Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2025-61594
URI Credential Leakage Bypass over CVE-2025-27221
CVE-2024-37031
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
CVE-2024-0241
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
CVE-2024-22050
Malicious URL drafting attack against iodines static file server may allow path traversal
CVE-2020-7659
HTTP Request Smuggling in reel
CVE-2022-24440
Command injection in cocoapods-downloader
CVE-2020-7663
Regular Expression Denial of Service in websocket-extensions (RubyGem)
CVE-2022-21223
Command injection in cocoapods-downloader
CVE-2021-23435
Clearance Gem Open Redirect Vulnerability
CVE-2024-49761
REXML ReDoS vulnerability
CVE-2023-46950
XSS sidekiq-unique-jobs UI server vulnerability
CVE-2020-7671
HTTP Request Smuggling in goliath
CVE-2021-32740
Regular Expression Denial of Service in Addressable templates
CVE-2021-29435
Cross-Site Request Forgery (CSRF) in trestle-auth
CVE-2023-34090
Decidim vulnerable to sensitive data disclosure
CVE-2020-4054
Cross-site Scripting in Sanitize
CVE-2020-26222
Remote code execution in dependabot-core branch names when cloning
CVE-2021-41098
Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby
CVE-2021-43805
ReDos vulnerability on guest checkout email validation
CVE-2021-21305
Code Injection vulnerability in CarrierWave::RMagick
CVE-2020-5257
Sort order SQL injection in Administrate
CVE-2020-15269
Ensure that doorkeeper_token is valid when authenticating requests in API v2 calls
CVE-2020-15134
Missing TLS certificate verification
CVE-2020-11052
Improper Restriction of Excessive Authentication Attempts in Sorcery
CVE-2021-29509
Puma's Keepalive Connections Causing Denial Of Service
CVE-2020-15240
Regression in JWT Signature Validation
CVE-2023-50448
Potential CSV export data leak
CVE-2023-4785
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
GHSA-mjgf-xj26-9qf9
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
CVE-2026-44161
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
CVE-2026-44025
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
CVE-2026-44160
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
CVE-2026-54592
Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
CVE-2026-54297
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
GHSA-mqq5-j7w8-2hgh
AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content
CVE-2026-45363
ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
CVE-2026-47737
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
CVE-2026-47736
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
CVE-2026-41316
ERB has an @_init deserialization guard bypass via def_module / def_method / def_class
CVE-2019-13118
libxslt Type Confusion vulnerability that affects Nokogiri
CVE-2019-18197
Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerability
CVE-2026-42205
Avo: Broken Access Control Through Unauthorized Execution of Arbitrary Action Classes Across Resources
CVE-2025-68696
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
CVE-2026-40869
Decidim amendments can be accepted or rejected by anyone
CVE-2026-44511
katalyst-koi: Session cookies can be replayed after user logout
CVE-2026-42084
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
CVE-2024-22051
Integer overflow in cmark-gfm table parsing extension leads to heap memory corruption
CVE-2026-40069
bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts
CVE-2026-40070
bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and issuance paths)
CVE-2026-23891
Decidim has a cross-site scripting (XSS) in user name
CVE-2026-34230
Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
CVE-2026-35611
Addressable has a Regular Expression Denial of Service in Addressable templates
CVE-2026-34829
Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads
CVE-2026-34827
Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters
CVE-2026-34785
Rack::Static prefix matching can expose unintended files under the static root
GHSA-c4rq-3m3g-8wgx
Nokogiri CSS selector tokenizer has regular expression backtracking
CVE-2025-59830
Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters
CVE-2026-1531
foreman_kubevirt disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set
CVE-2026-0980
rubyipmi is vulnerable to OS Command Injection through malicious usernames
CVE-2026-1530
fog-kubevirt allows remote attacker to perform MITM attack due to disabled certificate validation
Ready to move
Start Securing
Free, no credit card | First findings in minutes