CVE-2025-66388 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 14 hours ago Apache Airflow: Secrets in rendered templates not redacted properly and exposed in the UI A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secrets not being properly redacted, potentially exposing secrets to users without the appropriate authorization. Users are recommended to upgrade to version 3.1.4, which fixes this issue. Affected products apache-airflow <3.1.4 Matching in nixpkgs pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-25.05 ??? nixos-25.05-small 2.7.3 nixos-25.11 2.7.3 nixpkgs-25.11-darwin 2.7.3 nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3 Package maintainers: 3 @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> @ingenieroariel Ariel Nunez <ariel@nunez.co>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-25.05 ??? nixos-25.05-small 2.7.3 nixos-25.11 2.7.3 nixpkgs-25.11-darwin 2.7.3 nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3
CVE-2025-13053 created 3 days, 6 hours ago A missing encryption of sensitive data vulnerability was found in the UPS settings of ADM When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the UPS server configuation. This issue affects ADM: from 4.1.0 through 4.3.3.RKD2, from 5.0.0 through 5.1.0.RN42. Affected products UPS =<4.3.3.RKD2 =<5.1.0.RN42 Matching in nixpkgs pkgs.perlPackages.NetCUPS Common Unix Printing System Interface nixos-25.11 0.64 nixpkgs-25.11-darwin 0.64 nixos-unstable 0.64 nixos-unstable-small 0.64 nixpkgs-unstable 0.64 pkgs.perl538Packages.NetCUPS Common Unix Printing System Interface nixos-25.05 ??? nixos-25.05-small 0.64 nixos-25.11 0.64 nixpkgs-25.11-darwin 0.64 nixos-unstable 0.64 nixos-unstable-small 0.64 nixpkgs-unstable 0.64 pkgs.perl540Packages.NetCUPS Common Unix Printing System Interface nixos-25.05 ??? nixos-25.05-small 0.64 nixos-25.11 0.64 nixpkgs-25.11-darwin 0.64 nixos-unstable 0.64 nixos-unstable-small 0.64 nixpkgs-unstable 0.64 pkgs.perl540Packages.NetCUPS.x86_64-linux Common Unix Printing System Interface nixos-unstable ??? nixpkgs-unstable 0.64 pkgs.perl540Packages.NetCUPS.aarch64-linux Common Unix Printing System Interface nixos-unstable ??? nixpkgs-unstable 0.64 pkgs.perl540Packages.NetCUPS.x86_64-darwin Common Unix Printing System Interface nixos-unstable ??? nixpkgs-unstable 0.64 pkgs.perl540Packages.NetCUPS.aarch64-darwin Common Unix Printing System Interface nixos-unstable ??? nixpkgs-unstable 0.64
pkgs.perlPackages.NetCUPS Common Unix Printing System Interface nixos-25.11 0.64 nixpkgs-25.11-darwin 0.64 nixos-unstable 0.64 nixos-unstable-small 0.64 nixpkgs-unstable 0.64
pkgs.perl538Packages.NetCUPS Common Unix Printing System Interface nixos-25.05 ??? nixos-25.05-small 0.64 nixos-25.11 0.64 nixpkgs-25.11-darwin 0.64 nixos-unstable 0.64 nixos-unstable-small 0.64 nixpkgs-unstable 0.64
pkgs.perl540Packages.NetCUPS Common Unix Printing System Interface nixos-25.05 ??? nixos-25.05-small 0.64 nixos-25.11 0.64 nixpkgs-25.11-darwin 0.64 nixos-unstable 0.64 nixos-unstable-small 0.64 nixpkgs-unstable 0.64
pkgs.perl540Packages.NetCUPS.x86_64-linux Common Unix Printing System Interface nixos-unstable ??? nixpkgs-unstable 0.64
pkgs.perl540Packages.NetCUPS.aarch64-linux Common Unix Printing System Interface nixos-unstable ??? nixpkgs-unstable 0.64
pkgs.perl540Packages.NetCUPS.x86_64-darwin Common Unix Printing System Interface nixos-unstable ??? nixpkgs-unstable 0.64
pkgs.perl540Packages.NetCUPS.aarch64-darwin Common Unix Printing System Interface nixos-unstable ??? nixpkgs-unstable 0.64
