Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestions search

With package: sonar-scanner-cli-minimal

Found 1 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-19190
7.1 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 3 weeks, 1 day ago Activity log
  • Created suggestion
StableBit Scanner ScannerService Scanner.Service.exe permission

A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission issues. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks.

Affected products

Scanner
  • ==2.6.13.4088

Matching in nixpkgs

pkgs.s3scanner

Scan for misconfigured S3 buckets across S3-compatible APIs

pkgs.netscanner

Network scanner with features like WiFi scanning, packetdump and more

pkgs.osv-scanner

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

pkgs.http-scanner

HTTP security vulnerability scanner that detects a wide range of web application vulnerabilities

pkgs.mdns-scanner

Scan a network and create a list of IPs and associated hostnames, including mDNS hostnames and other aliases

pkgs.user-scanner

Email & Username OSINT suite

  • nixos-unstable -
    • nixpkgs-unstable 1.4.1
    • nixos-unstable-small 1.4.2

pkgs.secretscanner

Tool to find secrets and passwords in container images and file systems

pkgs.binary-object-scanner

C# protection, packer, and archive scanning library. Provides ProtectionScan and ExtractionTool

pkgs.gnomeExtensions.lan-scanner

Scans local network and displays connected devices (IP, MAC, hostname)

  • nixos-unstable -
    • nixos-unstable-small 3