Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
CVE-2026-0980
rubyipmi is vulnerable to OS Command Injection through malicious usernames
Malicious code in newrubylogger (RubyGems)
Malicious code in rubocop-vintedmetrics (RubyGems)
Nokogiri does not check the return value from xmlC14NExecute
CVE-2026-25500
Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href
CVE-2026-22860
Rack has a Directory Traversal via Rack:Directory
Malicious code in cucumber_json_schema (RubyGems)
Bitcoinrb Vulnerable to Command injection via RPC
CVE-2026-25765
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
CVE-2026-25758
Unauthenticated Spree Commerce users can access all guest addresses
CVE-2026-25757
Unauthenticated Spree Commerce users can view completed guest orders by Order ID
CVE-2025-65017
Decidim's private data exports can lead to data leaks
CVE-2026-1531
foreman_kubevirt disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set
CVE-2026-1530
fog-kubevirt allows remote attacker to perform MITM attack due to disabled certificate validation
CVE-2026-23885
AlchemyCMS: Authenticated Remote Code Execution (RCE) via eval injection in ResourcesHelper
Active Job - Object injection security vulnerability
ActiveRecord-JDBC-Adapter (AR-JDBC) lib/arjdbc/jdbc/adapter.rb sql.gsub() Function SQL Injection
CVE-2025-68271
openc3-api Vulnerable to Unauthenticated Remote Code Execution
CVE-2026-22589
Spree API has Unauthenticated IDOR - Guest Address
Showing 1 - 20 of 1,000+ results