CVE-2025-8083 8.6 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): HIGH updated 2 days, 4 hours ago by @Erethon Activity log Created automatic suggestion 3 days, 6 hours ago @Erethon removed package python312Packages.ipyvuetify.x86_64-darwin 2 days, 4 hours ago Vuetify Prototype Pollution via Preset options The Preset configuration https://v2.vuetifyjs.com/en/features/presets feature of Vuetify is vulnerable to Prototype Pollution https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html due to the internal 'mergeDeep' utility function used to merge options with defaults. Using a specially-crafted, malicious preset can result in polluting all JavaScript objects with arbitrary properties, which can further negatively affect all aspects of the application's behavior. This can lead to a wide range of security issues, including resource exhaustion/denial of service or unauthorized access to data. If the application utilizes Server-Side Rendering (SSR), this vulnerability could affect the whole server process. This issue affects Vuetify versions greater than or equal to 2.2.0-beta.2 and less than 3.0.0-alpha.10. Note: Version 2.x of Vuetify is End-of-Life and will not receive any updates to address this issue. For more information see here https://v2.vuetifyjs.com/en/about/eol/ . Affected products vuetify ==>=2.2.0-beta.2 <3.0.0-alpha.10 Matching in nixpkgs pkgs.python311Packages.ipyvuetify Jupyter widgets based on Vuetify UI Components nixos-unstable 1.10.0 nixos-unstable-small 1.10.0 nixpkgs-unstable 1.10.0 pkgs.python312Packages.ipyvuetify Jupyter widgets based on Vuetify UI Components nixos-25.05 ??? nixos-25.05-small 1.11.1 nixos-25.11 1.11.3 nixpkgs-25.11-darwin 1.11.3 nixos-unstable 1.11.3 nixos-unstable-small 1.11.3 nixpkgs-unstable 1.11.3 pkgs.python313Packages.ipyvuetify Jupyter widgets based on Vuetify UI Components nixos-25.05 ??? nixos-25.05-small 1.11.1 nixos-25.11 1.11.3 nixpkgs-25.11-darwin 1.11.3 nixos-unstable 1.11.1 nixos-unstable-small 1.11.3 nixpkgs-unstable 1.11.3 pkgs.python312Packages.ipyvuetify.x86_64-linux Jupyter widgets based on Vuetify UI Components nixos-unstable 1.10.0 pkgs.python312Packages.ipyvuetify.aarch64-linux Jupyter widgets based on Vuetify UI Components nixos-unstable 1.10.0 pkgs.python312Packages.ipyvuetify.aarch64-darwin Jupyter widgets based on Vuetify UI Components nixos-unstable 1.10.0 Package maintainers: 1 @drewrisinger Drew Risinger <drisinger+nixpkgs@gmail.com>
pkgs.python311Packages.ipyvuetify Jupyter widgets based on Vuetify UI Components nixos-unstable 1.10.0 nixos-unstable-small 1.10.0 nixpkgs-unstable 1.10.0
pkgs.python312Packages.ipyvuetify Jupyter widgets based on Vuetify UI Components nixos-25.05 ??? nixos-25.05-small 1.11.1 nixos-25.11 1.11.3 nixpkgs-25.11-darwin 1.11.3 nixos-unstable 1.11.3 nixos-unstable-small 1.11.3 nixpkgs-unstable 1.11.3
pkgs.python313Packages.ipyvuetify Jupyter widgets based on Vuetify UI Components nixos-25.05 ??? nixos-25.05-small 1.11.1 nixos-25.11 1.11.3 nixpkgs-25.11-darwin 1.11.3 nixos-unstable 1.11.1 nixos-unstable-small 1.11.3 nixpkgs-unstable 1.11.3
pkgs.python312Packages.ipyvuetify.x86_64-linux Jupyter widgets based on Vuetify UI Components nixos-unstable 1.10.0
pkgs.python312Packages.ipyvuetify.aarch64-linux Jupyter widgets based on Vuetify UI Components nixos-unstable 1.10.0
pkgs.python312Packages.ipyvuetify.aarch64-darwin Jupyter widgets based on Vuetify UI Components nixos-unstable 1.10.0
