Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
CVE-2026-73428
Trix: Stored XSS via HTMLParser attribute injection on paste
CVE-2026-54696
Ruby json: JSON generator heap buffer overflow when streaming to an IO
CVE-2026-73648
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
CVE-2026-73490
Loofah: SVG `href` attribute bypasses local-reference restriction
CVE-2026-61666
websocket-driver-ruby: Denial of service via malformed Host header
CVE-2026-73491
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
Malicious code in my_shoaib_gem (RubyGems)
Malicious code in ike-artifactory-ruby (RubyGems)
CVE-2026-50276
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-54497
ViewComponent: Reused Component Instances Retain Stale Render Context
CVE-2026-54498
ViewComponent: around_render HTML-Safety Bypass
CVE-2026-54465
websocket-driver: Memory exhaustion in HTTP header parser
CVE-2026-54464
websocket-driver: Resource limit bypass via message compression
CVE-2026-54463
websocket-driver: Memory exhaustion via abuse of protocol length headers
CVE-2026-45573
Decidim: Push subscriptions can be abused for server-side requests
CVE-2026-45572
Decidim: HTML content blocks allow stored script execution
CVE-2026-45415
Decidim: CSV census record endpoints improper authorization
CVE-2026-45414
Decidim: JWT-backed authentication can be replayed across organizations
CVE-2026-45378
Decidim: Verification documents can be downloaded through reusable links
Showing 1 - 20 of 1,000+ results