Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
327270
AlmaLinux
3841
Alpaquita
4756
Alpine
3767
Android
2824
BellSoft Hardened Containers
179
Bitnami
5716
Chainguard
24941
CRAN
10
crates.io
1737
Debian
47221
GHC
3
GIT
42310
GitHub Actions
31
Go
4433
Hackage
24
Hex
37
Linux
13574
Mageia
5650
Maven
5715
MinimOS
2059
npm
27789
NuGet
1449
openSUSE
10138
OSS-Fuzz
3084
Packagist
4753
Pub
10
PyPI
16026
Red Hat
16576
Rocky Linux
1916
RubyGems
1693
SUSE
16537
SwiftURL
35
Ubuntu
44975
Wolfi
13461
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-rrqh-93c8-j966
RubyGems/ruby-saml
Ruby SAML DOS vulnerability with large SAML response
9 hours ago
Fix available
Severity - 6.9 (Medium)
MAL-2025-6348
RubyGems/resource_registry
Malicious code in resource_registry (RubyGems)
17 hours ago
No fix available
MAL-2025-6265
RubyGems/message_gateway
Malicious code in message_gateway (RubyGems)
3 days ago
No fix available
GHSA-353f-x4gh-cqq8
RubyGems/nokogiri
Nokogiri patches vendored libxml2 to resolve multiple CVEs
21 Jul
Fix available
GHSA-mqcp-p2hv-vw6x
RubyGems/thor
Thor can construct an unsafe shell command from library input.
20 Jul
Fix available
Severity - 2.8 (Low)
GHSA-29g5-m8v7-v564
RubyGems/measured
Measured is vulnerable to Path Traversal attacks during class initialization
15 Jul
Fix available
Severity - 4.9 (Medium)
GHSA-xh69-987w-hrp8
RubyGems/resolv
resolv vulnerable to DoS via insufficient DNS domain name length validation
15 Jul
Fix available
Severity - 6.6 (Medium)
GHSA-6qjf-g333-pv38
RubyGems/job-iteration
Job Iteration API is vulnerable to OS Command Injection attack through its CsvEnumerator class
14 Jul
Fix available
Severity - 8.1 (High)
GHSA-hqp6-mjw3-f586
RubyGems/vagrant
HashiCorp Vagrant has code injection vulnerability through default synced folders
02 Jul
Fix available
Severity - 5.4 (Medium)
GHSA-r995-q44h-hr64
RubyGems/webrick
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
26 Jun
Fix available
Severity - 6.5 (Medium)
MAL-2025-5147
RubyGems/xxxxxxxx
Malicious code in xxxxxxxx (RubyGems)
18 Jun
No fix available
MAL-2025-5146
RubyGems/teaspoon-devkit
Malicious code in teaspoon-devkit (RubyGems)
18 Jun
No fix available
MAL-2025-5145
RubyGems/jdbc-zzz
Malicious code in jdbc-zzz (RubyGems)
18 Jun
No fix available
GHSA-cf8v-5mrc-jv7f
RubyGems/openc3-cosmos-tool-iframe
OpenC3 COSMOS Vulnerable to Directory Traversal via openc3-api/tables endpoint
13 Jun
No fix available
Severity - 7.5 (High)
GHSA-p67j-387g-75wc
RubyGems/openc3-cosmos-tool-iframe
OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/ endpoint
13 Jun
No fix available
Severity - 9.1 (Critical)
GHSA-47m2-26rw-j2jw
RubyGems/rack
ReDoS Vulnerability in Rack::Multipart handle_mime_head
05 Jun
Fix available
Severity - 6.6 (Medium)
Load more...
RubyGems - OSV