CVE-2025-8082 6.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW updated 2 days, 4 hours ago by @fricklerhandwerk Activity log Created automatic suggestion 3 days, 6 hours ago @fricklerhandwerk removed 2 packages python312Packages.ipyvuetify.aarch64-darwin python312Packages.ipyvuetify.x86_64-darwin 2 days, 4 hours ago Vuetify XSS via unsanitized 'titleDateFormat' in 'VDatePicker' Improper neutralization of the title date in the 'VDatePicker' component in Vuetify, allows unsanitized HTML to be inserted into the page. This can lead to a Cross-Site Scripting (XSS) https://owasp.org/www-community/attacks/xss attack. The vulnerability occurs because the 'title-date-format' property of the 'VDatePicker' can accept a user created function and assign its output to the 'innerHTML' property of the title element without sanitization. This issue affects Vuetify versions greater than or equal to 2.0.0 and less than 3.0.0. Note: Version 2.x of Vuetify is End-of-Life and will not receive any updates to address this issue. For more information see here https://v2.vuetifyjs.com/en/about/eol/ . Affected products vuetify ==>=2.0.0 <3.0.0 Matching in nixpkgs pkgs.python311Packages.ipyvuetify Jupyter widgets based on Vuetify UI Components nixos-unstable 1.10.0 nixos-unstable-small 1.10.0 nixpkgs-unstable 1.10.0 pkgs.python312Packages.ipyvuetify Jupyter widgets based on Vuetify UI Components nixos-25.05 ??? nixos-25.05-small 1.11.1 nixos-25.11 1.11.3 nixpkgs-25.11-darwin 1.11.3 nixos-unstable 1.11.3 nixos-unstable-small 1.11.3 nixpkgs-unstable 1.11.3 pkgs.python313Packages.ipyvuetify Jupyter widgets based on Vuetify UI Components nixos-25.05 ??? nixos-25.05-small 1.11.1 nixos-25.11 1.11.3 nixpkgs-25.11-darwin 1.11.3 nixos-unstable 1.11.1 nixos-unstable-small 1.11.3 nixpkgs-unstable 1.11.3 pkgs.python312Packages.ipyvuetify.x86_64-linux Jupyter widgets based on Vuetify UI Components nixos-unstable 1.10.0 pkgs.python312Packages.ipyvuetify.aarch64-linux Jupyter widgets based on Vuetify UI Components nixos-unstable 1.10.0 Package maintainers: 1 @drewrisinger Drew Risinger <drisinger+nixpkgs@gmail.com>
pkgs.python311Packages.ipyvuetify Jupyter widgets based on Vuetify UI Components nixos-unstable 1.10.0 nixos-unstable-small 1.10.0 nixpkgs-unstable 1.10.0
pkgs.python312Packages.ipyvuetify Jupyter widgets based on Vuetify UI Components nixos-25.05 ??? nixos-25.05-small 1.11.1 nixos-25.11 1.11.3 nixpkgs-25.11-darwin 1.11.3 nixos-unstable 1.11.3 nixos-unstable-small 1.11.3 nixpkgs-unstable 1.11.3
pkgs.python313Packages.ipyvuetify Jupyter widgets based on Vuetify UI Components nixos-25.05 ??? nixos-25.05-small 1.11.1 nixos-25.11 1.11.3 nixpkgs-25.11-darwin 1.11.3 nixos-unstable 1.11.1 nixos-unstable-small 1.11.3 nixpkgs-unstable 1.11.3
pkgs.python312Packages.ipyvuetify.x86_64-linux Jupyter widgets based on Vuetify UI Components nixos-unstable 1.10.0
pkgs.python312Packages.ipyvuetify.aarch64-linux Jupyter widgets based on Vuetify UI Components nixos-unstable 1.10.0
