Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
589830
AlmaLinux
4554
Alpaquita
8614
Alpine
4017
Android
2912
BellSoft Hardened Containers
399
Bitnami
6775
Chainguard
5322
CleanStart
428
CRAN
14
crates.io
2156
Debian
44910
Echo
3069
GHC
3
GIT
81202
GitHub Actions
48
Go
6301
Hackage
29
Hex
53
Julia
342
Linux
15389
Mageia
5843
Maven
6248
MinimOS
17325
npm
216496
NuGet
1619
opam
11
openEuler
6227
openSUSE
12276
OSS-Fuzz
3799
Packagist
5902
Pub
10
PyPI
18307
Red Hat
18961
Rocky Linux
2824
Root
11166
RubyGems
1905
SUSE
19975
SwiftURL
48
Ubuntu
50982
VSCode
18
Wolfi
3351
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-53p3-c7vp-4mcc
RubyGems/action_text-trix
npm/trix
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
2 days ago
Fix available
Severity - 2.1 (Low)
GHSA-c4r5-fxqw-vh93
RubyGems/ruby-lsp
Ruby LSP has arbitrary code execution through branch setting
3 days ago
Fix available
Severity - 7.1 (High)
GHSA-qvqr-5cv7-wh35
RubyGems/mcp
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
3 days ago
Fix available
Severity - 8.2 (High)
MAL-2026-2265
RubyGems/monolith-twirp-codingagentintegrations-codingagentintegrations
Malicious code in monolith-twirp-codingagentintegrations-codingagentintegrations (RubyGems)
4 days ago
No fix available
MAL-2026-2266
RubyGems/monolith-twirp-copilot-registry
Malicious code in monolith-twirp-copilot-registry (RubyGems)
4 days ago
No fix available
MAL-2026-2267
RubyGems/monolith-twirp-partitioning-pull_requests
Malicious code in monolith-twirp-partitioning-pull_requests (RubyGems)
4 days ago
No fix available
MAL-2026-2263
RubyGems/monolith-twirp-reposinsights-reposinsights
Malicious code in monolith-twirp-reposinsights-reposinsights (RubyGems)
4 days ago
No fix available
MAL-2026-2262
RubyGems/monolith-twirp-pullsd-teams
Malicious code in monolith-twirp-pullsd-teams (RubyGems)
4 days ago
No fix available
MAL-2026-2259
RubyGems/monolith-twirp-loops-core
Malicious code in monolith-twirp-loops-core (RubyGems)
4 days ago
No fix available
MAL-2026-2261
RubyGems/monolith-twirp-pullsd-repositories
Malicious code in monolith-twirp-pullsd-repositories (RubyGems)
4 days ago
No fix available
MAL-2026-2260
RubyGems/monolith-twirp-pullsd-pullrequestinfo
Malicious code in monolith-twirp-pullsd-pullrequestinfo (RubyGems)
4 days ago
No fix available
MAL-2026-2264
RubyGems/monolith-twirp-scribe-scribe
Malicious code in monolith-twirp-scribe-scribe (RubyGems)
4 days ago
No fix available
GHSA-2j22-pr5w-6gq8
RubyGems/loofah
Loofah has improper detection of disallowed URIs via
`
allowed_uri?
`
4 days ago
Fix available
Severity - 2.3 (Low)
GHSA-p9fm-f462-ggrg
RubyGems/activestorage
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
5 days ago
Fix available
Severity - 2.3 (Low)
GHSA-pv9c-9mfh-hvxq
RubyGems/icalendar
iCalendar has ICS injection via unsanitized URI property values
6 days ago
Fix available
Severity - 4.3 (Medium)
GHSA-73f9-jhhh-hr5m
RubyGems/activestorage
Rails Active Storage has possible glob injection in its DiskService
23 Mar
Fix available
Severity - 6.6 (Medium)
Load more...
RubyGems - OSV