RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2015-2179Mediumxaviershay-dm-rails: xaviershay-dm-rails Gem for Ruby exposes sensitive information via the process tableGHSA-636F-XM5J-PJ9MMediumcommonmarker: Several quadratic complexity bugs may lead to denial of service in CommonmarkerGHSA-Q95H-CQRV-8JV5Highexiftool_vendored: ExifTool vulnerable to arbitrary code executionCVE-2009-4123Highjruby-openssl: jruby-openssl gem for JRuby fails to do proper certificate validationCVE-2022-44571Lowrack: Denial of Service Vulnerability in Rack Content-Disposition parsingCVE-2023-22792Lowactionpack: ReDoS based DoS vulnerability in Action DispatchCVE-2023-22796Lowactivesupport: ReDoS based DoS vulnerability in Active Support's underscoreCVE-2023-22797Mediumactionpack: Open Redirect Vulnerability in Action PackCVE-2022-44566Highactiverecord: Denial of Service Vulnerability in ActiveRecord's PostgreSQL adapterCVE-2023-22795Lowactionpack: ReDoS based DoS vulnerability in Action DispatchCVE-2023-22794Highactiverecord: SQL Injection Vulnerability via ActiveRecord commentsCVE-2022-44570Highrack: Denial of service via header parsing in RackCVE-2022-44572Lowrack: Denial of service via multipart parsing in RackCVE-2023-22799Lowglobalid: ReDoS based DoS vulnerability in GlobalIDCVE-2022-4891Mediumsisimai: Sisimai Inefficient Regular Expression Complexity vulnerabilityCVE-2022-47318Highgit: Code injection in ruby gitCVE-2015-10053Criticalcurupira: curupira is vulnerable to SQL injectionCVE-2022-1812Criticalpublify_core: Integer overflow in publify_coreCVE-2022-2815Mediumpublify_core: Publify Core does not strip metadata from imagesCVE-2023-0299Criticalpublify_core: Publify Improper Input Validation vulnerabilityCVE-2022-46648Highgit: ruby-git has potential remote code execution vulnerabilityCVE-2020-36644Mediuminline_svg: Inline SVG vulnerable to Cross-site ScriptingCVE-2023-22626Highpghero: PgHero Allows Information Disclosure Through EXPLAIN FeatureCVE-2024-22049Mediumhttparty: httparty has multipart/form-data request tampering vulnerabilityCVE-2017-20159Mediumkeynote: keynote Cross-site Scripting vulnerability

Stop the waste.
Protect your environment with Kodem.