa_supplicant_ro_ssids Tool for connecting to WPA and WPA2-protected wireless networks nixos-unstable ??? nixpkgs-unstable 2.11 pkgs.python312Packages.vowpalwabbit Vowpal Wabbit is a fast machine learning library for online learning, and this is the python wrapper for the project nixos-unstable ??? nixpkgs-unstable 9.10.0 pkgs.python313Packages.vowpalwabbit Vowpal Wabbit is a fast machine learning library for online learning, and this is the python wrapper for the project nixos-unstable ??? nixpkgs-unstable 9.10.0 pkgs.python312Packages.mwparserfromhell MWParserFromHell is a parser for MediaWiki wikicode nixos-unstable ??? nixpkgs-unstable 0.7.2 pkgs.python313Packages.mwparserfromhell MWParserFromHell is a parser for MediaWiki wikicode nixos-unstable ??? nixpkgs-unstable 0.7.2 pkgs.vscode-extensions.twpayne.vscode-testscript Syntax highlighting support for testscript nixos-unstable ??? nixpkgs-unstable 0.0.7 Package maintainers: 9 @teh Tom Hunger <tehunger@gmail.com> @mattmelling Matt Melling <mattmelling@fastmail.com> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @nico202 Nicolò Balzarotti <anothersms@gmail.com> @MarcWeber Marc Weber <marco-oweber@gmx.de> @Ma27 Maximilian Bosch <maximilian@mbosch.me> @fsnkty fsnkty <fsnkty@shimeji.cafe> @DPDmancul Davide Peressoni <davide.peressoni@tuta.io> @jackgerrits Jack Gerrits <jack@jackgerrits.com> CVE-2024-7383 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 1 month, 1 week ago Libnbd: nbd server improper certificate validation A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic. libnbd <1.18.5 <1.20.2 * virt:rhel * virt:av/libnbd virt-devel:rhel * virt:rhel/libnbd pkgs.libnbd Network Block Device client library in userspace nixos-unstable ??? nixpkgs-unstable 1.22.1 pkgs.python312Packages.libnbd Network Block Device client library in userspace nixos-unstable ??? nixpkgs-unstable 1.22.1 pkgs.python313Packages.libnbd Network Block Device client library in userspace nixos-unstable ??? nixpkgs-unstable 1.22.1 Package maintainers: 1 @akshatagarwl Akshat Agarwal <humancalico@disroot.org> CVE-2021-46758 created 1 month, 1 week ago Insufficient validation of SPI flash addresses in the ASP (AMD … Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity. PI ==various pkgs.spoofdpi Simple and fast anti-censorship tool written in Go nixos-unstable ??? nixpkgs-unstable 0.12.0 pkgs.perlPackages.PPI Parse, Analyze and Manipulate Perl (without perl) nixos-unstable ??? nixpkgs-unstable 1.277 pkgs.perl538Packages.PPI Parse, Analyze and Manipulate Perl (without perl) nixos-unstable ??? nixpkgs-unstable 1.277 pkgs.perl540Packages.PPI Parse, Analyze and Manipulate Perl (without perl) nixos-unstable ??? nixpkgs-unstable 1.277 pkgs.perlPackages.GSSAPI Perl extension providing access to the GSSAPIv2 library nixos-unstable ??? nixpkgs-unstable 0.28 pkgs.perlPackages.PDFAPI2 Create, modify, and examine PDF files nixos-unstable ??? nixpkgs-unstable API2-2.045 pkgs.haskellPackages.hsPID PID control loop nixos-unstable ??? nixpkgs-unstable 0.1.2 pkgs.spirv-llvm-translator Tool and a library for bi-directional translation between SPIR-V and LLVM IR nixos-unstable ??? nixpkgs-unstable 19.1.10 pkgs.perl538Packages.GSSAPI Perl extension providing access to the GSSAPIv2 library nixos-unstable ??? nixpkgs-unstable 0.28 pkgs.perl540Packages.GSSAPI Perl extension providing access to the GSSAPIv2 library nixos-unstable ??? nixpkgs-unstable 0.28 pkgs.perlPackages.PPIxUtils Utility functions for PPI nixos-unstable ??? nixpkgs-unstable 0.003 pkgs.perl538Packages.PDFAPI2 Create, modify, and examine PDF files nixos-unstable ??? nixpkgs-unstable API2-2.045 pkgs.perl540Packages.PDFAPI2 Create, modify, and examine PDF files nixos-unstable ??? nixpkgs-unstable API2-2.045 pkgs.perlPackages.PPIxRegexp Parse regular expressions nixos-unstable ??? nixpkgs-unstable 0.088 pkgs.perlPackages.ProcPIDFile Manage process id files nixos-unstable ??? nixpkgs-unstable 1.29 pkgs.haskellPackages.EdisonAPI A library of efficient, purely-functional data structures (API) nixos-unstable ??? nixpkgs-unstable 1.3.3.2 pkgs.perl538Packages.PPIxUtils Utility functions for PPI nixos-unstable ??? nixpkgs-unstable 0.003 pkgs.perl540Packages.PPIxUtils Utility functions for PPI nixos-unstable ??? nixpkgs-unstable 0.003 pkgs.perlPackages.WWWTwilioAPI Accessing Twilio's REST API with Perl nixos-unstable ??? nixpkgs-unstable 0.21 pkgs.perl538Packages.PPIxRegexp Parse regular expressions nixos-unstable ??? nixpkgs-unstable 0.088 pkgs.perl540Packages.PPIxRegexp Parse regular expressions nixos-unstable ??? nixpkgs-unstable 0.088 pkgs.perlPackages.OpenAPIClient Client for talking to an Open API powered server nixos-unstable ??? nixpkgs-unstable 1.07 pkgs.perlPackages.PPIxQuoteLike Parse Perl string literals and string-literal-like things nixos-unstable ??? nixpkgs-unstable 0.023 pkgs.perlPackages.PPIxUtilities Extensions to PPI|PPI nixos-unstable ??? nixpkgs-unstable 1.001000 pkgs.perl538Packages.ProcPIDFile Manage process id files nixos-unstable ??? nixpkgs-unstable 1.29 pkgs.perl540Packages.ProcPIDFile Manage process id files nixos-unstable ??? nixpkgs-unstable 1.29 pkgs.perl538Packages.WWWTwilioAPI Accessing Twilio's REST API with Perl nixos-unstable ??? nixpkgs-unstable 0.21 pkgs.perl540Packages.WWWTwilioAPI Accessing Twilio's REST API with Perl nixos-unstable ??? nixpkgs-unstable 0.21 pkgs.perl538Packages.OpenAPIClient Client for talking to an Open API powered server nixos-unstable ??? nixpkgs-unstable 1.07 pkgs.perl538Packages.PPIxQuoteLike Parse Perl string literals and string-literal-like things nixos-unstable ??? nixpkgs-unstable 0.023 pkgs.perl538Packages.PPIxUtilities Extensions to PPI|PPI nixos-unstable ??? nixpkgs-unstable 1.001000 pkgs.perl540Packages.OpenAPIClient Client for talking to an Open API powered server nixos-unstable ??? nixpkgs-unstable 1.07 pkgs.perl540Packages.PPIxQuoteLike Parse Perl string literals and string-literal-like things nixos-unstable ??? nixpkgs-unstable 0.023 pkgs.perl540Packages.PPIxUtilities Extensions to PPI|PPI nixos-unstable ??? nixpkgs-unstable 1.001000 pkgs.perlPackages.MojoliciousPluginOpenAPI OpenAPI / Swagger plugin for Mojolicious nixos-unstable ??? nixpkgs-unstable 5.09 pkgs.perl538Packages.MojoliciousPluginOpenAPI OpenAPI / Swagger plugin for Mojolicious nixos-unstable ??? nixpkgs-unstable 5.09 pkgs.perl540Packages.MojoliciousPluginOpenAPI OpenAPI / Swagger plugin for Mojolicious nixos-unstable ??? nixpkgs-unstable 5.09 Package maintainers: 6 @stigtsp Stig Palmquist <stig@stig.io> @gloaming Craig Hall <ch9871@gmail.com> @despsyched Priyanshu Tripathi <priyanshu.tripathi@deshaw.com> @invokes-su Souvik Sen <nixpkgs-commits@deshaw.com> @de11n Elliot Cameron <nixpkgs-commits@deshaw.com> @s0me1newithhand7s hand7s <s0me1newithhand7s@gmail.com> CVE-2022-47161 