Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
CVE-2026-44511
katalyst-koi: Session cookies can be replayed after user logout
CVE-2026-44312
CSS Parser: Improper Certificate Validation allows MITM injection of remote CSS content
Nokogiri XSLT transform has a memory leak
Nokogiri CSS selector tokenizer has regular expression backtracking
GraphQL-Ruby's Ruby lexer does not count comment tokens for the purposes of max_query_string_tokens
CVE-2026-42257
net-imap vulnerable to command Injection via "raw" arguments to multiple commands
CVE-2026-42258
net-imap vulnerable to command Injection via unvalidated Symbol inputs
CVE-2026-42256
net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication
CVE-2026-42245
net-imap has quadratic complexity when reading response literals
CVE-2026-42246
net-imap vulnerable to STARTTLS stripping via invalid response timing
CVE-2026-42205
Avo: Broken Access Control Through Unauthorized Execution of Arbitrary Action Classes Across Resources
CVE-2026-41316
ERB has an @_init deserialization guard bypass via def_module / def_method / def_class
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
CVE-2026-42087
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
CVE-2026-42086
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
CVE-2026-42085
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
CVE-2026-42084
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
CVE-2026-41493
yard: Possible arbitrary path traversal and file access via yard server
CVE-2026-27820
Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption
Malicious code in monolith-twirp-pullsd-authorization (RubyGems)
Showing 1 - 20 of 1,000+ results