Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2024-6541
6.8 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Information Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 Products

The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.

Affected products

WSO2 API Manager
  • <4.1.0.167
  • <4.0.0.311
  • <3.2.0.394
  • <3.2.0
  • <3.2.1.21
  • <4.3.0.24
  • <4.2.0.110
WSO2 Micro Integrator
  • <4.3.0.7
  • <1.2.0.163
  • <4.1.0.103
  • <1.2.0
WSO2 Enterprise Integrator
  • <6.6.0.205
  • <6.6.0
org.apache.synapse:synapse-core
  • =<v4.0.0-wso2v*
  • <2.1.7.wso2v227_88
  • <4.0.0.wso2v105_3
  • <2.1.7.wso2v319_7
  • <4.0.0.wso2v20_63
  • <4.0.0.wso2v119_3
  • <2.1.7.wso2v143_119
  • <2.1.7.wso2v182_93
  • <2.1.7.wso2v183_62
  • <2.1.7.wso2v271_60
Dismissed
(no matching packages found)
Permalink CVE-2026-19019
2.9 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup

A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_session_persistence of the file executor/app/core/workspace.py of the component Claude File Handler. The manipulation results in incomplete cleanup. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks.

Affected products

poco-agent
  • ==0.5.2
  • ==0.5.0
  • ==0.5.4
  • ==0.5.3
  • ==0.5.1
Dismissed
(no matching packages found)
Permalink CVE-2026-18967
6.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow

A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user.

References

Affected products

keycloak-services
rhbk-keycloak-rhel9/rhbk-keycloak-rhel9
rhbk-openshift-rhel9/rhbk-openshift-rhel9
Dismissed
(no matching packages found)
Permalink CVE-2025-13394
5.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions

The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie attribute is employed for mitigation, this mechanism is bypassed as it permits cookies to be sent with cross-origin top-level navigation requests, including GET requests. This allows an attacker to trick an authenticated user's browser into unknowingly executing unintended actions. An attacker can exploit this vulnerability to perform unauthorized state-altering requests on behalf of authenticated users. This could lead to consequences such as data modification, account changes, or other actions that could result in data compromise or loss of user control over their account. However, this attack is only feasible if the Carbon console and related services are exposed to the public internet, which is not recommended according to WSO2's security guidelines.