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 1 month, 1 week ago WordPress Health Check & Troubleshooting Plugin <= 1.5.1 is vulnerable to Cross Site Request Forgery (CSRF) Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions. health-check =<1.5.1 pkgs.health-check Process monitoring tool nixos-unstable ??? nixpkgs-unstable 0.04.01 pkgs.grpc-health-check Minimal, high performance, memory-friendly, safe implementation of the gRPC health checking protocol nixos-unstable ??? nixpkgs-unstable 2022-08-19 pkgs.python312Packages.django-health-check Pluggable app that runs a full check on the deployment nixos-unstable ??? nixpkgs-unstable 3.20.0 pkgs.python313Packages.django-health-check Pluggable app that runs a full check on the deployment nixos-unstable ??? nixpkgs-unstable 3.20.0 pkgs.rubyPackages.github-pages-health-check nixos-unstable ??? nixpkgs-unstable 1.16.1 pkgs.python312Packages.grpcio-health-checking Standard Health Checking Service for gRPC nixos-unstable ??? nixpkgs-unstable 1.74.0 pkgs.python313Packages.grpcio-health-checking Standard Health Checking Service for gRPC nixos-unstable ??? nixpkgs-unstable 1.74.0 pkgs.rubyPackages_3_1.github-pages-health-check nixos-unstable ??? nixpkgs-unstable 1.16.1 pkgs.rubyPackages_3_2.github-pages-health-check nixos-unstable ??? nixpkgs-unstable 1.16.1 pkgs.rubyPackages_3_3.github-pages-health-check nixos-unstable ??? nixpkgs-unstable 1.16.1 pkgs.rubyPackages_3_4.github-pages-health-check nixos-unstable ??? nixpkgs-unstable 1.16.1 Package maintainers: 4 @onny Jonas Heinrich <onny@project-insanity.org> @happysalada Raphael Megzari <raphael@megzari.com> @dtzWill Will Dietz <w@wdtz.org> @flokli Florian Klink <flokli@flokli.de> CVE-2021-3429 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 1 month, 1 week ago sensitive data exposure in cloud-init logs When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user. cloud-init <21.2 pkgs.cloud-init Provides configuration and customization of cloud instance nixos-unstable ??? nixpkgs-unstable 25.2 Package maintainers: 2 @jfroche Jean-François Roche <jfroche@pyxel.be> @illustris Harikrishnan R <me@illustris.tech> CVE-2022-34148 4.8 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 1 month, 1 week ago WordPress Backup Guard Plugin <= 1.6.9.0 is vulnerable to Cross Site Scripting (XSS) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JetBackup JetBackup – WP Backup, Migrate & Restore plugin <= 1.6.9.0 versions. backup =<1.6.9.0 pkgs.ghbackup Backup your GitHub repositories with a simple command-line application written in Go nixos-unstable ??? nixpkgs-unstable 1.13.0 pkgs.dvdbackup Tool to rip video DVDs from the command line nixos-unstable ??? nixpkgs-unstable 0.4.2 pkgs.gb-backup Gamer Backup, a super opinionated cloud backup system nixos-unstable ??? nixpkgs-unstable 2021-10-27 pkgs.qr-backup Utility to generate paper backup of files using QR codes nixos-unstable ??? nixpkgs-unstable 1.1.4 pkgs.zfsbackup Backup ZFS snapshots to cloud storage such as Google, Amazon, Azure, etc nixos-unstable ??? nixpkgs-unstable 2022-09-23 pkgs.borgbackup Deduplicating archiver with compression and encryption nixos-unstable ??? nixpkgs-unstable 1.4.1 pkgs.luckybackup Powerful, fast and reliable backup & sync tool nixos-unstable ??? nixpkgs-unstable 0.5.0 pkgs.mylvmbackup Tool for quickly creating full physical backups of a MySQL server's data files nixos-unstable ??? nixpkgs-unstable 0.16 pkgs.pika-backup Simple backups based on borg nixos-unstable ??? nixpkgs-unstable 0.7.4 pkgs.storeBackup Backup suite that stores files on other disks nixos-unstable ??? nixpkgs-unstable 3.5.2 pkgs.rdiff-backup Backup system trying to combine best a mirror and an incremental backup system nixos-unstable ??? nixpkgs-unstable 2.2.6 pkgs.git-backup-go Backup all your GitHub & GitLab repositories nixos-unstable ??? nixpkgs-unstable 1.6.1 pkgs.github-backup Backup a github user or organization nixos-unstable ??? nixpkgs-unstable 0.50.3 pkgs.virtnbdbackup Backup utility for Libvirt/qemu/kvm nixos-unstable ??? nixpkgs-unstable 2.34 pkgs.zfs-autobackup ZFS backup, replicationand snapshot tool nixos-unstable ??? nixpkgs-unstable 3.3 pkgs.automysqlbackup Script to run daily, weekly and monthly backups for your MySQL database nixos-unstable ??? nixpkgs-unstable 3.0.7 pkgs.urbackup-client Easy to setup Open Source client/server backup system nixos-unstable ??? nixpkgs-unstable 2.5.25 pkgs.one-click-backup Simple Program to backup folders to an external location by copying them nixos-unstable ??? nixpkgs-unstable 1.2.2.1 pkgs.clickhouse-backup Tool for easy ClickHouse backup and restore using object storage for backup files nixos-unstable ??? nixpkgs-unstable 2.6.33 pkgs.signalbackup-tools Tool to work with Signal Backup files nixos-unstable ??? nixpkgs-unstable 20250824 pkgs.kdePackages.kbackup Backup program with an easy-to-use interface nixos-unstable ??? nixpkgs-unstable 25.08.1 pkgs.unifi-protect-backup Python tool to backup unifi event clips in realtime nixos-unstable ??? nixpkgs-unstable 0.11.0 pkgs.pinboard-notes-backup Back up the notes you've saved to Pinboard nixos-unstable ??? nixpkgs-unstable 1.0.7 pkgs.proxmox-backup-client Command line client for Proxmox Backup Server nixos-unstable ??? nixpkgs-unstable 4.0.14 pkgs.percona-xtrabackup_8_0 Non-blocking backup tool for MySQL nixos-unstable ??? nixpkgs-unstable 8.0.35-32 pkgs.percona-xtrabackup_lts Non-blocking backup tool for MySQL nixos-unstable ??? nixpkgs-unstable 8.4.0-2 pkgs.android-backup-extractor Utility to extract and repack Android backups created with adb backup nixos-unstable ??? nixpkgs-unstable 0-unstable-2025-01-15 pkgs.signal-backup-deduplicator Generate chunked backups for Signal messages nixos-unstable ??? nixpkgs-unstable 0-unstable-2024-05-24 pkgs.python312Packages.iosbackup Reads and extracts files from password-encrypted iOS backups nixos-unstable ??? nixpkgs-unstable 0.9.925 pkgs.python313Packages.iosbackup Reads and extracts files from password-encrypted iOS backups nixos-unstable ??? nixpkgs-unstable 0.9.925 pkgs.haskellPackages.amazonka-backup Amazon Backup SDK nixos-unstable ??? nixpkgs-unstable 2.0 pkgs.python312Packages.android-backup Unpack and repack android backups nixos-unstable ??? nixpkgs-unstable 0.2.0 pkgs.python313Packages.android-backup Unpack and repack android backups nixos-unstable ??? nixpkgs-unstable 0.2.0 pkgs.python312Packages.mypy-boto3-backup Type annotations for boto3 backup nixos-unstable ??? nixpkgs-unstable boto3-backup-1.40.0 pkgs.python313Packages.mypy-boto3-backup Type annotations for boto3 backup nixos-unstable ??? nixpkgs-unstable boto3-backup-1.40.0 pkgs.haskellPackages.pinboard-notes-backup Back up the notes you've saved to Pinboard nixos-unstable ??? nixpkgs-unstable 1.0.7 