⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

Create Draft to queue a suggestion for refinement.

Dismiss to remove a suggestion from the queue.

CVE-2025-22703
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 8 months, 3 weeks ago
WordPress Forge – Front-End Page Builder plugin <= 1.4.6 - CSRF to Stored Cross Site Scripting (XSS) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in manuelvicedo Forge – Front-End Page Builder allows Stored XSS. This issue affects Forge – Front-End Page Builder: from n/a through 1.4.6.

forge
=<1.4.6

pkgs.forge

OpenGL interop library that can be used with ArrayFire or any other application using CUDA or OpenCL compute backend

pkgs.forgejo

Self-hosted lightweight software forge

pkgs.forge-mtg

Magic: the Gathering card game with rules enforcement

pkgs.mindforger

Thinking Notebook & Markdown IDE

pkgs.forgejo-cli

CLI application for interacting with Forgejo

pkgs.forgejo-lts

Self-hosted lightweight software forge

pkgs.mcdreforged

Rewritten version of MCDaemon, a python tool to control your Minecraft server

pkgs.forge-sparks

Get Git forges notifications

pkgs.forgejo-runner

Runner for Forgejo based on act

pkgs.gnomeExtensions.forge

Tiling and window manager for GNOME
  • nixos-unstable 84
    • nixos-unstable-small 84
    • nixpkgs-unstable 84

pkgs.python312Packages.fontforge.x86_64-linux

Font editor

pkgs.python312Packages.fontforge.aarch64-linux

Font editor

pkgs.python312Packages.fontforge.x86_64-darwin

Font editor

pkgs.python312Packages.fontforge.aarch64-darwin

Font editor
Package maintainers: 16
CVE-2023-4911
7.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 8 months, 3 weeks ago
Glibc: buffer overflow in ld.so leading to privilege escalation

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

glibc
*
<2.39
compat-glibc
redhat-virtualization-host
*
redhat-release-virtualization-host
*

pkgs.mtrace

Perl script used to interpret and provide human readable output of the trace log contained in the file mtracedata, whose contents were produced by mtrace(3)

pkgs.glibcLocales

Locale information for the GNU C Library

pkgs.glibcLocalesUtf8

Locale information for the GNU C Library

pkgs.locale.x86_64-linux

pkgs.locale.aarch64-linux

pkgs.libiconv.x86_64-linux

pkgs.libiconv.aarch64-linux

Package maintainers: 2
CVE-2024-22029
7.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 8 months, 4 weeks ago
tomcat packaging allows for escalation to root from tomcat user

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

tomcat
<9.0.85-150200.57.1
<9.0.85-3.1

pkgs.tomcat9

Implementation of the Java Servlet and JavaServer Pages technologies

pkgs.tomcat10

Implementation of the Java Servlet and JavaServer Pages technologies

pkgs.tomcat11

Implementation of the Java Servlet and JavaServer Pages technologies

pkgs.tomcat-native

Optional component for use with Apache Tomcat that allows Tomcat to use certain native resources for performance, compatibility, etc
Package maintainers: 2
CVE-2023-46846
9.3 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 8 months, 4 weeks ago
Squid: request/response smuggling in http/1.1 and icap

SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.

squid
<6.4
*
squid34
squid:4
*

pkgs.squid

Caching proxy for the Web supporting HTTP, HTTPS, FTP, and more
Package maintainers: 1
CVE-2024-1488
8.0 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 9 months ago
Unbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.

