Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
792002
AlmaLinux
5377
Alpaquita
11989
Alpine
4312
Android
3403
Azure Linux
12016
BellSoft Hardened Containers
581
Bitnami
8517
Chainguard
9594
CleanStart
1988
CRAN
14
crates.io
2587
Debian
61087
Echo
7139
GHC
3
GIT
95697
GitHub Actions
54
Go
8494
Hackage
32
Hex
194
Julia
1129
Linux
26209
Mageia
6075
Maven
6755
MinimOS
97281
npm
223207
NuGet
1829
opam
22
openEuler
7401
openSUSE
13678
OSS-Fuzz
3967
Packagist
6745
Pub
11
PyPI
24072
Red Hat
21509
Rocky Linux
3741
Root
17802
RubyGems
4574
SUSE
21792
SwiftURL
59
TuxCare
5651
Ubuntu
58710
VSCode
20
Wolfi
6685
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-53g2-mvcc-q9x3
RubyGems/action_text-trix
npm/trix
Trix: Stored XSS via HTMLParser attribute injection on paste
3 days ago
Fix available
Severity - 4.6 (Medium)
GHSA-x2f5-4prf-w687
RubyGems/json
Ruby json: JSON generator heap buffer overflow when streaming to an IO
4 days ago
Fix available
Severity - 3.7 (Low)
GHSA-cj75-f6xr-r4g7
RubyGems/rails-html-sanitizer
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
6 days ago
Fix available
Severity - 5.1 (Medium)
GHSA-5qhf-9phg-95m2
RubyGems/loofah
Loofah
`
allowed_uri?
`
does not detect
`
javascript:
`
URIs split by numeric character references without semicolons
6 days ago
Fix available
Severity - 2.3 (Low)
GHSA-9wjq-cp2p-hrgf
RubyGems/loofah
Loofah: SVG
`
href
`
attribute bypasses local-reference restriction
6 days ago
Fix available
Severity - 4.7 (Medium)
GHSA-2x63-gw47-w4mm
RubyGems/websocket-driver
websocket-driver-ruby: Denial of service via malformed Host header
6 days ago
Fix available
Severity - 8.9 (High)
GHSA-8whx-365g-h9vv
RubyGems/loofah
Loofah
`
allowed_uri?
`
does not detect
`
javascript:
`
URIs split by named whitespace character references
21 Jul
Fix available
Severity - 2.3 (Low)
MAL-2026-10914
RubyGems/my_shoaib_gem
Malicious code in my_shoaib_gem (RubyGems)
20 Jul
No fix available
MAL-2026-10913
RubyGems/ike-artifactory-ruby
Malicious code in ike-artifactory-ruby (RubyGems)
20 Jul
No fix available
GHSA-p5f6-rccc-jv98
RubyGems/datadog
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
15 Jul
Fix available
Severity - 7.5 (High)
GHSA-9h85-g7w3-rh49
RubyGems/view_component
ViewComponent: Reused Component Instances Retain Stale Render Context
15 Jul
Fix available
Severity - 6.8 (Medium)
GHSA-97jw-64cj-jc58
RubyGems/view_component
ViewComponent: around_render HTML-Safety Bypass
15 Jul
Fix available
Severity - 8.7 (High)
GHSA-8j3g-f24p-4mpw
RubyGems/websocket-driver
websocket-driver: Memory exhaustion in HTTP header parser
15 Jul
Fix available
Severity - 6.3 (Medium)
GHSA-33ph-fccm-39pj
RubyGems/websocket-driver
websocket-driver: Resource limit bypass via message compression
15 Jul
Fix available
Severity - 6.3 (Medium)
GHSA-ghhp-3qvg-889p
RubyGems/websocket-driver
websocket-driver: Memory exhaustion via abuse of protocol length headers
15 Jul
Fix available
Severity - 6.9 (Medium)
GHSA-2g9c-vf8h-prxx
RubyGems/decidim-core
Decidim: Push subscriptions can be abused for server-side requests
13 Jul
Fix available
Severity - 6.4 (Medium)
Load more...
RubyGems - OSV