GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,748
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
439 advisories
Filter by severity
unpoly-rails Denial of Service vulnerability
Moderate
CVE-2023-28846
was published
for
unpoly-rails
(RubyGems)
Mar 30, 2023
Nokogiri updates packaged libxml2 to v2.10.4 to resolve multiple CVEs
Moderate
GHSA-pxvg-2qj5-37jq
was published
for
nokogiri
(RubyGems)
Apr 11, 2023
Commonmarker vulnerable to to several quadratic complexity bugs that may lead to denial of service
Moderate
GHSA-48wp-p9qv-4j64
was published
for
commonmarker
(RubyGems)
Apr 11, 2023
Cross-site Scripting Vulnerability in Action Pack
Moderate
CVE-2022-22577
was published
for
actionpack
(RubyGems)
Apr 27, 2022
ember-source Cross-site Scripting vulnerability
Moderate
CVE-2014-0014
was published
for
ember-source
(RubyGems)
May 14, 2022
protobuf-java has a potential Denial of Service issue
Moderate
CVE-2022-3171
was published
for
com.google.protobuf:protobuf-java
(RubyGems)
Oct 4, 2022
Fat Free CRM Cross-Site Request Forgery vulnerability
Moderate
CVE-2015-1585
was published
for
fat_free_crm
(RubyGems)
May 14, 2022
Cross-Site Scripting in Kaminari
Moderate
CVE-2020-11082
was published
for
kaminari
(RubyGems)
May 28, 2020
Improper one time password handling in devise-two-factor
Moderate
CVE-2021-43177
was published
for
devise-two-factor
(RubyGems)
Apr 7, 2022
ReDoS vulnerability in parser_apache2
Moderate
CVE-2021-41186
was published
for
fluentd
(RubyGems)
Nov 1, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
Moderate
CVE-2021-39197
was published
for
better_errors
(RubyGems)
Sep 7, 2021
In RubyGem excon, interrupted Persistent Connections May Leak Response Data
Moderate
CVE-2019-16779
was published
for
excon
(RubyGems)
Dec 16, 2019
Rails Multisite secure/signed cookies share secrets between sites in a multi-site application
Moderate
CVE-2021-41263
was published
for
rails_multisite
(RubyGems)
Nov 15, 2021
Silent Configuration Failure in Puppet Agent
Moderate
CVE-2021-27025
was published
for
puppet
(RubyGems)
Dec 2, 2021
Unsafe HTTP Redirect in Puppet Agent and Puppet Server
Moderate
CVE-2021-27023
was published
for
puppet
(RubyGems)
Dec 2, 2021
Publify `guest` role users can self-register even when the admin does not allow it
Moderate
CVE-2021-25973
was published
for
publify_core
(RubyGems)
Nov 3, 2021
A poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack
Moderate
CVE-2019-16770
was published
for
puma
(RubyGems)
Dec 5, 2019
Path traversal when MessageBus::Diagnostics is enabled
Moderate
CVE-2021-43840
was published
for
message_bus
(RubyGems)
Dec 17, 2021
Nokogiri::XML::Schema trusts input by default, exposing risk of XXE vulnerability
Moderate
CVE-2020-26247
was published
for
nokogiri
(RubyGems)
Dec 30, 2020
Uncontrolled resource consumption in nokogiri
Moderate
CVE-2017-18258
was published
for
nokogiri
(RubyGems)
Apr 13, 2018
Use of Uninitialized Variable in trilogy
Moderate
CVE-2022-31026
was published
for
trilogy
(RubyGems)
Jun 6, 2022
CSRF forgery protection bypass in solidus_frontend
Moderate
CVE-2021-43846
was published
for
solidus_frontend
(RubyGems)
Jan 6, 2022
Ability to change order address without triggering address validations in solidus
Moderate
CVE-2020-15109
was published
for
solidus_api
(RubyGems)
Aug 4, 2020
RubyGems Improper Input Validation vulnerability
Moderate
CVE-2015-4020
was published
for
rubygems-update
(RubyGems)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API