unbound
==1.16.2
*

pkgs.unbound

Validating, recursive, and caching DNS resolver

pkgs.unbound-full

Validating, recursive, and caching DNS resolver

pkgs.unbound-with-systemd

Validating, recursive, and caching DNS resolver

pkgs.lua52Packages.luaunbound

A binding to libunbound

pkgs.prometheus-unbound-exporter

Prometheus exporter for Unbound DNS resolver

pkgs.python311Packages.pyunbound

Python library for Unbound, the validating, recursive, and caching DNS resolver

pkgs.python312Packages.pyunbound

Python library for Unbound, the validating, recursive, and caching DNS resolver

pkgs.haskellPackages.unbounded-delays

Unbounded thread delays and timeouts

pkgs.luaPackages.luaunbound.x86_64-linux

A binding to libunbound

pkgs.luaPackages.luaunbound.aarch64-linux

A binding to libunbound

pkgs.luaPackages.luaunbound.x86_64-darwin

A binding to libunbound

pkgs.lua51Packages.luaunbound.x86_64-linux

A binding to libunbound

pkgs.lua53Packages.luaunbound.x86_64-linux

A binding to libunbound

pkgs.lua54Packages.luaunbound.x86_64-linux

A binding to libunbound

pkgs.luaPackages.luaunbound.aarch64-darwin

A binding to libunbound

pkgs.lua51Packages.luaunbound.aarch64-linux

A binding to libunbound

pkgs.lua51Packages.luaunbound.x86_64-darwin

A binding to libunbound

pkgs.lua53Packages.luaunbound.aarch64-linux

A binding to libunbound

pkgs.lua53Packages.luaunbound.x86_64-darwin

A binding to libunbound

pkgs.lua54Packages.luaunbound.aarch64-linux

A binding to libunbound

pkgs.lua54Packages.luaunbound.x86_64-darwin

A binding to libunbound

pkgs.lua51Packages.luaunbound.aarch64-darwin

A binding to libunbound

pkgs.lua53Packages.luaunbound.aarch64-darwin

A binding to libunbound

pkgs.lua54Packages.luaunbound.aarch64-darwin

A binding to libunbound

pkgs.python312Packages.pyunbound.x86_64-linux

Python library for Unbound, the validating, recursive, and caching DNS resolver

pkgs.python312Packages.pyunbound.aarch64-linux

Python library for Unbound, the validating, recursive, and caching DNS resolver

pkgs.python312Packages.pyunbound.x86_64-darwin

Python library for Unbound, the validating, recursive, and caching DNS resolver

pkgs.python312Packages.pyunbound.aarch64-darwin

Python library for Unbound, the validating, recursive, and caching DNS resolver
Package maintainers: 2
CVE-2025-23803
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 9 months ago
WordPress Snippy Plugin <= 1.4.1 - CSRF to Cross Site Scripting (XSS) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in PQINA Snippy allows Reflected XSS. This issue affects Snippy: from n/a through 1.4.1.

snippy
=<1.4.1
CVE-2025-23592
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 9 months ago
WordPress dForms plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound dForms allows Reflected XSS. This issue affects dForms: from n/a through 1.0.

dforms
=<1.0

pkgs.python311Packages.permissionedforms

Django extension for creating forms that vary according to user permissions

pkgs.python312Packages.permissionedforms

Django extension for creating forms that vary according to user permissions

pkgs.python312Packages.permissionedforms.x86_64-linux

Django extension for creating forms that vary according to user permissions

pkgs.python312Packages.permissionedforms.aarch64-linux

Django extension for creating forms that vary according to user permissions

pkgs.python312Packages.permissionedforms.x86_64-darwin

Django extension for creating forms that vary according to user permissions

pkgs.python312Packages.permissionedforms.aarch64-darwin

Django extension for creating forms that vary according to user permissions
Package maintainers: 1
CVE-2025-23919
5.4 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 9 months, 1 week ago
WordPress Slides & Presentations Plugin <= 0.0.39 - Content Injection vulnerability

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Ella van Durpe Slides & Presentations allows Code Injection.This issue affects Slides & Presentations: from n/a through 0.0.39.

slide
=<0.0.39

pkgs.slides

Terminal based presentation tool

pkgs.openslide

C library that provides a simple interface to read whole-slide images

pkgs.manim-slides

Tool for live presentations using manim

pkgs.dvd-slideshow

Suite of command line programs that creates a slideshow-style video from groups of pictures

pkgs.slides.x86_64-linux

Terminal based presentation tool

pkgs.slides.aarch64-linux

Terminal based presentation tool

pkgs.slides.x86_64-darwin

Terminal based presentation tool

pkgs.slides.aarch64-darwin

Terminal based presentation tool

pkgs.gnomeExtensions.backslide

Automatic background-image (wallpaper) slideshow for Gnome Shell
  • nixos-unstable 33
    • nixos-unstable-small 33
    • nixpkgs-unstable 33

pkgs.python311Packages.openslide

Python bindings to the OpenSlide library for reading whole-slide microscopy images

pkgs.python312Packages.openslide

Python bindings to the OpenSlide library for reading whole-slide microscopy images

