RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-53988Lowrails-html-sanitizer: rails-html-sanitizer has XSS vulnerability with certain configurationsCVE-2024-53986Lowrails-html-sanitizer: rails-html-sanitizer has XSS vulnerability with certain configurationsCVE-2024-53985Lowrails-html-sanitizer: rails-html-sanitize has XSS vulnerability with certain configurationsCVE-2024-52796Lowpwpush: Password Pusher rate limiter can be bypassed by forging proxy headersCVE-2024-45594Mediumdecidim-meetings: decidim-meetings Cross-site scripting vulnerability in the online or hybrid meeting embedsCVE-2024-43415Highdecidim-decidim_awesome: Decidim-Awesome has SQL injection in AdminAccountabilityCVE-2024-21510Mediumsinatra: Sinatra vulnerable to Reliance on Untrusted Inputs in a Security DecisionCVE-2024-49771Mediumnet.sf.mpxj:mpxj: MPXJ has a Potential Path Traversal VulnerabilityCVE-2024-49761Mediumrexml: REXML ReDoS vulnerabilityCVE-2024-49376HighAutolab: Autolab Misconfigured Reset Password PermissionsCVE-2024-48652Mediumcamaleon_cms: camaleon_cms affected by cross site scriptingCVE-2024-47889Mediumactionmailer: Possible ReDoS vulnerability in block_format in Action MailerCVE-2024-47888Mediumactiontext: Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action TextCVE-2024-47887Mediumactionpack: Possible ReDoS vulnerability in HTTP Token authentication in Action ControllerCVE-2024-41128Mediumactionpack: Possible ReDoS vulnerability in query parameter filtering in Action DispatchCVE-2024-47529Mediumopenc3: OpenC3 stores passwords in clear text (`GHSL-2024-129`)CVE-2024-46977Highopenc3: OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)CVE-2024-43795Mediumopenc3: OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)CVE-2024-41673Highdecidim: Decidim has a cross-site scripting vulnerability in the version control pageGHSA-75J2-9GMC-M855Mediumcamaleon_cms: Camaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)CVE-2024-46488Highsqlite-vec: Heap-based Buffer Overflow in sqlite-vecGHSA-8FX8-3RG2-79XWMediumcamaleon_cms: Camaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)CVE-2024-47220Highwebrick: HTTP Request Smuggling in ruby webrickCVE-2024-45614Mediumpuma: Puma's header normalization allows for client to clobber proxy set headersCVE-2024-7254Highcom.google.protobuf:protobuf-java: protobuf-java has potential Denial of Service issue

Stop the waste.
Protect your environment with Kodem.