Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-27820
Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption
CVE-2011-10019
Spree has Remote Command Execution vulnerability in search functionality
CVE-2019-11068
Nokogiri vulnerable to libxslt protection mechanism bypass
CVE-2024-45409
SAML authentication bypass via Incorrect XPath selector
CVE-2026-42087
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
CVE-2022-32224
Active Record RCE bug with Serialized Columns
GHSA-2wvh-87g2-89hr
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
CVE-2026-33286
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
CVE-2022-21831
Possible code injection vulnerability in Rails / Active Storage
CVE-2022-25648
Command injection in ruby-git
CVE-2019-13589
paranoid2 gem Code backdoor
CVE-2019-10842
Bootstrap-sass contains code execution backdoor
CVE-2019-14281
datagrid contains code Injection backdoor
CVE-2019-16676
Improper Input Validation in simple_form
CVE-2021-41275
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
CVE-2021-41274
Authentication Bypass by CSRF Weakness
CVE-2019-14282
Code backdoor in simple_captcha2
CVE-2019-10780
BibTeX-Ruby vulnerable to OS command injection
CVE-2021-41816
Buffer overrun in CGI.escape_html
CVE-2024-27280
StringIO buffer overread vulnerability
CVE-2022-32511
JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable
CVE-2025-25292
Ruby SAML allows a SAML authentication bypass due to namespace handling (parser differential)
GHSA-cvp8-5r8g-fhvq
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
CVE-2025-25291
Ruby SAML allows a SAML authentication bypass due to DOCTYPE handling (parser differential)
CVE-2025-68271
openc3-api Vulnerable to Unauthenticated Remote Code Execution
CVE-2025-27407
graphql allows remote code execution when loading a crafted GraphQL schema
CVE-2025-28384
OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/ endpoint
CVE-2014-10075
karo Metacharacter Handling Remote Command Execution
CVE-2025-54887
JWE is missing AES-GCM authentication tag validation in encrypted JWE
GHSA-gpqc-4pp7-5954
Duplicate Advisory: Authentication Bypass by CSRF Weakness
GHSA-6mqr-q86q-6gwr
Duplicate Advisory: Authentication Bypass by CSRF Weakness
GHSA-8xfw-5q82-3652
Duplicate Advisory: Authentication Bypass by CSRF Weakness
CVE-2020-8165
ActiveSupport potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
CVE-2016-7954
Bundler allows attacker to inject arbitrary code via secondary Gem source
CVE-2022-36231
Code injection in pdf_info
CVE-2025-27590
Oxidized Web RANCID migration page allows unauthenticated user to gain control over Linux user account
CVE-2015-20108
ruby-saml vulnerable to XPath injection
CVE-2022-33127
Improper handling of double quotes in file name in Diffy in Windows environment
CVE-2017-10906
Fluentd Escape Sequence Injection Vulnerability
CVE-2021-33575
Remote code execution in ruby-jss
CVE-2018-16395
Ruby Openssl Allows Incorrect Value Comparison
GHSA-5629-8855-gf4g
Authentication Bypass by CSRF Weakness
CVE-2024-43415
Decidim-Awesome has SQL injection in AdminAccountability
CVE-2019-17383
netaddr before 1.5.3 and 2.0.4 has Incorrect Default Permissions
CVE-2024-42360
Command Injection in sequenceserver
CVE-2012-3503
Katello uses hard coded credential
CVE-2023-28102
discordrb OS Command Injection vulnerability
CVE-2018-1000076
RubyGems Improper Verification of Cryptographic Signature vulnerability
CVE-2017-0903
RubyGems vulnerable to Deserialization of Untrusted Data
CVE-2019-5420
Use of Insufficiently Random Values in Railties Allows Remote Code Execution
CVE-2021-33473
Arbitrary file write in dragonfly
CVE-2018-12026
Phusion Passenger SpawningKit Contains Arbitrary Read/Write Vulnerability
CVE-2015-7541
colorscore Command Injection vulnerability
CVE-2022-25765
PDFKit vulnerable to Command Injection
CVE-2022-30123
Possible shell escape sequence injection vulnerability in Rack
CVE-2019-5477
Nokogiri Command Injection Vulnerability
CVE-2014-0156
OS Command Injection in awesome spawn
CVE-2020-14001
Unintended read access in kramdown gem
CVE-2021-28834
Remote code execution in Kramdown
CVE-2019-16377
Consul gem insufficient authentication check - Multiple powers in one controller are not always checked correctly
Ready to move
Start Securing
Free, no credit card | First findings in minutes