| Bug | Description | Note |
|---|
| CVE-2016-1584 | In all versions of Unity8 a running but not active application on a la ... | check proper tracking update |
| CVE-2016-20023 | In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users c ... | check |
| CVE-2018-25157 | Phraseanet 4.0.3 contains a stored cross-site scripting vulnerability ... | check |
| CVE-2019-25306 | BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vuln ... | check |
| CVE-2019-25307 | WorkgroupMail 7.5.1 contains an unquoted service path vulnerability in ... | check |
| CVE-2019-25308 | Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in ... | check |
| CVE-2019-25309 | Zilab Remote Console Server 3.2.9 contains an unquoted service path vu ... | check |
| CVE-2019-25310 | ActiveFax Server 6.92 Build 0316 contains an unquoted service path vul ... | check |
| CVE-2019-25311 | thesystem version 1.0 contains a persistent cross-site scripting vulne ... | check |
| CVE-2019-25312 | InoERP 0.7.2 contains a persistent cross-site scripting vulnerability ... | check |
| CVE-2019-25313 | FlexNet Publisher 11.12.1 contains a cross-site request forgery vulner ... | check |
| CVE-2019-25314 | Duplicate-Post WordPress Plugin 3.2.3 contains a persistent cross-site ... | check |
| CVE-2019-25315 | WordPress Server Log Viewer 1.0 contains a persistent cross-site scrip ... | check |
| CVE-2019-25316 | GOautodial 4.0 contains a persistent cross-site scripting vulnerabilit ... | check |
| CVE-2019-25317 | Kimai 2 contains a persistent cross-site scripting vulnerability that ... | check |
| CVE-2020-36968 | M/Monit 3.7.4 contains an authentication vulnerability that allows aut ... | check, unclear upstream status |
| CVE-2020-36969 | M/Monit 3.7.4 contains a privilege escalation vulnerability that allow ... | check, unclear upstream status |
| CVE-2020-37011 | Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability tha ... | check, unclear upstream status. Doesn't reproduce with the version in trixie |
| CVE-2020-37038 | Code Blocks 20.03 contains a denial of service vulnerability that allo ... | check, possibly just DoS of application and unimportant |
| CVE-2020-37040 | Code Blocks 17.12 contains a local buffer overflow vulnerability that ... | check, might be Windows specific issue |
| CVE-2020-37104 | ASTPP 4.0.1 contains an information disclosure vulnerability that allo ... | check |
| CVE-2020-37153 | ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scr ... | check |
| CVE-2020-37156 | BloodX 1.0 contains an authentication bypass vulnerability in login.ph ... | check |
| CVE-2020-37158 | AVideo Platform 8.1 contains a cross-site request forgery vulnerabilit ... | check |
| CVE-2020-37172 | AVideo Platform 8.1 contains a cross-site request forgery vulnerabilit ... | check |
| CVE-2020-37173 | AVideo Platform 8.1 contains an information disclosure vulnerability t ... | check |
| CVE-2020-37175 | P2PWIFICAM2 for iOS 10.4.1 contains a denial of service vulnerability ... | check |
| CVE-2020-37176 | Torrent 3GP Converter 1.51 contains a stack overflow vulnerability tha ... | check |
| CVE-2020-37177 | BOOTP Turbo 2.0 contains a denial of service vulnerability that allows ... | check |
| CVE-2020-37178 | KeePass Password Safe versions before 2.44 contain a denial of service ... | check |
| CVE-2020-37179 | APKF Product Key Finder 2.5.8.0 contains a denial of service vulnerabi ... | check |
| CVE-2020-37180 | GTalk Password Finder 2.2.1 contains a denial of service vulnerability ... | check |
| CVE-2020-37181 | Torrent FLV Converter 1.51 Build 117 contains a stack overflow vulnera ... | check |
| CVE-2020-37182 | Redir 3.3 contains a stack overflow vulnerability in the doproxyconnec ... | check |
| CVE-2020-37183 | Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 contains a stack over ... | check |
| CVE-2020-37184 | Allok Video Converter 4.6.1217 contains a stack overflow vulnerability ... | check |
