Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

CRITICAL 9.8
RubyGems

CVE-2022-32511

JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable

MEDIUM 4.7
RubyGems

CVE-2026-44587

CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters

UNKNOWN
RubyGems

CVE-2026-57436

Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type

UNKNOWN
RubyGems

CVE-2026-57434

Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes

CRITICAL 9.6
RubyGems

CVE-2026-42088

OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool

LOW 2.6
RubyGems

CVE-2026-57234

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

UNKNOWN
RubyGems

CVE-2026-57435

Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`

UNKNOWN
RubyGems

CVE-2026-57438

Nokogiri: Possible Use-After-Free in XInclude Processing

UNKNOWN
RubyGems

CVE-2026-57236

Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception

UNKNOWN
RubyGems

CVE-2026-57437

Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime

UNKNOWN
RubyGems

CVE-2026-57235

Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`

MEDIUM 5.8
RubyGems

CVE-2026-25765

Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url

NONE 0.0
RubyGems

CVE-2026-33637

Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping

LOW 3.2
RubyGems

CVE-2025-27221

URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+

HIGH 7.5
RubyGems

CVE-2025-61594

URI Credential Leakage Bypass over CVE-2025-27221

HIGH 7.2
RubyGems

CVE-2024-37031

activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends

LOW 3.1
RubyGems

CVE-2024-22047

Race Condition leading to logging errors

UNKNOWN
RubyGems

CVE-2024-22048

govuk_tech_docs vulnerable to unescaped HTML on search results page

HIGH 7.5
RubyGems

CVE-2024-0241

encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs

MEDIUM 6.5
RubyGems

CVE-2024-22049

httparty has multipart/form-data request tampering vulnerability

HIGH 7.5
RubyGems

CVE-2024-22050

Malicious URL drafting attack against iodines static file server may allow path traversal

HIGH 7.5
RubyGems

CVE-2020-7659

HTTP Request Smuggling in reel

HIGH 8.1
RubyGems

CVE-2022-24440

Command injection in cocoapods-downloader

HIGH 8.2
RubyGems

CVE-2020-7663

Regular Expression Denial of Service in websocket-extensions (RubyGem)

CRITICAL 9.8
RubyGems

CVE-2022-25648

Command injection in ruby-git

HIGH 8.1
RubyGems

CVE-2022-21223

Command injection in cocoapods-downloader

HIGH 7.6
RubyGems

CVE-2021-23435

Clearance Gem Open Redirect Vulnerability

HIGH 7.5
RubyGems

CVE-2024-49761

REXML ReDoS vulnerability

MEDIUM 6.1
RubyGems

CVE-2023-46950

Cross Site Scripting vulnerability in Contribsys Sidekiq

HIGH 7.5
RubyGems

CVE-2020-7671

HTTP Request Smuggling in goliath

HIGH 7.5
RubyGems

CVE-2021-32740

Regular Expression Denial of Service in Addressable templates

MEDIUM 5.3
RubyGems

CVE-2021-43846

CSRF forgery protection bypass in solidus_frontend

MEDIUM 4.8
RubyGems

CVE-2020-5267

Cross site scripting vulnerability in ActionView

HIGH 8.1
RubyGems

CVE-2021-29435

Cross-Site Request Forgery (CSRF) in trestle-auth

CRITICAL 9.3
RubyGems

CVE-2021-41275

Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness

HIGH 7.5
RubyGems

CVE-2023-34090

Decidim vulnerable to sensitive data disclosure

CRITICAL 9.3
RubyGems

CVE-2021-41274

Authentication Bypass by CSRF Weakness

HIGH 7.3
RubyGems

CVE-2020-4054

Cross-site Scripting in Sanitize

HIGH 8.7
RubyGems

CVE-2020-26222

Remote code execution in dependabot-core branch names when cloning

MEDIUM 5.9
RubyGems

CVE-2020-15237

Possible timing attack in derivation_endpoint

CRITICAL 9.8
RubyGems

CVE-2022-32224

Active Record RCE bug with Serialized Columns

MEDIUM 4.2
RubyGems

CVE-2021-43840

Path traversal when MessageBus::Diagnostics is enabled

MEDIUM 6.3
RubyGems

CVE-2021-39197

Older releases of better_errors open to Cross-Site Request Forgery attack

MEDIUM 5.9
RubyGems

CVE-2021-41186

ReDoS vulnerability in parser_apache2

HIGH 7.5
RubyGems

CVE-2021-41098

Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby

HIGH 7.5
RubyGems

CVE-2021-43805

ReDos vulnerability on guest checkout email validation

MEDIUM 6.2
RubyGems

CVE-2021-41263

Rails Multisite secure/signed cookies share secrets between sites in a multi-site application

LOW 3.7
RubyGems

CVE-2021-41136

Puma with proxy which forwards LF characters as line endings could allow HTTP request smuggling

HIGH 7.4
RubyGems

CVE-2021-21305

Code Injection vulnerability in CarrierWave::RMagick

HIGH 7.7
RubyGems

CVE-2020-5257

Sort order SQL injection in Administrate

MEDIUM 6.7
RubyGems

CVE-2021-43809

Local Code Execution through Argument Injection via dash leading git url parameter in Gemfile.

MEDIUM 6.5
RubyGems

CVE-2020-5247

HTTP Response Splitting in Puma

HIGH 7.4
RubyGems

CVE-2020-15269

Ensure that doorkeeper_token is valid when authenticating requests in API v2 calls

HIGH 8.0
RubyGems

CVE-2020-15134

Missing TLS certificate verification

MEDIUM 5.3
RubyGems

CVE-2019-16770

A poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack

HIGH 8.3
RubyGems

CVE-2020-11052

Improper Restriction of Excessive Authentication Attempts in Sorcery

HIGH 7.5
RubyGems

CVE-2021-29509

Puma's Keepalive Connections Causing Denial Of Service

HIGH 7.4
RubyGems

CVE-2020-15240

Regression in JWT Signature Validation

HIGH 8.4
RubyGems

CVE-2023-50448

Potential CSV export data leak

Ready to move

Start Securing

Free, no credit card | First findings in minutes