RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2017-15364Mediumccsv: ccsv Double Free vulnerabilityCVE-2013-4363Mediumrubygems-update: RubyGems Regular Expression Denial of ServiceCVE-2015-4020Mediumrubygems-update: RubyGems Improper Input Validation vulnerabilityCVE-2022-1553Mediumpublify_core: Publify exposes article metadataCVE-2022-0578Mediumpublify_core: Publify vulnerable to code injectionCVE-2022-0574Mediumpublify_core: Publify Incorrect AuthorizationCVE-2014-4991Highcodders-dataset: codders-dataset Process Table Local Plaintext Credential DisclosureCVE-2014-4995HighVladTheEnterprising: VladTheEnterprising allows local users to obtain sensitive information by reading MySQL root password from temporary fileCVE-2014-4996MediumVladTheEnterprising: VladTheEnterprising allows local users to write to arbitrary files via a symlink attackCVE-2014-4993Highbackup-agoddard: backup-agoddard and backup_checksum have Information Exposure vulnerabilityCVE-2014-4999Highkajam: kajam allows local users to obtain sensitive information by listing the processCVE-2014-4997Highpoint-cli: point-cli allows local users to obtain sensitive information by listing the processCVE-2014-4998Highlean-ruport: lean-ruport allows local users to obtain sensitive information by listing the processCVE-2014-1835Highechor: Echor Ruby Gem credentials can be stolen via process table monitoringCVE-2014-1834Highechor: Echor contains Command InjectionCVE-2012-5604Mediumldap_fluff: ldap_fluff authentication bypassCVE-2014-0013Mediumember-source: Ember.js Cross-site Scripting vulnerabilityCVE-2018-0499Mediumxapian-core: xapian-core Cross-site Scripting vulnerabilityCVE-2015-1585Mediumfat_free_crm: Fat Free CRM Cross-Site Request Forgery vulnerabilityCVE-2010-3978Mediumspree: Spree allows remote attackers to obtain sensitive informationCVE-2014-0014Mediumember-source: ember-source Cross-site Scripting vulnerabilityCVE-2017-15412Highnokogiri: Nokogiri gem, via libxml, is affected by DoS vulnerabilitiesCVE-2017-10784Highwebrick: WEBrick RCE VulnerabilityCVE-2017-14033Highopenssl: Ruby OpenSSL DoS VulnerabilityCVE-2018-1000079Mediumrubygems-update: RubyGems Path Traversal vulnerability

Stop the waste.
Protect your environment with Kodem.