| CVE-2020-37185 | Backup Key Recovery 2.2.5 contains a denial of service vulnerability t ... | check |
| CVE-2020-37186 | Chevereto 3.13.4 Core contains a remote code execution vulnerability t ... | check |
| CVE-2020-37187 | SpotDialup 1.6.7 contains a denial of service vulnerability in the reg ... | check |
| CVE-2020-37188 | SpotOutlook 1.2.6 contains a denial of service vulnerability in the re ... | check |
| CVE-2020-37189 | TaskCanvas 1.4.0 contains a denial of service vulnerability in the reg ... | check |
| CVE-2020-37190 | Top Password Firefox Password Recovery 2.8 contains a denial of servic ... | check |
| CVE-2020-37191 | Top Password Software Dialup Password Recovery 1.30 contains a denial ... | check |
| CVE-2020-37192 | MSN Password Recovery 1.30 contains an XML external entity injection v ... | check |
| CVE-2020-37193 | ZIP Password Recovery 2.30 contains a denial of service vulnerability ... | check |
| CVE-2020-37194 | Backup Key Recovery 2.2.5 contains a denial of service vulnerability t ... | check |
| CVE-2020-37195 | BlueAuditor 1.7.2.0 contains a denial of service vulnerability in the ... | check |
| CVE-2020-37196 | Dnss Domain Name Search Software contains a denial of service vulnerab ... | check |
| CVE-2020-37197 | Dnss Domain Name Search Software contains a denial of service vulnerab ... | check |
| CVE-2020-37198 | Duplicate Cleaner Pro 4.1.3 contains a denial of service vulnerability ... | check |
| CVE-2020-37199 | NBMonitor 1.6.6.0 contains a denial of service vulnerability in its re ... | check |
| CVE-2020-37200 | NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in th ... | check |
| CVE-2020-37201 | NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in th ... | check |
| CVE-2020-37202 | NetworkSleuth 3.0.0.0 contains a denial of service vulnerability that ... | check |
| CVE-2020-37203 | Office Product Key Finder 1.5.4 contains a denial of service vulnerabi ... | check |
| CVE-2020-37204 | RemShutdown 2.9.0.0 contains a denial of service vulnerability in its ... | check |
| CVE-2020-37205 | RemShutdown 2.9.0.0 contains a denial of service vulnerability that al ... | check |
| CVE-2020-37206 | ShareAlarmPro contains a denial of service vulnerability that allows a ... | check |
| CVE-2020-37207 | SpotDialup 1.6.7 contains a denial of service vulnerability in the reg ... | check |
| CVE-2020-37208 | SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the regist ... | check |
| CVE-2020-37209 | SpotFTP 3.0.0.0 contains a denial of service vulnerability in the regi ... | check |
| CVE-2020-37210 | SpotIE 2.9.5 contains a denial of service vulnerability in the registr ... | check |
| CVE-2020-37211 | SpotIM 2.2 contains a denial of service vulnerability that allows atta ... | check |
| CVE-2020-37212 | SpotMSN 2.4.6 contains a denial of service vulnerability in the regist ... | check |
| CVE-2020-37213 | TextCrawler Pro 3.1.1 contains a denial of service vulnerability that ... | check |
| CVE-2020-37214 | Voyager 1.3.0 contains a directory traversal vulnerability that allows ... | check |
| CVE-2020-37215 | MSN Password Recovery version 1.30 contains a denial of service vulner ... | check |
| CVE-2021-26381 | Improper system call parameter validation in the Trusted OS may allow ... | check |
| CVE-2021-26410 | Improper syscall input validation in ASP (AMD Secure Processor) may fo ... | check |
| CVE-2021-47793 | Telegram Desktop 2.9.2 contains a denial of service vulnerability that ... | check |
| CVE-2022-23538 | github.com/sylabs/scs-library-client is the Go client for the Singular ... | check details, might as well affect golang-github-apptainer-container-library-client |
| CVE-2022-50942 | Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerab ... | check status upstream |
| CVE-2023-20514 | Improper handling of parameters in the AMD Secure Processor (ASP) coul ... | check |
| CVE-2023-20548 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure ... | check |