pkgs.home-assistant-component-tests.backup Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3 pkgs.haskellPackages.amazonka-backupstorage Amazon Backup Storage SDK nixos-unstable ??? nixpkgs-unstable 2.0 pkgs.haskellPackages.amazonka-backup-gateway Amazon Backup Gateway SDK nixos-unstable ??? nixpkgs-unstable 2.0 pkgs.python312Packages.types-aiobotocore-backup Type annotations for aiobotocore backup nixos-unstable ??? nixpkgs-unstable 2.23.2 pkgs.python313Packages.types-aiobotocore-backup Type annotations for aiobotocore backup nixos-unstable ??? nixpkgs-unstable 2.23.2 pkgs.python312Packages.mypy-boto3-backup-gateway Type annotations for boto3 backup-gateway nixos-unstable ??? nixpkgs-unstable boto3-backup-gateway-1.40.15 pkgs.python313Packages.mypy-boto3-backup-gateway Type annotations for boto3 backup-gateway nixos-unstable ??? nixpkgs-unstable boto3-backup-gateway-1.40.15 pkgs.python312Packages.types-aiobotocore-backupstorage Type annotations for aiobotocore backupstorage nixos-unstable ??? nixpkgs-unstable 2.13.0 pkgs.python313Packages.types-aiobotocore-backupstorage Type annotations for aiobotocore backupstorage nixos-unstable ??? nixpkgs-unstable 2.13.0 pkgs.python312Packages.types-aiobotocore-backup-gateway Type annotations for aiobotocore backup-gateway nixos-unstable ??? nixpkgs-unstable 2.23.2 pkgs.python313Packages.types-aiobotocore-backup-gateway Type annotations for aiobotocore backup-gateway nixos-unstable ??? nixpkgs-unstable 2.23.2 pkgs.python312Packages.azure-mgmt-recoveryservicesbackup This is the Microsoft Azure Recovery Services Backup Management Client Library nixos-unstable ??? nixpkgs-unstable 9.2.0 pkgs.python313Packages.azure-mgmt-recoveryservicesbackup This is the Microsoft Azure Recovery Services Backup Management Client Library nixos-unstable ??? nixpkgs-unstable 9.2.0 Package maintainers: 44 @prusnak Pavol Rusnak <pavol@rusnak.io> @ryantm Ryan Mulligan <ryan@ryantm.com> @helsinki-Jo Joachim Ernst <joachim.ernst@helsinki-systems.de> @dasJ Janne Heß <janne@hess.ooo> @Conni2461 Simon Hauser <simon-hauser@outlook.com> @aanderse Aaron Andersen <aaron@fosslib.net> @mbalatsko Maksym Balatsko <mbalatsko@gmail.com> @mwilsoncoding Max Wilson <nixpkgs@maxwilson.dev> @Izorkin Yurii Izorkin <Izorkin@gmail.com> @frlan Frank Lanitz <frank@frank.uvena.de> @dpausp Tobias Stenzel <dpausp@posteo.de> @osnyx Oliver Schmidt <os@flyingcircus.io> @ctheune Christian Theune <ct@flyingcircus.io> @leona-ya Leona Maroni <nix@leona.is> @devusb Morgan Helton <mhelton@devusb.us> @bradediger Brad Ediger <brad@bradediger.com> @mgttlinger Merlin Humml <megoettlinger@gmail.com> @dotlambda Robert Schütz <rschuetz17@gmail.com> @PapayaJackal PapayaJackal @Aleksanaa Aleksana QwQ <me@aleksana.moe> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @MarcWeber Marc Weber <marco-oweber@gmx.de> @bdesham Benjamin Esham <benjamin@esham.io> @globin Robin Gloster <mail@glob.in> @christoph-heiss Christoph Heiss <christoph@c8h4.io> @cofob Egor Ternovoy <cofob@riseup.net> @malob Malo Bourgon <mbourgon@gmail.com> @LennyPenny Lenny. @dev-nis NSC IT Solutions @NickCao Nick Cao <nickcao@nichi.co> @ttuegel Thomas Tuegel <ttuegel@mailbox.org> @LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev> @ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru> @mjm Matt Moriarity <matt@mattmoriarity.com> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> @K900 Ilya K. <me@0upti.me> @genga898 Emmanuel Genga <genga898@gmail.com> @GaetanLepage Gaetan Lepage <gaetan@glepage.com> @michaelgrahamevans Michael Evans <michaelgrahamevans@gmail.com> @getchoo Seth Flynn <getchoo@tuta.io> @acuteaangle Summer Tea <zestypurple@protonmail.com> @peterhoeg Peter Hoeg <peter@hoeg.com> @babbaj babbaj <babbaj45@gmail.com> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> CVE-2022-4145 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 1 month, 1 week ago Content spoofing A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation. openshift pkgs.openshift Build, deploy, and manage your applications with Docker and Kubernetes nixos-unstable ??? nixpkgs-unstable 4.16.0 pkgs.python312Packages.openshift Python client for the OpenShift API nixos-unstable ??? nixpkgs-unstable 0.13.2 pkgs.python313Packages.openshift Python client for the OpenShift API nixos-unstable ??? nixpkgs-unstable 0.13.2 pkgs.python312Packages.azure-mgmt-redhatopenshift Microsoft Azure Red Hat Openshift Management Client Library for Python nixos-unstable ??? nixpkgs-unstable 2.0.0 pkgs.python313Packages.azure-mgmt-redhatopenshift Microsoft Azure Red Hat Openshift Management Client Library for Python nixos-unstable ??? nixpkgs-unstable 2.0.0 Package maintainers: 4 @teto Matthieu Coudron <mcoudron@hotmail.com> @offlinehacker Jaka Hudoklin <jaka@x-truder.net> @moretea Maarten Hoogendoorn <maarten@moretea.nl> @stehessel Stephan Heßelmann <stephan@stehessel.de> CVE-2022-47183 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress Extra Block Design, Style, CSS for ANY Gutenberg Blocks Plugin <= 0.2.6 is vulnerable to Cross Site Request Forgery (CSRF) Cross-Site Request Forgery (CSRF) vulnerability in StylistWP Extra Block Design, Style, CSS for ANY Gutenberg Blocks plugin <= 0.2.6 versions. stylist =<0.2.6 pkgs.haskellPackages.stylist-traits Traits, datatypes, & parsers for Haskell Stylist nixos-unstable ??? nixpkgs-unstable 0.1.4.0 CVE-2022-47613 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress AI ChatBot Plugin <= 4.3.0 is vulnerable to Cross Site Scripting (XSS) Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud AI ChatBot plugin <= 4.3.0 versions. chatbot =<4.3.0 pkgs.gnomeExtensions.penguin-ai-chatbot A GNOME Shell extension that provides a chatbot interface using various LLM providers, including Anthropic, OpenAI, Gemini, and OpenRouter. Features include multiple provider support, customizable models, chat history, customizable appearance, a keyboard shortcut, and copy-to-clipboard functionality. nixos-unstable ??? nixpkgs-unstable 22 Package maintainers: 1 @honnip Jung seungwoo <me@honnip.page> CVE-2022-4510 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago Path Traversal in binwalk A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesystem file, an attacker can get binwalk's PFS extractor to extract files at arbitrary locations when binwalk is run in extraction mode (-e option). Remote code execution can be achieved by building a PFS filesystem that, upon extraction, would extract a malicious binwalk module into the folder .config/binwalk/plugins. This vulnerability is associated with program files src/binwalk/plugins/unpfs.py. This issue affects binwalk from 2.1.2b through 2.3.3 included. binwalk =<2.3.3 pkgs.binwalk Firmware Analysis Tool nixos-unstable ??? nixpkgs-unstable 3.1.0 Package maintainers: 2 @k0ral Koral <koral@mailoo.org> @felbinger Nico Felbinger <nico@felbinger.eu>
