Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
CVE-2025-65017
Decidim's private data exports can lead to data leaks
CVE-2026-1531
foreman_kubevirt disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set
CVE-2026-1530
fog-kubevirt allows remote attacker to perform MITM attack due to disabled certificate validation
CVE-2026-23885
AlchemyCMS: Authenticated Remote Code Execution (RCE) via eval injection in ResourcesHelper
Active Job - Object injection security vulnerability
ActiveRecord-JDBC-Adapter (AR-JDBC) lib/arjdbc/jdbc/adapter.rb sql.gsub() Function SQL Injection
CVE-2025-68271
openc3-api Vulnerable to Unauthenticated Remote Code Execution
CVE-2026-22589
Spree API has Unauthenticated IDOR - Guest Address
CVE-2026-22588
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification
Shakapacker has environment variable leak via EnvironmentPlugin that exposes secrets to client-side bundles
Trix has a stored XSS vulnerability through its attachment attribute
CVE-2025-61594
URI Credential Leakage Bypass over CVE-2025-27221
CVE-2025-68696
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
Malicious code in verificator (RubyGems)
Malicious code in u2f_client (RubyGems)
Malicious code in stripe-server (RubyGems)
Malicious code in test_gem_978483406ebb19126a2e8c001649a4eb (RubyGems)
Malicious code in stripe-rubocop (RubyGems)
Malicious code in sq-samsa (RubyGems)
Malicious code in stripe-backup (RubyGems)
Showing 1 - 20 of 1,000+ results