| CVE-2023-26044 | react/http is an event-driven, streaming HTTP client and server implem ... | check, is embedded inicinga-php-thirdparty, icingaweb2-module-reactbundle possibly affected |
| CVE-2023-31324 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure ... | check |
| CVE-2023-49316 | In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ... | check if affecting ldap-account-manager or unused path |
| CVE-2023-50251 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50252 | php-svg-lib is an SVG file parsing / rendering library. Prior to versi ... | check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked |
| CVE-2023-50262 | Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Do ... | check sources embedding php-dompdf if affected |
| CVE-2024-4027 | A flaw was found in Undertow. Servlets using a method that calls HttpS ... | check details |
| CVE-2024-21953 | Improper input validation in IOMMU could allow a malicious hypervisor ... | check |
| CVE-2024-22420 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2024-22421 | JupyterLab is an extensible environment for interactive and reproducib ... | check completeness, src:jupyter-notebook? |
| CVE-2024-26477 | An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitiv ... | check |
| CVE-2024-26478 | An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitiv ... | check |
| CVE-2024-26479 | An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitiv ... | check |
| CVE-2024-26480 | An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitiv ... | check |
| CVE-2024-36310 | Improper input validation in the SMM communications buffer could allow ... | check |
| CVE-2024-36311 | A Time-of-check time-of-use (TOCTOU) race condition in the SMM communi ... | check |
| CVE-2024-36316 | The integer overflow vulnerability within AMD Graphics driver could al ... | check |
| CVE-2024-36320 | Integer Overflow within atihdwt6.sys can allow a local attacker to cau ... | check |
| CVE-2024-36324 | Improper input validation in AMD Graphics Driver could allow an attack ... | check |
| CVE-2024-50617 | Vulnerabilities in the File Download and Get File handler components i ... | check |
| CVE-2024-50618 | A Use of Single-factor Authentication vulnerability in the Authenticat ... | check |
| CVE-2024-50619 | Vulnerabilities in the My Account and User Management components in CI ... | check |
| CVE-2024-50620 | Unrestricted Upload of File with Dangerous Type vulnerabilities exist ... | check |
| CVE-2024-54192 | An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial ... | check |
| CVE-2025-0012 | Improper handling of overlap between the segmented reverse map table ( ... | check |
| CVE-2025-0029 | Improper handling of error condition during host-induced faults can al ... | check |
| CVE-2025-0031 | A use after free in the SEV firmware could allow a malicous hypervisor ... | check |
| CVE-2025-4382 | A flaw was found in systems utilizing LUKS-encrypted disks with GRUB c ... | double check if vulnerability only considered present after grub_is_cli_disabled is introduced |
| CVE-2025-6499 | A vulnerability classified as problematic was found in vstakhov libucl ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-8671 | A mismatch caused by client-triggered server-sent stream resets betwee ... | check, some projects will assign own CVEs and should then be covered under that specific CVE instead |
| CVE-2025-8941 | A flaw was found in linux-pam. The pam_namespace module may improperly ... | check likely RedHat specific incomplete fix for CVE-2025-6020, but asked to pinpoint incomplete fixes |
| CVE-2025-10174 | Cleartext Transmission of Sensitive Information vulnerability in Pan S ... | check |
| CVE-2025-10913 | Improper Neutralization of Input During Web Page Generation (XSS or 'C ... | check |
| CVE-2025-11010 | A vulnerability has been found in vstakhov libucl up to 0.9.2. Affecte ... | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2025-11147 | Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vuln ... | clarifying with reporter and Eduard Bloch on the issue. |