Affected products

WSO2 API Manager
  • <3.1.0.352
  • <4.5.0.38
  • <4.0.0.376
  • <4.3.0.91
  • <3.2.0.456
  • <4.2.0.179
  • <4.6.0.3
  • <3.1.0
  • <4.4.0.55
  • <3.2.1.75
  • <4.1.0.239
WSO2 Identity Server
  • <7.2.0.3
  • <7.0.0.133
  • <7.1.0.41
  • <6.1.0.256
  • <5.11.0.428
  • <6.0.0.255
  • <5.10.0
  • <5.10.0.381
WSO2 Open Banking AM
  • <2.0.0.401
  • <2.0.0
WSO2 Traffic Manager
  • <4.6.0.3
  • <4.5.0
  • <4.5.0.37
WSO2 Open Banking IAM
  • <2.0.0
  • <2.0.0.421
WSO2 API Control Plane
  • <4.6.0.3
  • <4.5.0
  • <4.5.0.39
WSO2 Universal Gateway
  • <4.6.0.3
  • <4.5.0
  • <4.5.0.37
WSO2 Enterprise Integrator
  • <6.6.0.227
  • <6.6.0
WSO2 Identity Server as Key Manager
  • <5.10.0.372
  • <5.10.0
org.wso2.carbon:org.wso2.carbon.task.ui
  • =<*
  • <4.7.30.53
org.wso2.carbon:org.wso2.carbon.ntask.core
  • =<*
  • <4.7.19.13
org.wso2.carbonorg.wso2.carbon.endpoint.ui
  • =<*
  • <4.7.30.53
org.wso2.carbon:org.wso2.carbon.rest.api.ui
  • =<*
  • <4.7.30.53
org.wso2.carbon:org.wso2.carbon.sequences.ui
  • =<*
  • <4.7.30.53
org.wso2.carbon:org.wso2.carbon.tenant.mgt.ui
  • <4.11.45.1
  • <4.9.31.1
  • <4.8.1.6
  • <4.8.7.3
  • <4.11.0.7
  • <4.9.27.1
  • <4.9.10.7
  • =<*
  • <4.9.8.7
  • <4.11.34.3
  • <4.9.34.1
  • <4.9.10.8
  • <4.9.42.1
  • <4.11.19.4
  • <4.9.20.5
org.wso2.carbon:org.wso2.carbon.security.mgt.ui
  • =<*
  • <5.14.127
org.wso2.carbon.commons:org.wso2.carbon.event.ui
  • =<*
  • <4.7.19.13
org.wso2.carbon:org.wso2.carbon.logging.admin.ui
  • <4.7.19.13
  • =<*
  • <4.7.52.5
  • <4.7.32.10
  • <4.7.24.5
org.wso2.carbon:org.wso2.carbon.mediator.rule.ui
  • =<*
  • <4.7.30.53
org.wso2.carbon:org.wso2.carbon.registry.info.ui
  • <4.7.35.15
  • =<*
  • <4.8.50.1
  • <4.8.3.10
  • <4.7.32.16
  • <4.8.13.9
  • <4.8.32.4
  • <4.8.43.2
  • <4.7.51.8
  • <4.8.36.2
  • <4.7.39.12
org.wso2.carbon.messaging:org.wso2.carbon.andes.ui
  • =<*
  • <3.3.12.3
org.wso2.carbon:org.wso2.carbon.event.simulator.ui
  • <2.2.14.11
  • <2.2.17.5
  • =<*
  • <2.2.11.1
  • <2.2.14.12
  • <2.3.1.4
  • <2.3.5.6
org.wso2.carbon:org.wso2.carbon.registry.search.ui
  • <4.7.35.15
  • <4.8.9.16
  • <4.8.24.6
  • =<*
  • <4.7.33.16
  • <4.8.3.10
  • <4.7.32.16
  • <4.8.12.8
  • <4.8.13.9
  • <4.7.32.18
  • <4.7.24.11
  • <4.7.51.8
  • <4.7.39.12
org.wso2.carbon:org.wso2.carbon.mediator.command.ui
  • =<*
  • <4.7.30.53
org.wso2.carbon:org.wso2.carbon.mediator.throttle.ui
  • =<*
  • <4.7.30.53
org.wso2.carbon:org.wso2.carbon.registry.profiles.ui
  • <4.8.9.16
  • <4.8.24.6
  • =<*
  • <4.8.50.3
  • <4.7.33.16
  • <4.8.12.8
  • <4.8.43.4
  • <4.7.32.18
org.wso2.carbon:org.wso2.carbon.registry.resource.ui
  • <4.8.50.3
  • <4.8.50.1
  • <4.8.12.8
  • <4.7.32.18
  • <4.7.35.15
  • <4.8.24.6
  • <4.8.3.10
  • <4.7.32.16
  • <4.8.13.9
  • <4.8.43.2
  • <4.8.32.4
  • <4.8.36.2
  • <4.7.39.12
  • =<*
  • <4.7.33.16
  • <4.8.43.4
  • <4.8.9.16
  • <4.7.24.11
  • <4.7.51.8
org.wso2.carbon:org.wso2.carbon.email.verification.ui
  • <4.7.19.14
  • =<*
org.wso2.carbon:org.wso2.carbon.registry.relations.ui
  • <4.7.35.15
  • =<*
  • <4.8.50.1
  • <4.8.3.10
  • <4.7.32.16
  • <4.8.13.9
  • <4.8.32.4
  • <4.8.43.2
  • <4.7.24.11
  • <4.7.51.8
  • <4.8.36.2
  • <4.7.39.12
org.wso2.carbon.commons:org.wso2.carbon.ndatasource.ui
  • <4.9.11.2
  • <4.7.19.13
  • <4.7.35.13
  • =<*
  • <4.7.49.7
  • <4.7.52.5
  • <4.9.2.8
  • <4.7.32.10
  • <4.7.24.5
  • <4.9.18.1
org.wso2.carbon:org.wso2.carbon.governance.wsdltool.ui
  • <4.8.33.4
  • <4.8.30.6
  • <4.8.19.8
  • <4.8.34.5
  • =<*
  • <4.8.28.4
  • <4.8.37.4
  • <4.8.21.10
  • <4.8.32.4
  • <4.8.14.4
org.wso2.carbon:org.wso2.carbon.registry.properties.ui
  • <4.8.50.3
  • <4.8.50.1
  • <4.8.12.8
  • <4.7.32.18
  • <4.7.35.15
  • <4.8.24.6
  • <4.8.3.10
  • <4.7.32.16
  • <4.8.13.9
  • <4.8.43.2
  • <4.8.32.4
  • <4.8.36.2
  • <4.7.39.12
  • =<*
  • <4.7.33.16
  • <4.8.43.4
  • <4.8.9.16
  • <4.7.24.11
  • <4.7.51.8
org.wso2.carbon.messaging:org.wso2.carbon.andes.event.ui
  • =<*
  • <3.3.12.3
org.wso2.carbon.governance:org.wso2.carbon.governance.api
  • =<*
  • <4.8.37.4
org.wso2.carbon.registry:org.wso2.carbon.registry.indexing
  • =<*
  • <4.7.24
org.wso2.carbon.governance:org.wso2.carbon.governance.lcm.ui
  • <4.8.30.6
  • <4.8.19.8
  • =<*
  • <4.8.28.4
  • <4.8.21.10
  • <4.8.32.4
  • <4.8.14.4
org.wso2.carbon.business-process:org.wso2.carbon.humantask.ui
  • =<*
  • <4.5.27.10
org.wso2.carbon.mediationorg.wso2.carbon.event.sink.config.ui
  • =<*
  • <4.7.30.53
org.wso2.carbon.governance:org.wso2.carbon.governance.generic.ui
  • <4.8.33.4
  • <4.8.30.6
  • <4.8.19.8
  • <4.8.34.5
  • =<*
  • <4.8.28.4
  • <4.8.37.4
  • <4.8.21.10
  • <4.8.32.4
  • <4.8.14.4
org.wso2.carbon.mediation:org.wso2.carbon.mediation.templates.ui
  • =<*
  • <4.7.30.53
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.mgt.ui
  • <5.17.5.331
  • <5.17.118.22
  • <5.17.5.330
  • <5.18.187.328
  • <5.18.248.31
  • =<*
  • <7.0.78.157
  • <5.18.187.329
  • <5.24.8.26
  • <5.25.705.21
  • <5.25.713.10
  • <5.23.8.210
  • <5.25.92.166
  • <5.25.724.5
  • <5.25.736.1
  • <7.8.23.67
  • <7.8.586.7
org.wso2.carbon.multitenancy:org.wso2.carbon.tenant.sso.redirector.ui
  • =<*
  • <4.8.1.6
org.wso2.carbon.mediation:org.wso2.carbon.business.messaging.hl7.store.ui
  • =<*
  • <4.7.30.53
org.wso2.carbon.analytics-common:org.wso2.carbon.event.template.manager.ui
  • <5.2.26.22
  • <5.3.5.9
  • =<*
  • <5.2.24.10
  • <5.2.57.10
  • <5.2.34.12
  • <5.2.41.7
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.entitlement.ui
  • <5.17.5.331
  • =<*
  • <7.0.78.157
  • <5.18.187.329
  • <5.23.8.210
  • <5.25.92.166
org.wso2.carbon.governance:org.wso2.carbon.governance.custom.lifecycles.checklist.ui
  • <4.8.30.6
  • <4.8.19.8
  • =<*
  • <4.8.28.4
  • <4.8.21.10
  • <4.8.32.4
  • <4.8.14.4
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.user.store.configuration.ui
  • <5.17.5.331
  • <5.17.118.22
  • <5.17.5.330
  • <5.18.187.328
  • =<*
  • <5.18.248.31
  • <7.0.78.157
  • <5.18.187.329
  • <5.24.8.26
  • <5.25.705.21
  • <5.25.713.10
  • <5.23.8.210
  • <5.25.92.166
  • <5.25.724.5
  • <5.25.736.1
  • <7.8.23.67
  • <7.8.586.7
  • <5.14.127.13
Dismissed
(no matching packages found)
Permalink CVE-2026-66457
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
WordPress Events Manager plugin <= 7.4.1 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.

