RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2019-25088Mediumoxidized-web: Oxidized Web vulnerable to Cross-site ScriptingCVE-2020-36624Mediumtext_helpers: text_helpers uses web link to untrusted target with window.opener accessCVE-2021-4250Highactive_attr: active_attr Improper Resource Shutdown or Release vulnerabilityCVE-2022-23520Mediumrails-html-sanitizer: Possible XSS vulnerability with certain configurations of rails-html-sanitizerCVE-2022-23519Mediumrails-html-sanitizer: Possible XSS vulnerability with certain configurations of rails-html-sanitizerCVE-2022-23518Mediumrails-html-sanitizer: Improper neutralization of data URIs may allow XSS in rails-html-sanitizerCVE-2022-23517Highrails-html-sanitizer: Inefficient Regular Expression Complexity in rails-html-sanitizerCVE-2022-23516Highloofah: Uncontrolled Recursion in LoofahCVE-2022-23515Mediumloofah: Improper neutralization of data URIs may allow XSS in LoofahCVE-2022-23514Highloofah: Inefficient Regular Expression Complexity in LoofahCVE-2022-23476Highnokogiri: Unchecked return value from xmlTextReaderExpandCVE-2022-45442Highsinatra: Sinatra vulnerable to Reflected File Download attackCVE-2022-4064Lowdalli: Unsanitized input leading to code injection in DalliCVE-2021-33621Highcgi: HTTP response splitting in CGICVE-2022-39379Lowfluentd: fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)GHSA-2QC6-MCVW-92CWMediumnokogiri: Update bundled libxml2 to v2.10.3 to resolve multiple CVEsCVE-2022-39281Mediumfat_free_crm: Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpointCVE-2022-3171Mediumcom.google.protobuf:protobuf-java: protobuf-java has a potential Denial of Service issueGHSA-MGVV-5MXP-XQ67Lowsqlite3: SQLite3 addresses vulnerability in packaged version of libsqliteGHSA-4QW4-JPP4-8GVPMediumcommonmarker: Unbounded resource exhaustion in cmark-gfm autolink extension may lead to denial of serviceCVE-2022-39224Higharr-pm: arr-pm vulnerable to arbitrary shell execution when extracting or listing files contained in a malicious rpm.GHSA-QCQV-38JG-2R43Highpageflow: Pageflow vulnerable to insecure direct object reference in membership update endpointGHSA-WRRW-CRP8-979QHighpageflow: Pageflow vulnerable to sensitive user data extraction via Ransack query injectionCVE-2022-25765Criticalpdfkit: PDFKit vulnerable to Command InjectionCVE-2020-36599Criticalomniauth: OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value

Stop the waste.
Protect your environment with Kodem.