CVE-2013-10031 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 3 days, 6 hours ago Plack::Middleware::Session versions before 0.17 for Perl may be vulnerable to HMAC comparison timing attacks Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks Affected products Plack-Middleware-Session <0.17 Matching in nixpkgs pkgs.perlPackages.PlackMiddlewareSession Middleware for session management nixos-25.11 0.33 nixpkgs-25.11-darwin 0.33 nixos-unstable 0.33 nixos-unstable-small 0.33 nixpkgs-unstable 0.33 pkgs.perl538Packages.PlackMiddlewareSession Middleware for session management nixos-25.05 ??? nixos-25.05-small 0.33 nixos-25.11 0.33 nixpkgs-25.11-darwin 0.33 nixos-unstable 0.33 nixos-unstable-small 0.33 nixpkgs-unstable 0.33 pkgs.perl540Packages.PlackMiddlewareSession Middleware for session management nixos-25.05 ??? nixos-25.05-small 0.33 nixos-25.11 0.33 nixpkgs-25.11-darwin 0.33 nixos-unstable 0.33 nixos-unstable-small 0.33 nixpkgs-unstable 0.33 pkgs.perl540Packages.PlackMiddlewareSession.x86_64-linux Middleware for session management nixos-unstable ??? nixpkgs-unstable 0.33 pkgs.perl540Packages.PlackMiddlewareSession.aarch64-linux Middleware for session management nixos-unstable ??? nixpkgs-unstable 0.33 pkgs.perl540Packages.PlackMiddlewareSession.x86_64-darwin Middleware for session management nixos-unstable ??? nixpkgs-unstable 0.33 pkgs.perl540Packages.PlackMiddlewareSession.aarch64-darwin Middleware for session management nixos-unstable ??? nixpkgs-unstable 0.33
pkgs.perlPackages.PlackMiddlewareSession Middleware for session management nixos-25.11 0.33 nixpkgs-25.11-darwin 0.33 nixos-unstable 0.33 nixos-unstable-small 0.33 nixpkgs-unstable 0.33
pkgs.perl538Packages.PlackMiddlewareSession Middleware for session management nixos-25.05 ??? nixos-25.05-small 0.33 nixos-25.11 0.33 nixpkgs-25.11-darwin 0.33 nixos-unstable 0.33 nixos-unstable-small 0.33 nixpkgs-unstable 0.33
pkgs.perl540Packages.PlackMiddlewareSession Middleware for session management nixos-25.05 ??? nixos-25.05-small 0.33 nixos-25.11 0.33 nixpkgs-25.11-darwin 0.33 nixos-unstable 0.33 nixos-unstable-small 0.33 nixpkgs-unstable 0.33
pkgs.perl540Packages.PlackMiddlewareSession.x86_64-linux Middleware for session management nixos-unstable ??? nixpkgs-unstable 0.33
pkgs.perl540Packages.PlackMiddlewareSession.aarch64-linux Middleware for session management nixos-unstable ??? nixpkgs-unstable 0.33
pkgs.perl540Packages.PlackMiddlewareSession.x86_64-darwin Middleware for session management nixos-unstable ??? nixpkgs-unstable 0.33
pkgs.perl540Packages.PlackMiddlewareSession.aarch64-darwin Middleware for session management nixos-unstable ??? nixpkgs-unstable 0.33
CVE-2025-5467 created 3 days, 6 hours ago Ubuntu Apport Insecure File Permissions Vulnerability It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups. Affected products apport <2.20.11-0ubuntu82.7 <2.20.9-0ubuntu7.29+esm1 <2.32.0-0ubuntu5.1 <2.28.1-0ubuntu3.6 <2.20.1-0ubuntu2.30+esm5 <2.20.11-0ubuntu27.28 <2.33.0-0ubuntu1 Matching in nixpkgs pkgs.haskellPackages.apportionment Round a set of numbers while maintaining its sum nixos-25.05 ??? nixos-25.05-small 0.0.0.4 nixos-25.11 0.0.0.4 nixpkgs-25.11-darwin 0.0.0.4 nixos-unstable 0.0.0.4 nixos-unstable-small 0.0.0.4 nixpkgs-unstable 0.0.0.4 Package maintainers: 1 @thielema Henning Thielemann <nix@henning-thielemann.de>
apport <2.20.11-0ubuntu82.7 <2.20.9-0ubuntu7.29+esm1 <2.32.0-0ubuntu5.1 <2.28.1-0ubuntu3.6 <2.20.1-0ubuntu2.30+esm5 <2.20.11-0ubuntu27.28 <2.33.0-0ubuntu1
pkgs.haskellPackages.apportionment Round a set of numbers while maintaining its sum nixos-25.05 ??? nixos-25.05-small 0.0.0.4 nixos-25.11 0.0.0.4 nixpkgs-25.11-darwin 0.0.0.4 nixos-unstable 0.0.0.4 nixos-unstable-small 0.0.0.4 nixpkgs-unstable 0.0.0.4