Affected products

events-manager
  • =<7.4.1
Dismissed
(no matching packages found)
Permalink CVE-2026-65556
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.

Affected products

goodbye-captcha
  • =<3.1.43
Dismissed
(no matching packages found)
Permalink CVE-2026-66370
4.8 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Active (A)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): Low (L)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Active (A)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): Low (L)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to retarget a form already on the rendering page and receive whatever the victim submits, including credentials, via the form and formaction attributes on an <input> element in sanitized HTML. HTML's form attribute associates an input with any form on the page by its id even when the input sits outside that form, and formaction on a submit control overrides the owning form's action. Neither attribute receives a scheme check, so an absolute cross-origin URL survives sanitizing. No script executes. The scrubber allows neither form nor button, so the attacker cannot introduce a form of their own and the rendering page must already contain a form carrying an id. This issue affects html_sanitize_ex: from 0.3.1 before 1.5.3.

Affected products

html_sanitize_ex
  • <1.5.3
rrrene/html_sanitize_ex
  • <a1e804ed997e780ea71d14393cf2f701330553a6
Dismissed
(no matching packages found)
Permalink CVE-2026-16316
1.3 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): Unreported (U)
  • Recovery (R): Automatic (A)
  • Vulnerability Response Effort (RE): Moderate (M)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Malformed IEC 61850 Sampled Values frames cause partial denial of service in StationGuard

OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame processing. A specially crafted SV frame can cause the affected process to terminate, disrupting alert processing for Sampled Values traffic. The vulnerability does not affect overall system availability or the processing of other traffic types, and the process is automatically restarted, and the failure is immediately reported to the user.

Affected products

OMICRON StationGuard
  • ==4.00
Dismissed
(no matching packages found)
Permalink CVE-2026-19020
2.1 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
itsourcecode Hospital Management System servicetype.php sql injection

A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /servicetype.php. This manipulation of the argument editid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

Affected products

Hospital Management System
  • ==1.0
Dismissed
(no matching packages found)
Permalink CVE-2026-18997
2.1 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
cosmicstack-labs mercury-agent bg agent.ts Agent.handleBgCommand authorization

A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/agent.ts of the component bg Command Handler. Performing a manipulation results in incorrect authorization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

mercury-agent
  • ==1.1.7
  • ==1.1.5
  • ==1.1.12
  • ==1.1.2
  • ==1.1.8
  • ==1.1.1
  • ==1.1.9
  • ==1.1.11
  • ==1.1.0
  • ==1.1.4
  • ==1.1.6
  • ==1.1.10
  • ==1.1.3