RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-7X4W-CJ9R-H4V9Highcamaleon_cms: Camaleon CMS vulnerable to remote code execution through code injection (GHSL-2024-185)GHSA-R9CR-QMFW-PMRCMediumcamaleon_cms: Camaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)CVE-2024-46987Highcamaleon_cms: Camaleon CMS vulnerable to arbitrary path traversal (GHSL-2024-183)CVE-2024-46986Highcamaleon_cms: Camaleon CMS affected by arbitrary file write to RCE (GHSL-2024-182)CVE-2024-8796Mediumdevise-two-factor: Devise-Two-Factor Authentication Uses Insufficient Default OTP Shared Secret LengthCVE-2024-39910Mediumdecidim: Decidim::Admin vulnerable to cross-site scripting (XSS) in the admin panel with QuillJS WYSWYG editorCVE-2024-32034Mediumdecidim-admin: Decidim::Admin vulnerable to cross-site scripting (XSS) in the admin activity logGHSA-CVP8-5R8G-FHVQCriticalomniauth-saml: omniauth-saml vulnerable to Improper Verification of Cryptographic SignatureCVE-2024-45409Criticalruby-saml: SAML authentication bypass via Incorrect XPath selectorCVE-2024-43791Mediumrequest_store: request_store has Incorrect Default PermissionsCVE-2024-43398Highrexml: REXML denial of service vulnerabilityCVE-2024-43380Mediumfugit: fugit parse and parse_nat stall on lengthy inputCVE-2024-42360Criticalsequenceserver: Command Injection in sequenceserverCVE-2024-41946Mediumrexml: REXML DoS vulnerabilityCVE-2024-41123Mediumrexml: REXML DoS vulnerabilityCVE-2024-7106Mediumspina: Cross-Site Request Forgery in SpinaCVE-2024-39908Mediumrexml: REXML denial of service vulnerabilityCVE-2024-27095Mediumdecidim-admin: Decidim cross-site scripting (XSS) in the admin panelCVE-2024-32469Mediumdecidim: Decidim cross-site scripting (XSS) in the paginationCVE-2024-27090Mediumdecidim: Decidim vulnerable to data disclosure through the embed featureCVE-2024-39308Mediumrails_admin: RailsAdmin Cross-site Scripting vulnerability in the list viewCVE-2024-39316Mediumrack: Rack ReDoS Vulnerability in HTTP Accept Headers ParsingCVE-2024-28103Mediumactionpack: Missing security headers in Action Pack on non-HTML responsesCVE-2024-32464Mediumactiontext: ActionText ContentAttachment can Contain Unsanitized HTMLCVE-2024-37031Highactiveadmin: activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends

Stop the waste.
Protect your environment with Kodem.