| Bug | Description | Note |
|---|
| CVE-2016-1584 | In all versions of Unity8 a running but not active application on a la ... | check proper tracking update |
| CVE-2016-20023 | In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users c ... | check |
| CVE-2018-25193 | Mongoose Web Server 6.9 contains a denial of service vulnerability tha ... | check |
| CVE-2019-25338 | DokuWiki 2018-04-22b contains a username enumeration vulnerability in ... | check upstream status |
| CVE-2019-25355 | gSOAP 2.8 contains a directory traversal vulnerability that allows una ... | check upstream status |
| CVE-2020-36968 | M/Monit 3.7.4 contains an authentication vulnerability that allows aut ... | check, unclear upstream status |
| CVE-2020-36969 | M/Monit 3.7.4 contains a privilege escalation vulnerability that allow ... | check, unclear upstream status |
| CVE-2020-37011 | Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability tha ... | check, unclear upstream status. Doesn't reproduce with the version in trixie |
| CVE-2020-37038 | Code Blocks 20.03 contains a denial of service vulnerability that allo ... | check, possibly just DoS of application and unimportant |
| CVE-2020-37040 | Code Blocks 17.12 contains a local buffer overflow vulnerability that ... | check, might be Windows specific issue |
| CVE-2020-37167 | ClamAV versions prior to 0.103.0-rc contain a vulnerability in functio ... | check upstream status |
| CVE-2020-37182 | Redir 3.3 contains a stack overflow vulnerability in the doproxyconnec ... | check details |
| CVE-2021-26381 | Improper system call parameter validation in the Trusted OS may allow ... | check |
| CVE-2021-26410 | Improper syscall input validation in ASP (AMD Secure Processor) may fo ... | check |
| CVE-2021-47793 | Telegram Desktop 2.9.2 contains a denial of service vulnerability that ... | check |
| CVE-2022-23538 | github.com/sylabs/scs-library-client is the Go client for the Singular ... | check details, might as well affect golang-github-apptainer-container-library-client |
| CVE-2022-50942 | Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerab ... | check status upstream |
| CVE-2023-20514 | Improper handling of parameters in the AMD Secure Processor (ASP) coul ... | check |
| CVE-2023-20548 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure ... | check |
| CVE-2023-20601 | Improper input validation within RAS TA Driver can allow a local attac ... | check |
| CVE-2023-26044 | react/http is an event-driven, streaming HTTP client and server implem ... | check, is embedded inicinga-php-thirdparty, icingaweb2-module-reactbundle possibly affected |
| CVE-2023-31313 | An unintended proxy or intermediary in the AMD power management firmwa ... | check |
| CVE-2023-31324 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure ... | check |
| CVE-2023-31364 | Improper handling of direct memory writes in the input-output memory m ... | check |
| CVE-2023-49316 | In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ... | check if affecting ldap-account-manager or unused path |
| CVE-2023-50251 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50252 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50262 | Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Do ... | check sources embedding php-dompdf if affected |
| CVE-2024-4027 | A flaw was found in Undertow. Servlets using a method that calls HttpS ... | check details |
| CVE-2024-21953 | Improper input validation in IOMMU could allow a malicious hypervisor ... | check |
| CVE-2024-22420 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2024-22421 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2024-36310 | Improper input validation in the SMM communications buffer could allow ... | check |
| CVE-2024-36311 | A Time-of-check time-of-use (TOCTOU) race condition in the SMM communi ... | check |
| CVE-2024-36316 | The integer overflow vulnerability within AMD Graphics driver could al ... | check |
| CVE-2024-36324 | Improper input validation in AMD Graphics Driver could allow an attack ... | check |
| CVE-2024-54192 | An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial ... | check |
| CVE-2025-0012 | Improper handling of overlap between the segmented reverse map table ( ... | check |
| CVE-2025-0029 | Improper handling of error condition during host-induced faults can al ... | check |
| CVE-2025-0031 | A use after free in the SEV firmware could allow a malicous hypervisor ... | check |
| CVE-2025-4382 | A flaw was found in systems utilizing LUKS-encrypted disks with GRUB c ... | double check if vulnerability only considered present after grub_is_cli_disabled is introduced |
| CVE-2025-6499 | A vulnerability classified as problematic was found in vstakhov libucl ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-8671 | A mismatch caused by client-triggered server-sent stream resets betwee ... | check, some projects will assign own CVEs and should then be covered under that specific CVE instead |
| CVE-2025-8941 | A flaw was found in linux-pam. The pam_namespace module may improperly ... | check likely RedHat specific incomplete fix for CVE-2025-6020, but asked to pinpoint incomplete fixes |
