CVE-2025-48797 7.3 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 6 months, 3 weeks ago Gimp: multiple heap buffer overflows in tga parser A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow. Affected products gimp * <3.0.0 gimp:2.8 * gimp:2.8/gimp Matching in nixpkgs pkgs.zigimports Automatically remove unused imports and globals from Zig files nixos-25.05 ??? nixos-25.05-small 0.1.0 nixos-unstable ??? nixos-unstable-small 0.1.0 nixpkgs-unstable 0.1.0 pkgs.gimpPlugins.gap GIMP Animation Package nixos-unstable 2.6.0-unstable-2023-05-20 nixos-unstable-small 2.6.0-unstable-2023-05-20 nixpkgs-unstable 2.6.0-unstable-2023-05-20 pkgs.gimpPlugins.bimp Batch Image Manipulation Plugin for GIMP nixos-25.05 ??? nixos-25.05-small 2.6 nixos-unstable 2.6 nixos-unstable-small 2.6 nixpkgs-unstable 2.6 pkgs.gimpPlugins.gimp GNU Image Manipulation Program nixos-25.05 ??? nixos-25.05-small 2.10.38 nixos-unstable 2.10.38 nixos-unstable-small 2.10.38 nixpkgs-unstable 2.10.38 pkgs.gimpPlugins.gmic GIMP plugin for the G'MIC image processing framework nixos-25.05 ??? nixos-25.05-small 3.5.0 nixos-unstable 3.4.2 nixos-unstable-small 3.4.2 nixpkgs-unstable 3.4.2 pkgs.gimp-with-plugins GNU Image Manipulation Program nixos-25.05 ??? nixos-25.05-small 2.10.38 nixos-unstable 2.10.38 nixos-unstable-small 2.10.38 nixpkgs-unstable 2.10.38 pkgs.gimp3Plugins.gimp GNU Image Manipulation Program nixos-25.05 ??? nixos-25.05-small 3.0.2 nixos-unstable ??? nixos-unstable-small 3.0.2 nixpkgs-unstable 3.0.2 pkgs.gimp3Plugins.gmic GIMP plugin for the G'MIC image processing framework nixos-25.05 ??? nixos-25.05-small 3.5.0 nixos-unstable ??? nixos-unstable-small 3.5.0 nixpkgs-unstable 3.5.0 pkgs.gimp3-with-plugins GNU Image Manipulation Program nixos-25.05 ??? nixos-25.05-small 3.0.2 nixos-unstable ??? nixos-unstable-small 3.0.2 nixpkgs-unstable 3.0.2 pkgs.gimpPlugins.fourier GIMP plug-in to do the fourier transform nixos-25.05 ??? nixos-25.05-small 0.4.3 nixos-unstable 0.4.3 nixos-unstable-small 0.4.3 nixpkgs-unstable 0.4.3 pkgs.gimpPlugins.farbfeld Gimp plug-in for the farbfeld image format nixos-25.05 ??? nixos-25.05-small 2019-08-12 nixos-unstable 2019-08-12 nixos-unstable-small 2019-08-12 nixpkgs-unstable 2019-08-12 pkgs.gimpPlugins.lightning nixos-25.05 ??? nixos-25.05-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable pkgs.gimpPlugins.lqrPlugin nixos-25.05 ??? nixos-25.05-small 0.7.2 nixos-unstable 0.7.2 nixos-unstable-small 0.7.2 nixpkgs-unstable 0.7.2 pkgs.gimpPlugins.texturize nixos-25.05 ??? nixos-25.05-small 2.2+unstable=2021-12-03 nixos-unstable 2.2+unstable=2021-12-03 nixos-unstable-small 2.2+unstable=2021-12-03 nixpkgs-unstable 2.2+unstable=2021-12-03 pkgs.gimp3Plugins.lightning nixos-25.05 ??? nixos-25.05-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable pkgs.gimpPlugins.gimplensfun GIMP plugin to correct lens distortion using the lensfun library and database nixos-25.05 ??? nixos-25.05-small 2018-10-21 nixos-unstable 2018-10-21 nixos-unstable-small 2018-10-21 nixpkgs-unstable 2018-10-21 pkgs.gimpPlugins.resynthesizer nixos-25.05 ??? nixos-25.05-small 2.0.3 nixos-unstable ??? nixos-unstable-small 2.0.3 nixpkgs-unstable 2.0.3 pkgs.gimpPlugins.waveletSharpen nixos-25.05 ??? nixos-25.05-small 0.1.2 nixos-unstable 0.1.2 nixos-unstable-small 0.1.2 nixpkgs-unstable 0.1.2 Package maintainers: 3 @jmbaur Jared Baur <jaredbaur@fastmail.com> @jtojnar Jan Tojnar <jtojnar@gmail.com> @sikmir Nikolay Korotkiy <sikmir@disroot.org>
pkgs.zigimports Automatically remove unused imports and globals from Zig files nixos-25.05 ??? nixos-25.05-small 0.1.0 nixos-unstable ??? nixos-unstable-small 0.1.0 nixpkgs-unstable 0.1.0