| CVE-2025-12059 | Insertion of Sensitive Information into Externally-Accessible File or ... | check |
| CVE-2025-13648 | An attacker with access to the web application ZeusWeb of the provider ... | check |
| CVE-2025-13649 | An attacker with access to the web applicationZeusWeb of the provider ... | check |
| CVE-2025-13650 | An attacker with access to the web application ZeusWeb of the provider ... | check |
| CVE-2025-13651 | Exposure of Sensitive System Information to an Unauthorized Actor vuln ... | check |
| CVE-2025-15569 | A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The im ... | check |
| CVE-2025-15577 | An unauthenticated attacker can exploit this vulnerability by manipula ... | check |
| CVE-2025-22453 | Improper input validation for some Server Firmware Update Utility(SysF ... | check |
| CVE-2025-22849 | Incorrect default permissions for the Intel(R) Optane(TM) PMem managem ... | check |
| CVE-2025-22885 | Improper buffer restrictions in the firmware for the TDX Module may al ... | check |
| CVE-2025-24851 | Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet C ... | check |
| CVE-2025-25058 | Improper initialization for some ESXi kernel mode driver for the Intel ... | check |
| CVE-2025-25210 | Improper input validation for some Server Firmware Update Utility(SysF ... | check |
| CVE-2025-27243 | Out-of-bounds write in the firmware for some Intel(R) Ethernet Control ... | check |
| CVE-2025-27535 | Exposed ioctl with insufficient access control in the firmware for som ... | check |
| CVE-2025-27560 | Loop with unreachable exit condition ('infinite loop') for some Intel( ... | check |
| CVE-2025-27572 | Exposure of sensitive information during transient execution for some ... | check |
| CVE-2025-27708 | Out-of-bounds read in the firmware for some Intel(R) Converged Securit ... | check |
| CVE-2025-27940 | Out-of-bounds read for some TDX Module before version tdx1.5 within Ri ... | check |
| CVE-2025-29939 | Improper access control in secure encrypted virtualization (SEV) could ... | check |
| CVE-2025-29946 | Insufficient or Incomplete Data Removal in Hardware Component in SEV f ... | check |
| CVE-2025-29948 | Improper access control in AMD Secure Encrypted Virtualization (SEV) f ... | check |
| CVE-2025-29949 | Insufficient input parameter sanitization in AMD Secure Processor (ASP ... | check |
| CVE-2025-29950 | Improper input validation in system management mode (SMM) could allow ... | check |
| CVE-2025-29951 | A buffer overflow in the AMD Secure Processor (ASP) bootloader could a ... | check |
| CVE-2025-29952 | Improper Initialization within the AMD Secure Encrypted Virtualization ... | check |
| CVE-2025-30508 | Improper authorization in the Intel(R) Quick Assist Technology for som ... | check |
| CVE-2025-30513 | Race condition for some TDX Module within Ring 0: Hypervisor may allow ... | check |
| CVE-2025-31655 | Incorrect default permissions for some Intel(R) Battery Life Diagnosti ... | check |
| CVE-2025-31944 | Race condition for some TDX Module before version tdx1.5 within Ring 0 ... | check |
| CVE-2025-32003 | Out-of-bounds read in the firmware for some 100GbE Intel(R) Ethernet N ... | check |
| CVE-2025-32007 | Out-of-bounds read for some TDX before version tdx module 1.5.24 withi ... | check |
| CVE-2025-32008 | Out-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) ... | check |
| CVE-2025-32092 | Insecure inherited permissions for some Intel(R) Graphics Software bef ... | check |
| CVE-2025-32453 | Incorrect default permissions for some Intel(R) Graphics Driver softwa ... | check |
| CVE-2025-32467 | Use of uninitialized variable for some TDX Module before version tdx1. ... | check |
| CVE-2025-32739 | Improper conditions check in some firmware for some Intel(R) Graphics ... | check |
