Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: pulse-visualizer

Found 8 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-92860
9.4 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): High (H)
  • Subsequent System Impact Availability (SA): High (H)
  • Exploit Maturity (E): Not Defined (X)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): High (H)
  • Modified Subsequent System Impact Availability (MSA): High (H)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 4 days, 4 hours ago Activity log
  • Created suggestion
rcourtman Pulse Quick Security Setup quick-setup fmt.Sprintf input validation

A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Sprintf of the file /api/security/quick-setup of the component Quick Security Setup Handler. The manipulation of the argument Username results in improper input validation. The attack may be performed from remote. Upgrading the affected component is advised.

Affected products

Pulse
  • ==6.0.0
  • ==6.1.0-rc.4
  • ==6.1.0-rc.1
  • ==6.1.0-rc.2
  • ==6.0.3
  • ==6.0.4
  • ==6.0.1
  • ==6.1.0-rc.3
  • ==6.0.2
  • ==6.1.0-rc.0

Matching in nixpkgs

pkgs.apulse

PulseAudio emulation for ALSA

  • nixos-unstable -
  • nixos-26.05 -

pkgs.pulseaudio

Sound server for POSIX and Win32 systems

  • nixos-unstable -
    • nixos-unstable-small 17.0
  • nixos-26.05 -
    • nixos-26.05-small 17.0

pkgs.pulsemixer

Cli and curses mixer for pulseaudio

  • nixos-unstable -
    • nixos-unstable-small 1.5.1
  • nixos-26.05 -
    • nixos-26.05-small 1.5.1

pkgs.pulsemeeter

Pulseaudio and pipewire audio mixer inspired by voicemeeter

  • nixos-unstable -
    • nixos-unstable-small 2.2.0
  • nixos-26.05 -
    • nixos-26.05-small 2.0.0

pkgs.libpulseaudio

Sound server for POSIX and Win32 systems

  • nixos-unstable -
    • nixos-unstable-small 17.0
  • nixos-26.05 -
    • nixos-26.05-small 17.0

pkgs.pulseaudio-ctl

Control pulseaudio volume from the shell or mapped to keyboard shortcuts. No need for alsa-utils

  • nixos-unstable -
    • nixos-unstable-small 1.70
  • nixos-26.05 -
    • nixos-26.05-small 1.70

pkgs.pulseaudioFull

Sound server for POSIX and Win32 systems

  • nixos-unstable -
    • nixos-unstable-small 17.0
  • nixos-26.05 -
    • nixos-26.05-small 17.0

pkgs.pulseaudio-dlna

Lightweight streaming server which brings DLNA / UPNP and Chromecast support to PulseAudio and Linux

pkgs.pulse-visualizer

Real-time audio visualizer inspired by MiniMeters

  • nixos-unstable -
    • nixos-unstable-small 1.3.9
  • nixos-26.05 -
    • nixos-26.05-small 1.3.9

pkgs.rofi-pulse-select

Rofi-based interface to select source/sink (aka input/output) with PulseAudio

  • nixos-unstable -
    • nixos-unstable-small 0.2.0
  • nixos-26.05 -
    • nixos-26.05-small 0.2.0

pkgs.xfce4-volumed-pulse

Volume keys control daemon for Xfce using pulseaudio

  • nixos-unstable -
    • nixos-unstable-small 0.3.0
  • nixos-26.05 -
    • nixos-26.05-small 0.3.0

pkgs.pulseaudio-module-xrdp

xrdp sink/source pulseaudio modules

  • nixos-unstable -
    • nixos-unstable-small 0.8
  • nixos-26.05 -
    • nixos-26.05-small 0.8

pkgs.xfce4-pulseaudio-plugin

Adjust the audio volume of the PulseAudio sound system

  • nixos-unstable -
    • nixos-unstable-small 0.5.1
  • nixos-26.05 -
    • nixos-26.05-small 0.5.1

pkgs.polybar-pulseaudio-control

Polybar module to control PulseAudio devices, also known as Pavolume

  • nixos-unstable -
    • nixos-unstable-small 3.1.1
  • nixos-26.05 -
    • nixos-26.05-small 3.1.1

pkgs.python313Packages.aiopulse

Python Rollease Acmeda Automate Pulse hub protocol implementation

  • nixos-unstable -
    • nixos-unstable-small 0.4.7
  • nixos-26.05 -
    • nixos-26.05-small 0.4.7

pkgs.python313Packages.libpulse

Asyncio interface to the Pulseaudio and Pipewire pulse library

  • nixos-unstable -
    • nixos-unstable-small 0.7
  • nixos-26.05 -
    • nixos-26.05-small 0.7

pkgs.python314Packages.aiopulse

Python Rollease Acmeda Automate Pulse hub protocol implementation

  • nixos-unstable -
    • nixos-unstable-small 0.4.7
  • nixos-26.05 -
    • nixos-26.05-small 0.4.7

pkgs.python314Packages.libpulse

Asyncio interface to the Pulseaudio and Pipewire pulse library

  • nixos-unstable -
    • nixos-unstable-small 0.7
  • nixos-26.05 -
    • nixos-26.05-small 0.7

Package maintainers

Untriaged
created 5 days, 4 hours ago Activity log
  • Created suggestion
Visualizer < 4.0.8 - Contributor+ Stored XSS via JSON Data Source

The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before outputting it back in the chart editor, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any higher-privileged user, such as an administrator, who reviews the affected chart.

