Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • H
Unsafe Reflection
stimulus_reflex<3.4.2>=3.5.0-pre0, <3.5.0-rc4RubyGems13 Mar 2024
  • M
Cross-site Scripting (XSS)
yard<0.9.35RubyGems29 Feb 2024
  • H
Exposure of Data Element to Wrong Session
actionpack>=5.2.0, <6.1.7.7>=7.0.0, <7.0.8.1RubyGems25 Feb 2024
  • M
Regular Expression Denial of Service (ReDoS)
actionpack>=7.1.0, <7.1.3.1RubyGems25 Feb 2024
  • M
Cross-site Scripting (XSS)
actionpack>=7.0.0, <7.0.8.1>=7.1.0, <7.1.3.1RubyGems25 Feb 2024
  • H
Denial of Service (DoS)
rack>=1.3.0, <2.2.8.1>=3.0.0, <3.0.9.1RubyGems25 Feb 2024
  • M
Regular Expression Denial of Service (ReDoS)
rack>=0.4.0, <2.2.8.1>=3.0.0, <3.0.9.1RubyGems25 Feb 2024
  • M
Regular Expression Denial of Service (ReDoS)
rack<2.0.9.4>=2.1.0, <2.1.4.4>=2.2.0, <2.2.8.1>=3.0.0, <3.0.9.1RubyGems25 Feb 2024
  • M
Cross-site Scripting (XSS)
decidim>=0.27.0, <0.27.5RubyGems22 Feb 2024
  • M
Cross-site Scripting (XSS)
decidim-core>=0.27.0, <0.27.5RubyGems22 Feb 2024
  • L
Race Condition
decidim>=0.10.0, <0.26.9>=0.27.0, <0.27.5RubyGems21 Feb 2024
  • M
Server-Side Request Forgery (SSRF)
decidim-templates>=0.23.0, <0.27.5RubyGems21 Feb 2024
  • M
Operation on a Resource after Expiration or Release
decidim-system>=0.0.1, <0.26.9>=0.27.0, <0.27.5RubyGems21 Feb 2024
  • M
Operation on a Resource after Expiration or Release
decidim-admin>=0.0.1, <0.26.9>=0.27.0, <0.27.5RubyGems21 Feb 2024
  • M
Operation on a Resource after Expiration or Release
devise_invitable>=0.4.0, <2.0.9RubyGems21 Feb 2024
  • H
Cross-site Scripting (XSS)
sidekiq-unique-jobs<7.1.33>=8.0.0, <8.0.7RubyGems14 Feb 2024
  • M
Use After Free
nokogiri<1.15.6>=1.16.0, <1.16.2RubyGems5 Feb 2024
  • M
NULL Pointer Dereference
openssl>=0.0.0RubyGems31 Jan 2024
  • M
Cross-site Scripting (XSS)
avo<3.0.2RubyGems18 Jan 2024
  • M
Cross-site Scripting (XSS)
avo<2.47.0>=3.0.0.beta1, <3.3.0RubyGems18 Jan 2024
  • M
Resource Exhaustion
openssl>=3.0.0RubyGems16 Jan 2024
  • M
HTTP Request Smuggling
puma<5.6.8>=6.0.0, <6.4.2RubyGems9 Jan 2024
  • H
Uncontrolled Resource Consumption ('Resource Exhaustion')
encoded_id<1.0.0.rc3RubyGems5 Jan 2024
  • M
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
view_component<2.83.0>=3.0.0, <3.9.0RubyGems5 Jan 2024
  • H
Improper Authentication
omniauth-microsoft_graph<2.0.0RubyGems3 Jan 2024
  • H
Improper Verification of Cryptographic Signature
json-jwt<1.15.3.1>=1.16.0, <1.16.6RubyGems27 Dec 2023
  • C
Improper Neutralization of Formula Elements in a CSV File
activeadmin<3.2.0RubyGems24 Dec 2023
  • M
Cross-site Scripting (XSS)
resque-scheduler<4.10.2RubyGems20 Dec 2023
  • M
Cross-site Scripting (XSS)
resque<2.2.1RubyGems19 Dec 2023
  • M
Cross-site Scripting (XSS)
resque<2.6.0RubyGems19 Dec 2023