| CVE-2025-11010 | A vulnerability has been found in vstakhov libucl up to 0.9.2. Affecte ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-11147 | Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vuln ... | clarifying with reporter and Eduard Bloch on the issue. |
| CVE-2025-14905 | A flaw was found in the 389-ds-base server. A heap buffer overflow vul ... | check details |
| CVE-2025-15569 | A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The im ... | check |
| CVE-2025-29939 | Improper access control in secure encrypted virtualization (SEV) could ... | check |
| CVE-2025-29946 | Insufficient or Incomplete Data Removal in Hardware Component in SEV f ... | check |
| CVE-2025-29948 | Improper access control in AMD Secure Encrypted Virtualization (SEV) f ... | check |
| CVE-2025-29952 | Improper Initialization within the AMD Secure Encrypted Virtualization ... | check |
| CVE-2025-45691 | An Arbitrary File Read vulnerability exists in the ImageTextPromptValu ... | check |
| CVE-2025-58064 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ... | check |
| CVE-2025-60796 | phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ... | check, possibly not reported upstream |
| CVE-2025-60797 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60798 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60799 | phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ... | check, possibly not reported upstream |
| CVE-2025-61261 | A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1 ... | check |
| CVE-2025-61982 | An arbitrary code execution vulnerability exists in the Code Stream di ... | check upstream status |
| CVE-2025-65102 | PJSIP is a free and open source multimedia communication library. Prio ... | check, might affect asterisk and ring |
| CVE-2025-65865 | An integer overflow in eProsima Fast-DDS v3.3 allows attackers to caus ... | check https://gist.github.com/lkloliver/7aa48cb9fc7a1dd74cb595212bb69d33, unclear if reported upstream |
| CVE-2025-66578 | xmlseclibs is a library written in PHP for working with XML Encryption ... | check |
| CVE-2025-67108 | eProsima Fast-DDS v3.3 was discovered to contain improper validation f ... | check https://gist.github.com/lkloliver/81b5d5a8328d712dbfd497bf11dbe913, unclear if reported upstream |
| CVE-2025-69653 | A crafted JavaScript input can trigger an internal assertion failure i ... | check |
| CVE-2025-69654 | A crafted JavaScript input executed with the QuickJS release 2025-09-1 ... | check |
| CVE-2025-69969 | A lack of authentication and authorization mechanisms in the Bluetooth ... | check |
| CVE-2026-0708 | | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2026-0847 | A vulnerability in NLTK versions up to and including 3.9.2 allows arbi ... | check details, report not public so far |
| CVE-2026-1703 | When pip is installing and extracting a maliciously crafted wheel arch ... | check as well pipenv |
| CVE-2026-3054 | A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impa ... | check, check upstream details |
| CVE-2026-3351 | Improper authorization in the API endpoint GET /1.0/certificates in Ca ... | check |
| CVE-2026-22866 | Ethereum Name Service (ENS) is a distributed, open, and extensible nam ... | check |
| CVE-2026-23925 | An authenticated Zabbix user (User role) with template/host write perm ... | check |
| CVE-2026-24732 | Files or Directories Accessible to External Parties, Incorrect Permiss ... | check |
| CVE-2026-25048 | xgrammar is an open-source library for efficient, flexible, and portab ... | check |
| CVE-2026-25701 | An Insecure Temporary File vulnerability in openSUSE sdbootutil allows ... | check |
| CVE-2026-25702 | A Improper Access Control vulnerability in the kernel of SUSE SUSE Lin ... | check |
| CVE-2026-26200 | HDF5 is software for managing data. Prior to version 1.14.4-2, an atta ... | check details, said to be fixed in 1.14.4-2 upstream |
| CVE-2026-27586 | Caddy is an extensible server platform that uses TLS by default. Prior ... | check, introducing version |
| CVE-2026-27641 | Flask-Reuploaded provides file uploads for Flask. A critical path trav ... | check |
| CVE-2026-27704 | The Dart and Flutter SDKs provide software development kits for the Da ... | check |
| CVE-2026-27738 | The Angular SSR is a server-rise rendering tool for Angular applicatio ... | check |
| CVE-2026-27739 | The Angular SSR is a server-rise rendering tool for Angular applicatio ... | check |
| CVE-2026-27970 | Angular is a development platform for building mobile and desktop web ... | check status for older versions |
| CVE-2026-28207 | Zen C is a systems programming language that compiles to human-readabl ... | check |
| CVE-2026-28343 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ... | check |
| CVE-2026-28410 | The Graph is an indexing protocol for querying networks like Ethereum, ... | check |
| CVE-2026-29022 | dr_libs version 0.14.4 and earlier (fixed in commit 8a7258c) contain a ... | qtads, dosbox-x, roc-toolkit, octave-ltfat, faudio bundle a copy, check security impact |
| CVE-2026-29790 | dbt-common is the shared common utilities for dbt-core and adapter imp ... | check |