pkgs.gimpPlugins.gap GIMP Animation Package nixos-unstable 2.6.0-unstable-2023-05-20 nixos-unstable-small 2.6.0-unstable-2023-05-20 nixpkgs-unstable 2.6.0-unstable-2023-05-20
pkgs.gimpPlugins.bimp Batch Image Manipulation Plugin for GIMP nixos-25.05 ??? nixos-25.05-small 2.6 nixos-unstable 2.6 nixos-unstable-small 2.6 nixpkgs-unstable 2.6
pkgs.gimpPlugins.gimp GNU Image Manipulation Program nixos-25.05 ??? nixos-25.05-small 2.10.38 nixos-unstable 2.10.38 nixos-unstable-small 2.10.38 nixpkgs-unstable 2.10.38
pkgs.gimpPlugins.gmic GIMP plugin for the G'MIC image processing framework nixos-25.05 ??? nixos-25.05-small 3.5.0 nixos-unstable 3.4.2 nixos-unstable-small 3.4.2 nixpkgs-unstable 3.4.2
pkgs.gimp-with-plugins GNU Image Manipulation Program nixos-25.05 ??? nixos-25.05-small 2.10.38 nixos-unstable 2.10.38 nixos-unstable-small 2.10.38 nixpkgs-unstable 2.10.38
pkgs.gimp3Plugins.gimp GNU Image Manipulation Program nixos-25.05 ??? nixos-25.05-small 3.0.2 nixos-unstable ??? nixos-unstable-small 3.0.2 nixpkgs-unstable 3.0.2
pkgs.gimp3Plugins.gmic GIMP plugin for the G'MIC image processing framework nixos-25.05 ??? nixos-25.05-small 3.5.0 nixos-unstable ??? nixos-unstable-small 3.5.0 nixpkgs-unstable 3.5.0
pkgs.gimp3-with-plugins GNU Image Manipulation Program nixos-25.05 ??? nixos-25.05-small 3.0.2 nixos-unstable ??? nixos-unstable-small 3.0.2 nixpkgs-unstable 3.0.2
pkgs.gimpPlugins.fourier GIMP plug-in to do the fourier transform nixos-25.05 ??? nixos-25.05-small 0.4.3 nixos-unstable 0.4.3 nixos-unstable-small 0.4.3 nixpkgs-unstable 0.4.3
pkgs.gimpPlugins.farbfeld Gimp plug-in for the farbfeld image format nixos-25.05 ??? nixos-25.05-small 2019-08-12 nixos-unstable 2019-08-12 nixos-unstable-small 2019-08-12 nixpkgs-unstable 2019-08-12
pkgs.gimpPlugins.lightning nixos-25.05 ??? nixos-25.05-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable
pkgs.gimpPlugins.lqrPlugin nixos-25.05 ??? nixos-25.05-small 0.7.2 nixos-unstable 0.7.2 nixos-unstable-small 0.7.2 nixpkgs-unstable 0.7.2
pkgs.gimpPlugins.texturize nixos-25.05 ??? nixos-25.05-small 2.2+unstable=2021-12-03 nixos-unstable 2.2+unstable=2021-12-03 nixos-unstable-small 2.2+unstable=2021-12-03 nixpkgs-unstable 2.2+unstable=2021-12-03
pkgs.gimp3Plugins.lightning nixos-25.05 ??? nixos-25.05-small nixos-unstable ??? nixos-unstable-small nixpkgs-unstable
pkgs.gimpPlugins.gimplensfun GIMP plugin to correct lens distortion using the lensfun library and database nixos-25.05 ??? nixos-25.05-small 2018-10-21 nixos-unstable 2018-10-21 nixos-unstable-small 2018-10-21 nixpkgs-unstable 2018-10-21
pkgs.gimpPlugins.resynthesizer nixos-25.05 ??? nixos-25.05-small 2.0.3 nixos-unstable ??? nixos-unstable-small 2.0.3 nixpkgs-unstable 2.0.3
pkgs.gimpPlugins.waveletSharpen nixos-25.05 ??? nixos-25.05-small 0.1.2 nixos-unstable 0.1.2 nixos-unstable-small 0.1.2 nixpkgs-unstable 0.1.2
CVE-2025-23394 9.8 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 6 months, 3 weeks ago daily-backup.sh script in cyrus-imapd allows escalation from cyrus to root A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed cyrus-imapd before 3.8.4-2.1. Affected products cyrus-imapd <3.8.4-2.1 Matching in nixpkgs pkgs.cyrus-imapd Email, contacts and calendar server nixos-25.05 ??? nixos-25.05-small 3.12.0 nixos-unstable 3.10.0 nixos-unstable-small 3.10.0 nixpkgs-unstable 3.10.0 Package maintainers: 2 @Moraxyc Moraxyc Xu <i@qaq.li> @pingiun Jelle Besseling <nixos@pingiun.com>
pkgs.cyrus-imapd Email, contacts and calendar server nixos-25.05 ??? nixos-25.05-small 3.12.0 nixos-unstable 3.10.0 nixos-unstable-small 3.10.0 nixpkgs-unstable 3.10.0
