Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-47241
Net::IMAP: Denial of Service via incomplete raw argument validation
CVE-2026-47242
Net::IMAP: Command Injection via ID command argument
CVE-2026-47240
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
CVE-2026-27820
Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption
CVE-2019-13117
Uninitialized read in Nokogiri gem
CVE-2026-47737
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
CVE-2026-47736
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
CVE-2026-44476
Doorkeeper Openid Connect: Dynamic Client Registration feature creates public clients with client_secret
CVE-2011-10019
Spree has Remote Command Execution vulnerability in search functionality
CVE-2026-41493
yard: Possible arbitrary path traversal and file access via yard server
CVE-2026-44587
CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters
CVE-2026-41316
ERB has an @_init deserialization guard bypass via def_module / def_method / def_class
CVE-2019-11068
Nokogiri vulnerable to libxslt protection mechanism bypass
CVE-2019-13118
libxslt Type Confusion vulnerability that affects Nokogiri
CVE-2019-18197
Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerability
CVE-2024-26143
Rails has possible XSS Vulnerability in Action Controller
CVE-2026-44836
view_component: Preview Route Can Dispatch Inherited Helper Methods
CVE-2026-44837
view_component: System Test Entry Point Path Check Allows Sibling Directory Escape
CVE-2018-14042
Bootstrap Cross-site Scripting vulnerability
CVE-2024-32887
Sidekiq vulnerable to a Reflected XSS in Queues Web Page
CVE-2026-44312
CSS Parser: Improper Certificate Validation allows MITM injection of remote CSS content
CVE-2026-42205
Avo: Broken Access Control Through Unauthorized Execution of Arbitrary Action Classes Across Resources
CVE-2026-41146
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
CVE-2025-68696
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
CVE-2024-45409
SAML authentication bypass via Incorrect XPath selector
CVE-2024-27281
RDoc RCE vulnerability with .rdoc_options
CVE-2023-5349
memory leak flaw was found in ruby-magick
CVE-2026-33637
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
GHSA-xf4v-w5x5-pv79
Spree: CSV Formula Injection in Customer Export
CVE-2026-45363
ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
CVE-2019-8331
Bootstrap Vulnerable to Cross-Site Scripting
CVE-2026-4324
Katello: Denial of Service and potential information disclosure via SQL injection
CVE-2025-67202
Sidekiq-cron is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL
CVE-2026-40869
Decidim amendments can be accepted or rejected by anyone
CVE-2026-40295
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
CVE-2026-42087
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
CVE-2026-42086
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
CVE-2026-44511
katalyst-koi: Session cookies can be replayed after user logout
CVE-2026-42084
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
CVE-2026-42085
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
CVE-2025-61594
URI Credential Leakage Bypass over CVE-2025-27221
CVE-2026-42246
net-imap vulnerable to STARTTLS stripping via invalid response timing
CVE-2026-42258
net-imap vulnerable to command Injection via unvalidated Symbol inputs
CVE-2024-22051
Integer overflow in cmark-gfm table parsing extension leads to heap memory corruption
CVE-2026-42256
net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication
CVE-2026-42245
net-imap has quadratic complexity when reading response literals
CVE-2026-32762
Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing
CVE-2026-33169
Rails Active Support has a possible ReDoS vulnerability in number_to_delimited
CVE-2026-34835
Rack::Request accepts invalid Host characters, enabling host allowlist bypass
CVE-2026-34831
Rack has Content-Length mismatch in Rack::Files error responses
CVE-2026-40069
bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts
CVE-2026-40070
bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and issuance paths)
CVE-2026-26962
Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values
CVE-2026-23891
Decidim has a cross-site scripting (XSS) in user name
CVE-2026-34830
Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect
CVE-2026-34230
Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
CVE-2026-35611
Addressable has a Regular Expression Denial of Service in Addressable templates
CVE-2026-34829
Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads
CVE-2026-26961
Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.
CVE-2026-33170
Rails Active Support has a possible XSS vulnerability in SafeBuffer#%
Ready to move
Start Securing
Free, no credit card | First findings in minutes