Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • M
Improper Input Validation
personnummer<3.0.1RubyGems22 Sept 2022
  • H
Arbitrary Code Execution
arr-pm<0.0.12RubyGems22 Sept 2022
  • M
Information Exposure
pageflow<14.5.2>=15.0.0, <15.7.1RubyGems15 Sept 2022
  • H
Authorization Bypass Through User-Controlled Key
pageflow<14.5.2>=15.0.0, <15.7.1RubyGems15 Sept 2022
  • C
Command Injection
pdfkit<0.8.7.2RubyGems8 Sept 2022
  • L
Insecure Permissions
octokit>=4.23.0, <4.25.0RubyGems22 Aug 2022
  • H
Improper Authentication
omniauth<1.9.2>=2.0.0.pre.rc1, <2.0.0RubyGems19 Aug 2022
  • H
SQL Injection
update_by_case<0.1.3RubyGems12 Aug 2022
  • H
Directory Traversal
tzinfo<0.3.61>=1.0.0, <1.2.10RubyGems22 Jul 2022
  • M
Information Exposure
bolt<3.24.0RubyGems20 Jul 2022
  • M
Cross-site Scripting (XSS)
gollum>=5.0.0, <5.1.2RubyGems17 Jul 2022
  • C
Remote Code Execution (RCE)
activerecord<5.2.8.1>=6.0.0, <6.0.5.1>=6.1.0, <6.1.6.1>=7.0.0, <7.0.3.1RubyGems13 Jul 2022
  • M
HTTP Request Smuggling
llhttp>=0.0.0RubyGems10 Jul 2022
  • M
HTTP Request Smuggling
llhttp>=0.0.0RubyGems10 Jul 2022
  • M
HTTP Request Smuggling
llhttp>=0.0.0RubyGems10 Jul 2022
  • H
Deserialization of Untrusted Data
opensearch-ruby<2.0.2RubyGems1 Jul 2022
  • M
Access Restriction Bypass
ruby-mysql<2.10.0RubyGems29 Jun 2022
  • M
Cross-site Scripting (XSS)
rails-html-sanitizer<1.4.3RubyGems26 Jun 2022
  • H
Remote Code Execution (RCE)
diffy<3.4.1RubyGems24 Jun 2022
  • H
Improper Encoding or Escaping of Output
motor-admin<0.2.61RubyGems22 Jun 2022
  • L
Insecure Permissions
octopoller>=0.2.0, <0.3.0RubyGems16 Jun 2022
  • M
Insufficiently Protected Credentials
mechanize<2.8.5RubyGems10 Jun 2022
  • H
Deserialization of Untrusted Data
jmespath<1.6.1RubyGems7 Jun 2022
  • M
Use of Uninitialized Resource
trilogy<2.1.1RubyGems7 Jun 2022
  • M
Cross-site Scripting (XSS)
publify_core>=8.0, <9.2.5RubyGems6 Jun 2022
  • L
Cross-site Request Forgery (CSRF)
solidus_backend<2.11.16>=3.0.0, <3.0.6>=3.1.0, <3.1.6RubyGems2 Jun 2022
  • H
Denial of Service (DoS)
rack>=1.2, <2.0.9.1>=2.1.0, <2.1.4.1>=2.2.0, <2.2.3.1RubyGems28 May 2022
  • C
Arbitrary Code Injection
rack<2.0.9.1>=2.1.0, <2.1.4.1>=2.2.0, <2.2.3.1RubyGems28 May 2022
  • M
Improper Access Control
publify_core<9.2.9RubyGems24 May 2022
  • M
Cross-site Scripting (XSS)
publify_core<9.2.9RubyGems24 May 2022