CVE-2025-32286 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 6 months, 3 weeks ago WordPress Butcher <= 2.40 - Local File Inclusion Vulnerability Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Butcher allows PHP Local File Inclusion. This issue affects Butcher: from n/a through 2.40. Affected products butcher =<2.40 Matching in nixpkgs pkgs.haskellPackages.butcher Chops a command or program invocation into digestable pieces nixos-25.05 ??? nixos-25.05-small 1.3.3.2 nixos-unstable 1.3.3.2 nixos-unstable-small 1.3.3.2 nixpkgs-unstable 1.3.3.2 pkgs.haskellPackages.butcher.x86_64-linux Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2 pkgs.haskellPackages.butcher.aarch64-linux Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2 pkgs.haskellPackages.butcher.x86_64-darwin Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2 pkgs.haskellPackages.butcher.aarch64-darwin Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2
pkgs.haskellPackages.butcher Chops a command or program invocation into digestable pieces nixos-25.05 ??? nixos-25.05-small 1.3.3.2 nixos-unstable 1.3.3.2 nixos-unstable-small 1.3.3.2 nixpkgs-unstable 1.3.3.2
pkgs.haskellPackages.butcher.x86_64-linux Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2
pkgs.haskellPackages.butcher.aarch64-linux Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2
pkgs.haskellPackages.butcher.x86_64-darwin Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2
pkgs.haskellPackages.butcher.aarch64-darwin Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2
CVE-2025-46448 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 6 months, 3 weeks ago WordPress Document Management System <= 1.24 - Cross Site Scripting (XSS) Vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reifsnyderb Document Management System allows Reflected XSS. This issue affects Document Management System: from n/a through 1.24. Affected products dms =<1.24 Matching in nixpkgs pkgs.dms UPnP DLNA Digital Media Server with basic video transcoding nixos-25.05 ??? nixos-25.05-small 1.7.1 nixos-unstable 1.7.1 nixos-unstable-small 1.7.1 nixpkgs-unstable 1.7.1 pkgs.adms automatic device model synthesizer nixos-25.05 ??? nixos-25.05-small 2.3.7 nixos-unstable 2.3.7 nixos-unstable-small 2.3.7 nixpkgs-unstable 2.3.7 pkgs.haskellPackages.amazonka-dms Amazon Database Migration Service SDK nixos-25.05 ??? nixos-25.05-small 2.0 nixos-unstable 2.0 nixos-unstable-small 2.0 nixpkgs-unstable 2.0 pkgs.python311Packages.ndms2-client Keenetic NDMS 2.x and 3.x client nixos-unstable ndms2-client-0.1.3 nixos-unstable-small ndms2-client-0.1.3 nixpkgs-unstable ndms2-client-0.1.3 pkgs.python312Packages.ndms2-client Keenetic NDMS 2.x and 3.x client nixos-25.05 ??? nixos-25.05-small ndms2-client-0.1.3 nixos-unstable ndms2-client-0.1.3 nixos-unstable-small ndms2-client-0.1.3 nixpkgs-unstable ndms2-client-0.1.3 pkgs.python313Packages.ndms2-client Keenetic NDMS 2.x and 3.x client nixos-25.05 ??? nixos-25.05-small ndms2-client-0.1.3 pkgs.azure-cli-extensions.dms-preview Support for new Database Migration Service scenarios nixos-25.05 ??? nixos-25.05-small 0.15.0 nixos-unstable 0.15.0 nixos-unstable-small 0.15.0 nixpkgs-unstable 0.15.0 pkgs.python311Packages.mypy-boto3-dms Type annotations for boto3 dms nixos-unstable boto3-dms-1.35.45 nixos-unstable-small boto3-dms-1.35.45 nixpkgs-unstable boto3-dms-1.35.45 pkgs.python312Packages.mypy-boto3-dms Type annotations for boto3 dms nixos-25.05 ??? nixos-25.05-small boto3-dms-1.38.0 nixos-unstable boto3-dms-1.35.45 nixos-unstable-small boto3-dms-1.35.45 nixpkgs-unstable boto3-dms-1.35.45 pkgs.python313Packages.mypy-boto3-dms Type annotations for boto3 dms nixos-25.05 ??? nixos-25.05-small boto3-dms-1.38.0 pkgs.home-assistant-component-tests.dlna_dms