RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-35231Highrack-contrib: rack-contrib vulnerable to Denial of Service due to the unconstrained value of the incoming "profiler_runs" parameterCVE-2024-32978Mediumkaminari: Kaminari Insecure File Permissions VulnerabilityCVE-2024-35176Mediumrexml: REXML contains a denial of service vulnerabilityGHSA-R95H-9X8F-R3F7Lownokogiri: Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459CVE-2024-34341Mediumtrix: Trix Editor Arbitrary Code Execution VulnerabilityCVE-2024-32970Highphlex: Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and valuesCVE-2024-32887Mediumsidekiq: Sidekiq vulnerable to a Reflected XSS in Queues Web PageCVE-2024-32463Highphlex: Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tagsCVE-2024-29034Mediumcarrierwave: CarrierWave content-Type allowlist bypass vulnerability which possibly leads to XSS remainedCVE-2024-27281Lowrdoc: RDoc RCE vulnerability with .rdoc_optionsCVE-2024-27280Criticalstringio: StringIO buffer overread vulnerabilityCVE-2024-28862Mediumrotp: ROTP 6.2.2 and 6.2.1 has 0666 permissions for the .rb files.CVE-2024-28181Highturbo_boost-commands: TurboBoost Commands vulnerable to arbitrary method invocationCVE-2023-28102Criticaldiscordrb: discordrb OS Command Injection vulnerabilityCVE-2024-28121Highstimulus_reflex: StimulusReflex arbitrary method callCVE-2024-28199Highphlex: Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in PhlexCVE-2023-46950Mediumsidekiq-unique-jobs: Cross Site Scripting vulnerability in Contribsys Sidekiq CVE-2023-51774Mediumjson-jwt: json-jwt allows bypass of identity checks via a sign/encryption confusion attackCVE-2024-25126Mediumrack: Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)CVE-2024-26141Lowrack: Rack has possible DoS Vulnerability with Range HeaderCVE-2024-26146Lowrack: Rack Header Parsing leads to Possible Denial of Service VulnerabilityCVE-2024-27285Mediumyard: YARD's default template vulnerable to Cross-site Scripting in generated frames.htmlCVE-2024-26144Mediumactivestorage: Rails has possible Sensitive Session Information Leak in Active StorageCVE-2024-26143Mediumactionpack: Rails has possible XSS Vulnerability in Action ControllerCVE-2024-26142Lowactionpack: Rails has possible ReDoS vulnerability in Accept header parsing in Action Dispatch

Stop the waste.
Protect your environment with Kodem.