Open Source Vulnerabilities
validator
Moderate severity vulnerability that affects validator
validator
Moderate severity vulnerability that affects validator
rack-ssl
rack-ssl Cross-site Scripting vulnerability
serve-index
Cross-Site Scripting in serve-index
sfpagent
sfpagent Command Injection vulnerability
ember, ember, ember, ember, ember, ember
Moderate severity vulnerability that affects ember
ember/ ember/ ember/ ember/ ember/ ember
Moderate severity vulnerability that affects ember
actionpack
actionpack Cross-site Scripting vulnerability
mustache
Cross-Site Scripting in mustache
actionpack, actionpack
actionpack allows bypass of database-query restrictions
actionpack/ actionpack
actionpack allows bypass of database-query restrictions
rbovirt
rbovirt uses the rest-client gem with SSL verification disabled
rbovirt
rbovirt uses the rest-client gem with SSL verification disabled
sequelize
SQL Injection in sequelize
activerecord, activerecord, activerecord, activerecord
Active Record Improper Access Control
activerecord/ activerecord/ activerecord/ activerecord
Active Record Improper Access Control
bio-basespace-sdk
Exposure of Sensitive Information in bio-basespace-sdk
bio-basespace-sdk
Exposure of Sensitive Information in bio-basespace-sdk
jquery-rails, jquery-rails, jquery-ujs
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
jquery-rails/ jquery-rails/ jquery-ujs
jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
activesupport, activesupport
activesupport Cross-site Scripting vulnerability
activesupport/ activesupport
activesupport Cross-site Scripting vulnerability
semver
Regular Expression Denial of Service in semver
plotly.js
Cross Site Scripting (XSS) in plotly.js
doorkeeper
Doorkeeper is vulnerable to replay attacks
espeak-ruby
espeak-ruby allows arbitrary command execution
espeak-ruby
espeak-ruby allows arbitrary command execution
activemodel, activemodel
activemodel contains Improper Input Validation
activemodel/ activemodel
activemodel contains Improper Input Validation
safemode
Safemode Gem Has Incomplete List of Disallowed Inputs
safemode
Safemode Gem Has Incomplete List of Disallowed Inputs
openssl
OpenSSL gem for Ruby using inadequate encryption strength
openssl
OpenSSL gem for Ruby using inadequate encryption strength
actionpack, actionpack, actionpack
actionpack allows remote code execution via application's unrestricted use of render method
actionpack/ actionpack/ actionpack
actionpack allows remote code execution via application's unrestricted use of render method
moment
Regular Expression Denial of Service in moment
safemode
safemode gem allows context-dependent attackers to obtain sensitive information via the inspect method
safemode
safemode gem allows context-dependent attackers to obtain sensitive information via the inspect method
festivaltts4r
festivaltts4r allows arbitrary command execution
festivaltts4r
festivaltts4r allows arbitrary command execution
actionpack, actionpack, actionpack
actionpack is vulnerable to denial of service via a crafted HTTP Accept header
actionpack/ actionpack/ actionpack
actionpack is vulnerable to denial of service via a crafted HTTP Accept header
rubyzip
Directory traversal vulnerability in RubyZip
electron
High severity vulnerability that affects electron
electron
High severity vulnerability that affects electron
archive-tar-minitar, minitar
archive-tar-minitar and minitar vulnerable to Path Traversal
archive-tar-minitar/ minitar
archive-tar-minitar and minitar vulnerable to Path Traversal
jquery-ui, jquery-ui-rails, org.webjars.npm:jquery-ui, jQuery.UI.Combined
jQuery-UI vulnerable to Cross-site Scripting in dialog closeText
jquery-ui/ jquery-ui-rails/ org.webjars.npm:jquery-ui/ jQuery.UI.Combined
jQuery-UI vulnerable to Cross-site Scripting in dialog closeText
rack-mini-profiler
rack-mini-profiler allows remote attackers to obtain sensitive information about allocated strings and objects
rack-mini-profiler
rack-mini-profiler allows remote attackers to obtain sensitive information about allocated strings and objects
actionview, actionview, actionview
actionview Cross-site Scripting vulnerability
actionview/ actionview/ actionview
actionview Cross-site Scripting vulnerability
activerecord
ActiveRecord in Ruby on Rails allows database-query bypass
activerecord
ActiveRecord in Ruby on Rails allows database-query bypass
actionview, actionview, actionpack, actionpack
actionview contains Path Traversal vulnerability
actionview/ actionview/ actionpack/ actionpack
actionview contains Path Traversal vulnerability
is-my-json-valid
Regular Expression Denial of Service in is-my-json-valid
is-my-json-valid
Regular Expression Denial of Service in is-my-json-valid
actionview, actionview, actionpack, actionpack, actionpack
Directory traversal vulnerability in Action View in Ruby on Rails
actionview/ actionview/ actionpack/ actionpack/ actionpack
Directory traversal vulnerability in Action View in Ruby on Rails
