Launch Week Day 1: Announcing Security Design Review

Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

CRITICAL 9.8
RubyGems

CVE-2026-27820

Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption

CRITICAL 9.8
RubyGems

CVE-2011-10019

Spree has Remote Command Execution vulnerability in search functionality

CRITICAL 9.8
RubyGems

CVE-2019-11068

Nokogiri vulnerable to libxslt protection mechanism bypass

CRITICAL 10.0
RubyGems

CVE-2024-45409

SAML authentication bypass via Incorrect XPath selector

CRITICAL 9.6
RubyGems

CVE-2026-42087

OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database

CRITICAL 9.8
RubyGems

CVE-2022-32224

Active Record RCE bug with Serialized Columns

CRITICAL 9.6
RubyGems

GHSA-2wvh-87g2-89hr

OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool

CRITICAL 9.1
RubyGems

CVE-2026-33286

Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names

CRITICAL 9.8
RubyGems

CVE-2022-21831

Possible code injection vulnerability in Rails / Active Storage

CRITICAL 9.8
RubyGems

CVE-2022-25648

Command injection in ruby-git

CRITICAL 9.8
RubyGems

CVE-2019-13589

paranoid2 gem Code backdoor

CRITICAL 9.8
RubyGems

CVE-2019-10842

Bootstrap-sass contains code execution backdoor

CRITICAL 9.8
RubyGems

CVE-2019-14281

datagrid contains code Injection backdoor

CRITICAL 9.8
RubyGems

CVE-2019-16676

Improper Input Validation in simple_form

CRITICAL 9.3
RubyGems

CVE-2021-41275

Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness

CRITICAL 9.3
RubyGems

CVE-2021-41274

Authentication Bypass by CSRF Weakness

CRITICAL 9.8
RubyGems

CVE-2019-14282

Code backdoor in simple_captcha2

CRITICAL 9.8
RubyGems

CVE-2019-10780

BibTeX-Ruby vulnerable to OS command injection

CRITICAL 9.8
RubyGems

CVE-2021-41816

Buffer overrun in CGI.escape_html

CRITICAL 9.8
RubyGems

CVE-2024-27280

StringIO buffer overread vulnerability

CRITICAL 9.8
RubyGems

CVE-2022-32511

JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable

CRITICAL 9.8
RubyGems

CVE-2025-25292

Ruby SAML allows a SAML authentication bypass due to namespace handling (parser differential)

CRITICAL 10.0
RubyGems

GHSA-cvp8-5r8g-fhvq

omniauth-saml vulnerable to Improper Verification of Cryptographic Signature

CRITICAL 9.8
RubyGems

CVE-2025-25291

Ruby SAML allows a SAML authentication bypass due to DOCTYPE handling (parser differential)

CRITICAL 10.0
RubyGems

CVE-2025-68271

openc3-api Vulnerable to Unauthenticated Remote Code Execution

CRITICAL 9.0
RubyGems

CVE-2025-27407

graphql allows remote code execution when loading a crafted GraphQL schema

CRITICAL 9.1
RubyGems

CVE-2025-28384

OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/ endpoint

CRITICAL 9.8
RubyGems

CVE-2014-10075

karo Metacharacter Handling Remote Command Execution

CRITICAL 9.1
RubyGems

CVE-2025-54887

JWE is missing AES-GCM authentication tag validation in encrypted JWE

CRITICAL 9.3
RubyGems

GHSA-gpqc-4pp7-5954

Duplicate Advisory: Authentication Bypass by CSRF Weakness

CRITICAL 9.3
RubyGems

GHSA-6mqr-q86q-6gwr

Duplicate Advisory: Authentication Bypass by CSRF Weakness

CRITICAL 9.3
RubyGems

GHSA-8xfw-5q82-3652

Duplicate Advisory: Authentication Bypass by CSRF Weakness

CRITICAL 9.8
RubyGems

CVE-2020-8165

ActiveSupport potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore

CRITICAL 9.8
RubyGems

CVE-2016-7954

Bundler allows attacker to inject arbitrary code via secondary Gem source

CRITICAL 9.8
RubyGems

CVE-2022-36231

Code injection in pdf_info

CRITICAL 9.0
RubyGems

CVE-2025-27590

Oxidized Web RANCID migration page allows unauthenticated user to gain control over Linux user account

CRITICAL 9.8
RubyGems

CVE-2015-20108

ruby-saml vulnerable to XPath injection

CRITICAL 9.8
RubyGems

CVE-2022-33127

Improper handling of double quotes in file name in Diffy in Windows environment

CRITICAL 9.8
RubyGems

CVE-2017-10906

Fluentd Escape Sequence Injection Vulnerability

CRITICAL 9.8
RubyGems

CVE-2021-33575

Remote code execution in ruby-jss

CRITICAL 9.8
RubyGems

CVE-2018-16395

Ruby Openssl Allows Incorrect Value Comparison

CRITICAL 9.3
RubyGems

GHSA-5629-8855-gf4g

Authentication Bypass by CSRF Weakness

CRITICAL 9.0
RubyGems

CVE-2024-43415

Decidim-Awesome has SQL injection in AdminAccountability

CRITICAL 9.8
RubyGems

CVE-2019-17383

netaddr before 1.5.3 and 2.0.4 has Incorrect Default Permissions

CRITICAL 9.8
RubyGems

CVE-2024-42360

Command Injection in sequenceserver

CRITICAL 9.8
RubyGems

CVE-2012-3503

Katello uses hard coded credential

CRITICAL 9.6
RubyGems

CVE-2023-28102

discordrb OS Command Injection vulnerability

CRITICAL 9.8
RubyGems

CVE-2018-1000076

RubyGems Improper Verification of Cryptographic Signature vulnerability

CRITICAL 9.8
RubyGems

CVE-2017-0903

RubyGems vulnerable to Deserialization of Untrusted Data

CRITICAL 9.8
RubyGems

CVE-2019-5420

Use of Insufficiently Random Values in Railties Allows Remote Code Execution

CRITICAL 9.1
RubyGems

CVE-2021-33473

Arbitrary file write in dragonfly

CRITICAL 9.8
RubyGems

CVE-2018-12026

Phusion Passenger SpawningKit Contains Arbitrary Read/Write Vulnerability

CRITICAL 10.0
RubyGems

CVE-2015-7541

colorscore Command Injection vulnerability

CRITICAL 9.8
RubyGems

CVE-2022-25765

PDFKit vulnerable to Command Injection

CRITICAL 10.0
RubyGems

CVE-2022-30123

Possible shell escape sequence injection vulnerability in Rack

CRITICAL 9.8
RubyGems

CVE-2019-5477

Nokogiri Command Injection Vulnerability

CRITICAL 9.8
RubyGems

CVE-2014-0156

OS Command Injection in awesome spawn

CRITICAL 9.8
RubyGems

CVE-2020-14001

Unintended read access in kramdown gem

CRITICAL 9.8
RubyGems

CVE-2021-28834

Remote code execution in Kramdown

CRITICAL 9.8
RubyGems

CVE-2019-16377

Consul gem insufficient authentication check - Multiple powers in one controller are not always checked correctly

Ready to move

Start Securing

Free, no credit card | First findings in minutes