References

Affected products

Visualizer
  • <4.0.8

Matching in nixpkgs

pkgs.dbvisualizer

Universal database tool

  • nixos-unstable -
  • nixos-26.05 -

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3

pkgs.ttnn-visualizer

Tool for visualizing and analyzing TT-NN model execution

  • nixos-unstable -
    • nixos-unstable-small

pkgs.pulse-visualizer

Real-time audio visualizer inspired by MiniMeters

  • nixos-unstable -
    • nixos-unstable-small 1.3.9
  • nixos-26.05 -
    • nixos-26.05-small 1.3.9

pkgs.pkgsRocm.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3
Untriaged
Permalink CVE-2026-86779
2.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 week, 3 days ago Activity log
  • Created suggestion
Visualizer < 4.0.6 - Contributor+ Arbitrary Chart Deletion via deleteChart

The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above to permanently delete any chart on the site, including charts created by other users such as administrators.

References

Affected products

Visualizer
  • <4.0.6

Matching in nixpkgs

pkgs.dbvisualizer

Universal database tool

  • nixos-unstable -
  • nixos-26.05 -

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3

pkgs.ttnn-visualizer

Tool for visualizing and analyzing TT-NN model execution

  • nixos-unstable -
    • nixos-unstable-small

pkgs.pulse-visualizer

Real-time audio visualizer inspired by MiniMeters

  • nixos-unstable -
    • nixos-unstable-small 1.3.9
  • nixos-26.05 -
    • nixos-26.05-small 1.3.9

pkgs.pkgsRocm.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3
Untriaged
Permalink CVE-2026-86782
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 week, 3 days ago Activity log
  • Created suggestion
Visualizer < 4.0.6 - Contributor+ Arbitrary Post/Page Modification via IDOR

The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite the content of posts and pages they do not own, including other users' private drafts.

References

Affected products

Visualizer
  • <4.0.6

Matching in nixpkgs

pkgs.dbvisualizer

Universal database tool

  • nixos-unstable -
  • nixos-26.05 -

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3

pkgs.ttnn-visualizer

Tool for visualizing and analyzing TT-NN model execution

  • nixos-unstable -
    • nixos-unstable-small

pkgs.pulse-visualizer

Real-time audio visualizer inspired by MiniMeters

  • nixos-unstable -
    • nixos-unstable-small 1.3.9
  • nixos-26.05 -
    • nixos-26.05-small 1.3.9

pkgs.pkgsRocm.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3
Untriaged
created 1 month ago Activity log
  • Created suggestion
Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure

The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above to read the full configuration of any chart on the site, including charts the Visualizer WordPress plugin before 4.0.7's own interface denies them, and to retrieve every chart's configuration in a single request. The disclosed configuration can include the credentials of a remote data source a chart reads from.

References

Affected products

Visualizer
  • <4.0.7

Matching in nixpkgs

pkgs.dbvisualizer

Universal database tool

  • nixos-unstable -
  • nixos-26.05 -

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3

pkgs.ttnn-visualizer

Tool for visualizing and analyzing TT-NN model execution

  • nixos-unstable -
    • nixos-unstable-small

pkgs.pulse-visualizer

Real-time audio visualizer inspired by MiniMeters

  • nixos-unstable -
    • nixos-unstable-small 1.3.9
  • nixos-26.05 -
    • nixos-26.05-small 1.3.9

pkgs.pkgsRocm.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-14939
6.8 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 1 month, 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Visualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Request Forgery via JSON Import

The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-level access and above to perform Server-Side Request Forgery against link-local instance-metadata endpoints. As the fetched response is returned in the reply, the attack is non-blind, enabling retrieval of cloud instance metadata (including IAM credentials) on cloud-hosted sites.

References

Affected products

Visualizer
  • <4.0.6

Matching in nixpkgs

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable 7.3
    • nixpkgs-unstable 7.3
    • nixos-unstable-small 7.3
  • nixos-26.05 7.3
    • nixos-26.05-small 7.3
    • nixpkgs-26.05-darwin 7.3

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-65526
8.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 1 month, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
WordPress Visualizer plugin <= 4.0.6 - SQL Injection vulnerability

Contributor SQL Injection in Visualizer <= 4.0.6 versions.

Affected products

visualizer
  • =<4.0.6

Matching in nixpkgs

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable 7.3
    • nixpkgs-unstable 7.3
    • nixos-unstable-small 7.3
  • nixos-26.05 7.3
    • nixos-26.05-small 7.3
    • nixpkgs-26.05-darwin 7.3

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-24573
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 4 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
WordPress Visualizer plugin < 4.0.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS. This issue affects Visualizer: from n/a before 4.0.0.

Affected products

visualizer
  • <4.0.0

Matching in nixpkgs

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable 7.3
    • nixos-unstable-small 7.3

Package maintainers