Dec 10 CVE-2024-54133 (actionpack): Possible Content Security Policy bypass in Action Dispatch posted in •
Dec 02 CVE-2024-53989 (rails-html-sanitizer): rails-html-sanitizer has XSS vulnerability with certain configurations posted in •
Dec 02 CVE-2024-53988 (rails-html-sanitizer): rails-html-sanitizer has XSS vulnerability with certain configurations posted in •
Dec 02 CVE-2024-53987 (rails-html-sanitizer): rails-html-sanitizer has XSS vulnerability with certain configurations posted in •
Dec 02 CVE-2024-53986 (rails-html-sanitizer): rails-html-sanitizer has XSS vulnerability with certain configurations posted in •
Dec 02 CVE-2024-53985 (rails-html-sanitizer): rails-html-sanitizer has XSS vulnerability with certain configurations posted in •
Nov 20 CVE-2024-52796 (pwpush): Password Pusher rate limiter can be bypassed by forging proxy headers posted in •
Nov 13 CVE-2024-45594 (decidim-meetings): decidim-meetings Cross-site scripting vulnerability in the online or hybrid meeting embeds posted in •
Nov 12 CVE-2024-43415 (decidim-decidim_awesome): Decidim-Awesome has SQL injection in AdminAccountability posted in •
Nov 01 CVE-2024-21510 (sinatra): Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision posted in •