Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
568588
AlmaLinux
4352
Alpaquita
8101
Alpine
3959
Android
3138
BellSoft Hardened Containers
327
Bitnami
6447
Chainguard
4865
CRAN
12
crates.io
1947
Debian
52225
Echo
2816
GHC
3
GIT
77111
GitHub Actions
37
Go
5385
Hackage
27
Hex
44
Julia
332
Linux
23022
Mageia
5799
Maven
6136
MinimOS
10446
npm
214421
NuGet
1517
openEuler
5822
openSUSE
10323
OSS-Fuzz
3761
Packagist
5605
Pub
10
PyPI
17672
Red Hat
18212
Rocky Linux
2623
RubyGems
1849
SUSE
17097
SwiftURL
46
Ubuntu
50105
VSCode
15
Wolfi
2979
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-3cx6-j9j4-54mp
RubyGems/decidim
RubyGems/decidim-core
Decidim's private data exports can lead to data leaks
1 hour ago
Fix available
Severity - 8.2 (High)
GHSA-2qxw-7fmx-gqfm
RubyGems/foreman_kubevirt
foreman_kubevirt disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set
yesterday
Fix available
Severity - 8.1 (High)
GHSA-m3hq-3qj8-c5fm
RubyGems/fog-kubevirt
fog-kubevirt allows remote attacker to perform MITM attack due to disabled certificate validation
yesterday
Fix available
Severity - 8.1 (High)
GHSA-2762-657x-v979
RubyGems/alchemy_cms
AlchemyCMS: Authenticated Remote Code Execution (RCE) via eval injection in ResourcesHelper
21 Jan
Fix available
Severity - 6.4 (Medium)
GHSA-mpwp-4h2m-765c
RubyGems/activejob
Active Job - Object injection security vulnerability
16 Jan
Fix available
Severity - 6.6 (Medium)
GHSA-5qw5-wf2q-f538
RubyGems/activerecord-jdbc-adapter
ActiveRecord-JDBC-Adapter (AR-JDBC) lib/arjdbc/jdbc/adapter.rb sql.gsub() Function SQL Injection
16 Jan
Fix available
Severity - 8.8 (High)
GHSA-w757-4qv9-mghp
RubyGems/openc3
openc3-api Vulnerable to Unauthenticated Remote Code Execution
13 Jan
Fix available
Severity - 10.0 (Critical)
GHSA-3ghg-3787-w2xr
RubyGems/spree_core
Spree API has Unauthenticated IDOR - Guest Address
08 Jan
Fix available
Severity - 7.5 (High)
GHSA-g268-72p7-9j6j
RubyGems/spree_api
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification
08 Jan
Fix available
Severity - 6.5 (Medium)
GHSA-96qw-h329-v5rg
RubyGems/shakapacker
npm/shakapacker
Shakapacker has environment variable leak via EnvironmentPlugin that exposes secrets to client-side bundles
08 Jan
Fix available
Severity - 7.5 (High)
GHSA-g9jg-w8vm-g96v
RubyGems/action_text-trix
npm/trix
Trix has a stored XSS vulnerability through its attachment attribute
31 Dec 2025
Fix available
Severity - 4.6 (Medium)
GHSA-j4pr-3wm6-xx2r
RubyGems/uri
URI Credential Leakage Bypass over CVE-2025-27221
30 Dec 2025
Fix available
Severity - 2.7 (Low)
GHSA-hm5p-x4rq-38w4
RubyGems/httparty
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
23 Dec 2025
Fix available
Severity - 7.8 (High)
MAL-2025-192925
RubyGems/verificator
Malicious code in verificator (RubyGems)
23 Dec 2025
No fix available
MAL-2025-192924
RubyGems/u2f_client
Malicious code in u2f_client (RubyGems)
23 Dec 2025
No fix available
MAL-2025-192922
RubyGems/stripe-server
Malicious code in stripe-server (RubyGems)
23 Dec 2025
No fix available
Load more...
RubyGems - OSV