| Bug | Description | Note |
|---|
| CVE-2021-4472 | The mistral-dashboard plugin for openstack has a local file inclusion ... | check |
| CVE-2022-23538 | github.com/sylabs/scs-library-client is the Go client for the Singular ... | check details, might as well affect golang-github-apptainer-container-library-client |
| CVE-2023-26044 | react/http is an event-driven, streaming HTTP client and server implem ... | check, is embedded inicinga-php-thirdparty, icingaweb2-module-reactbundle possibly affected |
| CVE-2023-49316 | In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ... | check if affecting ldap-account-manager or unused path |
| CVE-2023-50251 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50252 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50262 | Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Do ... | check sources embedding php-dompdf if affected |
| CVE-2024-21922 | A DLL hijacking vulnerability in AMD StoreMI\u2122 could allow an atta ... | check |
| CVE-2024-21923 | Incorrect default permissions in AMD StoreMI\u2122 could allow an atta ... | check |
| CVE-2024-22420 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2024-22421 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2025-0003 | Inadequate lock protection within Xilinx Run time may allow a local at ... | check |
| CVE-2025-0005 | Improper input validation within the XOCL driver may allow a local att ... | check |
| CVE-2025-0007 | Insufficient validation within Xilinx Run Time framework could allow a ... | check |
| CVE-2025-2486 | The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI S ... | check |
| CVE-2025-4382 | A flaw was found in systems utilizing LUKS-encrypted disks with GRUB c ... | double check if vulnerability only considered present after grub_is_cli_disabled is introduced |
| CVE-2025-4690 | A regular expression used by AngularJS' linky https://docs.angularjs.o ... | check |
| CVE-2025-4953 | A flaw was found in Podman. In a Containerfile or Podman, data written ... | check details |
| CVE-2025-6499 | A vulnerability classified as problematic was found in vstakhov libucl ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-8671 | A mismatch caused by client-triggered server-sent stream resets betwee ... | check, some projects will assign own CVEs and should then be covered under that specific CVE instead |
| CVE-2025-8941 | A flaw was found in linux-pam. The pam_namespace module may improperly ... | check if RedHat specific incomplete fix for CVE-2025-6020 |
| CVE-2025-11010 | A vulnerability has been found in vstakhov libucl up to 0.9.2. Affecte ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-11147 | Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vuln ... | clarifying with reporter and Eduard Bloch on the issue. |
| CVE-2025-12383 | In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can ca ... | check |
| CVE-2025-13502 | A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allow ... | check |
| CVE-2025-13601 | A heap-based buffer overflow problem was found in glib through an inco ... | check |
| CVE-2025-45311 | Insecure permissions in fail2ban-client v0.11.2 allows attackers with ... | check |
| CVE-2025-48507 | The security state of the calling processor into Arm\xae Trusted Firmw ... | check |
| CVE-2025-52538 | Improper input validation within the XOCL driver may allow a local att ... | check |
| CVE-2025-52539 | A buffer overflow with Xilinx Run Time Environment may allow a local a ... | check |
| CVE-2025-54515 | The Secure Flag passed to Versal\u2122 Adaptive SoC\u2019s Arm\xae Tru ... | check |
| CVE-2025-58064 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ... | check |
| CVE-2025-59390 | Apache Druid\u2019s Kerberos authenticator uses a weak fallback secret ... | check |
| CVE-2025-60796 | phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ... | check, possibly not reported upstream |
| CVE-2025-60797 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60798 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60799 | phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ... | check, possibly not reported upstream |
| CVE-2025-61261 | A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1 ... | check |
| CVE-2025-62728 | SQL injection vulnerability in Hive Metastore Server (HMS) when proces ... | check |
| CVE-2025-65102 | PJSIP is a free and open source multimedia communication library. Prio ... | check, might affect asterisk and ring |
| CVE-2025-65502 | Null pointer dereference in add_ca_certs() in Cesanta Mongoose before ... | check |