CVE-2024-5290 8.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago An issue was discovered in Ubuntu wpa_supplicant that resulted in … An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root). Membership in the netdev group or access to the dbus interface of wpa_supplicant allow an unprivileged user to specify an arbitrary path to a module to be loaded by the wpa_supplicant process; other escalation paths might exist. wpa <2:2.9-1ubuntu4.4 <2.4-0ubuntu6.8+esm1 <2:2.10-21ubuntu0.1 <2:2.10-6ubuntu2.1 <2.1-0ubuntu1.7+esm5 <2:2.6-15ubuntu2.8+esm1 pkgs.wpaperd Minimal wallpaper daemon for Wayland nixos-unstable ??? nixpkgs-unstable 1.2.2 pkgs.cowpatty Offline dictionary attack against WPA/WPA2 networks nixos-unstable ??? nixpkgs-unstable 4.8 pkgs.vowpal-wabbit Machine learning system focused on online reinforcement learning nixos-unstable ??? nixpkgs-unstable 9.10.0 pkgs.wpa_supplicant_gui Qt-based GUI for wpa_supplicant nixos-unstable ??? nixpkgs-unstable 2.11 pkgs.wpa_supplicant_ro_ssids Tool for connecting to WPA and WPA2-protected wireless networks nixos-unstable ??? nixpkgs-unstable 2.11 pkgs.python312Packages.vowpalwabbit Vowpal Wabbit is a fast machine learning library for online learning, and this is the python wrapper for the project nixos-unstable ??? nixpkgs-unstable 9.10.0 pkgs.python313Packages.vowpalwabbit Vowpal Wabbit is a fast machine learning library for online learning, and this is the python wrapper for the project nixos-unstable ??? nixpkgs-unstable 9.10.0 pkgs.python312Packages.mwparserfromhell MWParserFromHell is a parser for MediaWiki wikicode nixos-unstable ??? nixpkgs-unstable 0.7.2 pkgs.python313Packages.mwparserfromhell MWParserFromHell is a parser for MediaWiki wikicode nixos-unstable ??? nixpkgs-unstable 0.7.2 pkgs.vscode-extensions.twpayne.vscode-testscript Syntax highlighting support for testscript nixos-unstable ??? nixpkgs-unstable 0.0.7 Package maintainers: 9 @teh Tom Hunger <tehunger@gmail.com> @mattmelling Matt Melling <mattmelling@fastmail.com> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @nico202 Nicolò Balzarotti <anothersms@gmail.com> @MarcWeber Marc Weber <marco-oweber@gmx.de> @Ma27 Maximilian Bosch <maximilian@mbosch.me> @fsnkty fsnkty <fsnkty@shimeji.cafe> @DPDmancul Davide Peressoni <davide.peressoni@tuta.io> @jackgerrits Jack Gerrits <jack@jackgerrits.com>
wpa <2:2.9-1ubuntu4.4 <2.4-0ubuntu6.8+esm1 <2:2.10-21ubuntu0.1 <2:2.10-6ubuntu2.1 <2.1-0ubuntu1.7+esm5 <2:2.6-15ubuntu2.8+esm1
pkgs.cowpatty Offline dictionary attack against WPA/WPA2 networks nixos-unstable ??? nixpkgs-unstable 4.8
pkgs.vowpal-wabbit Machine learning system focused on online reinforcement learning nixos-unstable ??? nixpkgs-unstable 9.10.0
pkgs.wpa_supplicant_ro_ssids Tool for connecting to WPA and WPA2-protected wireless networks nixos-unstable ??? nixpkgs-unstable 2.11
pkgs.python312Packages.vowpalwabbit Vowpal Wabbit is a fast machine learning library for online learning, and this is the python wrapper for the project nixos-unstable ??? nixpkgs-unstable 9.10.0
pkgs.python313Packages.vowpalwabbit Vowpal Wabbit is a fast machine learning library for online learning, and this is the python wrapper for the project nixos-unstable ??? nixpkgs-unstable 9.10.0
pkgs.python312Packages.mwparserfromhell MWParserFromHell is a parser for MediaWiki wikicode nixos-unstable ??? nixpkgs-unstable 0.7.2
pkgs.python313Packages.mwparserfromhell MWParserFromHell is a parser for MediaWiki wikicode nixos-unstable ??? nixpkgs-unstable 0.7.2
pkgs.vscode-extensions.twpayne.vscode-testscript Syntax highlighting support for testscript nixos-unstable ??? nixpkgs-unstable 0.0.7
CVE-2024-7383 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 1 month, 1 week ago Libnbd: nbd server improper certificate validation A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic. libnbd <1.18.5 <1.20.2 * virt:rhel * virt:av/libnbd virt-devel:rhel * virt:rhel/libnbd pkgs.libnbd Network Block Device client library in userspace nixos-unstable ??? nixpkgs-unstable 1.22.1 pkgs.python312Packages.libnbd Network Block Device client library in userspace nixos-unstable ??? nixpkgs-unstable 1.22.1 pkgs.python313Packages.libnbd Network Block Device client library in userspace nixos-unstable ??? nixpkgs-unstable 1.22.1 Package maintainers: 1 @akshatagarwl Akshat Agarwal <humancalico@disroot.org>
pkgs.libnbd Network Block Device client library in userspace nixos-unstable ??? nixpkgs-unstable 1.22.1
pkgs.python312Packages.libnbd Network Block Device client library in userspace nixos-unstable ??? nixpkgs-unstable 1.22.1
pkgs.python313Packages.libnbd Network Block Device client library in userspace nixos-unstable ??? nixpkgs-unstable 1.22.1
CVE-2021-46758 created 1 month, 1 week ago Insufficient validation of SPI flash addresses in the ASP (AMD … Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity. PI ==various pkgs.spoofdpi Simple and fast anti-censorship tool written in Go nixos-unstable ??? nixpkgs-unstable 0.12.0 pkgs.perlPackages.PPI Parse, Analyze and Manipulate Perl (without perl) nixos-unstable ??? nixpkgs-unstable 1.277 pkgs.perl538Packages.PPI Parse, Analyze and Manipulate Perl (without perl) nixos-unstable ??? nixpkgs-unstable 1.277 pkgs.perl540Packages.PPI Parse, Analyze and Manipulate Perl (without perl) nixos-unstable ??? nixpkgs-unstable 1.277 pkgs.perlPackages.GSSAPI Perl extension providing access to the GSSAPIv2 library nixos-unstable ??? nixpkgs-unstable 0.28 pkgs.perlPackages.PDFAPI2 Create, modify, and examine PDF files nixos-unstable ??? nixpkgs-unstable API2-2.045 pkgs.haskellPackages.hsPID PID control loop nixos-unstable ??? nixpkgs-unstable 0.1.2 pkgs.spirv-llvm-translator Tool and a library for bi-directional translation between SPIR-V and LLVM IR nixos-unstable ??? nixpkgs-unstable 19.1.10 pkgs.perl538Packages.GSSAPI Perl extension providing access to the GSSAPIv2 library nixos-unstable ??? nixpkgs-unstable 0.28 pkgs.perl540Packages.GSSAPI Perl extension providing access to the GSSAPIv2 library nixos-unstable ??? nixpkgs-unstable 0.28 pkgs.perlPackages.PPIxUtils Utility functions for PPI nixos-unstable ??? nixpkgs-unstable 0.003 pkgs.perl538Packages.PDFAPI2 Create, modify, and examine PDF files nixos-unstable ??? nixpkgs-unstable API2-2.045 pkgs.perl540Packages.PDFAPI2 Create, modify, and examine PDF files nixos-unstable ??? nixpkgs-unstable API2-2.045 pkgs.perlPackages.PPIxRegexp Parse regular expressions nixos-unstable ??? nixpkgs-unstable 0.088 pkgs.perlPackages.ProcPIDFile Manage process id files nixos-unstable ??? nixpkgs-unstable 1.29 pkgs.haskellPackages.EdisonAPI A library of efficient, purely-functional data structures (API) nixos-unstable ??? nixpkgs-unstable 1.3.3.2 pkgs.perl538Packages.PPIxUtils