RubyGems vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2014-10075Criticalkaro: karo Metacharacter Handling Remote Command ExecutionCVE-2014-10077Highi18n: i18n Vulnerable to Denial of Service AttackCVE-2013-2516Highfileutils: Fileutils Command Injection vulnerabilityCVE-2018-12029Highpassenger: Phusion Passenger Race Condition Allows Privilege EscalationCVE-2018-12026Criticalpassenger: Phusion Passenger SpawningKit Contains Arbitrary Read/Write VulnerabilityCVE-2011-4969Mediumjquery: jQuery vulnerable to Cross-Site Scripting (XSS)CVE-2016-3072Highkatello: Katello SQL Injection vulnerabilitiesCVE-2015-3900Highrubygems-update: RubyGems vulnerable to DNS hijack attackCVE-2013-4287Mediumrubygems-update: RubyGems Regular Expression Denial of Service vulnerabilityCVE-2017-0900Highrubygems-update: RubyGems Improper Input Validation vulnerabilityCVE-2018-16887Mediumkatello: katello Cross-site Scripting vulnerabilityCVE-2018-1000074Highrubygems-update: RubyGems Deserialization of Untrusted Data vulnerabilityCVE-2018-1000076Criticalrubygems-update: RubyGems Improper Verification of Cryptographic Signature vulnerabilityCVE-2018-1000078Mediumrubygems-update: RubyGems Cross-site Scripting vulnerabilityCVE-2018-1000077Mediumrubygems-update: RubyGems Improper Input Validation vulnerabilityCVE-2014-4326Highlogstash: Elasticsearch Logstash allows remote attackers to execute arbitrary commandsCVE-2016-1000221Highlogstash-core: Logstash Logs Sensitive InformationCVE-2016-7954Criticalbundler: Bundler allows attacker to inject arbitrary code via secondary Gem sourceCVE-2011-3871Mediumpuppet: Puppet uses predictable filenames, allowing arbitrary file overwriteCVE-2011-0528Mediumpuppet: Puppet does not properly restrict access to node resourcesCVE-2011-3870Mediumpuppet: Puppet allows local users to modify the permissions of arbitrary filesCVE-2011-3869Mediumpuppet: Puppet arbitrary file overwriteCVE-2015-1426Lowfacter: Puppet Labs Facter allows local users to obtain sensitive Amazon EC2 IAM instance metadataCVE-2012-1987Lowpuppet: Puppet Denial of Service and Arbitrary File WriteCVE-2012-1906Mediumpuppet: Puppet uses predictable filenames, allowing arbitrary file overwrite

Stop the waste.
Protect your environment with Kodem.