pkgs.python311Packages.manim-slides

Tool for live presentations using manim

pkgs.python312Packages.manim-slides

Tool for live presentations using manim

pkgs.vscode-extensions.antfu.slidev

pkgs.python311Packages.textual-slider

Textual widget for a simple slider

pkgs.python312Packages.textual-slider

Textual widget for a simple slider

pkgs.gnomeExtensions.wallpaper-slideshow

Wallpaper slideshow extension. Optionally downloads BING wallpaper of the day.
  • nixos-unstable 10
    • nixos-unstable-small 10
    • nixpkgs-unstable 10

pkgs.python312Packages.openslide.x86_64-linux

Python bindings to the OpenSlide library for reading whole-slide microscopy images

pkgs.gnomeExtensions.keyboard-backlight-slider

Allow setting the keyboard backlight brightness with a slider in the main menu
  • nixos-unstable 6
    • nixos-unstable-small 6
    • nixpkgs-unstable 6

pkgs.python312Packages.openslide.aarch64-linux

Python bindings to the OpenSlide library for reading whole-slide microscopy images

pkgs.python312Packages.openslide.x86_64-darwin

Python bindings to the OpenSlide library for reading whole-slide microscopy images

pkgs.gnomeExtensions.night-light-slider-updated

Kiyui's Night Light Slider updated for GNOME >= 45. Provides a slider in the quick settings menu to control the night light temperature. Some nice options can be set in the extension preferences menu. Original implementation: https://codeberg.org/kiyui/gnome-shell-night-light-slider-extension/
  • nixos-unstable 12
    • nixos-unstable-small 12
    • nixpkgs-unstable 12

pkgs.python312Packages.openslide.aarch64-darwin

Python bindings to the OpenSlide library for reading whole-slide microscopy images

pkgs.python312Packages.manim-slides.x86_64-linux

Tool for live presentations using manim

pkgs.vscode-extensions.antfu.slidev.x86_64-linux

pkgs.python312Packages.manim-slides.aarch64-linux

Tool for live presentations using manim

pkgs.vscode-extensions.antfu.slidev.aarch64-linux

pkgs.vscode-extensions.antfu.slidev.x86_64-darwin

pkgs.python312Packages.textual-slider.x86_64-linux

Textual widget for a simple slider

pkgs.vscode-extensions.antfu.slidev.aarch64-darwin

pkgs.python312Packages.textual-slider.aarch64-linux

Textual widget for a simple slider

pkgs.python312Packages.textual-slider.x86_64-darwin

Textual widget for a simple slider

pkgs.python312Packages.textual-slider.aarch64-darwin

Textual widget for a simple slider

pkgs.vscode-extensions.ms-toolsai.vscode-jupyter-slideshow

pkgs.vscode-extensions.ms-toolsai.vscode-jupyter-slideshow.x86_64-linux

pkgs.vscode-extensions.ms-toolsai.vscode-jupyter-slideshow.aarch64-linux

pkgs.vscode-extensions.ms-toolsai.vscode-jupyter-slideshow.x86_64-darwin

pkgs.vscode-extensions.ms-toolsai.vscode-jupyter-slideshow.aarch64-darwin

Package maintainers: 9
CVE-2024-12086
6.1 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 9 months, 1 week ago
Rsync: rsync server leaks arbitrary client files

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client.

