Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2022-32511
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
CVE-2026-44587
CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters
CVE-2026-57436
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
CVE-2026-57434
Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
CVE-2026-42088
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
CVE-2026-57234
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
CVE-2026-57435
Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
CVE-2026-57438
Nokogiri: Possible Use-After-Free in XInclude Processing
CVE-2026-57236
Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
CVE-2026-57437
Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
CVE-2026-57235
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
CVE-2026-25765
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
CVE-2026-33637
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
CVE-2025-27221
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
CVE-2025-61594
URI Credential Leakage Bypass over CVE-2025-27221
CVE-2024-37031
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
CVE-2024-22047
Race Condition leading to logging errors
CVE-2024-22048
govuk_tech_docs vulnerable to unescaped HTML on search results page
CVE-2024-0241
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
CVE-2024-22049
httparty has multipart/form-data request tampering vulnerability
CVE-2024-22050
Malicious URL drafting attack against iodines static file server may allow path traversal
CVE-2020-7659
HTTP Request Smuggling in reel
CVE-2022-24440
Command injection in cocoapods-downloader
CVE-2020-7663
Regular Expression Denial of Service in websocket-extensions (RubyGem)
CVE-2022-25648
Command injection in ruby-git
CVE-2022-21223
Command injection in cocoapods-downloader
CVE-2021-23435
Clearance Gem Open Redirect Vulnerability
CVE-2024-49761
REXML ReDoS vulnerability
CVE-2023-46950
Cross Site Scripting vulnerability in Contribsys Sidekiq
CVE-2020-7671
HTTP Request Smuggling in goliath
CVE-2021-32740
Regular Expression Denial of Service in Addressable templates
CVE-2021-43846
CSRF forgery protection bypass in solidus_frontend
CVE-2020-5267
Cross site scripting vulnerability in ActionView
CVE-2021-29435
Cross-Site Request Forgery (CSRF) in trestle-auth
CVE-2021-41275
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
CVE-2023-34090
Decidim vulnerable to sensitive data disclosure
CVE-2021-41274
Authentication Bypass by CSRF Weakness
CVE-2020-4054
Cross-site Scripting in Sanitize
CVE-2020-26222
Remote code execution in dependabot-core branch names when cloning
CVE-2020-15237
Possible timing attack in derivation_endpoint
CVE-2022-32224
Active Record RCE bug with Serialized Columns
CVE-2021-43840
Path traversal when MessageBus::Diagnostics is enabled
CVE-2021-39197
Older releases of better_errors open to Cross-Site Request Forgery attack
CVE-2021-41186
ReDoS vulnerability in parser_apache2
CVE-2021-41098
Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby
CVE-2021-43805
ReDos vulnerability on guest checkout email validation
CVE-2021-41263
Rails Multisite secure/signed cookies share secrets between sites in a multi-site application
CVE-2021-41136
Puma with proxy which forwards LF characters as line endings could allow HTTP request smuggling
CVE-2021-21305
Code Injection vulnerability in CarrierWave::RMagick
CVE-2020-5257
Sort order SQL injection in Administrate
CVE-2021-43809
Local Code Execution through Argument Injection via dash leading git url parameter in Gemfile.
CVE-2020-5247
HTTP Response Splitting in Puma
CVE-2020-15269
Ensure that doorkeeper_token is valid when authenticating requests in API v2 calls
CVE-2020-15134
Missing TLS certificate verification
CVE-2019-16770
A poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack
CVE-2020-11052
Improper Restriction of Excessive Authentication Attempts in Sorcery
CVE-2021-29509
Puma's Keepalive Connections Causing Denial Of Service
CVE-2020-15240
Regression in JWT Signature Validation
CVE-2023-50448
Potential CSV export data leak
Ready to move
Start Securing
Free, no credit card | First findings in minutes