Utility functions for PPI nixos-unstable ??? nixpkgs-unstable 0.003 pkgs.perl540Packages.PPIxUtils Utility functions for PPI nixos-unstable ??? nixpkgs-unstable 0.003 pkgs.perlPackages.WWWTwilioAPI Accessing Twilio's REST API with Perl nixos-unstable ??? nixpkgs-unstable 0.21 pkgs.perl538Packages.PPIxRegexp Parse regular expressions nixos-unstable ??? nixpkgs-unstable 0.088 pkgs.perl540Packages.PPIxRegexp Parse regular expressions nixos-unstable ??? nixpkgs-unstable 0.088 pkgs.perlPackages.OpenAPIClient Client for talking to an Open API powered server nixos-unstable ??? nixpkgs-unstable 1.07 pkgs.perlPackages.PPIxQuoteLike Parse Perl string literals and string-literal-like things nixos-unstable ??? nixpkgs-unstable 0.023 pkgs.perlPackages.PPIxUtilities Extensions to PPI|PPI nixos-unstable ??? nixpkgs-unstable 1.001000 pkgs.perl538Packages.ProcPIDFile Manage process id files nixos-unstable ??? nixpkgs-unstable 1.29 pkgs.perl540Packages.ProcPIDFile Manage process id files nixos-unstable ??? nixpkgs-unstable 1.29 pkgs.perl538Packages.WWWTwilioAPI Accessing Twilio's REST API with Perl nixos-unstable ??? nixpkgs-unstable 0.21 pkgs.perl540Packages.WWWTwilioAPI Accessing Twilio's REST API with Perl nixos-unstable ??? nixpkgs-unstable 0.21 pkgs.perl538Packages.OpenAPIClient Client for talking to an Open API powered server nixos-unstable ??? nixpkgs-unstable 1.07 pkgs.perl538Packages.PPIxQuoteLike Parse Perl string literals and string-literal-like things nixos-unstable ??? nixpkgs-unstable 0.023 pkgs.perl538Packages.PPIxUtilities Extensions to PPI|PPI nixos-unstable ??? nixpkgs-unstable 1.001000 pkgs.perl540Packages.OpenAPIClient Client for talking to an Open API powered server nixos-unstable ??? nixpkgs-unstable 1.07 pkgs.perl540Packages.PPIxQuoteLike Parse Perl string literals and string-literal-like things nixos-unstable ??? nixpkgs-unstable 0.023 pkgs.perl540Packages.PPIxUtilities Extensions to PPI|PPI nixos-unstable ??? nixpkgs-unstable 1.001000 pkgs.perlPackages.MojoliciousPluginOpenAPI OpenAPI / Swagger plugin for Mojolicious nixos-unstable ??? nixpkgs-unstable 5.09 pkgs.perl538Packages.MojoliciousPluginOpenAPI OpenAPI / Swagger plugin for Mojolicious nixos-unstable ??? nixpkgs-unstable 5.09 pkgs.perl540Packages.MojoliciousPluginOpenAPI OpenAPI / Swagger plugin for Mojolicious nixos-unstable ??? nixpkgs-unstable 5.09 Package maintainers: 6 @stigtsp Stig Palmquist <stig@stig.io> @gloaming Craig Hall <ch9871@gmail.com> @despsyched Priyanshu Tripathi <priyanshu.tripathi@deshaw.com> @invokes-su Souvik Sen <nixpkgs-commits@deshaw.com> @de11n Elliot Cameron <nixpkgs-commits@deshaw.com> @s0me1newithhand7s hand7s <s0me1newithhand7s@gmail.com>
pkgs.spoofdpi Simple and fast anti-censorship tool written in Go nixos-unstable ??? nixpkgs-unstable 0.12.0
pkgs.perlPackages.PPI Parse, Analyze and Manipulate Perl (without perl) nixos-unstable ??? nixpkgs-unstable 1.277
pkgs.perl538Packages.PPI Parse, Analyze and Manipulate Perl (without perl) nixos-unstable ??? nixpkgs-unstable 1.277
pkgs.perl540Packages.PPI Parse, Analyze and Manipulate Perl (without perl) nixos-unstable ??? nixpkgs-unstable 1.277
pkgs.perlPackages.GSSAPI Perl extension providing access to the GSSAPIv2 library nixos-unstable ??? nixpkgs-unstable 0.28
pkgs.perlPackages.PDFAPI2 Create, modify, and examine PDF files nixos-unstable ??? nixpkgs-unstable API2-2.045
pkgs.spirv-llvm-translator Tool and a library for bi-directional translation between SPIR-V and LLVM IR nixos-unstable ??? nixpkgs-unstable 19.1.10
pkgs.perl538Packages.GSSAPI Perl extension providing access to the GSSAPIv2 library nixos-unstable ??? nixpkgs-unstable 0.28
pkgs.perl540Packages.GSSAPI Perl extension providing access to the GSSAPIv2 library nixos-unstable ??? nixpkgs-unstable 0.28
pkgs.perl538Packages.PDFAPI2 Create, modify, and examine PDF files nixos-unstable ??? nixpkgs-unstable API2-2.045
pkgs.perl540Packages.PDFAPI2 Create, modify, and examine PDF files nixos-unstable ??? nixpkgs-unstable API2-2.045
pkgs.haskellPackages.EdisonAPI A library of efficient, purely-functional data structures (API) nixos-unstable ??? nixpkgs-unstable 1.3.3.2
pkgs.perlPackages.WWWTwilioAPI Accessing Twilio's REST API with Perl nixos-unstable ??? nixpkgs-unstable 0.21
pkgs.perlPackages.OpenAPIClient Client for talking to an Open API powered server nixos-unstable ??? nixpkgs-unstable 1.07
pkgs.perlPackages.PPIxQuoteLike Parse Perl string literals and string-literal-like things nixos-unstable ??? nixpkgs-unstable 0.023
pkgs.perl538Packages.WWWTwilioAPI Accessing Twilio's REST API with Perl nixos-unstable ??? nixpkgs-unstable 0.21
pkgs.perl540Packages.WWWTwilioAPI Accessing Twilio's REST API with Perl nixos-unstable ??? nixpkgs-unstable 0.21
pkgs.perl538Packages.OpenAPIClient Client for talking to an Open API powered server nixos-unstable ??? nixpkgs-unstable 1.07
pkgs.perl538Packages.PPIxQuoteLike Parse Perl string literals and string-literal-like things nixos-unstable ??? nixpkgs-unstable 0.023
pkgs.perl538Packages.PPIxUtilities Extensions to PPI|PPI nixos-unstable ??? nixpkgs-unstable 1.001000
pkgs.perl540Packages.OpenAPIClient Client for talking to an Open API powered server nixos-unstable ??? nixpkgs-unstable 1.07
pkgs.perl540Packages.PPIxQuoteLike Parse Perl string literals and string-literal-like things nixos-unstable ??? nixpkgs-unstable 0.023
pkgs.perl540Packages.PPIxUtilities Extensions to PPI|PPI nixos-unstable ??? nixpkgs-unstable 1.001000
pkgs.perlPackages.MojoliciousPluginOpenAPI OpenAPI / Swagger plugin for Mojolicious nixos-unstable ??? nixpkgs-unstable 5.09
pkgs.perl538Packages.MojoliciousPluginOpenAPI OpenAPI / Swagger plugin for Mojolicious nixos-unstable ??? nixpkgs-unstable 5.09
pkgs.perl540Packages.MojoliciousPluginOpenAPI OpenAPI / Swagger plugin for Mojolicious nixos-unstable ??? nixpkgs-unstable 5.09
CVE-2022-47161 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 1 month, 1 week ago WordPress Health Check & Troubleshooting Plugin <= 1.5.1 is vulnerable to Cross Site Request Forgery (CSRF) Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions. health-check =<1.5.1 pkgs.health-check Process monitoring tool nixos-unstable ??? nixpkgs-unstable 0.04.01 pkgs.grpc-health-check Minimal, high performance, memory-friendly, safe implementation of the gRPC health checking protocol nixos-unstable ??? nixpkgs-unstable 2022-08-19 pkgs.python312Packages.django-health-check Pluggable app that runs a full check on the deployment nixos-unstable ??? nixpkgs-unstable 3.20.0 pkgs.python313Packages.django-health-check Pluggable app that runs a full check on the deployment nixos-unstable ??? nixpkgs-unstable 3.20.0 pkgs.rubyPackages.github-pages-health-check nixos-unstable ??? nixpkgs-unstable 1.16.1 pkgs.python312Packages.grpcio-health-checking Standard Health Checking Service for gRPC nixos-unstable ??? nixpkgs-unstable 1.74.0 pkgs.python313Packages.grpcio-health-checking Standard Health Checking Service for gRPC nixos-unstable ??? nixpkgs-unstable 1.74.0 pkgs.rubyPackages_3_1.github-pages-health-check nixos-unstable ??? nixpkgs-unstable 1.16.1 pkgs.rubyPackages_3_2.github-pages-health-check nixos-unstable ??? nixpkgs-unstable 1.16.1 pkgs.rubyPackages_3_3.github-pages-health-check nixos-unstable ??? nixpkgs-unstable 1.16.1 pkgs.rubyPackages_3_4.github-pages-health-check nixos-unstable ??? nixpkgs-unstable 1.16.1 Package maintainers: 4 @onny Jonas Heinrich <onny@project-insanity.org> @happysalada Raphael Megzari <raphael@megzari.com> @dtzWill Will Dietz <w@wdtz.org> @flokli Florian Klink <flokli@flokli.de>
