RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-35956Mediumupdate_by_case: update_by_case before 0.1.3 can be vulnerable to sql injectionCVE-2016-3098Mediumadministrate: administrate vulnerable to Cross-Site Request ForgeryCVE-2022-31163Hightzinfo: TZInfo relative path traversal vulnerability allows loading of arbitrary filesCVE-2022-31160Mediumjquery-ui: jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text labelCVE-2020-35305Mediumgollum: Gollum Cross-site Scripting vulnerability via filename parameter to New Page dialogCVE-2022-32224Criticalactiverecord: Active Record RCE bug with Serialized ColumnsCVE-2022-31115Highopensearch-ruby: opensearch-ruby 2.x before 2.0.2 vulnerable to unsafe YAML deserializationCVE-2013-4170Mediumember-source: Ember.js Potential XSS Exploit When Binding `tagName` to User-Supplied DataCVE-2014-0156Criticalawesome_spawn: OS Command Injection in awesome spawnCVE-2021-3779Mediumruby-mysql: Externally Controlled Reference to a Resource in Another Sphere in ruby-mysqlCVE-2022-32209Mediumrails-html-sanitizer: Rails::Html::Sanitizer vulnerable to Cross-site ScriptingCVE-2022-33127Criticaldiffy: Improper handling of double quotes in file name in Diffy in Windows environmentCVE-2022-31072Lowoctokit: Octokit gem published with world-writable filesCVE-2022-31071Lowoctopoller: Octopoller gem published with world-writable filesCVE-2022-31033Mediummechanize: Mechanize before v2.8.5 vulnerable to authorization header leak on port redirectCVE-2022-32511Criticaljmespath: JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferableCVE-2022-31026Mediumtrilogy: Use of Uninitialized Variable in trilogyCVE-2021-33473Criticaldragonfly: Arbitrary file write in dragonflyCVE-2022-31000Lowsolidus_backend: CSRF allows attacker to finalize/unfinalize order adjustments in solidus_backendCVE-2022-30122Highrack: Denial of Service Vulnerability in Rack Multipart ParsingCVE-2022-30123Criticalrack: Possible shell escape sequence injection vulnerability in RackCVE-2021-25969Mediumcamaleon_cms: Camaleon CMS Stored Cross-site Scripting vulnerabilityCVE-2021-25974Mediumpublify_core: Cross site scripting in publifyCVE-2021-25970Highcamaleon_cms: Camaleon CMS Insufficient Session Expiration vulnerabilityCVE-2021-25975Mediumpublify_core: Cross site scripting in publify

Stop the waste.
Protect your environment with Kodem.