Open source home automation that puts local control and privacy first nixos-25.05 ??? nixos-25.05-small 2025.5.1 nixos-unstable 2024.11.3 nixos-unstable-small 2024.11.3 nixpkgs-unstable 2024.11.3 pkgs.python311Packages.types-aiobotocore-dms Type annotations for aiobotocore dms nixos-unstable 2.15.2 nixos-unstable-small 2.15.2 nixpkgs-unstable 2.15.2 pkgs.python312Packages.types-aiobotocore-dms Type annotations for aiobotocore dms nixos-25.05 ??? nixos-25.05-small 2.21.1 nixos-unstable 2.15.2 nixos-unstable-small 2.15.2 nixpkgs-unstable 2.15.2 pkgs.python313Packages.types-aiobotocore-dms Type annotations for aiobotocore dms nixos-25.05 ??? nixos-25.05-small 2.21.1 pkgs.python312Packages.ndms2-client.x86_64-linux Keenetic NDMS 2.x and 3.x client nixos-unstable ndms2-client-0.1.3 pkgs.python312Packages.ndms2-client.aarch64-linux Keenetic NDMS 2.x and 3.x client nixos-unstable ndms2-client-0.1.3 pkgs.python312Packages.ndms2-client.x86_64-darwin Keenetic NDMS 2.x and 3.x client nixos-unstable ndms2-client-0.1.3 pkgs.home-assistant-component-tests.keenetic_ndms2 Open source home automation that puts local control and privacy first nixos-25.05 ??? nixos-25.05-small keenetic_ndms2-2025.5.1 nixos-unstable keenetic_ndms2-2024.11.3 nixos-unstable-small keenetic_ndms2-2024.11.3 nixpkgs-unstable keenetic_ndms2-2024.11.3 pkgs.python312Packages.mypy-boto3-dms.x86_64-linux Type annotations for boto3 dms nixos-unstable boto3-dms-1.35.45 pkgs.python312Packages.ndms2-client.aarch64-darwin Keenetic NDMS 2.x and 3.x client nixos-unstable ndms2-client-0.1.3 pkgs.python312Packages.mypy-boto3-dms.aarch64-linux Type annotations for boto3 dms nixos-unstable boto3-dms-1.35.45 pkgs.python312Packages.mypy-boto3-dms.x86_64-darwin Type annotations for boto3 dms nixos-unstable boto3-dms-1.35.45 pkgs.python312Packages.mypy-boto3-dms.aarch64-darwin Type annotations for boto3 dms nixos-unstable boto3-dms-1.35.45 pkgs.python312Packages.types-aiobotocore-dms.x86_64-linux Type annotations for aiobotocore dms nixos-unstable 2.15.2 pkgs.python312Packages.types-aiobotocore-dms.aarch64-linux Type annotations for aiobotocore dms nixos-unstable 2.15.2 pkgs.python312Packages.types-aiobotocore-dms.x86_64-darwin Type annotations for aiobotocore dms nixos-unstable 2.15.2 pkgs.python312Packages.types-aiobotocore-dms.aarch64-darwin Type annotations for aiobotocore dms nixos-unstable 2.15.2 Package maintainers: 9 @katexochen Paul Meyer <katexochen0@gmail.com> @ulrikstrid Ulrik Strid <ulrik.strid@outlook.com> @dotlambda Robert Schütz <rschuetz17@gmail.com> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @mbalatsko Maksym Balatsko <mbalatsko@gmail.com> @claes Claes Holmerson <claes.holmerson@gmail.com> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @Mic92 Jörg Thalheim <joerg@thalheim.io> @disassembler Samuel Leathers <disasm@gmail.com>
pkgs.dms UPnP DLNA Digital Media Server with basic video transcoding nixos-25.05 ??? nixos-25.05-small 1.7.1 nixos-unstable 1.7.1 nixos-unstable-small 1.7.1 nixpkgs-unstable 1.7.1
pkgs.adms automatic device model synthesizer nixos-25.05 ??? nixos-25.05-small 2.3.7 nixos-unstable 2.3.7 nixos-unstable-small 2.3.7 nixpkgs-unstable 2.3.7
pkgs.haskellPackages.amazonka-dms Amazon Database Migration Service SDK nixos-25.05 ??? nixos-25.05-small 2.0 nixos-unstable 2.0 nixos-unstable-small 2.0 nixpkgs-unstable 2.0
pkgs.python311Packages.ndms2-client Keenetic NDMS 2.x and 3.x client nixos-unstable ndms2-client-0.1.3 nixos-unstable-small ndms2-client-0.1.3 nixpkgs-unstable ndms2-client-0.1.3
pkgs.python312Packages.ndms2-client Keenetic NDMS 2.x and 3.x client nixos-25.05 ??? nixos-25.05-small ndms2-client-0.1.3 nixos-unstable ndms2-client-0.1.3 nixos-unstable-small ndms2-client-0.1.3 nixpkgs-unstable ndms2-client-0.1.3