CVE-2025-66004 5.7 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): LOW created 3 days, 6 hours ago Local privilege escalation in usbmuxd from arbitrary local user to usbmux A Path Traversal vulnerability in usbmuxd allows local users to escalate to the service user.This issue affects usbmuxd: before 3ded00c9985a5108cfc7591a309f9a23d57a8cba. Affected products usbmuxd <3ded00c9985a5108cfc7591a309f9a23d57a8cba Matching in nixpkgs pkgs.usbmuxd Socket daemon to multiplex connections from and to iOS devices nixos-25.05 ??? nixos-25.05-small 1.1.1+date=2023-05-05 nixos-25.11 1.1.1+date=2023-05-05 nixpkgs-25.11-darwin 1.1.1+date=2023-05-05 nixos-unstable 1.1.1+date=2023-05-05 nixos-unstable-small 1.1.1+date=2023-05-05 nixpkgs-unstable 1.1.1+date=2023-05-05 pkgs.usbmuxd2 Socket daemon to multiplex connections from and to iOS devices nixos-25.05 ??? nixos-25.05-small 2023-12-12 nixos-25.11 2023-12-12 nixpkgs-25.11-darwin 2023-12-12 nixos-unstable 2023-12-12 nixos-unstable-small 2023-12-12 nixpkgs-unstable 2023-12-12 pkgs.libusbmuxd Client library to multiplex connections from and to iOS devices nixos-25.05 ??? nixos-25.05-small 2.1.0 nixos-25.11 2.1.1 nixpkgs-25.11-darwin 2.1.1 nixos-unstable 2.1.1 nixos-unstable-small 2.1.1 nixpkgs-unstable 2.1.1 pkgs.libusbmuxd.x86_64-linux Client library to multiplex connections from and to iOS devices nixos-unstable ??? nixos-unstable-small 2.1.0 pkgs.libusbmuxd.aarch64-linux Client library to multiplex connections from and to iOS devices nixos-unstable ??? nixos-unstable-small 2.1.0 pkgs.libusbmuxd.x86_64-darwin Client library to multiplex connections from and to iOS devices nixos-unstable ??? nixos-unstable-small 2.1.0 pkgs.libusbmuxd.aarch64-darwin Client library to multiplex connections from and to iOS devices nixos-unstable ??? nixos-unstable-small 2.1.0 Package maintainers: 1 @onny Jonas Heinrich <onny@project-insanity.org>
pkgs.usbmuxd Socket daemon to multiplex connections from and to iOS devices nixos-25.05 ??? nixos-25.05-small 1.1.1+date=2023-05-05 nixos-25.11 1.1.1+date=2023-05-05 nixpkgs-25.11-darwin 1.1.1+date=2023-05-05 nixos-unstable 1.1.1+date=2023-05-05 nixos-unstable-small 1.1.1+date=2023-05-05 nixpkgs-unstable 1.1.1+date=2023-05-05
pkgs.usbmuxd2 Socket daemon to multiplex connections from and to iOS devices nixos-25.05 ??? nixos-25.05-small 2023-12-12 nixos-25.11 2023-12-12 nixpkgs-25.11-darwin 2023-12-12 nixos-unstable 2023-12-12 nixos-unstable-small 2023-12-12 nixpkgs-unstable 2023-12-12
pkgs.libusbmuxd Client library to multiplex connections from and to iOS devices nixos-25.05 ??? nixos-25.05-small 2.1.0 nixos-25.11 2.1.1 nixpkgs-25.11-darwin 2.1.1 nixos-unstable 2.1.1 nixos-unstable-small 2.1.1 nixpkgs-unstable 2.1.1
pkgs.libusbmuxd.x86_64-linux Client library to multiplex connections from and to iOS devices nixos-unstable ??? nixos-unstable-small 2.1.0
pkgs.libusbmuxd.aarch64-linux Client library to multiplex connections from and to iOS devices nixos-unstable ??? nixos-unstable-small 2.1.0
pkgs.libusbmuxd.x86_64-darwin Client library to multiplex connections from and to iOS devices nixos-unstable ??? nixos-unstable-small 2.1.0
pkgs.libusbmuxd.aarch64-darwin Client library to multiplex connections from and to iOS devices nixos-unstable ??? nixos-unstable-small 2.1.0
CVE-2025-66527 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 3 days, 6 hours ago WordPress Lobo theme <= 2.8.6 - Broken Access Control vulnerability Missing Authorization vulnerability in VanKarWai Lobo lobo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lobo: from n/a through <= 2.8.6. Affected products lobo =<<= 2.8.6 Matching in nixpkgs pkgs.colobot Colobot: Gold Edition is a real-time strategy game, where you can program your bots nixos-25.05 ??? nixos-25.05-small 0.2.2-alpha nixos-25.11 0.2.2-alpha nixpkgs-25.11-darwin 0.2.2-alpha nixos-unstable 0.2.2-alpha nixos-unstable-small 0.2.2-alpha nixpkgs-unstable 0.2.2-alpha Package maintainers: 1 @freezeboy freezeboy