rhcos
rsync
=<3.3.0

pkgs.rsync

Fast incremental file transfer utility

pkgs.grsync

Synchronize folders, files and make backups

pkgs.rrsync

Helper to run rsync-only environments from ssh-logins

pkgs.librsync

Implementation of the rsync remote-delta algorithm

pkgs.diskrsync

Rsync for block devices and disk images

pkgs.vdirsyncer

Synchronize calendars and contacts

pkgs.rsync.x86_64-linux

Fast incremental file transfer utility

pkgs.rrsync.x86_64-linux

Helper to run rsync-only environments from ssh-logins

pkgs.rsync.aarch64-linux

Fast incremental file transfer utility

pkgs.rsync.x86_64-darwin

Fast incremental file transfer utility

pkgs.rrsync.aarch64-linux

Helper to run rsync-only environments from ssh-logins

pkgs.rrsync.x86_64-darwin

Helper to run rsync-only environments from ssh-logins

pkgs.rsync.aarch64-darwin

Fast incremental file transfer utility

pkgs.librsync.x86_64-linux

Implementation of the rsync remote-delta algorithm

pkgs.rrsync.aarch64-darwin

Helper to run rsync-only environments from ssh-logins

pkgs.librsync.aarch64-linux

Implementation of the rsync remote-delta algorithm

pkgs.librsync.x86_64-darwin

Implementation of the rsync remote-delta algorithm

pkgs.librsync.aarch64-darwin

Implementation of the rsync remote-delta algorithm

pkgs.python311Packages.sysrsync

Simple and safe system's rsync wrapper for Python

pkgs.python312Packages.sysrsync

Simple and safe system's rsync wrapper for Python

pkgs.python311Packages.vdirsyncer

Synchronize calendars and contacts

pkgs.python312Packages.vdirsyncer

Synchronize calendars and contacts

pkgs.python312Packages.sysrsync.x86_64-linux

Simple and safe system's rsync wrapper for Python

pkgs.python312Packages.sysrsync.aarch64-linux

Simple and safe system's rsync wrapper for Python

pkgs.python312Packages.sysrsync.x86_64-darwin

Simple and safe system's rsync wrapper for Python

pkgs.python312Packages.sysrsync.aarch64-darwin

Simple and safe system's rsync wrapper for Python

pkgs.python312Packages.vdirsyncer.x86_64-linux

Synchronize calendars and contacts

pkgs.python312Packages.vdirsyncer.aarch64-linux

Synchronize calendars and contacts

pkgs.python312Packages.vdirsyncer.x86_64-darwin

Synchronize calendars and contacts

pkgs.python312Packages.vdirsyncer.aarch64-darwin

Synchronize calendars and contacts
Package maintainers: 7
CVE-2024-12747
5.6 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): HIGH
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 9 months, 1 week ago
Rsync: race condition in rsync handling symbolic links

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.

rhcos
rsync
*
=<3.3.0
registry.redhat.io/discovery/discovery-ui-rhel9
*

pkgs.rsync

Fast incremental file transfer utility

pkgs.grsync

Synchronize folders, files and make backups

pkgs.rrsync

Helper to run rsync-only environments from ssh-logins

pkgs.librsync

Implementation of the rsync remote-delta algorithm

pkgs.diskrsync

Rsync for block devices and disk images

pkgs.vdirsyncer

Synchronize calendars and contacts

pkgs.rsync.x86_64-linux

Fast incremental file transfer utility

pkgs.rrsync.x86_64-linux

Helper to run rsync-only environments from ssh-logins

pkgs.rsync.aarch64-linux

Fast incremental file transfer utility

pkgs.rsync.x86_64-darwin

Fast incremental file transfer utility

pkgs.rrsync.aarch64-linux

Helper to run rsync-only environments from ssh-logins

pkgs.rrsync.x86_64-darwin

Helper to run rsync-only environments from ssh-logins

pkgs.rsync.aarch64-darwin

Fast incremental file transfer utility

pkgs.librsync.x86_64-linux

Implementation of the rsync remote-delta algorithm

pkgs.rrsync.aarch64-darwin

Helper to run rsync-only environments from ssh-logins

pkgs.librsync.aarch64-linux

Implementation of the rsync remote-delta algorithm

pkgs.librsync.x86_64-darwin

Implementation of the rsync remote-delta algorithm

pkgs.librsync.aarch64-darwin

Implementation of the rsync remote-delta algorithm

pkgs.python311Packages.sysrsync

Simple and safe system's rsync wrapper for Python

pkgs.python312Packages.sysrsync

Simple and safe system's rsync wrapper for Python

pkgs.python311Packages.vdirsyncer

Synchronize calendars and contacts

pkgs.python312Packages.vdirsyncer

Synchronize calendars and contacts

pkgs.python312Packages.sysrsync.x86_64-linux

Simple and safe system's rsync wrapper for Python

pkgs.python312Packages.sysrsync.aarch64-linux

Simple and safe system's rsync wrapper for Python

pkgs.python312Packages.sysrsync.x86_64-darwin

Simple and safe system's rsync wrapper for Python

pkgs.python312Packages.sysrsync.aarch64-darwin

Simple and safe system's rsync wrapper for Python

pkgs.python312Packages.vdirsyncer.x86_64-linux

Synchronize calendars and contacts

pkgs.python312Packages.vdirsyncer.aarch64-linux

Synchronize calendars and contacts

pkgs.python312Packages.vdirsyncer.x86_64-darwin

Synchronize calendars and contacts

pkgs.python312Packages.vdirsyncer.aarch64-darwin

Synchronize calendars and contacts
Package maintainers: 7