CVE-2024-25583 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 3 months ago Crafted responses can lead to a denial of service in Recursor if recursive forwarding is configured A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The default configuration of the Recursor does not use recursive forwarding and is not affected. Affected products pdns-recursor ==4.9.4 ==5.0.3 ==4.8.7 Matching in nixpkgs pkgs.pdns-recursor Recursive DNS server nixos-unstable ??? nixpkgs-unstable 5.2.5 Package maintainers: 1 @rnhmjoj Michele Guerini Rocco <rnhmjoj@inventati.org>
CVE-2023-47774 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago WordPress Jetpack plugin < 12.7 - Auth. Iframe Injection vulnerability Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7. Affected products jetpack <12.7 Matching in nixpkgs pkgs.wordpressPackages.plugins.jetpack nixos-unstable ??? nixpkgs-unstable 14.5 pkgs.wordpressPackages.plugins.jetpack-lite nixos-unstable ??? nixpkgs-unstable 3.0.3
CVE-2023-23923 created 3 months ago Moodle: possible to set the preferred "start page" of other users The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality. Affected products moodle <4.0.6 <3.9.19 <4.1.1 <3.11.12 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13
CVE-2023-30944 5.6 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago Moodle: minor sql injection risk in external wiki method for listing pages The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database. Affected products moodle <4.1.3 <3.11.14 <3.9.21 <4.0.8 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13
CVE-2023-5548 3.3 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 3 months ago Moodle: cache poisoning risk with endpoint revision numbers Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection. Affected products moodle <4.0.11 <4.2.3 <4.1.6 <3.9.24 <3.11.17 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13
CVE-2023-0330 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): HIGH Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 3 months ago Qemu: lsi53c895a: dma reentrancy issue leads to stack overflow A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free. Affected products qemu * Matching in nixpkgs pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.canokey-qemu CanoKey QEMU Virt Card nixos-unstable ??? nixpkgs-unstable 0-unstable-2023-06-06 pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_defconfig-2025.07 pkgs.ubootQemuX86_64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_64_defconfig-2025.07 pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable qemu_arm64_defconfig-2025.07 pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable ??? nixpkgs-unstable 2.13.0 pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.python313Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.python312Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3 pkgs.python313Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3 Package maintainers: 11 @oxalica oxalica <oxalicc@pm.me> @DavHau David Hauer <d.hauer.it@gmail.com> @devplayer0 Jack O'Sullivan <dev@nul.ie> @brianmcgillion Brian McGillion <bmg.avoin@gmail.com> @alyssais Alyssa Ross <hi@alyssa.is> @hehongbo Hongbo @SigmaSquadron Fernando Rodrigues <alpha@sigmasquadron.net> @digitalrane Rane <rane+git@junkyard.systems> @CertainLach Yaroslav Bolyukin <iam@lach.pw> @dezgeg Tuomas Tynkkynen <tuomas.tynkkynen@iki.fi> @lopsided98 Ben Wolsieffer <benwolsieffer@gmail.com>
pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_defconfig-2025.07
pkgs.ubootQemuX86_64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_64_defconfig-2025.07
pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable qemu_arm64_defconfig-2025.07
pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable ??? nixpkgs-unstable 2.13.0
pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.python313Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.python312Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3
pkgs.python313Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3
CVE-2023-28331 6.1 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 3 months ago Moodle: xss risk when outputting database activity filter data Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk. Affected products moodle <4.0.7 <3.11.13 <3.9.20 <4.1.2 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13
CVE-2023-5551 3.3 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 3 months ago Moodle: forum summary report shows students from other groups when in separate groups mode Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups. Affected products moodle <4.0.11 <4.2.3 <4.1.6 <3.9.24 <3.11.17 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13
CVE-2023-5549 3.3 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 3 months ago Moodle: insufficient capability checks when updating the parent of a course category Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage. Affected products moodle <4.0.11 <4.2.3 <4.1.6 <3.9.24 <3.11.17 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13
CVE-2023-23922 created 3 months ago Moodle: reflected xss risk in blog search The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website. This flaw allows a remote attacker to perform cross-site scripting (XSS) attacks. Affected products moodle <4.0.6 <4.1.1 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13