pkgs.python313Packages.ndms2-client Keenetic NDMS 2.x and 3.x client nixos-25.05 ??? nixos-25.05-small ndms2-client-0.1.3
pkgs.azure-cli-extensions.dms-preview Support for new Database Migration Service scenarios nixos-25.05 ??? nixos-25.05-small 0.15.0 nixos-unstable 0.15.0 nixos-unstable-small 0.15.0 nixpkgs-unstable 0.15.0
pkgs.python311Packages.mypy-boto3-dms Type annotations for boto3 dms nixos-unstable boto3-dms-1.35.45 nixos-unstable-small boto3-dms-1.35.45 nixpkgs-unstable boto3-dms-1.35.45
pkgs.python312Packages.mypy-boto3-dms Type annotations for boto3 dms nixos-25.05 ??? nixos-25.05-small boto3-dms-1.38.0 nixos-unstable boto3-dms-1.35.45 nixos-unstable-small boto3-dms-1.35.45 nixpkgs-unstable boto3-dms-1.35.45
pkgs.python313Packages.mypy-boto3-dms Type annotations for boto3 dms nixos-25.05 ??? nixos-25.05-small boto3-dms-1.38.0
pkgs.home-assistant-component-tests.dlna_dms Open source home automation that puts local control and privacy first nixos-25.05 ??? nixos-25.05-small 2025.5.1 nixos-unstable 2024.11.3 nixos-unstable-small 2024.11.3 nixpkgs-unstable 2024.11.3
pkgs.python311Packages.types-aiobotocore-dms Type annotations for aiobotocore dms nixos-unstable 2.15.2 nixos-unstable-small 2.15.2 nixpkgs-unstable 2.15.2
pkgs.python312Packages.types-aiobotocore-dms Type annotations for aiobotocore dms nixos-25.05 ??? nixos-25.05-small 2.21.1 nixos-unstable 2.15.2 nixos-unstable-small 2.15.2 nixpkgs-unstable 2.15.2
pkgs.python313Packages.types-aiobotocore-dms Type annotations for aiobotocore dms nixos-25.05 ??? nixos-25.05-small 2.21.1
pkgs.python312Packages.ndms2-client.x86_64-linux Keenetic NDMS 2.x and 3.x client nixos-unstable ndms2-client-0.1.3
pkgs.python312Packages.ndms2-client.aarch64-linux Keenetic NDMS 2.x and 3.x client nixos-unstable ndms2-client-0.1.3
pkgs.python312Packages.ndms2-client.x86_64-darwin Keenetic NDMS 2.x and 3.x client nixos-unstable ndms2-client-0.1.3
pkgs.home-assistant-component-tests.keenetic_ndms2 Open source home automation that puts local control and privacy first nixos-25.05 ??? nixos-25.05-small keenetic_ndms2-2025.5.1 nixos-unstable keenetic_ndms2-2024.11.3 nixos-unstable-small keenetic_ndms2-2024.11.3 nixpkgs-unstable keenetic_ndms2-2024.11.3
pkgs.python312Packages.mypy-boto3-dms.x86_64-linux Type annotations for boto3 dms nixos-unstable boto3-dms-1.35.45
pkgs.python312Packages.ndms2-client.aarch64-darwin Keenetic NDMS 2.x and 3.x client nixos-unstable ndms2-client-0.1.3
pkgs.python312Packages.mypy-boto3-dms.aarch64-linux Type annotations for boto3 dms nixos-unstable boto3-dms-1.35.45
pkgs.python312Packages.mypy-boto3-dms.x86_64-darwin Type annotations for boto3 dms nixos-unstable boto3-dms-1.35.45
pkgs.python312Packages.mypy-boto3-dms.aarch64-darwin Type annotations for boto3 dms nixos-unstable boto3-dms-1.35.45
pkgs.python312Packages.types-aiobotocore-dms.x86_64-linux Type annotations for aiobotocore dms nixos-unstable 2.15.2
pkgs.python312Packages.types-aiobotocore-dms.aarch64-linux Type annotations for aiobotocore dms nixos-unstable 2.15.2
pkgs.python312Packages.types-aiobotocore-dms.x86_64-darwin Type annotations for aiobotocore dms nixos-unstable 2.15.2
pkgs.python312Packages.types-aiobotocore-dms.aarch64-darwin Type annotations for aiobotocore dms nixos-unstable 2.15.2