pkgs.grpc-health-check Minimal, high performance, memory-friendly, safe implementation of the gRPC health checking protocol nixos-unstable ??? nixpkgs-unstable 2022-08-19
pkgs.python312Packages.django-health-check Pluggable app that runs a full check on the deployment nixos-unstable ??? nixpkgs-unstable 3.20.0
pkgs.python313Packages.django-health-check Pluggable app that runs a full check on the deployment nixos-unstable ??? nixpkgs-unstable 3.20.0
pkgs.python312Packages.grpcio-health-checking Standard Health Checking Service for gRPC nixos-unstable ??? nixpkgs-unstable 1.74.0
pkgs.python313Packages.grpcio-health-checking Standard Health Checking Service for gRPC nixos-unstable ??? nixpkgs-unstable 1.74.0
CVE-2021-3429 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 1 month, 1 week ago sensitive data exposure in cloud-init logs When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user. cloud-init <21.2 pkgs.cloud-init Provides configuration and customization of cloud instance nixos-unstable ??? nixpkgs-unstable 25.2 Package maintainers: 2 @jfroche Jean-François Roche <jfroche@pyxel.be> @illustris Harikrishnan R <me@illustris.tech>
pkgs.cloud-init Provides configuration and customization of cloud instance nixos-unstable ??? nixpkgs-unstable 25.2
CVE-2022-34148 4.8 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 1 month, 1 week ago WordPress Backup Guard Plugin <= 1.6.9.0 is vulnerable to Cross Site Scripting (XSS) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JetBackup JetBackup – WP Backup, Migrate & Restore plugin <= 1.6.9.0 versions. backup =<1.6.9.0 pkgs.ghbackup Backup your GitHub repositories with a simple command-line application written in Go nixos-unstable ??? nixpkgs-unstable 1.13.0 pkgs.dvdbackup Tool to rip video DVDs from the command line nixos-unstable ??? nixpkgs-unstable 0.4.2 pkgs.gb-backup Gamer Backup, a super opinionated cloud backup system nixos-unstable ??? nixpkgs-unstable 2021-10-27 pkgs.qr-backup Utility to generate paper backup of files using QR codes nixos-unstable ??? nixpkgs-unstable 1.1.4 pkgs.zfsbackup Backup ZFS snapshots to cloud storage such as Google, Amazon, Azure, etc nixos-unstable ??? nixpkgs-unstable 2022-09-23 pkgs.borgbackup Deduplicating archiver with compression and encryption nixos-unstable ??? nixpkgs-unstable 1.4.1 pkgs.luckybackup Powerful, fast and reliable backup & sync tool nixos-unstable ??? nixpkgs-unstable 0.5.0 pkgs.mylvmbackup Tool for quickly creating full physical backups of a MySQL server's data files nixos-unstable ??? nixpkgs-unstable 0.16 pkgs.pika-backup Simple backups based on borg nixos-unstable ??? nixpkgs-unstable 0.7.4 pkgs.storeBackup Backup suite that stores files on other disks nixos-unstable ??? nixpkgs-unstable 3.5.2 pkgs.rdiff-backup Backup system trying to combine best a mirror and an incremental backup system nixos-unstable ??? nixpkgs-unstable 2.2.6 pkgs.git-backup-go Backup all your GitHub & GitLab repositories nixos-unstable ??? nixpkgs-unstable 1.6.1 pkgs.github-backup Backup a github user or organization nixos-unstable ??? nixpkgs-unstable 0.50.3 pkgs.virtnbdbackup Backup utility for Libvirt/qemu/kvm nixos-unstable ??? nixpkgs-unstable 2.34 pkgs.zfs-autobackup ZFS backup, replicationand snapshot tool nixos-unstable ??? nixpkgs-unstable 3.3 pkgs.automysqlbackup Script to run daily, weekly and monthly backups for your MySQL database nixos-unstable ??? nixpkgs-unstable 3.0.7 pkgs.urbackup-client Easy to setup Open Source client/server backup system nixos-unstable ??? nixpkgs-unstable 2.5.25 pkgs.one-click-backup Simple Program to backup folders to an external location by copying them nixos-unstable ??? nixpkgs-unstable 1.2.2.1 pkgs.clickhouse-backup Tool for easy ClickHouse backup and restore using object storage for backup files nixos-unstable ??? nixpkgs-unstable 2.6.33 pkgs.signalbackup-tools Tool to work with Signal Backup files nixos-unstable ??? nixpkgs-unstable 20250824 pkgs.kdePackages.kbackup Backup program with an easy-to-use interface nixos-unstable ??? nixpkgs-unstable 25.08.1 pkgs.unifi-protect-backup Python tool to backup unifi event clips in realtime nixos-unstable ??? nixpkgs-unstable 0.11.0 pkgs.pinboard-notes-backup Back up the notes you've saved to Pinboard nixos-unstable ??? nixpkgs-unstable 1.0.7 pkgs.proxmox-backup-client Command line client for Proxmox Backup Server nixos-unstable ??? nixpkgs-unstable 4.0.14 pkgs.percona-xtrabackup_8_0 Non-blocking backup tool for MySQL nixos-unstable ??? nixpkgs-unstable 8.0.35-32 pkgs.percona-xtrabackup_lts Non-blocking backup tool for MySQL nixos-unstable ??? nixpkgs-unstable 8.4.0-2 pkgs.android-backup-extractor Utility to extract and repack Android backups created with adb backup nixos-unstable ??? nixpkgs-unstable 0-unstable-2025-01-15 pkgs.signal-backup-deduplicator Generate chunked backups for Signal messages nixos-unstable ??? nixpkgs-unstable 0-unstable-2024-05-24 pkgs.python312Packages.iosbackup Reads and extracts files from password-encrypted iOS backups nixos-unstable ??? nixpkgs-unstable 0.9.925 pkgs.python313Packages.iosbackup Reads and extracts files from password-encrypted iOS backups nixos-unstable ??? nixpkgs-unstable 0.9.925 pkgs.haskellPackages.amazonka-backup Amazon Backup SDK nixos-unstable ??? nixpkgs-unstable 2.0 pkgs.python312Packages.android-backup Unpack and repack android backups nixos-unstable ??? nixpkgs-unstable 0.2.0 pkgs.python313Packages.android-backup Unpack and repack android backups nixos-unstable ??? nixpkgs-unstable 0.2.0 pkgs.python312Packages.mypy-boto3-backup Type annotations for boto3 backup nixos-unstable ??? nixpkgs-unstable boto3-backup-1.40.0 pkgs.python313Packages.mypy-boto3-backup Type annotations for boto3 backup nixos-unstable ??? nixpkgs-unstable boto3-backup-1.40.0 pkgs.haskellPackages.pinboard-notes-backup Back up the notes you've saved to Pinboard nixos-unstable ??? nixpkgs-unstable 1.0.7 pkgs.home-assistant-component-tests.backup Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3 pkgs.haskellPackages.amazonka-backupstorage