Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
629401
AlmaLinux
4656
Alpaquita
8853
Alpine
4049
Android
3261
Azure Linux
12016
BellSoft Hardened Containers
432
Bitnami
6983
Chainguard
5729
CleanStart
791
CRAN
14
crates.io
2232
Debian
54522
Echo
3188
GHC
3
GIT
81483
GitHub Actions
49
Go
6580
Hackage
30
Hex
57
Julia
513
Linux
15361
Mageia
5877
Maven
6325
MinimOS
26803
npm
217500
NuGet
1659
opam
12
openEuler
6386
openSUSE
12552
OSS-Fuzz
3835
Packagist
6082
Pub
11
PyPI
18695
Red Hat
19421
Rocky Linux
2948
Root
11968
RubyGems
1938
SUSE
20483
SwiftURL
50
Ubuntu
52357
VSCode
18
Wolfi
3679
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-2wvh-87g2-89hr
RubyGems/openc3
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
1 hour ago
Fix available
Severity - 9.6 (Critical)
GHSA-v529-vhwc-wfc5
RubyGems/openc3
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
1 hour ago
Fix available
Severity - 9.6 (Critical)
GHSA-ffq5-qpvf-xq7x
RubyGems/openc3
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
17 hours ago
Fix available
Severity - 4.6 (Medium)
GHSA-4jvx-93h3-f45h
RubyGems/openc3
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
17 hours ago
Fix available
Severity - 4.3 (Medium)
GHSA-wgx6-g857-jjf7
RubyGems/openc3
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
17 hours ago
Fix available
Severity - 8.1 (High)
GHSA-3jfp-46x4-xgfj
RubyGems/yard
yard: Possible arbitrary path traversal and file access via yard server
5 days ago
Fix available
Severity - 6.9 (Medium)
GHSA-g857-hhfv-j68w
RubyGems/zlib
Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption
6 days ago
Fix available
Severity - 5.9 (Medium)
MAL-2026-2815
RubyGems/monolith-twirp-pullsd-authorization
Malicious code in monolith-twirp-pullsd-authorization (RubyGems)
16 Apr
No fix available
MAL-2026-2816
RubyGems/monolith-twirp-pullsd-users
Malicious code in monolith-twirp-pullsd-users (RubyGems)
16 Apr
No fix available
MAL-2026-2814
RubyGems/gitlab-orchestrator
Malicious code in gitlab-orchestrator (RubyGems)
16 Apr
No fix available
GHSA-2x79-gwq3-vxxm
RubyGems/iodine
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
14 Apr
No fix available
Severity - 8.7 (High)
GHSA-w5xj-99cg-rccm
RubyGems/decidim-core
Decidim amendments can be accepted or rejected by anyone
14 Apr
Fix available
Severity - 7.5 (High)
GHSA-9pm8-vwc5-w2hm
RubyGems/fat_free_crm
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
14 Apr
Fix available
Severity - 2.1 (Low)
GHSA-fc46-r95f-hq7g
RubyGems/decidim-core
Decidim has a cross-site scripting (XSS) in user name
13 Apr
Fix available
Severity - 9.3 (Critical)
GHSA-9hfr-gw99-8rhx
RubyGems/bsv-sdk
bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts
09 Apr
Fix available
Severity - 7.5 (High)
GHSA-hc36-c89j-5f4j
RubyGems/bsv-sdk
RubyGems/bsv-wallet
bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and issuance paths)
09 Apr
Fix available
Severity - 8.1 (High)
Load more...
RubyGems - OSV