pkgs.colobot Colobot: Gold Edition is a real-time strategy game, where you can program your bots nixos-25.05 ??? nixos-25.05-small 0.2.2-alpha nixos-25.11 0.2.2-alpha nixpkgs-25.11-darwin 0.2.2-alpha nixos-unstable 0.2.2-alpha nixos-unstable-small 0.2.2-alpha nixpkgs-unstable 0.2.2-alpha
CVE-2025-62103 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 3 days, 6 hours ago WordPress Media Library File Download plugin <= 1.4 - Cross Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability in wpmediadownload Media Library File Download media-download allows Cross Site Request Forgery.This issue affects Media Library File Download: from n/a through <= 1.4. Affected products media-download =<<= 1.4 Matching in nixpkgs pkgs.media-downloader Qt/C++ GUI front end for yt-dlp and others nixos-25.05 ??? nixos-25.05-small 5.3.2 nixos-25.11 5.4.6 nixpkgs-25.11-darwin 5.4.6 nixos-unstable 5.4.1 nixos-unstable-small 5.4.1 nixpkgs-unstable 5.2.0 Package maintainers: 2 @zendo zendo <linzway@qq.com> @Aleksanaa Aleksana QwQ <me@aleksana.moe>
pkgs.media-downloader Qt/C++ GUI front end for yt-dlp and others nixos-25.05 ??? nixos-25.05-small 5.3.2 nixos-25.11 5.4.6 nixpkgs-25.11-darwin 5.4.6 nixos-unstable 5.4.1 nixos-unstable-small 5.4.1 nixpkgs-unstable 5.2.0
CVE-2025-67549 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 days, 7 hours ago WordPress oik plugin <= 4.15.3 - Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik oik allows DOM-Based XSS.This issue affects oik: from n/a through <= 4.15.3. Affected products oik =<<= 4.15.3 Matching in nixpkgs pkgs.libvoikko Finnish language processing library nixos-25.05 ??? nixos-25.05-small 4.3.2 nixos-25.11 4.3.3 nixpkgs-25.11-darwin 4.3.3 nixos-unstable 4.3.2 nixos-unstable-small 4.3.2 nixpkgs-unstable 4.3.3 pkgs.voikko-fi Description of Finnish morphology written for libvoikko nixos-25.11 2.5 nixpkgs-25.11-darwin 2.5 pkgs.libvoikko.x86_64-linux Finnish language processing library nixos-unstable ??? nixos-unstable-small 4.3.2 pkgs.libvoikko.aarch64-linux Finnish language processing library nixos-unstable ??? nixos-unstable-small 4.3.2 pkgs.libvoikko.x86_64-darwin Finnish language processing library nixos-unstable ??? nixos-unstable-small 4.3.2 pkgs.libvoikko.aarch64-darwin Finnish language processing library nixos-unstable ??? nixos-unstable-small 4.3.2 Package maintainers: 2 @Lurkki14 Jussi Kuokkanen <jussi.kuokkanen@protonmail.com> @lajp Luukas Pörtfors <lajp@iki.fi>
pkgs.libvoikko Finnish language processing library nixos-25.05 ??? nixos-25.05-small 4.3.2 nixos-25.11 4.3.3 nixpkgs-25.11-darwin 4.3.3 nixos-unstable 4.3.2 nixos-unstable-small 4.3.2 nixpkgs-unstable 4.3.3
pkgs.voikko-fi Description of Finnish morphology written for libvoikko nixos-25.11 2.5 nixpkgs-25.11-darwin 2.5
pkgs.libvoikko.x86_64-linux Finnish language processing library nixos-unstable ??? nixos-unstable-small 4.3.2
pkgs.libvoikko.aarch64-linux Finnish language processing library nixos-unstable ??? nixos-unstable-small 4.3.2
pkgs.libvoikko.x86_64-darwin Finnish language processing library nixos-unstable ??? nixos-unstable-small 4.3.2
pkgs.libvoikko.aarch64-darwin Finnish language processing library nixos-unstable ??? nixos-unstable-small 4.3.2