Amazon Backup Storage SDK nixos-unstable ??? nixpkgs-unstable 2.0 pkgs.haskellPackages.amazonka-backup-gateway Amazon Backup Gateway SDK nixos-unstable ??? nixpkgs-unstable 2.0 pkgs.python312Packages.types-aiobotocore-backup Type annotations for aiobotocore backup nixos-unstable ??? nixpkgs-unstable 2.23.2 pkgs.python313Packages.types-aiobotocore-backup Type annotations for aiobotocore backup nixos-unstable ??? nixpkgs-unstable 2.23.2 pkgs.python312Packages.mypy-boto3-backup-gateway Type annotations for boto3 backup-gateway nixos-unstable ??? nixpkgs-unstable boto3-backup-gateway-1.40.15 pkgs.python313Packages.mypy-boto3-backup-gateway Type annotations for boto3 backup-gateway nixos-unstable ??? nixpkgs-unstable boto3-backup-gateway-1.40.15 pkgs.python312Packages.types-aiobotocore-backupstorage Type annotations for aiobotocore backupstorage nixos-unstable ??? nixpkgs-unstable 2.13.0 pkgs.python313Packages.types-aiobotocore-backupstorage Type annotations for aiobotocore backupstorage nixos-unstable ??? nixpkgs-unstable 2.13.0 pkgs.python312Packages.types-aiobotocore-backup-gateway Type annotations for aiobotocore backup-gateway nixos-unstable ??? nixpkgs-unstable 2.23.2 pkgs.python313Packages.types-aiobotocore-backup-gateway Type annotations for aiobotocore backup-gateway nixos-unstable ??? nixpkgs-unstable 2.23.2 pkgs.python312Packages.azure-mgmt-recoveryservicesbackup This is the Microsoft Azure Recovery Services Backup Management Client Library nixos-unstable ??? nixpkgs-unstable 9.2.0 pkgs.python313Packages.azure-mgmt-recoveryservicesbackup This is the Microsoft Azure Recovery Services Backup Management Client Library nixos-unstable ??? nixpkgs-unstable 9.2.0 Package maintainers: 44 @prusnak Pavol Rusnak <pavol@rusnak.io> @ryantm Ryan Mulligan <ryan@ryantm.com> @helsinki-Jo Joachim Ernst <joachim.ernst@helsinki-systems.de> @dasJ Janne Heß <janne@hess.ooo> @Conni2461 Simon Hauser <simon-hauser@outlook.com> @aanderse Aaron Andersen <aaron@fosslib.net> @mbalatsko Maksym Balatsko <mbalatsko@gmail.com> @mwilsoncoding Max Wilson <nixpkgs@maxwilson.dev> @Izorkin Yurii Izorkin <Izorkin@gmail.com> @frlan Frank Lanitz <frank@frank.uvena.de> @dpausp Tobias Stenzel <dpausp@posteo.de> @osnyx Oliver Schmidt <os@flyingcircus.io> @ctheune Christian Theune <ct@flyingcircus.io> @leona-ya Leona Maroni <nix@leona.is> @devusb Morgan Helton <mhelton@devusb.us> @bradediger Brad Ediger <brad@bradediger.com> @mgttlinger Merlin Humml <megoettlinger@gmail.com> @dotlambda Robert Schütz <rschuetz17@gmail.com> @PapayaJackal PapayaJackal @Aleksanaa Aleksana QwQ <me@aleksana.moe> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @MarcWeber Marc Weber <marco-oweber@gmx.de> @bdesham Benjamin Esham <benjamin@esham.io> @globin Robin Gloster <mail@glob.in> @christoph-heiss Christoph Heiss <christoph@c8h4.io> @cofob Egor Ternovoy <cofob@riseup.net> @malob Malo Bourgon <mbourgon@gmail.com> @LennyPenny Lenny. @dev-nis NSC IT Solutions @NickCao Nick Cao <nickcao@nichi.co> @ttuegel Thomas Tuegel <ttuegel@mailbox.org> @LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev> @ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru> @mjm Matt Moriarity <matt@mattmoriarity.com> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> @K900 Ilya K. <me@0upti.me> @genga898 Emmanuel Genga <genga898@gmail.com> @GaetanLepage Gaetan Lepage <gaetan@glepage.com> @michaelgrahamevans Michael Evans <michaelgrahamevans@gmail.com> @getchoo Seth Flynn <getchoo@tuta.io> @acuteaangle Summer Tea <zestypurple@protonmail.com> @peterhoeg Peter Hoeg <peter@hoeg.com> @babbaj babbaj <babbaj45@gmail.com> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
pkgs.ghbackup Backup your GitHub repositories with a simple command-line application written in Go nixos-unstable ??? nixpkgs-unstable 1.13.0
pkgs.dvdbackup Tool to rip video DVDs from the command line nixos-unstable ??? nixpkgs-unstable 0.4.2
pkgs.gb-backup Gamer Backup, a super opinionated cloud backup system nixos-unstable ??? nixpkgs-unstable 2021-10-27
pkgs.qr-backup Utility to generate paper backup of files using QR codes nixos-unstable ??? nixpkgs-unstable 1.1.4
pkgs.zfsbackup Backup ZFS snapshots to cloud storage such as Google, Amazon, Azure, etc nixos-unstable ??? nixpkgs-unstable 2022-09-23
pkgs.borgbackup Deduplicating archiver with compression and encryption nixos-unstable ??? nixpkgs-unstable 1.4.1
pkgs.luckybackup Powerful, fast and reliable backup & sync tool nixos-unstable ??? nixpkgs-unstable 0.5.0
pkgs.mylvmbackup Tool for quickly creating full physical backups of a MySQL server's data files nixos-unstable ??? nixpkgs-unstable 0.16
pkgs.storeBackup Backup suite that stores files on other disks nixos-unstable ??? nixpkgs-unstable 3.5.2
pkgs.rdiff-backup Backup system trying to combine best a mirror and an incremental backup system nixos-unstable ??? nixpkgs-unstable 2.2.6
pkgs.git-backup-go Backup all your GitHub & GitLab repositories nixos-unstable ??? nixpkgs-unstable 1.6.1
pkgs.automysqlbackup Script to run daily, weekly and monthly backups for your MySQL database nixos-unstable ??? nixpkgs-unstable 3.0.7
pkgs.urbackup-client Easy to setup Open Source client/server backup system nixos-unstable ??? nixpkgs-unstable 2.5.25
pkgs.one-click-backup Simple Program to backup folders to an external location by copying them nixos-unstable ??? nixpkgs-unstable 1.2.2.1
pkgs.clickhouse-backup Tool for easy ClickHouse backup and restore using object storage for backup files nixos-unstable ??? nixpkgs-unstable 2.6.33
pkgs.signalbackup-tools Tool to work with Signal Backup files nixos-unstable ??? nixpkgs-unstable 20250824
pkgs.kdePackages.kbackup Backup program with an easy-to-use interface nixos-unstable ??? nixpkgs-unstable 25.08.1
pkgs.unifi-protect-backup Python tool to backup unifi event clips in realtime nixos-unstable ??? nixpkgs-unstable 0.11.0
pkgs.pinboard-notes-backup Back up the notes you've saved to Pinboard nixos-unstable ??? nixpkgs-unstable 1.0.7
pkgs.proxmox-backup-client Command line client for Proxmox Backup Server nixos-unstable ??? nixpkgs-unstable 4.0.14
pkgs.percona-xtrabackup_8_0 Non-blocking backup tool for MySQL nixos-unstable ??? nixpkgs-unstable 8.0.35-32
pkgs.percona-xtrabackup_lts Non-blocking backup tool for MySQL nixos-unstable ??? nixpkgs-unstable 8.4.0-2
pkgs.android-backup-extractor Utility to extract and repack Android backups created with adb backup nixos-unstable ??? nixpkgs-unstable 0-unstable-2025-01-15
pkgs.signal-backup-deduplicator Generate chunked backups for Signal messages nixos-unstable ??? nixpkgs-unstable 0-unstable-2024-05-24
pkgs.python312Packages.iosbackup Reads and extracts files from password-encrypted iOS backups nixos-unstable ??? nixpkgs-unstable 0.9.925
