Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
589583
AlmaLinux
4399
Alpaquita
8194
Alpine
3962
Android
2912
BellSoft Hardened Containers
367
Bitnami
6477
Chainguard
4900
CleanStart
15
CRAN
12
crates.io
1973
Debian
52324
Echo
2803
GHC
3
GIT
80135
GitHub Actions
39
Go
5491
Hackage
26
Hex
44
Julia
332
Linux
22697
Mageia
5807
Maven
6148
MinimOS
10571
npm
214592
NuGet
1519
opam
9
openEuler
5902
openSUSE
10321
OSS-Fuzz
3733
Packagist
5648
Pub
10
PyPI
17757
Red Hat
18409
Rocky Linux
2673
Root
17001
RubyGems
1852
SUSE
17130
SwiftURL
46
Ubuntu
50334
VSCode
15
Wolfi
3001
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-q66h-m87m-j2q6
RubyGems/bitcoinrb
Bitcoinrb Vulnerable to Command injection via RPC
3 days ago
Fix available
Severity - 2.0 (Low)
GHSA-33mh-2634-fwr2
RubyGems/faraday
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
3 days ago
Fix available
Severity - 5.8 (Medium)
GHSA-w67g-2h6v-vjgq
RubyGems/phlex
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
6 days ago
Fix available
Severity - 7.1 (High)
GHSA-87fh-rc96-6fr6
RubyGems/spree_api
Unauthenticated Spree Commerce users can access all guest addresses
05 Feb
Fix available
Severity - 7.7 (High)
GHSA-p6pv-q7rc-g4h9
RubyGems/spree_storefront
Unauthenticated Spree Commerce users can view completed guest orders by Order ID
05 Feb
Fix available
Severity - 7.7 (High)
GHSA-3cx6-j9j4-54mp
RubyGems/decidim
RubyGems/decidim-core
Decidim's private data exports can lead to data leaks
03 Feb
Fix available
Severity - 8.2 (High)
GHSA-2qxw-7fmx-gqfm
RubyGems/foreman_kubevirt
foreman_kubevirt disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set
02 Feb
Fix available
Severity - 8.1 (High)
GHSA-m3hq-3qj8-c5fm
RubyGems/fog-kubevirt
fog-kubevirt allows remote attacker to perform MITM attack due to disabled certificate validation
02 Feb
Fix available
Severity - 8.1 (High)
GHSA-2762-657x-v979
RubyGems/alchemy_cms
AlchemyCMS: Authenticated Remote Code Execution (RCE) via eval injection in ResourcesHelper
21 Jan
Fix available
Severity - 6.4 (Medium)
GHSA-mpwp-4h2m-765c
RubyGems/activejob
Active Job - Object injection security vulnerability
16 Jan
Fix available
Severity - 6.6 (Medium)
GHSA-5qw5-wf2q-f538
RubyGems/activerecord-jdbc-adapter
ActiveRecord-JDBC-Adapter (AR-JDBC) lib/arjdbc/jdbc/adapter.rb sql.gsub() Function SQL Injection
16 Jan
Fix available
Severity - 8.8 (High)
GHSA-w757-4qv9-mghp
RubyGems/openc3
openc3-api Vulnerable to Unauthenticated Remote Code Execution
13 Jan
Fix available
Severity - 10.0 (Critical)
GHSA-3ghg-3787-w2xr
RubyGems/spree_core
Spree API has Unauthenticated IDOR - Guest Address
08 Jan
Fix available
Severity - 7.5 (High)
GHSA-g268-72p7-9j6j
RubyGems/spree_api
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification
08 Jan
Fix available
Severity - 6.5 (Medium)
GHSA-g9jg-w8vm-g96v
RubyGems/action_text-trix
npm/trix
Trix has a stored XSS vulnerability through its attachment attribute
31 Dec 2025
Fix available
Severity - 4.6 (Medium)
GHSA-j4pr-3wm6-xx2r
RubyGems/uri
URI Credential Leakage Bypass over CVE-2025-27221
30 Dec 2025
Fix available
Severity - 2.7 (Low)
Load more...
RubyGems - OSV