Bugs with TODO items

Hide "check" TODOs

BugDescriptionNote
CVE-2016-1584In all versions of Unity8 a running but not active application on a la ...check proper tracking update
CVE-2016-20023In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users c ...check
CVE-2020-36939Cassandra Web 0.5.0 contains a directory traversal vulnerability that ...check
CVE-2020-36968M/Monit 3.7.4 contains an authentication vulnerability that allows aut ...check, unclear upstream status
CVE-2020-36969M/Monit 3.7.4 contains a privilege escalation vulnerability that allow ...check, unclear upstream status
CVE-2020-37011Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability tha ...check, unclear upstream status
CVE-2020-37038Code Blocks 20.03 contains a denial of service vulnerability that allo ...check, possibly just DoS of application and unimportant
CVE-2020-37040Code Blocks 17.12 contains a local buffer overflow vulnerability that ...check, might be Windows specific issue
CVE-2021-47793Telegram Desktop 2.9.2 contains a denial of service vulnerability that ...check
CVE-2021-47865ProFTPD 1.3.7a contains a denial of service vulnerability that allows ...check
CVE-2022-23538github.com/sylabs/scs-library-client is the Go client for the Singular ...check details, might as well affect golang-github-apptainer-container-library-client
CVE-2022-50942Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerab ...check status upstream
CVE-2023-26044react/http is an event-driven, streaming HTTP client and server implem ...check, is embedded inicinga-php-thirdparty, icingaweb2-module-reactbundle possibly affected
CVE-2023-49316In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ...check if affecting ldap-account-manager or unused path
CVE-2023-50251php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked
CVE-2023-50252php-svg-lib is an SVG file parsing / rendering library. Prior to versi ...check, other packages are embedding the library: civicrm, icinga-php-thirdparty and icingaweb2 to be checked
CVE-2023-50262Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Do ...check sources embedding php-dompdf if affected
CVE-2024-4027A flaw was found in Undertow. Servlets using a method that calls HttpS ...check details
CVE-2024-22420JupyterLab is an extensible environment for interactive and reproducib ...check completeness, src:jupyter-notebook?
CVE-2024-22421JupyterLab is an extensible environment for interactive and reproducib ...check completeness, src:jupyter-notebook?
CVE-2025-4382A flaw was found in systems utilizing LUKS-encrypted disks with GRUB c ...double check if vulnerability only considered present after grub_is_cli_disabled is introduced
CVE-2025-6499A vulnerability classified as problematic was found in vstakhov libucl ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2025-8671A mismatch caused by client-triggered server-sent stream resets betwee ...check, some projects will assign own CVEs and should then be covered under that specific CVE instead
CVE-2025-8941A flaw was found in linux-pam. The pam_namespace module may improperly ...check likely RedHat specific incomplete fix for CVE-2025-6020, but asked to pinpoint incomplete fixes
CVE-2025-11010A vulnerability has been found in vstakhov libucl up to 0.9.2. Affecte ...check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2025-11147Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vuln ...clarifying with reporter and Eduard Bloch on the issue.
CVE-2025-50537Stack overflow vulnerability in eslint before 9.26.0 when serializing ...check details
CVE-2025-55095The function _ux_host_class_storage_media_mount()is responsible for mo ...check
CVE-2025-55102A denial-of-service vulnerability exists in the NetX IPv6 component fu ...check
CVE-2025-58064CKEditor 5 is a modern JavaScript rich-text editor with an MVC archite ...check
CVE-2025-60796phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting ( ...check, possibly not reported upstream
CVE-2025-60797phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...check, possibly not reported upstream
CVE-2025-60798phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability i ...check, possibly not reported upstream
CVE-2025-60799phpPgAdmin 7.13.0 and earlier contains an incorrect access control vul ...check, possibly not reported upstream
CVE-2025-61261A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1 ...check
CVE-2025-65102PJSIP is a free and open source multimedia communication library. Prio ...check, might affect asterisk and ring
CVE-2025-65865An integer overflow in eProsima Fast-DDS v3.3 allows attackers to caus ...check https://gist.github.com/lkloliver/7aa48cb9fc7a1dd74cb595212bb69d33, unclear if reported upstream
CVE-2025-66412Angular is a development platform for building mobile and desktop web ...check, might not impact the 1.x versions of Angular
CVE-2025-66433HTCondor Access Point before 25.3.1 allows an authenticated user to im ...check, upstream advisory claims only affects 24.7.3 and above but unclear if only listing supported versions, and no details on fix
CVE-2025-66567The ruby-saml library is for implementing the client side of a SAML au ...check
CVE-2025-66568The ruby-saml library implements the client side of an SAML authorizat ...check
CVE-2025-66578xmlseclibs is a library written in PHP for working with XML Encryption ...check
CVE-2025-67108eProsima Fast-DDS v3.3 was discovered to contain improper validation f ...check https://gist.github.com/lkloliver/81b5d5a8328d712dbfd497bf11dbe913, unclear if reported upstream
CVE-2026-0648The vulnerability stems from an incorrect error-checking logic in the ...check
CVE-2026-0671Improper Neutralization of Input During Web Page Generation (XSS or 'C ...check
CVE-2026-0708check if impacts security wise rspamd, which embeds libucl and uses it a compile time
CVE-2026-1699In the Eclipse Theia Website repository, the GitHub Actions workflow . ...check
CVE-2026-1703When pip is installing and extracting a maliciously crafted wheel arch ...check as well pipenv
CVE-2026-23864Multiple denial of service vulnerabilities exist in React Server Compo ...check
CVE-2026-24480QGIS is a free, open source, cross platform geographical information s ...check
CVE-2026-24491check upstream details
CVE-2026-24675check upstream details
CVE-2026-24676check upstream details
CVE-2026-24677check upstream details
CVE-2026-24678check upstream details
CVE-2026-24679check upstream details
CVE-2026-24680check upstream details
CVE-2026-24681check upstream details
CVE-2026-24682check upstream details
CVE-2026-24683check upstream details
CVE-2026-24684check upstream details
CVE-2026-24842node-tar,a Tar for Node.js, contains a vulnerability in versions prior ...check, possibly introduced with fix for CVE-2026-23745, reached out to maintainers

Search for package or bug name: Reporting problems