pkgs.python313Packages.iosbackup Reads and extracts files from password-encrypted iOS backups nixos-unstable ??? nixpkgs-unstable 0.9.925
pkgs.python312Packages.android-backup Unpack and repack android backups nixos-unstable ??? nixpkgs-unstable 0.2.0
pkgs.python313Packages.android-backup Unpack and repack android backups nixos-unstable ??? nixpkgs-unstable 0.2.0
pkgs.python312Packages.mypy-boto3-backup Type annotations for boto3 backup nixos-unstable ??? nixpkgs-unstable boto3-backup-1.40.0
pkgs.python313Packages.mypy-boto3-backup Type annotations for boto3 backup nixos-unstable ??? nixpkgs-unstable boto3-backup-1.40.0
pkgs.haskellPackages.pinboard-notes-backup Back up the notes you've saved to Pinboard nixos-unstable ??? nixpkgs-unstable 1.0.7
pkgs.home-assistant-component-tests.backup Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3
pkgs.haskellPackages.amazonka-backupstorage Amazon Backup Storage SDK nixos-unstable ??? nixpkgs-unstable 2.0
pkgs.haskellPackages.amazonka-backup-gateway Amazon Backup Gateway SDK nixos-unstable ??? nixpkgs-unstable 2.0
pkgs.python312Packages.types-aiobotocore-backup Type annotations for aiobotocore backup nixos-unstable ??? nixpkgs-unstable 2.23.2
pkgs.python313Packages.types-aiobotocore-backup Type annotations for aiobotocore backup nixos-unstable ??? nixpkgs-unstable 2.23.2
pkgs.python312Packages.mypy-boto3-backup-gateway Type annotations for boto3 backup-gateway nixos-unstable ??? nixpkgs-unstable boto3-backup-gateway-1.40.15
pkgs.python313Packages.mypy-boto3-backup-gateway Type annotations for boto3 backup-gateway nixos-unstable ??? nixpkgs-unstable boto3-backup-gateway-1.40.15
pkgs.python312Packages.types-aiobotocore-backupstorage Type annotations for aiobotocore backupstorage nixos-unstable ??? nixpkgs-unstable 2.13.0
pkgs.python313Packages.types-aiobotocore-backupstorage Type annotations for aiobotocore backupstorage nixos-unstable ??? nixpkgs-unstable 2.13.0
pkgs.python312Packages.types-aiobotocore-backup-gateway Type annotations for aiobotocore backup-gateway nixos-unstable ??? nixpkgs-unstable 2.23.2
pkgs.python313Packages.types-aiobotocore-backup-gateway Type annotations for aiobotocore backup-gateway nixos-unstable ??? nixpkgs-unstable 2.23.2
pkgs.python312Packages.azure-mgmt-recoveryservicesbackup This is the Microsoft Azure Recovery Services Backup Management Client Library nixos-unstable ??? nixpkgs-unstable 9.2.0
pkgs.python313Packages.azure-mgmt-recoveryservicesbackup This is the Microsoft Azure Recovery Services Backup Management Client Library nixos-unstable ??? nixpkgs-unstable 9.2.0
CVE-2022-4145 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 1 month, 1 week ago Content spoofing A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation. openshift pkgs.openshift Build, deploy, and manage your applications with Docker and Kubernetes nixos-unstable ??? nixpkgs-unstable 4.16.0 pkgs.python312Packages.openshift Python client for the OpenShift API nixos-unstable ??? nixpkgs-unstable 0.13.2 pkgs.python313Packages.openshift Python client for the OpenShift API nixos-unstable ??? nixpkgs-unstable 0.13.2 pkgs.python312Packages.azure-mgmt-redhatopenshift Microsoft Azure Red Hat Openshift Management Client Library for Python nixos-unstable ??? nixpkgs-unstable 2.0.0 pkgs.python313Packages.azure-mgmt-redhatopenshift Microsoft Azure Red Hat Openshift Management Client Library for Python nixos-unstable ??? nixpkgs-unstable 2.0.0 Package maintainers: 4 @teto Matthieu Coudron <mcoudron@hotmail.com> @offlinehacker Jaka Hudoklin <jaka@x-truder.net> @moretea Maarten Hoogendoorn <maarten@moretea.nl> @stehessel Stephan Heßelmann <stephan@stehessel.de>
pkgs.openshift Build, deploy, and manage your applications with Docker and Kubernetes nixos-unstable ??? nixpkgs-unstable 4.16.0
pkgs.python312Packages.openshift Python client for the OpenShift API nixos-unstable ??? nixpkgs-unstable 0.13.2
pkgs.python313Packages.openshift Python client for the OpenShift API nixos-unstable ??? nixpkgs-unstable 0.13.2
pkgs.python312Packages.azure-mgmt-redhatopenshift Microsoft Azure Red Hat Openshift Management Client Library for Python nixos-unstable ??? nixpkgs-unstable 2.0.0
pkgs.python313Packages.azure-mgmt-redhatopenshift Microsoft Azure Red Hat Openshift Management Client Library for Python nixos-unstable ??? nixpkgs-unstable 2.0.0
CVE-2022-47183 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress Extra Block Design, Style, CSS for ANY Gutenberg Blocks Plugin <= 0.2.6 is vulnerable to Cross Site Request Forgery (CSRF) Cross-Site Request Forgery (CSRF) vulnerability in StylistWP Extra Block Design, Style, CSS for ANY Gutenberg Blocks plugin <= 0.2.6 versions. stylist =<0.2.6 pkgs.haskellPackages.stylist-traits Traits, datatypes, & parsers for Haskell Stylist nixos-unstable ??? nixpkgs-unstable 0.1.4.0
pkgs.haskellPackages.stylist-traits Traits, datatypes, & parsers for Haskell Stylist nixos-unstable ??? nixpkgs-unstable 0.1.4.0
CVE-2022-47613 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress AI ChatBot Plugin <= 4.3.0 is vulnerable to Cross Site Scripting (XSS) Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud AI ChatBot plugin <= 4.3.0 versions. chatbot =<4.3.0 pkgs.gnomeExtensions.penguin-ai-chatbot A GNOME Shell extension that provides a chatbot interface using various LLM providers, including Anthropic, OpenAI, Gemini, and OpenRouter. Features include multiple provider support, customizable models, chat history, customizable appearance, a keyboard shortcut, and copy-to-clipboard functionality. nixos-unstable ??? nixpkgs-unstable 22 Package maintainers: 1 @honnip Jung seungwoo <me@honnip.page>
pkgs.gnomeExtensions.penguin-ai-chatbot A GNOME Shell extension that provides a chatbot interface using various LLM providers, including Anthropic, OpenAI, Gemini, and OpenRouter. Features include multiple provider support, customizable models, chat history, customizable appearance, a keyboard shortcut, and copy-to-clipboard functionality. nixos-unstable ??? nixpkgs-unstable 22
CVE-2022-4510 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago Path Traversal in binwalk A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesystem file, an attacker can get binwalk's PFS extractor to extract files at arbitrary locations when binwalk is run in extraction mode (-e option). Remote code execution can be achieved by building a PFS filesystem that, upon extraction, would extract a malicious binwalk module into the folder .config/binwalk/plugins. This vulnerability is associated with program files src/binwalk/plugins/unpfs.py. This issue affects binwalk from 2.1.2b through 2.3.3 included. binwalk =<2.3.3 pkgs.binwalk Firmware Analysis Tool nixos-unstable ??? nixpkgs-unstable 3.1.0 Package maintainers: 2 @k0ral Koral <koral@mailoo.org> @felbinger Nico Felbinger <nico@felbinger.eu>