CVE-2025-32293 8.8 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 6 months, 3 weeks ago WordPress Finance Consultant <= 2.8 - PHP Object Injection Vulnerability Deserialization of Untrusted Data vulnerability in designthemes Finance Consultant allows Object Injection. This issue affects Finance Consultant: from n/a through 2.8. Affected products finance =<2.8 Matching in nixpkgs pkgs.python311Packages.yfinance Module to doiwnload Yahoo! Finance market data nixos-unstable 0.2.50 nixos-unstable-small 0.2.50 nixpkgs-unstable 0.2.50 pkgs.python312Packages.yfinance Module to doiwnload Yahoo! Finance market data nixos-25.05 ??? nixos-25.05-small 0.2.58 nixos-unstable 0.2.50 nixos-unstable-small 0.2.50 nixpkgs-unstable 0.2.50 pkgs.python313Packages.yfinance Module to doiwnload Yahoo! Finance market data nixos-25.05 ??? nixos-25.05-small 0.2.58 pkgs.python311Packages.mplfinance Matplotlib utilities for the visualization, and visual analysis, of financial data nixos-unstable 0.12.7a7 nixos-unstable-small 0.12.7a7 nixpkgs-unstable 0.12.7a7 pkgs.python312Packages.mplfinance Matplotlib utilities for the visualization, and visual analysis, of financial data nixos-25.05 ??? nixos-25.05-small 0.12.7a7 nixos-unstable 0.12.7a7 nixos-unstable-small 0.12.7a7 nixpkgs-unstable 0.12.7a7 pkgs.python313Packages.mplfinance Matplotlib utilities for the visualization, and visual analysis, of financial data nixos-25.05 ??? nixos-25.05-small 0.12.7a7 pkgs.python311Packages.finvizfinance Finviz Finance information downloader nixos-unstable 1.1.0 nixos-unstable-small 1.1.0 nixpkgs-unstable 1.1.0 pkgs.python312Packages.finvizfinance Finviz Finance information downloader nixos-25.05 ??? nixos-25.05-small 1.1.0 nixos-unstable 1.1.0 nixos-unstable-small 1.1.0 nixpkgs-unstable 1.1.0 pkgs.python313Packages.finvizfinance Finviz Finance information downloader nixos-25.05 ??? nixos-25.05-small 1.1.0 pkgs.python312Packages.yfinance.x86_64-linux Module to doiwnload Yahoo! Finance market data nixos-unstable 0.2.50 pkgs.python312Packages.yfinance.aarch64-linux Module to doiwnload Yahoo! Finance market data nixos-unstable 0.2.50 pkgs.python312Packages.yfinance.x86_64-darwin Module to doiwnload Yahoo! Finance market data nixos-unstable 0.2.50 pkgs.python312Packages.mplfinance.x86_64-linux Matplotlib utilities for the visualization, and visual analysis, of financial data nixos-unstable 0.12.7a7 pkgs.python312Packages.yfinance.aarch64-darwin Module to doiwnload Yahoo! Finance market data nixos-unstable 0.2.50 pkgs.python312Packages.mplfinance.aarch64-linux Matplotlib utilities for the visualization, and visual analysis, of financial data nixos-unstable 0.12.7a7 pkgs.python312Packages.mplfinance.x86_64-darwin Matplotlib utilities for the visualization, and visual analysis, of financial data nixos-unstable 0.12.7a7 pkgs.python312Packages.mplfinance.aarch64-darwin Matplotlib utilities for the visualization, and visual analysis, of financial data nixos-unstable 0.12.7a7 pkgs.python312Packages.finvizfinance.x86_64-linux Finviz Finance information downloader nixos-unstable 1.1.0 pkgs.python312Packages.finvizfinance.aarch64-linux Finviz Finance information downloader nixos-unstable 1.1.0 pkgs.python312Packages.finvizfinance.x86_64-darwin Finviz Finance information downloader nixos-unstable 1.1.0 pkgs.python312Packages.finvizfinance.aarch64-darwin Finviz Finance information downloader nixos-unstable 1.1.0 Package maintainers: 2 @drewrisinger Drew Risinger <drisinger+nixpkgs@gmail.com> @icyrockcom icyrock
pkgs.python311Packages.yfinance Module to doiwnload Yahoo! Finance market data nixos-unstable 0.2.50 nixos-unstable-small 0.2.50 nixpkgs-unstable 0.2.50
pkgs.python312Packages.yfinance Module to doiwnload Yahoo! Finance market data nixos-25.05 ??? nixos-25.05-small 0.2.58 nixos-unstable 0.2.50 nixos-unstable-small 0.2.50 nixpkgs-unstable 0.2.50
pkgs.python313Packages.yfinance Module to doiwnload Yahoo! Finance market data nixos-25.05 ??? nixos-25.05-small 0.2.58
