RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2014-0083Mediumnet-ldap: net-ldap has weak salt when generating passwordsCVE-2021-25971Mediumcamaleon_cms: Camaleon CMS vulnerable to Uncaught ExceptionCVE-2021-25972Mediumcamaleon_cms: Camaleon CMS vulnerable to Server-Side Request ForgeryCVE-2021-39880Mediumapollo_upload_server: apollo_upload_server has Denial of Service vulnerabilityCVE-2021-30560Highnokogiri: Nokogiri has vulnerable dependencies on libxml2 and libxsltCVE-2021-35440Mediumsmashing: Smashing Cross-site Scripting vulnerabilityCVE-2021-3517Highnokogiri: Nokogiri contains libxml Out-of-bounds Write vulnerabilityCVE-2021-3518Highnokogiri: Nokogiri Implements libxml2 version vulnerable to use-after-freeCVE-2021-3537Mediumnokogiri: Nokogiri Implements libxml2 version vulnerable to null pointer dereferencingCVE-2020-7385Highmetasploit-framework: Metasploit Framework user exposes Metasploit to same deserialization issue that is exploited by that moduleCVE-2020-13353Lowgitaly: Gitaly Insufficient Session Expiration vulnerabilityCVE-2020-25613Highwebrick: WEBRick vulnerable to HTTP Request/Response SmugglingCVE-2019-17268Criticalomniauth-weibo-oauth2: omniauth-weibo-oauth2 included a code-execution backdoor inserted by a third partyCVE-2015-2784Criticalpapercrop: papercrop does not properly handle crop inputCVE-2019-5815Highnokogiri: Nokogiri implementation of libxslt vulnerable to heap corruptionCVE-2019-14825Lowkatello: Katello cleartext password storage issueCVE-2019-12408Highred-arrow: Missing Initialization of Resource in Apache ArrowCVE-2019-12410Highred-arrow: Missing Initialization of Resource in Apache ArrowCVE-2019-18197Highnokogiri: Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerabilityCVE-2019-16751Mediumdevise_token_auth: Devise Token Auth vulnerable to Cross-site ScriptingCVE-2019-7615Highelastic-apm: Elastic APM agent for Ruby vulnerable to Improper Certificate ValidationCVE-2019-13118Highnokogiri: libxslt Type Confusion vulnerability that affects NokogiriCVE-2019-13117Mediumnokogiri: Uninitialized read in Nokogiri gemCVE-2022-1810Mediumpublify_core: Publify has Improper Access ControlsCVE-2022-1811Criticalpublify_core: Publify vulnerable to cross site scripting

Stop the waste.
Protect your environment with Kodem.