| CVE-2025-48503 | A DLL hijacking vulnerability in the AMD Software Installer could allo ... | check |
| CVE-2025-48508 | Improper Hardware reset flow logic in the GPU GFX Hardware IP block co ... | check |
| CVE-2025-48518 | Improper input validation in AMD Graphics Driver could allow a local a ... | check |
| CVE-2025-52541 | A DLL hijacking vulnerability in Vivado could allow a local attacker t ... | check |
| CVE-2025-58064 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ... | check |
| CVE-2025-60796 | phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ... | check, possibly not reported upstream |
| CVE-2025-60797 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60798 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ... | check, possibly not reported upstream |
| CVE-2025-60799 | phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ... | check, possibly not reported upstream |
| CVE-2025-61261 | A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1 ... | check |
| CVE-2025-61969 | Incorrect permission assignment in AMD \xb5Prof may allow a local user ... | check |
| CVE-2025-64075 | A path traversal vulnerability in the check_token function of Shenzhen ... | check |
| CVE-2025-65102 | PJSIP is a free and open source multimedia communication library. Prio ... | check, might affect asterisk and ring |
| CVE-2025-65127 | A lack of session validation in the web API component of Shenzhen Zhib ... | check |
| CVE-2025-65128 | A missing authentication mechanism in the web management API component ... | check |
| CVE-2025-65480 | An issue was discovered in Pacom Unison Client 5.13.1. Authenticated u ... | check |
| CVE-2025-65865 | An integer overflow in eProsima Fast-DDS v3.3 allows attackers to caus ... | check https://gist.github.com/lkloliver/7aa48cb9fc7a1dd74cb595212bb69d33, unclear if reported upstream |
| CVE-2025-66412 | Angular is a development platform for building mobile and desktop web ... | check, might not impact the 1.x versions of Angular |
| CVE-2025-66567 | The ruby-saml library is for implementing the client side of a SAML au ... | check |
| CVE-2025-66568 | The ruby-saml library implements the client side of an SAML authorizat ... | check |
| CVE-2025-66578 | xmlseclibs is a library written in PHP for working with XML Encryption ... | check |
| CVE-2025-67108 | eProsima Fast-DDS v3.3 was discovered to contain improper validation f ... | check https://gist.github.com/lkloliver/81b5d5a8328d712dbfd497bf11dbe913, unclear if reported upstream |
| CVE-2025-69871 | A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and e ... | check |
| CVE-2025-69872 | DiskCache (python-diskcache) through 5.6.3 uses Python pickle for seri ... | check, check upstream (report) status |
| CVE-2025-69873 | ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerab ... | check, verify upstream (report) status |
| CVE-2026-0671 | Improper Neutralization of Input During Web Page Generation (XSS or 'C ... | check |
| CVE-2026-0708 | | check if impacts security wise rspamd, which embeds libucl and uses it a compile time |
| CVE-2026-1703 | When pip is installing and extracting a maliciously crafted wheel arch ... | check as well pipenv |
| CVE-2026-2327 | Versions of the package markdown-it from 13.0.0 and before 14.1.1 are ... | check |
| CVE-2026-2391 | ### Summary The `arrayLimit` option in qs does not enforce limits for ... | check |
| CVE-2026-25924 | Kanboard is project management software focused on Kanban methodology. ... | check |
| CVE-2026-25990 | Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, n ou ... | check where introduced, GHSA-cfh3-3jmp-rvhc claims only >= 10.3.0 are affected |
| CVE-2026-25994 | PJSIP is a free and open source multimedia communication library writt ... | check |
| CVE-2026-26014 | Pion DTLS is a Go implementation of Datagram Transport Layer Security. ... | check |
| CVE-2026-26021 | set-in provides the set value of nested associative structure given ar ... | check |