pkgs.python311Packages.mplfinance Matplotlib utilities for the visualization, and visual analysis, of financial data nixos-unstable 0.12.7a7 nixos-unstable-small 0.12.7a7 nixpkgs-unstable 0.12.7a7
pkgs.python312Packages.mplfinance Matplotlib utilities for the visualization, and visual analysis, of financial data nixos-25.05 ??? nixos-25.05-small 0.12.7a7 nixos-unstable 0.12.7a7 nixos-unstable-small 0.12.7a7 nixpkgs-unstable 0.12.7a7
pkgs.python313Packages.mplfinance Matplotlib utilities for the visualization, and visual analysis, of financial data nixos-25.05 ??? nixos-25.05-small 0.12.7a7
pkgs.python311Packages.finvizfinance Finviz Finance information downloader nixos-unstable 1.1.0 nixos-unstable-small 1.1.0 nixpkgs-unstable 1.1.0
pkgs.python312Packages.finvizfinance Finviz Finance information downloader nixos-25.05 ??? nixos-25.05-small 1.1.0 nixos-unstable 1.1.0 nixos-unstable-small 1.1.0 nixpkgs-unstable 1.1.0
pkgs.python313Packages.finvizfinance Finviz Finance information downloader nixos-25.05 ??? nixos-25.05-small 1.1.0
pkgs.python312Packages.yfinance.x86_64-linux Module to doiwnload Yahoo! Finance market data nixos-unstable 0.2.50
pkgs.python312Packages.yfinance.aarch64-linux Module to doiwnload Yahoo! Finance market data nixos-unstable 0.2.50
pkgs.python312Packages.yfinance.x86_64-darwin Module to doiwnload Yahoo! Finance market data nixos-unstable 0.2.50
pkgs.python312Packages.mplfinance.x86_64-linux Matplotlib utilities for the visualization, and visual analysis, of financial data nixos-unstable 0.12.7a7
pkgs.python312Packages.yfinance.aarch64-darwin Module to doiwnload Yahoo! Finance market data nixos-unstable 0.2.50
pkgs.python312Packages.mplfinance.aarch64-linux Matplotlib utilities for the visualization, and visual analysis, of financial data nixos-unstable 0.12.7a7
pkgs.python312Packages.mplfinance.x86_64-darwin Matplotlib utilities for the visualization, and visual analysis, of financial data nixos-unstable 0.12.7a7
pkgs.python312Packages.mplfinance.aarch64-darwin Matplotlib utilities for the visualization, and visual analysis, of financial data nixos-unstable 0.12.7a7
pkgs.python312Packages.finvizfinance.x86_64-linux Finviz Finance information downloader nixos-unstable 1.1.0
pkgs.python312Packages.finvizfinance.aarch64-linux Finviz Finance information downloader nixos-unstable 1.1.0
pkgs.python312Packages.finvizfinance.x86_64-darwin Finviz Finance information downloader nixos-unstable 1.1.0
pkgs.python312Packages.finvizfinance.aarch64-darwin Finviz Finance information downloader nixos-unstable 1.1.0
CVE-2024-22309 8.7 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): NONE created 6 months, 3 weeks ago WordPress ChatBot Plugin <= 5.1.0 is vulnerable to PHP Object Injection Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from n/a through 5.1.0. Affected products chatbot =<5.1.0 Matching in nixpkgs pkgs.gnomeExtensions.penguin-ai-chatbot A GNOME Shell extension that uses openrouter.ai services - a platform/marketplace that offers APIs to talk to LLMs. Some of these APIs are free to use, including the one used by default in the extension: Llama 3.1 8B. nixos-25.05 ??? nixos-25.05-small 22 nixos-unstable 11 nixos-unstable-small 11 nixpkgs-unstable 11 Package maintainers: 1 @honnip Jung seungwoo <me@honnip.page>
pkgs.gnomeExtensions.penguin-ai-chatbot A GNOME Shell extension that uses openrouter.ai services - a platform/marketplace that offers APIs to talk to LLMs. Some of these APIs are free to use, including the one used by default in the extension: Llama 3.1 8B. nixos-25.05 ??? nixos-25.05-small 22 nixos-unstable 11 nixos-unstable-small 11 nixpkgs-unstable 11
