Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

HIGH 7.5
RubyGems

CVE-2025-61594

URI Credential Leakage Bypass over CVE-2025-27221

HIGH 7.2
RubyGems

CVE-2024-37031

activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends

HIGH 7.5
RubyGems

CVE-2024-0241

encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs

HIGH 7.5
RubyGems

CVE-2024-22050

Malicious URL drafting attack against iodines static file server may allow path traversal

HIGH 7.5
RubyGems

CVE-2020-7659

HTTP Request Smuggling in reel

HIGH 8.1
RubyGems

CVE-2022-24440

Command injection in cocoapods-downloader

HIGH 8.2
RubyGems

CVE-2020-7663

Regular Expression Denial of Service in websocket-extensions (RubyGem)

HIGH 8.1
RubyGems

CVE-2022-21223

Command injection in cocoapods-downloader

HIGH 7.6
RubyGems

CVE-2021-23435

Clearance Gem Open Redirect Vulnerability

HIGH 7.5
RubyGems

CVE-2024-49761

REXML ReDoS vulnerability

HIGH 7.1
RubyGems

CVE-2023-46950

XSS sidekiq-unique-jobs UI server vulnerability

HIGH 7.5
RubyGems

CVE-2020-7671

HTTP Request Smuggling in goliath

HIGH 7.5
RubyGems

CVE-2021-32740

Regular Expression Denial of Service in Addressable templates

HIGH 8.1
RubyGems

CVE-2021-29435

Cross-Site Request Forgery (CSRF) in trestle-auth

HIGH 7.5
RubyGems

CVE-2023-34090

Decidim vulnerable to sensitive data disclosure

HIGH 7.3
RubyGems

CVE-2020-4054

Cross-site Scripting in Sanitize

HIGH 8.7
RubyGems

CVE-2020-26222

Remote code execution in dependabot-core branch names when cloning

HIGH 7.5
RubyGems

CVE-2021-41098

Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby

HIGH 7.5
RubyGems

CVE-2021-43805

ReDos vulnerability on guest checkout email validation

HIGH 7.4
RubyGems

CVE-2021-21305

Code Injection vulnerability in CarrierWave::RMagick

HIGH 7.7
RubyGems

CVE-2020-5257

Sort order SQL injection in Administrate

HIGH 7.4
RubyGems

CVE-2020-15269

Ensure that doorkeeper_token is valid when authenticating requests in API v2 calls

HIGH 8.0
RubyGems

CVE-2020-15134

Missing TLS certificate verification

HIGH 8.3
RubyGems

CVE-2020-11052

Improper Restriction of Excessive Authentication Attempts in Sorcery

HIGH 7.5
RubyGems

CVE-2021-29509

Puma's Keepalive Connections Causing Denial Of Service

HIGH 7.4
RubyGems

CVE-2020-15240

Regression in JWT Signature Validation

HIGH 8.4
RubyGems

CVE-2023-50448

Potential CSV export data leak

HIGH 7.5
RubyGems

CVE-2023-4785

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

HIGH 7.4
RubyGems

GHSA-mjgf-xj26-9qf9

pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier

HIGH 7.2
RubyGems

CVE-2026-44161

Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

HIGH 7.5
RubyGems

CVE-2026-44025

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

HIGH 7.5
RubyGems

CVE-2026-44160

Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`

HIGH 7.5
RubyGems

CVE-2026-54592

Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input

HIGH 7.5
RubyGems

CVE-2026-54297

Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters

HIGH 7.5
RubyGems

GHSA-mqq5-j7w8-2hgh

AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content

HIGH 7.4
RubyGems

CVE-2026-45363

ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351

HIGH 7.5
RubyGems

CVE-2026-47737

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

HIGH 7.5
RubyGems

CVE-2026-47736

Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion

HIGH 8.1
RubyGems

CVE-2026-41316

ERB has an @_init deserialization guard bypass via def_module / def_method / def_class

HIGH 7.5
RubyGems

CVE-2019-13118

libxslt Type Confusion vulnerability that affects Nokogiri

HIGH 7.5
RubyGems

CVE-2019-18197

Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerability

HIGH 8.8
RubyGems

CVE-2026-42205

Avo: Broken Access Control Through Unauthorized Execution of Arbitrary Action Classes Across Resources

HIGH 8.2
RubyGems

CVE-2025-68696

httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage

HIGH 7.5
RubyGems

CVE-2026-40869

Decidim amendments can be accepted or rejected by anyone

HIGH 7.4
RubyGems

CVE-2026-44511

katalyst-koi: Session cookies can be replayed after user logout

HIGH 8.1
RubyGems

CVE-2026-42084

OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence

HIGH 8.8
RubyGems

CVE-2024-22051

Integer overflow in cmark-gfm table parsing extension leads to heap memory corruption

HIGH 7.5
RubyGems

CVE-2026-40069

bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts

HIGH 8.1
RubyGems

CVE-2026-40070

bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and issuance paths)

HIGH 8.7
RubyGems

CVE-2026-23891

Decidim has a cross-site scripting (XSS) in user name

HIGH 7.5
RubyGems

CVE-2026-34230

Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header

HIGH 7.5
RubyGems

CVE-2026-35611

Addressable has a Regular Expression Denial of Service in Addressable templates

HIGH 7.5
RubyGems

CVE-2026-34829

Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads

HIGH 7.5
RubyGems

CVE-2026-34827

Rack's multipart header parsing allows Denial of Service via escape-heavy quoted parameters

HIGH 7.5
RubyGems

CVE-2026-34785

Rack::Static prefix matching can expose unintended files under the static root

HIGH 7.5
RubyGems

GHSA-c4rq-3m3g-8wgx

Nokogiri CSS selector tokenizer has regular expression backtracking

HIGH 7.5
RubyGems

CVE-2025-59830

Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters

HIGH 8.1
RubyGems

CVE-2026-1531

foreman_kubevirt disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set

HIGH 8.3
RubyGems

CVE-2026-0980

rubyipmi is vulnerable to OS Command Injection through malicious usernames

HIGH 8.1
RubyGems

CVE-2026-1530

fog-kubevirt allows remote attacker to perform MITM attack due to disabled certificate validation

Ready to move

Start Securing

Free, no credit card | First findings in minutes