Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • M
Regular Expression Denial of Service (ReDoS)
rack>=0.4.0, <2.2.8.1>=3.0.0, <3.0.9.1RubyGems25 Feb 2024
  • M
Regular Expression Denial of Service (ReDoS)
rack<2.0.9.4>=2.1.0, <2.1.4.4>=2.2.0, <2.2.8.1>=3.0.0, <3.0.9.1RubyGems25 Feb 2024
  • M
Cross-site Scripting (XSS)
decidim>=0.27.0, <0.27.5RubyGems22 Feb 2024
  • M
Cross-site Scripting (XSS)
decidim-core>=0.27.0, <0.27.5RubyGems22 Feb 2024
  • L
Race Condition
decidim>=0.10.0, <0.26.9>=0.27.0, <0.27.5RubyGems21 Feb 2024
  • M
Server-Side Request Forgery (SSRF)
decidim-templates>=0.23.0, <0.27.5RubyGems21 Feb 2024
  • M
Operation on a Resource after Expiration or Release
decidim-system>=0.0.1, <0.26.9>=0.27.0, <0.27.5RubyGems21 Feb 2024
  • M
Operation on a Resource after Expiration or Release
decidim-admin>=0.0.1, <0.26.9>=0.27.0, <0.27.5RubyGems21 Feb 2024
  • M
Operation on a Resource after Expiration or Release
devise_invitable>=0.4.0, <2.0.9RubyGems21 Feb 2024
  • H
Cross-site Scripting (XSS)
sidekiq-unique-jobs<7.1.33>=8.0.0, <8.0.7RubyGems14 Feb 2024
  • M
Use After Free
nokogiri<1.15.6>=1.16.0, <1.16.2RubyGems5 Feb 2024
  • M
Cross-site Scripting (XSS)
avo<3.0.2RubyGems18 Jan 2024
  • M
Cross-site Scripting (XSS)
avo<2.47.0>=3.0.0.beta1, <3.3.0RubyGems18 Jan 2024
  • M
HTTP Request Smuggling
puma<5.6.8>=6.0.0, <6.4.2RubyGems9 Jan 2024
  • H
Uncontrolled Resource Consumption ('Resource Exhaustion')
encoded_id<1.0.0.rc3RubyGems5 Jan 2024
  • M
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
view_component<2.83.0>=3.0.0, <3.9.0RubyGems5 Jan 2024
  • H
Improper Authentication
omniauth-microsoft_graph<2.0.0RubyGems3 Jan 2024
  • H
Improper Verification of Cryptographic Signature
json-jwt<1.15.3.1>=1.16.0, <1.16.6RubyGems27 Dec 2023
  • C
Improper Neutralization of Formula Elements in a CSV File
activeadmin<3.2.0RubyGems24 Dec 2023
  • M
Cross-site Scripting (XSS)
resque-scheduler<4.10.2RubyGems20 Dec 2023
  • M
Cross-site Scripting (XSS)
resque<2.2.1RubyGems19 Dec 2023
  • M
Cross-site Scripting (XSS)
resque<2.6.0RubyGems19 Dec 2023
  • M
Cross-site Scripting (XSS)
resque<2.1.0RubyGems19 Dec 2023
  • M
Information Exposure
activeadmin<2.12.0RubyGems17 Dec 2023
  • M
Insufficient Entropy
pubnub<5.3.0RubyGems5 Dec 2023
  • M
Cross-site Scripting (XSS)
carrierwave<2.2.5>=3.0.0, <3.0.5RubyGems30 Nov 2023
  • M
Uncontrolled Resource Consumption ('Resource Exhaustion')
rmagick<5.3.0RubyGems31 Oct 2023
  • M
Missing Cryptographic Step
openssl>=3.0.0, <3.2.0RubyGems26 Oct 2023
  • M
XML External Entity (XXE) Injection
svg_optimizer>=0.2.6, <0.3.0RubyGems22 Oct 2023
  • M
Improper Privilege Management
bolt<3.27.4RubyGems16 Oct 2023