CVE-2023-52125 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 6 months, 3 weeks ago WordPress iFrame Plugin <= 4.8 is vulnerable to Cross Site Scripting (XSS) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly iframe allows Stored XSS.This issue affects iframe: from n/a through 4.8. Affected products iframe =<4.8 Matching in nixpkgs
CVE-2025-31423 9.8 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 6 months, 3 weeks ago WordPress Umberto <= 1.2.8 - PHP Object Injection Vulnerability Deserialization of Untrusted Data vulnerability in AncoraThemes Umberto allows Object Injection. This issue affects Umberto: from n/a through 1.2.8. Affected products umberto =<1.2.8 Matching in nixpkgs pkgs.vimPlugins.vim-numbertoggle nixos-unstable 2021-07-14 nixos-unstable-small 2021-07-14 nixpkgs-unstable 2021-07-14 pkgs.vimPlugins.vim-numbertoggle.x86_64-linux nixos-unstable ??? nixos-unstable-small 2021-07-14 pkgs.vimPlugins.vim-numbertoggle.aarch64-linux nixos-unstable ??? nixos-unstable-small 2021-07-14 pkgs.vimPlugins.vim-numbertoggle.x86_64-darwin nixos-unstable ??? nixos-unstable-small 2021-07-14 pkgs.vimPlugins.vim-numbertoggle.aarch64-darwin nixos-unstable ??? nixos-unstable-small 2021-07-14
pkgs.vimPlugins.vim-numbertoggle nixos-unstable 2021-07-14 nixos-unstable-small 2021-07-14 nixpkgs-unstable 2021-07-14
CVE-2025-32285 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 6 months, 3 weeks ago WordPress Butcher theme <= 2.40 - Reflected Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ApusTheme Butcher allows Reflected XSS. This issue affects Butcher: from n/a through 2.40. Affected products butcher =<2.40 Matching in nixpkgs pkgs.haskellPackages.butcher Chops a command or program invocation into digestable pieces nixos-25.05 ??? nixos-25.05-small 1.3.3.2 nixos-unstable 1.3.3.2 nixos-unstable-small 1.3.3.2 nixpkgs-unstable 1.3.3.2 pkgs.haskellPackages.butcher.x86_64-linux Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2 pkgs.haskellPackages.butcher.aarch64-linux Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2 pkgs.haskellPackages.butcher.x86_64-darwin Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2 pkgs.haskellPackages.butcher.aarch64-darwin Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2
pkgs.haskellPackages.butcher Chops a command or program invocation into digestable pieces nixos-25.05 ??? nixos-25.05-small 1.3.3.2 nixos-unstable 1.3.3.2 nixos-unstable-small 1.3.3.2 nixpkgs-unstable 1.3.3.2
pkgs.haskellPackages.butcher.x86_64-linux Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2
pkgs.haskellPackages.butcher.aarch64-linux Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2
pkgs.haskellPackages.butcher.x86_64-darwin Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2
pkgs.haskellPackages.butcher.aarch64-darwin Chops a command or program invocation into digestable pieces nixos-unstable ??? nixpkgs-unstable 1.3.3.2
CVE-2025-5024 7.4 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 6 months, 3 weeks ago Gnome-remote-desktop: uncontrolled resource consumption due to malformed rdp pdus A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd. Affected products gnome-remote-desktop * Matching in nixpkgs pkgs.gnome-remote-desktop GNOME Remote Desktop server nixos-25.05 ??? nixos-25.05-small 48.1 nixos-unstable 47.2 nixos-unstable-small 47.2 nixpkgs-unstable 47.2 Package maintainers: 4 @jtojnar Jan Tojnar <jtojnar@gmail.com> @bobby285271 Bobby Rong <rjl931189261@126.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk>
pkgs.gnome-remote-desktop GNOME Remote Desktop server nixos-25.05 ??? nixos-25.05-small 48.1 nixos-unstable 47.2 nixos-unstable-small 47.2 nixpkgs-unstable 47.2